- Joined
- Feb 9, 2013
So I know this was discussed before, but it's a bitch to search for when I want to bring it up to someone, so just for posterity:
Since npm doesn't have package signing, the npm central repository is entirely at the mercy of the sjw speds who work at npm. Including Isaac Schlueter.
This means that, if npm user Alice publishes a package to npm, and npm user Bob uses it in his project, that Isaac has the capability to selectively insert arbitrary code into the version of Alice's package that Bob ends up downloading. If Isaac doesn't like Bob's politics, he can (for example) steal all of Bob's user's data and leak it all.
You can sift through Isaac's twitter to get a taste of his goofy politics.
Isaac has actually been asked, point blank, if he'd maliciously fuck with, say, the Daily Stormer. And he completely ghosts the question.
Posts:
https://www.reddit.com/r/node/comments/73nr01/the_real_important_question_about_npm/ https://archive.fo/gywjc
https://www.reddit.com/r/node/comments/72tndc/is_the_ecosystem_at_risk/dnlixlp/?context=8&depth=9 https://archive.fo/1nXPq
https://www.reddit.com/r/node/comments/72tndc/is_the_ecosystem_at_risk/dnm29p7/?context=8&depth=9 https://archive.fo/MCsoZ
https://www.reddit.com/r/node/comme...ter_npm_has_officially_lost_his_shit/dnqv6iy/ https://archive.fo/9y0Ef
Since npm doesn't have package signing, the npm central repository is entirely at the mercy of the sjw speds who work at npm. Including Isaac Schlueter.
This means that, if npm user Alice publishes a package to npm, and npm user Bob uses it in his project, that Isaac has the capability to selectively insert arbitrary code into the version of Alice's package that Bob ends up downloading. If Isaac doesn't like Bob's politics, he can (for example) steal all of Bob's user's data and leak it all.
You can sift through Isaac's twitter to get a taste of his goofy politics.
Isaac has actually been asked, point blank, if he'd maliciously fuck with, say, the Daily Stormer. And he completely ghosts the question.
Posts:
https://www.reddit.com/r/node/comments/73nr01/the_real_important_question_about_npm/ https://archive.fo/gywjc
https://www.reddit.com/r/node/comments/72tndc/is_the_ecosystem_at_risk/dnlixlp/?context=8&depth=9 https://archive.fo/1nXPq
https://www.reddit.com/r/node/comments/72tndc/is_the_ecosystem_at_risk/dnm29p7/?context=8&depth=9 https://archive.fo/MCsoZ
https://www.reddit.com/r/node/comme...ter_npm_has_officially_lost_his_shit/dnqv6iy/ https://archive.fo/9y0Ef