ChanServ changed the topic of #picolisp to: PicoLisp language | Channel Log: https://irclog.whitequark.org/picolisp/ | Check also http://www.picolisp.com for more information
Viaken[m] has quit [Remote host closed the connection]
Viaken[m] has joined #picolisp
_whitelogger has joined #picolisp
xkapastel has quit [Quit: Connection closed for inactivity]
orivej has joined #picolisp
alexshendi has quit [Ping timeout: 252 seconds]
KingRiver has joined #picolisp
KingRiver has quit [Remote host closed the connection]
xkapastel has joined #picolisp
orivej has quit [Ping timeout: 250 seconds]
beneroth has joined #picolisp
michelp_ has joined #picolisp
<beneroth> hi all
michelp has quit [*.net *.split]
michelp_ is now known as michelp
<Regenaxer> Hi beneroth, welcome back!
<beneroth> Hey Regenaxer, thank you :)
<Regenaxer> :)
<Nistur> mornin' all
<Regenaxer> Hi Nistur
<beneroth> morning Nistu'
<Nistur> o/
ubLIX has joined #picolisp
orivej has joined #picolisp
ubLIX has quit [Quit: ubLIX]
ubLIX has joined #picolisp
lodsw has quit [Ping timeout: 268 seconds]
lodsw has joined #picolisp
jibanes has quit [Ping timeout: 246 seconds]
jibanes has joined #picolisp
ubLIX has quit [Quit: ubLIX]
ubLIX has joined #picolisp
orivej has quit [Ping timeout: 272 seconds]
alexshendi has joined #picolisp
alexshendi has quit [Ping timeout: 246 seconds]
alexshendi has joined #picolisp
orivej has joined #picolisp
orivej has quit [Ping timeout: 250 seconds]
xkapastel has quit [Quit: Connection closed for inactivity]
aw- has joined #picolisp
<aw-> rick42: hey, i was on vacation, sorry ;)
xkapastel has joined #picolisp
<beneroth> hey aw-
<aw-> hey bene
<beneroth> "he emailed me and said he wanted to maintain the module, so I gave it to him. I don't get any thing from maintaining this module, and I don't even use it anymore, and havn't for years."
<beneroth> maintainer gives ownership to new guy, new guy injects malware :)
<Regenaxer> Oh, aw-! WB
<beneroth> hey Regenaxer :)
<aw-> hi
<aw-> thanks
<beneroth> "part in the original report where it stated that the malicious code was only present in the minified version of the package? Seems there is an underlying issue of npm not enforcing deterministic minification or something along those lines here."
<beneroth> so... despite the social-political dimension of problems like this... I would blame NPM for that :)
<aw-> wow
<beneroth> maybe interesting for tankf33der too, the injected malware is apparently modifying the behaviour when used in combination with crypto code
<xkapastel> woww
<xkapastel> another attack like this?
<xkapastel> is npm even safe to use
<xkapastel> i guess it really isn't. they need to rethink the model
<beneroth> npm is not safe to use!
<beneroth> that was obvious years ago.
<beneroth> NPM itself (the company, the repo) had 2 (or was it 3?) incidents which allowed undetected placing of malware (without having to social-engineer the original owner to hand over ownership/maintainer-rights)
<beneroth> they promised to fix their process and add controls after each case, which they obviously didn't do
<beneroth> this case is a bit more special, as the maintainer/owner-rights got handed to a bad actor - but still, that the guy managed to put the malware only in the minified version of the code (while the non-minified-code looks good) I would see as failure of NPM.
<beneroth> obviously the minified version is usually used in production code, and the non-minified version for development and debugging.
<beneroth> just about 2 million downloads a week and 1'584 package depending on this package
<beneroth> hahaha
<aw-> haven't checked news in a few weeks... why is Bitcoin so low now?
<beneroth> "the package attempts to steal Bitcoin from an installed Bitcoin wallet"
<beneroth> aw-, no idea
<Regenaxer> It is only relevant for the two bitcoin-cash forks
aw- has quit [Quit: Leaving.]
aw- has joined #picolisp
<Regenaxer> And not steal, but double-spend
<Regenaxer> the two forks are in conflict, a kind of war
<beneroth> Regenaxer, I was talking about the malware in the NPM repo.
<Regenaxer> ah, ok
<beneroth> it's (yet?) unrelated to current bitcoin value, I believe
<aw-> so, nobody knows why the currency fluctuates that way?
<Regenaxer> aw talked about attempts to steal Bitcoin
<Regenaxer> general loss of trust because of that
<aw-> oh ok
<beneroth> maybe course correction, in recent times (weeks, months, dunno) multiple bitcoin course manipulations came to light afaik
<beneroth> I don't have any sources for that at hand right now
<Regenaxer> I'm not sure too