Coffee with Developers

Node and Package Security - Zbyszek Tenerowicz

WeAreDevelopers

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:08:30

On this episode of WeAreDevelopers LIVE we're joined by Zbyszek Tenerowicz, LavaMoat R&D team lead at Consensys, as well as WeAreDevelopers Product Marketing Manager Joshua Shulman, to talk about the latest news from the world of tech, play a round of Fake or News, and talk about Node and Package Security.

----------------------------------------
Welcome to WeAreDevelopers, the #1 developer community in Europe!
This is your one-stop destination for the latest tech insights, tutorials, and career advice to elevate your developer career.

Stay updated Dev Digest, with our weekly newsletter featuring the most recent tech trends, career guidance, and original content crafted by developers, for developers. Subscribe now

Interested in advancing your career? Browse through our job board featuring over 190,000 jobs. Unlock job opportunities with a free developer profile

Don't miss out on the annual highlight of every developer's calendar - the WeAreDevelopers World Congress. Network with 15,000 peers and learn from over 500 speakers.  Secure your spot and save 10% with "wearedevs_yt"

#CareerInTech #Tech #ProgrammingTutorials #DevRel #CodingTools #TechJobs #TechTalks #DeveloperSkill...

SPEAKER_00

Hello and welcome to another We Are Developers Live. It's Wednesday again. I really messed this up. There's supposed to be an intro video right now, and I played the wrong intro video, but anyways, it's not gonna be that much of an issue. It's just gonna be different things telling you that this is We Are Developers Live. So without further ado, I have a guest today, and I also have a different guest today who is the new member of We Are Developers. And as Dan, the normal host, the co-host here, is right now on a plane to San Jose to actually go to this event and plan for that one. We want to talk about a bit current affairs, uh show a few tools, and then we're gonna go deep dive into security of um of npm and package models. So um without further ado, let's first have Josh. Josh is a new colleague of mine, uh, and you just joined the office in Vienna, but you're not from there, right?

SPEAKER_01

I'm originally from San Francisco, so quite close to where we're having our next Congress event. But yeah, I've been based out here in Europe for the past roughly 10 years, give or take. So excited to be part of the We are developers team and uh glad to be chatting with you all.

SPEAKER_00

And what's a PMM do?

SPEAKER_01

So in short, um making sure that the messaging that we put out there is actually reflective of how our external audience perceives us and then tries to match that against what we as a company are trying to do, and really finding the marriage between those kind of systems between them. So we are developers, we have our Congress events, and then we have our platform. And from that perspective, we have two pretty unique target audience groups. We have the partners that we're working with, the larger vendors that you all know, the dockers, AWS, Kubernetes, etc., of the world. And then we have yourselves, the developers who attend the events. Those communications need to be quite different. And it's on me to talk with everyone and figure out hey, what works best? Who how will everyone get the best value from working with us, with communicating with us, and honestly, just sharing content and their thoughts with us?

SPEAKER_00

Cool. And the other guest that we have today is actually by his stage name, much like Josh S. That's your street name as well, right? Uh so uh uh Noctur, which is uh hard to pronounce, but then your real name is uh Sibiszek Tenerowicz? Am I even that's pretty good?

SPEAKER_03

Yes, very good.

SPEAKER_00

Cool, which of course means you're from Poland because uh uh vowels there cost a lot of money, so that's why you don't use any of them. You just basically use the consonants and make one word out of it. So, what what do you do? What's what drives you every day?

SPEAKER_03

So um I'm mostly into JavaScript, JavaScript everything. Um started out very early on. Uh the first five lines of JavaScript that I've written with Crash uh Internet Explorer on Windows 98. That was fun. Um and I kind of stayed. Uh and these days for for the last five, six, maybe ten years, depending on if you count the hobby time I've been uh doing uh open source supply chain security.

SPEAKER_00

Cool. And we talked earlier, but before during the intro and everything, that you were one of the users of Firefox OS and one of the daily drivers, one of the early adopters back then. And uh the idea of an open source uh mobile phone environment was very, very tempting for all of us. I worked on that for two years, and it's kind of sad that there's like I mean, even Microsoft didn't make it to break into the mobile market. There's only uh there's only uh Android and iOS, and that's it. Like everything else, like Sailfish, um what other open alternatives are there?

SPEAKER_03

There are Linux-based uh OSs that are alive. I have a buddy who's been working on one of those uh full time, maybe still is, didn't catch up, but uh yeah, there's there's Librem, Pinephone, these kind of things.

SPEAKER_00

If the OnePlus was also another option. I I loved the first OnePlus that was uh that was like uh uh uh basically building blocks, so you can actually add your phone together rather than just having a fixed phone. You can say, like, I want this, I want a better camera, so you can buy a better camera and put that one in and all these formats. And now everybody's like, Oh, our phone folds six times, and like uh that's the next new feature that nobody I mean. I still see people on planes having foldable phones, and it just feels wrong to me every single time I see them using them. I'm just like, this is this is just breaking it. I mean, every phone is foldable once if you put enough effort in, but like the the uh the whole idea of having the screen. I mean, I cannot see how this actually lasts more than one year or two years. This is just really bizarre.

