5 comments

  • ThreatSystems1 hour ago
    I run training courses on developer security to broaden their understanding of threat surface from their behaviour, day-to-day tooling, the repositories they work on and broader supply chain. One of the modules covers this exact scenario, it&#x27;s amazing how many people do these exercises on corporate machines let alone their personal device!<p>There are mitigations you can put in place by using containers, virtual machines or even the execution environment e.g. Deno&#x27;s ability to block&#x2F;whitelist network calls[0], Bun&#x27;s --ignore-scripts [1] and supply chain package managers have made some strides here like pnpm [2]. But it&#x27;s knowing your threat surface and how to use your tooling which can be quite overbearing on cognitive load, especially in fast paced scenarios like &quot;job of a lifetime offer!&quot; from linked in.<p>Easiest way by default is to use ephemeral VMs &#x2F; Sandbox Containers for such tasks which don&#x27;t have mounted directories to your system etc. Or spin up a cheap EC2 &#x2F; VPS to work on them in a short period of time.<p>[0] - <a href="https:&#x2F;&#x2F;deno.com&#x2F;blog&#x2F;deno-protects-npm-exploits" rel="nofollow">https:&#x2F;&#x2F;deno.com&#x2F;blog&#x2F;deno-protects-npm-exploits</a> and <a href="https:&#x2F;&#x2F;docs.deno.com&#x2F;runtime&#x2F;fundamentals&#x2F;security&#x2F;" rel="nofollow">https:&#x2F;&#x2F;docs.deno.com&#x2F;runtime&#x2F;fundamentals&#x2F;security&#x2F;</a><p>[1] - <a href="https:&#x2F;&#x2F;bun.com&#x2F;docs&#x2F;pm&#x2F;lifecycle" rel="nofollow">https:&#x2F;&#x2F;bun.com&#x2F;docs&#x2F;pm&#x2F;lifecycle</a><p>[2] - <a href="https:&#x2F;&#x2F;pnpm.io&#x2F;supply-chain-security" rel="nofollow">https:&#x2F;&#x2F;pnpm.io&#x2F;supply-chain-security</a><p>[2] - https:&#x2F;&#x2F;
  • tptacek2 hours ago
    I snagged right away at &quot;the kind of low-level reliability judgment that most teams only notice when something breaks.&quot; Real people don&#x27;t talk like the J. Peterman catalog.
  • bobkb1 hour ago
    This type of attack is going on for few years now. I had 2 in my credit.<p>Some details <a href="https:&#x2F;&#x2F;freebird.in&#x2F;malicious-code-source-code-shared-via-job-offers-business-offers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;freebird.in&#x2F;malicious-code-source-code-shared-via-jo...</a>
  • timfsu2 hours ago
    Wow, this is pretty scary. LLMs have made phishing attempts look so much more legit, and the damage they can do so much greater.
  • nesarkvechnep2 hours ago
    All these mid sentence questions in parentheses look so unprofessional to me.
    • OsrsNeedsf2P39 minutes ago
      I found them refreshing and hacker vibes. I understand that&#x27;s not welcome on HN though
    • ggm2 hours ago
      Blame post modernism.