Hacker News new | ask | show | jobs
by woodruffw 16 days ago
> But if everyone will be delaying updates, won't be there less chances to catch it in time?

No: the security assumption behind cooldowns rests on security scanning parties, not on innocent users being victimized. Three days is a short cooldown, but it should be a good enough lead for scanning parties.

> I'm not fully sure if it's possible to preventively scan all NPM packages or how much compute it would require.

It’s not that much data, particularly for parties that are directly financially incentivized to be the first to report malware.

1 comments

Do you have an example of those things you're alleging?

All package malware related news I see are related to users being affected by it (then security firms do their analysis whatever) ...

If you google “supply chain security company” you will find various companies of various reputations vying for attention in this space.
Didn't find any. Found a lot scammers, though.

Just post one link of a "supply chain" problem that was prevented by any of these companies before it went into the wild and affected users.

Simple.

I generally try not to name the companies directly, because I don’t want to give them free advertising. But you can look up e.g. the recent Shai Hulud campaign.

> Just post one link of a "supply chain" problem that was prevented by any of these companies before it went into the wild and affected users.

This is not the claim being made, since cooldowns are not widely adopted at the moment.

I see. So, it has never happened before.
Well, yeah. There’s no package police that’ll stop you from installing malware. The argument has never revolved around that; the argument is solely that cooldowns are effective if you use them, and timely detection by third parties is strong evidence of that.
Analysis and detection are not the same.