SPEAKER_01

I can't lie, I'm always drawn to it. You know, growing up, we had the Motorola of flip phones as the cool thing to have, and then you had the sidekicks. Um I mean, I can imagine it's a development nightmare figuring out how to build effective apps first for, for example, the modular devices. Like, okay, how do you make sure that the app can actually function with the different hardware that you're putting in? Things in the middle and next week, uh yeah. I mean, I know from the I was in the video video tech world for a while. I know with adaptive video players, it's not difficult, for example, to play with the aspect ratios. A lot of it is quite responsive at this point, but I can't imagine having to deal with that with the like you know, the what do they call it, the notebook style flip phones at this point. When you have to always consider the aspect ratios with your different app or platform that you're building.

SPEAKER_00

Well, a lot of apps and a lot of stuff becomes streaming these days, especially games like you don't even install them anymore, and you just have like a video stream, and that adapting that to different screens and needs is much easier than actually the interface itself. So uh, I mean, I always find it fun when I've got this like five-year-old fire stick for my phone, Amazon Fire Stick, and it says, like, oh, you can play AAA games on that. And you're like, Yeah, the refresh rate always makes me not reach a button. So I'm quite sure AAA game will be really beautiful on that, on that old TV set from 10 years ago. I'm quite sure that's gonna be a real success. It's like, what the and also this upsell. I mean, I basically I do that to watch telly on it and to watch my Netflix and my Disney. And it's like it shows me like a two new movie. Oh, cool, so let's watch it. No, in the cinemas right now. And I'm like, why do I see that on my telly then? Like, where where is the point of me? Uh it's like I'm not gonna go, like, oh, I'm gonna go to the cinema now. Like, no, I turned, but don't show me that here. Like, it's really bizarre. It was fun during the World Cup, that basically seeing the German television, how they uh showed the games, and then watching it on Magenta TV, which is like the T online one. Um a few of the games there, it's the amount of ads shown in between on Magenta compared to like the normal AID Z thing was just hilarious. Like, and that's why the whole like refresh breaks or or or or drink breaks were just like so short amount of ads.

SPEAKER_03

Hydration, we watched them hydrate, which they didn't. Well, I mean there were no ads in Europe, pretty much.

SPEAKER_00

Yeah, exactly. But I'm quite sure in America there were like six thousand. And I mean, I also liked how they interrupted everything to show that three-second uh uh FIFA animation that meant nothing and then went away again. Like, and it's like I mean, Josh, you probably will will uh disagree with me in terms of branding is necessary, but I always felt like they had a conversation and then they just showed that thing for three seconds and went back to conversation and everything, the flow was gone.

SPEAKER_03

I mean, the style is consistent.

SPEAKER_01

There's a right time and a right place for everything. Like the best type of advertising, in my opinion, is the kind that's non-disruptive to the user experience. So forcing unnecessary water breaks, inserting you know, it's something in the middle of a speech that's incredibly disruptive and helps no one. Like the water breaks for what a lot of these players can play what in 40 degree temperature without taking a water break, and now they're forced to do it in a domed stadium or they're regularly experiencing 20, 22 degrees. Yeah, yeah. That was the funniest thing.

SPEAKER_00

It was air conditioned stadiums, and they're like, okay, and now we have a water break because it's too hot. You're like, where? Like, what are you talking about? Okay. Uh, but yeah, it's uh it's an interesting thing. It went out, and I'm very happy that the FIFA finally made some money. I mean, we always wanted to make sure that they that they're not only there for the sport, uh, and so that's good to hear. So, yeah. Anyways, let's take a look at some of the bits that I connected with uh that I collected for this. Um let's see if uh if uh StreamYard is again kicking it out after a few minutes, which it kept doing the last few weeks. So I don't know if that's an issue, but we'll see if it happens or not. So um the big news, of course, that uh everybody is talking about and everybody's going crazy about is that there's a new new EU law for deepfake AI content, meaning that if something is a deep fake or something has been AI generated and it's not a real person, would it be in an advertising, would it be in a political campaign, would it be anywhere else? It actually you have to give it a label that it is AI generated, otherwise you can get fined by the European Commission for like a few million whatever euros, and everybody's going bonkers about it right now, saying, Oh, I can't use AI anymore, and the EU is holding us back. And um, yeah, it's I think it's just an honest thing to do. It just feels uh very bizarre that people are not understanding that deepfaking somebody else is actually an intrusion into their privacy and actually uh into their uh digital identity as well. So having to label it is is not a big thing. I remember like all the all the uh comedy programs in the BBC and also in in Europe, they all have like, okay, they have deep fakes of politicians, but they then have AI generated in the corner, and they had that for a year now. So it's not an uncommon thing. But I myself I'm I'm I I feel cheated when you actually give me a product product and you have an uh an avatar generated person talking to me, or even worse, if I call a helpline and actually it's an AI-generated person without telling me that it is. What about you? Like what do you think about that ruling? Is it something that the EU is just doing to annoy America, or is it something that you consider a necessity as well?

