Remix.run Logo
lynndotpy 14 hours ago

For anyone confused, this is (very good imo) fiction about supply-chain incidents. It had me very worried during a brief scan that it was real though, which made me read it more attentively :)

junon an hour ago | parent | next [-]

As the victim of the one from last year, it wasn't particularly fun to read.

The implication that I don't know what I'm looking at, or that I don't know what security is (despite having a clean track record for about 15 years now) was a bit aggravating.

In fact, even months later, the lasting effects have been panicking over anything that is remotely suspicious. The most recent example was just a few days ago. Had just gotten on the plane to go on vacation when someone Liked the original "I've been pwned" post on Bluesky. I misread the notification as being a new message to me saying "You've been pwned" and started to panick. I'd have had no way to address it and it would have ruined the small chance per year I get to have a break.

The attack last year wasn't me misunderstanding security. It was the sum of many, many small things (my history with and perception of npm especially w.r.t. their security posture and poor outreach over the years, being stressed out overall, and being in a rush at that particular moment, and a few other personal things) coming together in a perfect storm that resulted in the attack.

adastra22 12 hours ago | parent | prev | next [-]

I couldn't tell at first, tbh. It had this vibe: https://github.com/bitcoin/bips/blob/master/bip-0042.mediawi...

OhMeadhbh 9 hours ago | parent [-]

Yeah. Me too. It looked like a spoof when I started reading, but as I went on it didn't seem to be increasing in it's implausibility.

adastra22 3 hours ago | parent [-]

Well, the one I linked to is real. BIP-42 made bitcoin's monetary policy fixed, by fixing a bug in the client which would have resulted in the initial subsidy code being reset every ~250 years or so. It's just the official writeup documenting it that is silly.

zahlman 7 hours ago | parent | prev | next [-]

"left-justify" absolutely slayed me :)

dirkc 2 hours ago | parent [-]

I should have known when the first package was left-justify, but I read until karen before I realized it must be fiction

fvv 2 hours ago | parent | prev | next [-]

Just because it's not important to pay attention to CVEs, why not waste the readers' time by creating "fictional" CVEs without a disclaimer in the first line? Just because it's not already difficult to scrape through the information and noise on this internet... especially if it appears on the front page of hackernews

jmusall an hour ago | parent | next [-]

Could one mistake this

> Status: Resolved (accidentally)

> Severity: Critical → Catastrophic → Somehow Fine

for a real CVE report?

dasyatidprime an hour ago | parent | prev [-]

The tag list at the top of the page includes “satire”.

smsm42 8 hours ago | parent | prev | next [-]

Searching for CVE-2024-YIKES also provides a gallery of AI slop blogs that AI-rewrite the content of this post while being absolutely stone cold serious about it.

b473a 7 hours ago | parent [-]

Currently a Google search for vulpine-lz4 gives a very serious AI overview.

trollbridge 5 hours ago | parent [-]

Googling is no longer a reliable way to figure out if something is real or not (since, in this case, it just regurgitates the original article, including a couple slop blogs about it)

philipwhiuk 14 hours ago | parent | prev [-]

'nmp'

INTPenis 13 hours ago | parent | next [-]

Node's Malicious Packages.

krautsauer 9 hours ago | parent | prev [-]

I only noticed at goat farming. But anyway, what would a left-justify package do?

smsm42 8 hours ago | parent | next [-]

Same as left-pad (https://en.wikipedia.org/wiki/Npm_left-pad_incident) but much better?

swiftcoder 2 hours ago | parent | prev | next [-]

> I only noticed at goat farming

Heh. I didn't even blink at that. I know a couple of open-source folks who actually packed up to buy off-grid farms in Portugal

yk 8 hours ago | parent | prev [-]

Pull left-pad as dependency presumably.

yellowapple 6 hours ago | parent [-]

Which then, inexplicably, pulls left-justify as a recursive dependency.