Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Nicholas Zakas

๐Ÿ‘ค Speaker
455 total appearances

Appearances Over Time

Podcast Appearances

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

When you treat these attacks as a nuisance,

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

you leave the door open for more sophisticated attacks that are going to cause more trouble in the future.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I don't know what those look like.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

I mean, I could imagine another type of situation where we had the crypto stealing package.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

What if that wasn't targeting a crypto website?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

What if that was targeting a major banking website?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

or a major stock exchange website.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

What would happen in that situation?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And would those people who lost money through an NPM package that was compromised

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

would they even understand what was going on?

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Or would it just be like, oh, by virtue of being on the laptop, I just got screwed.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

So I feel like that bigger attack is coming if something major doesn't change.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

I've only had direct contact with one person.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And I don't feel at liberty to discuss what we've talked about.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

But I don't have an idea of how big the team is.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

My only sense is that it's fairly small.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Yeah, I mean, I think last year I opened up an issue on NPM and maybe by the end of the year it got a response, like not even a like, oh, this is a good idea, this is a bad idea, just a like...

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

Oh, hey, that's interesting.

The Changelog: Software Development, Open Source
Securing npm is table stakes (Interview)

And that was a good indicator to me that it was probably not resourced appropriately.