SPEAKER_03

Well, it's been a while for uh most of internet-related regulation to be uh tested out in Europe first. So they're just continuing on the same road. Uh this is uh regulation that probably flawed but still pioneers uh what we will be doing in the future if we want to have societies uh when AI uh is all over the place. Uh although you know at some point uh when the costs uh are real again, where uh the subsidizing tokens goes away, uh if we don't build enough infrastructure, this is gonna be too expensive to waste on stupid stuff. So one problem with regulating both AI and social media is that people are going to ignore the regulation and uh enforcing the regulation is much, much more expensive than whatever they're doing. And this is a lost game at scale. So what you need uh is regulation that uh can be easily enforced, or regulation that is created with the assumption that it's not gonna be uh enforced, uh, but it's there to uh set up a social contract where people will expect, like with uh teenagers not being allowed to use uh social media, some countries coming to more countries. This is not a regulation to actually stop it from happening, although you have to publicly say it, but it's a regulation to introduce a taboo on parents who are just giving kids hey, play with this Facebook thing for a bit while I'm slicing my carrots.

SPEAKER_01

What about you talking about? I think ultimately a lot of this boils down to hey, how much effort are you willing to put into a given task or response? The organizations and the people who are upset about this are the people who never understood the fundamentals of doing uh these tasks yourself. So using Photoshop to create uh defakes, you know, uh and when you come actually to the moral and ethical obligations of this, yeah, the EU has always been the leading use case of what's morally and ethically uh kind of much higher ground than what's in the state. It's uh to your point, Noctur, uh to your point, it's exactly oriented about enforcement and what are people actually willing to do about it, to be honest, because at this point, we're gonna keep exploiting this unless there's no uh end-all value to it. I think what will have a bigger impact on deep fake AI content and AI usage is actually the restriction on the potential building of said infrastructure because we know how much negative impact all of these data centers have on the environment. And that will once you re once you put restrictions on the infrastructure build, you're gonna have that increase in cost. You're gonna have companies saying, All right, this isn't worth it for me to use anymore. And you should have a reduction. I mean, not to the point of it being political or other sensitive content. There's always gonna be bad actors and you're gonna need to chase those down. But of course, it is rage-baiting America a little bit, but I think this is steeped in a good cause and for good reason, and it's gonna force us to continue staying on the line of what's reality, what's good quality, and staying the line realistically, and maintaining some semblance of humanity in the digital world.

SPEAKER_00

Yeah, I think it's an interesting one because also people like LinkedIn now have a button saying like this is AI-generated content and flag it up. Facebook had similar things in Europe as well before. And yeah, I'm kind of done. I'm so, I mean, I I only use Facebook to follow dogs, and uh, I'm so done with all these fake dog videos of like, oh, our 15-year-old, our dog is 16-year-old now, and it's like dog breeds that go up to like five years, and it's obviously a picture of a puppy, and you're like, uh, and it's just interaction bait, like, oh, don't scroll past me, send me some love, kind of thing. And you're like, yeah, these these chances really annoy the hell out of me. It's like we made social media not social anymore. We just made it a machine that actually gets fed and actually feeds interaction from other bots, and I find it like it's a good opportunity to restart that whole thing. And I would, I would, I would pay for a button to actually filter out all AI generated content. But of course, that's not going to happen because these are the people that make the most money for these platforms as well. But it is interesting when companies do something like uh Substack right now actually did something similar. It actually now has a an AI detection tool, and the users call it a witch hunt, uh, which of course is a very Substacky answer to do to uh in things. But it's interesting to see that like if you as a platform you basically say, like, okay, that's obviously AI generated, please uh link it up like that. Um, how the community or the community that got that that replaced the original community, like the AI generators kind of thing, get annoyed with that. And I love the term witch hunt for it. And you're like, no, you're not a witch, you're not even ginger. What the hell? Like, but I don't know, I'm not into Substack that much. Are you CB?

SPEAKER_03

I've had uh sorry. Not not really, uh, but uh yeah, been been reading occasionally some things, but I don't subscribe to anything in particular. Um well it's it's not something that I invented, I'm quoting someone, but there's there's this quote that I use for this situation, and it pretty much summarizes my whole approach. Uh why should I bother reading something you didn't bother to write?

