The insider perspective on the event-stream compromise (Interview)
- Forfatter
- Afsnit
- 330
- Udgivet
- 5. dec. 2018
- Forlag
- 0 Anmeldelser
- 0
- Afsnit
- 330 of 1014
- Længde
- 1T 8M
- Sprog
- Engelsk
- Format
- Kategori
- Fakta
Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.
They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.
Other podcasts you might like ...
- M’usa, con l’apostrofo. Le donne di PicassoLetizia Bravi
- FC PopCornFilm Companion
- Do I Like It?The Quint
- The Big StoryThe Quint
- DiskoteksbrandenAntonio de la Cruz
- Dragon gateEdith Söderström
- En amerikansk epidemiPatrick Stanelius
- En värld i brand: Andra världskriget och sanningenAnton Vretander
- FamiljenFrida Anund
- Hagen-fallet: Spårlöst försvunnenAntonio de la Cruz
- M’usa, con l’apostrofo. Le donne di PicassoLetizia Bravi
- FC PopCornFilm Companion
- Do I Like It?The Quint
- The Big StoryThe Quint
- DiskoteksbrandenAntonio de la Cruz
- Dragon gateEdith Söderström
- En amerikansk epidemiPatrick Stanelius
- En värld i brand: Andra världskriget och sanningenAnton Vretander
- FamiljenFrida Anund
- Hagen-fallet: Spårlöst försvunnenAntonio de la Cruz
