I can't decide if this is real or an advertisement for the linked article service. I don't see any CVE in the article which seems to be a good indication of the quality of the content.
I'm not saying that this is misinformation, but I'm extremely sceptical about the nature of this article.
Side Note: It was already believed that SSH encryption was broken by state actors since the first NSA leaks. So, people should at least always use it over another encrypted channel anyway.
Btw, Jia Tan is an awesome software dev that you should hire. /s
We're all completely pwned. That's the only way to feel ok for me. My info has been compromised tons of times and no one notified me. I just accept it. I practice good security and I know that some of the companies on the other side don't. I can't change that.
Have you accepted that you're gonna die? If yes, you should adopt this attitude. If not, I'm sorry that you're so afraid of the natural process. Try to be healthy. Try to be secure. Accept that you're gonna die or get pwned or both. It's a lot healthier mindset (IMO).
So, lets all switch to Rust and use cargo.. Oh, fuuu, wait, how about maven, they too? .... It's in the nature of the thing. Assess your dependencies and get your SBOM monitored.
11 Comments
vk6flab@lemmy.radio · 11 pts · 90d
I can't decide if this is real or an advertisement for the linked article service. I don't see any CVE in the article which seems to be a good indication of the quality of the content.
I'm not saying that this is misinformation, but I'm extremely sceptical about the nature of this article.
sraars@isawthat.fyi · 7 pts · 90d
I did see it also here - https://thecybersecguru.com/news/red-hat-npm-packages-compromised-miasma-worm/
some_guy@lemmy.sdf.org · 10 pts · 89d
Oh, cool! Red Hat! The people who run a company charging for support. This makes me feel very safe.
Ever since the ssh thing, but especially in the last few months, I really don't feel safe with anything on the internet.
badmin@lemmy.today · 2 pts · 88d
Dare I ask, what ssh thing?
Side Note: It was already believed that SSH encryption was broken by state actors since the first NSA leaks. So, people should at least always use it over another encrypted channel anyway.
some_guy@lemmy.sdf.org · 1 pts · 85d
YES! This was a huge deal that what a lucky mishap rather than a sign of good security.
https://en.wikipedia.org/wiki/XZ_Utils_backdoor
Btw, Jia Tan is an awesome software dev that you should hire. /s
We're all completely pwned. That's the only way to feel ok for me. My info has been compromised tons of times and no one notified me. I just accept it. I practice good security and I know that some of the companies on the other side don't. I can't change that.
Have you accepted that you're gonna die? If yes, you should adopt this attitude. If not, I'm sorry that you're so afraid of the natural process. Try to be healthy. Try to be secure. Accept that you're gonna die or get pwned or both. It's a lot healthier mindset (IMO).
waitmarks@lemmy.world · 9 pts · 89d
Can we all stop using npm at this point?
KingThrillgore@lemmy.ml · 5 pts · 89d
Sure but npm is a target due to reach. Its happened with Python too.
fschaupp@lemmy.ml · 2 pts · 88d
So, lets all switch to Rust and use cargo.. Oh, fuuu, wait, how about maven, they too? .... It's in the nature of the thing. Assess your dependencies and get your SBOM monitored.
thingsiplay@lemmy.ml · 5 pts · 90d
It's a compromise between Red Hat and the Hacker.
Kristof12@lemmy.ml · 3 pts · 89d
Not so much of a problem then
MousePotatoDoesStuff@piefed.social · 5 pts · 89d
"would you still love me if I was a credential thief?"