SPEAKER_01

I I don't disagree entirely, but I can tell you from my point of view right now. So I joined the company two and a half weeks ago, and we have this massive event coming up. And in order to help build some buzz, I want to summarize a good significant proportion of the content that we had in our Berlin event. And we had 450 sessions, so we had more if you include uh workshops and master classes, but we had 450 recorded sessions, and in order to build awareness around what we did and what we want to do, I just don't have the time to sift through this. I'm using AI to ingest all that material, come up with summaries. And frankly, I trained my Claude co-work, I trained a Claude Skill to be like very, very good at extracting quality content. It's not great, but I still have to review it extensively. And I'll tell you, hey, listen, on an output piece, if it is a blog, I'll still spend two, three hours making sure that it's good quality, that the sources are accurate. But when it comes to creating at scale, and if you're on a time limitation, I'll lean into it, but if I really I will spend time writing. So I think that there's a middle ground in that case. And to the point of Substack, that's necessary. I mean, in the past two years, I think Substack was completely taken over by marketers as another lead gen tactic because LinkedIn's not working anymore. Uh newsletters to your inbox are rarely being read. Substack was supposed to be that quality-oriented medium where people, to your point, aren't writing AI-generated content or people are writing their true thoughts, they're publishing their research, doing this, this, and this. And infusing too much AI is when you suffer that qualitative degradation. So I'd love for me, I'm okay with the AI stamp being on it, but I think it'd be even better if, for example, you say, hey, this portion of the article was researched by AI, but this part was written by myself. So I think we're kind of in this weird time of AI application where we haven't found that perfect balance of what's good, what should be written manually. What's your point? Absolutely. Uh I get it. I I read some AI stuff. I I get the point of don't read it if you didn't spend the time writing it. Heard, absolutely heard.

SPEAKER_00

I think there's just kind of like I think there's aided and enhanced, and there should be different levels. It should be like completely AI generated, like a fake person or a video, or these kind of things. We tried to do that with the newsletter as well, and with the blog post that we have in our magazine. And every time we used it to gen uh we used AI to generate a video from, for example, a list of links, it was just atrocious. And we just we we couldn't at any point say, like, uh, this is not what we want the world to see. We are developers as, so we didn't do it. But like it feels like a lot of people, it's just like if you if you play the game of having to generate tons and tons of things just to be available to people, um, that's the thing. But like playing hacker news, playing uh uh in the past, playing like uh um product hunt, like all these all these different platforms you had to actually flood with lots and lots of crap, even be even if you don't have done it. But yeah, it's an interesting one. I'm not too worried about it because it also feels weird as somebody who blocked since 2005 and published a few books, seeing people who just go into that publishing world just to make money. You know, that that's that's another thing that just drove me nuts. Like how everybody is I mean, you see people like publishing a book every three days, and you're like, no, that's not possible. I'm sorry. This is like you're not uh you're not like uh Jay uh Tokian or somebody. Like this is not a this is not a thing that people do. So uh don't pretend that this was not done by AI. But yeah, okay. This is an interesting counter.

SPEAKER_03

At this point, uh uh just wanted to add that uh I have no problem with people using AI extensively to work on the concept, even to build uh an early draft. Uh it's it's about human attention to curation of uh what they want to say that is important to me. And uh if I have the guarantee of that human curation that every sentence in that text was intended uh and the person believes it's true uh and to the point of what they're trying to say, uh it could even be uh partially AI generated for me, and that would be fine. The problem with that is if you see it being partially AI generated, it's really hard to gather up the trust uh that this person really paid attention to what I'm reading now. Uh and this this whole thing boils down to articles, content in general, just being transfer of ideas. Like we don't have means to transfer directly between brains because uh they're incompatible, they're not compatible hardware, so you can't just transfer you have to uh put them in writing. Uh language is a great invention. This is the only transfer of ideas uh that ever existed in nature. Uh so I want to use it, and uh AI-generated content is just not that. There's just not a brain from which this idea comes from double from. Yes. See, this is hard. So I don't mind if someone uses AI to not say from twice in a sentence around the same verb, but I guess the idea has transferred.

SPEAKER_00

And also, like everybody going on, it's all about voice, it's all about video, it's all about like people listening to things like oh, I've got a podcast that's three and a half hours that talks, that could be a three-paragraph article. Like uh it's uh the the more engagement kind of bait thing is another bit there. This is also interesting that there's a new thing about killing the track the cookie banner, because basically the new EU uh commission uh says like if the browser has a privacy setting, then you actually don't need to actually bring up the banner anymore. And it's just incredible how many banner uh pop-up, banner pop-ups you see in Europe that are just incredibly frustrating. I mean, I've seen like eight-level processes, like eight eight-step processes to say yes or no to which cookies you want to have on that thing. I mean, most of the time I'm using LibriFox, so basically it's a browser that if I did if I close it deletes everything again, so it doesn't really matter. But like it just feels to me like the uh that's in America it's a meme already that basically that uh the cookie banner is a joke that our internet is so horrible to use because of it. I remember the EU commission now also wants to redesign the euro bills, so one of the one of the supposed designs I saw was a cookie banner on the 50 euro note uh to to depict what Europe is about. But yeah, it's an interesting thing, and it also says like what you can do and what you can talk about, and that the tracking industry is actually pushing against the idea that they still want to have the cookie banners because it is already uh um already a measure that somebody has seen the site, which is kind of ironic because it's against the idea of it. But yeah, it's an it's an interesting bit, and yeah, to keep to make things obvious, these are obviously AI-generated images, but yeah. How about you, uh uh CB, what do you do about banner cookie banner things? Do you just delete them? You just say yes to everything, you just gave up on uh banner blindness by now.

SPEAKER_03

Well, I mostly don't see them uh because they tend to be integrations of a third-party script, and I have an add-on that blocks all JavaScript that I didn't approve up front, so they just don't work. But I do have a buddy who's uh running an entire uh foundation for uh making internet better and improving privacy online, and they built a browser add-on and a uh mobile app analyzer tool uh that help them uh put together a report that they can send to authorities uh about a website and to the website owners first, uh obviously, uh saying that hey, you're sending user data, this and this and this data to the following third parties before they consent to anything. And that's uh a concern because the kookie banners are often just there for malicious compliance or just to have something, because that's the law. So someone at the company said, Hey, uh, tell this guy we're paying the least to get something installed uh while everyone else is busy making us money. And many of those just don't work. Like there's uh a lot of websites where your data uh has already gone to Facebook before the cookie banner was even displayed.

SPEAKER_00

I mean, this case was hilarious as well that the commission actually filed a complaint against Dick.cc, which is an online dictionary, and it has 1741 partner cookies. And you do it with you you do consent with one click, and I just like what the hell is going on there? But yeah, it seems to be not uncommon.

SPEAKER_01

It's insane. It's insane. I can tell you, like, as a individual, as a let's say as a consumer, I hate cookies. Like to you to your point, I've to your point, Susie. I've absolutely like I got essentially my brain is now hardwired automatically to click the only accept necessary cookies, or at least to go through that freaking ridiculous flow to unselect which ones because they do share. And then even if you don't have a meta account, you have to go into meta and say, do not buy or sell my information. It's just this entire ecosystem of like, yeah, as a marketer, cookies, I need them, I hate them. Uh, and the fact that we want to get rid of them kind of makes it worse as a marketer because you do very much want to have uh I I'm a fan of GDPR compliance, so I want to have like legitimate interest with people that I'm communicating with. That said, it's insane. Yeah, look at that. Uh look at that. Chris is clicking through on the register and going through his cookies on his own. It's it's a very frustrating back and forth. I think even if we get rid of cookies, if we get rid of uh the GDPR click, the ad industry is always gonna find a different way to buy your information somehow, somehow. It's an endless back and forth cycle. But I don't know, the 1700 informed consents for a dictionary website is insane. That doesn't strike me as surprising for some of these other media pages. Like I don't know, I don't know anything about the register, but I used to work for an ad tech company, and a lot of these media publications, they have at least a thousand partners. And who's gonna read through all that?

SPEAKER_03

Who's gonna read through so yeah, no, um but patching the most uh horrible atrocies out there uh is changing the scale. So uh instead of your data going out to thousands of third parties, uh maybe in the future as things get more and more difficult for the ad tech uh companies, they are going to compromise a little and uh do a better job of handling the data because they have to. Uh and they will not get out of business, they will find something else to use, even if cookies are gone. Uh, but it means it's gonna be more difficult to uh have this negative impact on people at uh huge scale, like the Facebook like button that it had. Um and it's too early to tie it to uh supply chain security, but the same is happening in the realm of supply chain security right now, which I'm happy to revisit in a bunch of minutes.

SPEAKER_00

Cool. Yeah, this was another thing that has been around for quite some time. There have been like quite a few fonts right now uh in the making that actually or humans can read it and machines can't. So this one is a is a font that actually uses uh ligatures to actually make uh uh hide text inside it. So it's actually this is the text that you would see, and this is the text that is actually in the HTML that a scraper would get. Now, my worry about this is accessibility, like somebody who doesn't see the screen and somebody uses a screen reader, or somebody who actually translates websites into another language will probably get the other one as well. So I think it's a it's a haha. We're actually fighting against the evil AI scrapers, but you're also uh a lot of times you're actually uh sacrificing accessibility and hurt other humans with it. So I don't think that this is the right way to do it, but it's a clever way of doing it. So uh typography fans will be happy about knowing that this is a possibility. Others were just like overlaying with like with like uh blurry things, and like, yeah, I'm I'm just like this is cool, but I I think the scraper problem, scraping content and ingesting content that it shouldn't should be done on uh on an HTTP level and not on a display level. So that feels uh feels like the wrong way to actually protect these things because that has never been an option. Like as soon as something is on the screen, I will get to it. And if it basically uh a lot of a lot of scraping bots also take screenshots of the picture now and don't even look at the HTML and then OCR scan that and have your text again. So it feels a bit um yeah, too clever for its own good. But uh cool techy geek shit. Talking about other geek stuff, uh we have to move a bit faster because I realize we have another thing. I love this. Uh, another cookie consent. Look at that. Uh it's actually uh written by Neil, uh, who's been who I wanted on the show a few times, but he actually isn't a person that wants to be on shows. And what it does, it actually goes to Wikipedia and searches all the pictures of Wikipedia, which are all PNGs, and then makes these sticker sheets out of it. So if you say like uh car, uh you can actually see that. And now that uh that Google image search is basically like, oh, do you want to generate stuff rather than finding images? I found that actually really cool. That basically uh it's super fast. That's the other interesting thing about it. So it's beautifully done, and yeah, so you basically can click through to the different Wikipedia as well.

SPEAKER_01

Why is the default birds? Why is the default image search birds?

SPEAKER_00

I don't know, because turd would be a different thing, it's still birds, so okay. Ah, see? Uh, like it's uh I guess it's just a matter of like uh would be maybe a different reload every single time it does different ones. Yeah, it does. Look, it's not birds, it's just the first load was birds, and now it's like different random things from Wikipedia. But I love the aesthetic of it, it's like very 2000s 2002, uh uh uh like MySpace pages and stuff. That's pretty huge.

SPEAKER_01

Oh, there you go. You gotta clear, uh you gotta clear the search bar, and then you get an absolute hodgepodge of material. It's I don't even know what images I'm looking at here. This is burger.

SPEAKER_00

I love anyway. I love this. I love this one as well. This is the IKEA complexity index. So it's actually taking IKEA models, it's a price, uh, how many steps you have to do, how many kinds it has, but how many kinds of parts, how many parts, how many manual pages, what the complexity level is, or the estimated time of having to build it. So people have done that with Lego uh models in the past, but now somebody did it for IKEA. And in essence, and in essence, IKEA is just yeah, it's it's Lego for grown-ups and uh less expensive than Lego. But uh it's just really cool to actually see, like, okay, when your uh when when your partner or your friend actually says, like, I want to build this thing and want to build it with me. So this is a good website to take a look at and say, like, how complex it will it be to actually build that thing. And yeah, I love that people just do that stuff for free. Nobody paid him to do that, like it's just a random data analysis thing, and then making it at a data table for sorting. And I wouldn't be surprised if IKEA takes it on in uh in the future and actually puts that in the page because they're a company. They have been a partner of ours as well at the Congress a few times, and they're just a very interesting company. So it will be interesting to show it to them and see if they are interested in actually putting in the page itself.

SPEAKER_01

I never thought that PAX models were the most complex sets to build.

SPEAKER_03

The ones that you can't know. I think that's the whole wardrobe, like you know, entire wall size of wardrobe. So that's a lot of stuff to build on the inside.

SPEAKER_00

They have single single-step bathroom cabinets and stuff as well. I think that the best test for a relationship is to go to IKEA on a Saturday morning, and when you're still a couple at the end of it, then you actually know that you're you've done well because that is the hardcore test and everything. Because it always cracks me up when you're like, I'm not gonna buy much, and then you just turn around, you turn around, like, and she stands there with like 5,000 things, and you're like, What is all that? Like, okay, and then you see things, and you yeah, we always go out and like more than more things that you wanted to have.

SPEAKER_01

No, the true test is when you get home and if you're still in a relationship after trying to assemble that Pax wardrobe after you like spending hours trying to assemble it, you know, if you if you can still get along.

SPEAKER_00

We got this we got the same with cooking. I mean, like I like to cook, but don't watch me doing it. Uh and and the result will be will be tasty and good. And but I don't need you to actually every step of the way tell me that you shouldn't have done that, and this is not how you how you shave how you shave a cucumber or whatever other things are in there. So, yeah. Let's talk about a few tips and tricks. Uh, passwords. Uh, this is an infographic. How to uh that comes out every year, I think. Uh, how long it takes to actually brute brute force. Wow! What the hell? Oh, yeah, more pop-ups. Excellent. Uh, how long it takes to actually crack passwords and um I don't want passwords anymore, but it's it seems to me like that is an article that has been written quite to a large degree by AI. But it's still interesting to see that when you see uh the uh when when when things uh actually get get leaked, and you see that the password, the most used passwords were one, two, three, four, five, and uh or baseball and these kind of things. So we all know that these things, but we don't actually do something about it, so it's interesting. But yeah, basically it's uh it's so much it's just a few spaces making a sentence and changing a few characters around helps, and the longer the better. But that also means like you don't remember them, and that's one thing when we talked about macOS, macOS earlier. Like, I love that I have my fingerprint, that I have my facial recognition, but every two or three logins it asks me to type my password in. And I'm like, if I use a super complex password and I have to type it into start my machine, I cannot have a super complex password.

SPEAKER_01

So yeah, I was locked out of my company computer from day one until week two for that exact reason because I logged into my computer and then immediately forgot my password and then it locked me out. It took me a full I got locked out for a week before I could start using my official company computer to work again.

SPEAKER_03

I'm biting my tongue here because I work in security. Uh you know what I mean with uh my SSH key to push to GitHub. Uh I uh have a uh SSH key that is encrypted uh when stored and uh it's encrypted uh with uh a a password that's I don't know how long it is, like 30 digits or something, like 30 characters, and then I use so many iterations uh of the encryption uh algorithm that it literally takes five seconds for it to be ready after I finish uh entering the passwords. So uh don't get me started on on passwords. But uh there's there's a lot of fun to be had around passwords. Are you familiar with uh the uh project uh uh uh ecsa dot fail? No, what is it called? E S D? Uh I sent you a link you can click, but if it's not visible, it's E C D S A E S A. E C D S A.fail Okay. So uh Google Google published a paper uh where they gave a uh zero knowledge proof uh of uh making a vast improvement uh to the algorithm that future potential uh uh quantum computers uh could use to crack our passwords easily. Uh and they made the necessary size of the quantum computer to crack modern passwords significantly smaller, like by two digit percent. And then people took their uh testing framework for that and the the the proving thing uh and made uh it into a leaderboard, and now people keep improving that. They started with a small improvement that someone pulled off with the help of AI, and now people are fighting for the first place, and they have long surpassed uh the score that Google bragged about.

SPEAKER_00

Okay. Well why is it the same person three times?

SPEAKER_03

Uh because they are submitting improvements, so there's a score that keeps going up, and there's uh a group of people uh working on it. My uh my uh university buddy uh who's still at the university uh has the right kind of mind to participate in that, and he was at the top of the leaderboard for like 45 minutes, I guess, something like that.

SPEAKER_00

Not bad. Okay, cool. Yeah, okay.

SPEAKER_01

So five or five years old. This is essentially measuring how efficiently people can in the future crack uh passwords, uh passwords using quantum computers.

SPEAKER_03

Yeah, this is the uh the the clearest I can make it is uh improvements to the algorithm that decrease the size of the quantum computer necessary to be able to crack modern passwords. So we're struggling to build any size of quantum computer, uh and the larger it gets, it it gets exponentially more difficult. So making it uh half the size uh means you're not having the problem, uh, you're making the problem like 10 times or 50 times smaller to build the quantum computer necessary.

SPEAKER_00

Cool. Uh quick one. Uh um I'm gonna move some of them to the newsletter because we're running out of time here. This is uh uh a tool called undo, which I found really interesting because it actually takes destructive Unix commands and actually allows you to undo them. Uh, I mean if you set up your machine to allow an RM minus RF, then you should have a Problem anyways on the route, but this one actually allows you to undo these changes and might be an interesting thing to try out, and especially for you, uh CB to take a look at if it really does what it's supposed to do. But uh I remember there was also one called the fk, which is like if you if you mistyped a Unix command, it actually gave you the command that's closest to what you mistyped. But this one is actually uh something that might be interesting to do for agents and these kind of things as well. So uh I'm not quite sure how it's done. Uh it just aliases the other ones or it explained it.

SPEAKER_03

Uh it uh adds a small hook that records what the command was doing. There was uh there was a line on the screen for a moment.

SPEAKER_00

Okay. So yeah, it actually there's a behind the scenes as well uh explaining you what it does, which is not much actually at all. Good thing I clicked the multiple for that. Uh no demons, no snapshots, no new hash shell hook. Okay, yeah. Interesting. Uh, because yeah, I've been the most retweeted thing I've done in the last few years was like uh to remove all the French files from your server to RM-fr. And people um yeah, people I hope they didn't fall for it, but it was really interesting that's still a thing people to do. So we have a game here called Fake On News. So I came up with uh news headlines, uh, and you have to tell me if they are actually real or if I made them up. Google Workspace's AI writing assistant occasionally changes professional tone to casual slang mid document.

SPEAKER_01

That sounds true.

SPEAKER_03

Uh I say not true because it's uh not impactful enough to be newsworthy.

SPEAKER_00

Fake, you're right. Apple's iMessage scanning flecked a video of my friend's dog as nudity.

SPEAKER_03

I'd say true.

SPEAKER_01

Uh I'm gonna I'm gonna go contrarian. I'm gonna say false on this one. I'm gonna go 0 for 5.

SPEAKER_00

German techno predecessors craft work released new AI generated album called Even More Fun to Compute.

SPEAKER_03

Uh I'm a metal head. This is hard. Probably not. I'm gonna side with you on this one. This this sounds like fake.

SPEAKER_00

It is fake. And I got the cup to prove it. It was actually a great concert. It's they still have it, it's amazing. Python 3.14 or Python Pi deprecates loops entirely, encourages recursive thinking instead. That performance degrades by 34%.

SPEAKER_03

It would be so much fun if this was true. But I guess not.

SPEAKER_01

Yeah, that seems to like it's too perfect. Like why follows the rule pie? Yeah.

SPEAKER_00

Snapchat AI filter is called selling user biometric data to security contractor.

SPEAKER_01

Wasn't that the whole like fake with Snapchat from the beginning? If the this is old. This seems like old news.

SPEAKER_00

It's still fake.

SPEAKER_01

Uh uh.

SPEAKER_00

We need to we need to quarantine we need to quarantine aliens on the moon, scientists propose.

SPEAKER_01

Which scientists? Fake.

SPEAKER_00

I'm gonna say it's true. It's news. But this is this is a common thing that annoys the hell out of me. Like uh uh researchers say scientists propose. This has become a very common headline, and it's just like, yeah, which exactly which scientists? How does that prove anything? Yeah. And wasn't that the plot for Man in Black 2 where they had this uh this space moon prison? New North Korean campaign uses fake coding interviews to steal developer credentials.

SPEAKER_01

There's nothing new about it. It's very true. I agree. I think it sounds true to me. Sounds true to me.

SPEAKER_00

It is news, yeah. Vatican's official prayer app leaks 700k plus global users personal identifiable information.

SPEAKER_03

Uh prayer app?

SPEAKER_01

Yeah, I hope it's not true. Me too, but I think it is. This sounds true.

SPEAKER_00

It is true. Ah, many prayer apps out there, and they make a lot of money. It's really, really weird. But yeah. Postgres UL.

SPEAKER_01

Oh, sorry.

SPEAKER_00

Postgres SQL adds optimistic sharding that sometimes loses data but tries to guess what you wanted back.

SPEAKER_01

That's gotta be fake. That sounds like a clawed thing.

SPEAKER_00

It's fake.

SPEAKER_01

Yeah.

SPEAKER_00

AI companies are buying maybe, but AI companies are buying tons of old books because they're free of AI slop. Yeah, apparently they're also destroying all the books now, so that's the really annoying thing about it. Linux kernel now requires three-factor authentication before allowing sudo adoption of fingerprint scanners mandatory by 2027.

SPEAKER_03

Uh I think it's not true, but inspired by something that actually happened.

SPEAKER_01

I have no idea. I'm gonna I'm gonna say I'm gonna say true.

SPEAKER_00

It's fake. TikTok algorithm found to be training on user smartwatch activity.

SPEAKER_03

Uh how? Now that doesn't seem technically plausible.

SPEAKER_01

Maybe how maybe with Apple Watch? I think it's all interconnected. It goes to a topic from before, or like they're selling with all of these tools are selling data. I think it's true. I think it's true. It's fake.

SPEAKER_00

US accuses American of allegedly wiping his phone using a duress password during border search.

SPEAKER_01

Oh, this is true.

SPEAKER_00

Oh, he's suing them now. It's true. Yeah, it's a Graphino S uh with a Grafino S phone, yeah. VC backed startups commit more fraud, and researchers think they know why. True.

SPEAKER_03

I don't know what else. Well, the first part is true, but the the second part I doubt it.

SPEAKER_00

It goes true. Pinterest tests dynamic pricing for safe pins at two cents per save users revolve. Gotta be fake.

SPEAKER_01

It's gotta be fake.

SPEAKER_00

And it is fake. Yeah, that was fake on news for today. So you did not too bad, actually. So yeah. It's getting harder and harder to come up with things that sound plausible because there's so many things that are just completely mental happening. But yeah, it's fun again. And you can always go back and play with it later as well. It's all listed here on the Fake One News site. Cool. So uh let's go to your specialist topic when if my browser is not crashing, because it seems to be right now. So um there's an article by Evil Martians, the secure way to release an NPM package in 2026. Again, also available as a skill. I'm not sure. Okay, I'm not gonna click through all of them right now. That's something to read up on, to think about. But you have a project actually happening uh that you work on that's called Harden. And what does that mean? What does that do? Tell us about Harden.

SPEAKER_03

All right, so Lavamote Harden is usable for any project that has a package.json and uh defines any dependencies. Uh, and this is a tool that you can use to automate configuring it uh optimally uh with the latest changes to package managers. So we've had a lot of good news uh in the npm ecosystem uh this year with npm uh client itself making uh a lot of changes that were, I gotta say, long awaited, and they were breaking changes, uh, but we're good. These are security changes. Uh we are now uh at a point where every package manager uh lets you control what scripts uh are going to run during installation, and they have plenty of other configurations. And Lavamoat Harden, which is currently a pre-release uh 1.0 coming soon, uh, is a tool to make the best out of your package manager's configuration. Currently supporting npm, p npm, and yarn. Uh might add vault uh if I find something that can be hardened in there. Uh other than that, um there's there's some extra features uh if you want to really ramp up uh your project's security. Um but this is mostly built around what package managers can already do, and it's leveraging uh all of the configurations that were made available, most of them recently. So the main thing it does, it makes sure your package manager uh is uh set to a version that will support these things, and then it generates all of the configuration. So you can either go with a one CLI command that just configures everything and lets you push it to repository, or you can run a wizard that's going to ask you questions about every setting uh that can improve your project security to get that configured. Um and this is a prerequisite to not getting hacked with things like post install scripts or other bogus things that your dependencies might do. Um and uh it's been made available now uh mainly because of the ecosystem evolving. So with npm now helping people block install scripts and blocking them by default, actually, um attackers are going to move on to more advanced things, and that's where Lavamote, other tools from Lavamote also come in. Uh so we have to stay ahead. And everyone else can stay ahead because it's a free and open source project.

SPEAKER_00

I can hear you again, so that's good. Uh so I mean the the uh the bigger problem was that npm was basically uh very easy to uh to to sort these things out, but didn't uh uh uh using a system like that, of course, helps you. But do you think we the platform should catch up on these things as well? