Email or username:

Password:

Forgot your password?
Eugen Rochko

"Select versions of the massively popular 'node-ipc' package were caught containing malicious code that would overwrite or delete arbitrary files on a system for users based in Russia and Belarus"

bleepingcomputer.com/news/secu

Do not do this

33 comments
DELETED

@Gargron "We hate your government, not you. So we're going to screw you over just for being in a specific place."

Dag Ågren ↙︎↙︎↙︎

@Gargron I think the real problem here is that it is *possible* to do this in the first place. So many package managers are absolute security nightmares on every level.

Nach ✖️

@Gargron fuck fuck FUCK people really need to knock it off with this poorly thought through performative shit. Ticket removed from github, but it links here now: snippet.host/kvcb

Screenshot of github ticket, titled "American NGO affected by your recklessness", text copied at link
:umu: :umu:
@Nach @Gargron saw the stupidest take on it today, like "We can thank the author for fake and other shit got deleted".

I can't even describe what happens in their mind.
Iutech

@Gargron

You're Russian, right ?
How does the diaspora interacts with the motherland ?
Are you able to give different informations than the official medias or is the effect extremely limited ?

Eugen Rochko

@Iutech I try not to give too many personal details away online. So I’m afraid i can’t give you a satisfying answer.

Iutech

@Gargron

I understand, and thank you for replying anyway.
But I wasn't really asking for personal details, more for a general understanding on an important topic that not many people talk about (that I know of, at least).

Arne Babenhauserheide

@Gargron I would like to invite you to freenetproject.org while it is still accessible from Russia (or is it — via VPN?), but if you were to do that, I would also suggest to create a new unconnected pseudonym, so I’ll likely never know whether you actually joined up …

About Russian people, Conan the Terminator-Dad got it right: ieji.de/@eichkat3r/10797366966

We are all human beings, and attacking Russian people for their government’s actions helps Putin's propaganda of an us vs. them.

@Iutech

@Gargron I would like to invite you to freenetproject.org while it is still accessible from Russia (or is it — via VPN?), but if you were to do that, I would also suggest to create a new unconnected pseudonym, so I’ll likely never know whether you actually joined up …

About Russian people, Conan the Terminator-Dad got it right: ieji.de/@eichkat3r/10797366966

Григорий Клюшников

Modern software development is such a mess. How did we come to networked dependency managers downloading and executing untrusted code with no sandboxing without user consent being the norm? These used to be called RCE vulnerabilities. There need to be technical measures against this stuff. Or better yet: avoid networked dependency managers if you can. Treat every dependency like a liability it is.

ruff

@Gargron Do not do what what exactly, protest against the war?

Григорий Клюшников

ruff, this is pure vandalism, not a protest. Do protest. Don't vandalize stuff. That simple.

ruff

@grishka Oh right, of course. When your family is hot you request authorities to allow protest. got it. and if they reject - you oblige. Of course.

Григорий Клюшников

ruff, you aren't making any sense. Please answer this simple question: how exactly a piece of malware unleashed upon innocent people is an act of protest?

ruff

@grishka @Gargron Innocent people will say - "shit happens" and learn the lesson (not to use npm). If there's a slim chance it can compromise a single nut in a russian war machine it's already a good win.

ruff

@grishka @Gargron And by good win I mean not moral satisfaction of some jerk but potentially saved lives.

Григорий Клюшников

ruff, it's a fun assumption that Russian military uses computers at all.

> "shit happens" and learn the lesson (not to use npm)
This isn't how this works.

івась тарасик

@grishka
russian military uses money that russian government gets from taxes that «simple innocent» russians pay when buying and using computers. also, i'm like 99,99% sure every army today does use computers.

i'm not defending the nmp maintainer here... just pointing out that the rather manipulative game of looking for holes in one's logic you're playing here can be turned both ways.

@ruff @Gargron

ruff

@Gargron @grishka I was waiting when it will come to this - to compare your buttheart from malware with killing people. Good luck with that.

Alexey Skobkin

@ruff @grishka @Gargron

Something is really messed up in your head 🤦‍♂️

I hope that it's only a side-effect of emotions and not your everyday thinking process.

Alexey Skobkin

@ruff @grishka

Let's say your family was shot by some African American. Now you're going to set a bunch of African American houses on fire because some of them MAY be SOMEHOW related to that.

Sounds like a solid plan, yeah?

ruff

@skobkin @grishka let say you are trying to persuade me they you are innocent to doge criminal responsibilities your president. Because presumably you personally don't pull the trigger.
Sounds totally pathetic, indeed.

Григорий Клюшников

ruff, this isn't "my" president. I didn't elect him. I'm as ashamed of him as everyone else but there's nothing I personally can do to help this situation.

Alexey Skobkin

@ruff @grishka
Oh, so now you're trying to use ad hominem to avoid the problem I just pointed out in your discourse?

I mean this would probably work on general public, but looks like we have people who are able to think critically in this thread.

I hope that someday you'll understand that this is the way to fool yourself and not to "defeat" your "opponent".

ruff

@skobkin @grishka Oh so you insist on derailing the topic by injecting false narrative. So my only remaining words to you - русский долбойоб - иди нахуй.

Eugen Rochko

@ruff Protesting the war is fine, but protesting the war in the west is also completely performative. Putin won’t change his plans because somebody in the west went to a rally or a celebrity recorded a touching message.

Turning your software package into malware that targets Russian civilians is pointless cruelty. They have no say over this war either, and it will hit the ones that are against it just as much. It already hit an NGO that documents Russian war crimes.

ruff

@Gargron
> They have no say over this war either...

This war is happening because they have nothing to say.

Eugen Rochko

@ruff Okay, you don't know what you're talking about, got it.

peturbg

@Gargron
General message for WHAT happend IN PEARL HARBL. that united states of america KILL INOCCENT PEOPLES. what happend in IRAN, IRAQ. Other day my mastodon was flooded from developers of mastodon for not working. Very bad.

Go Up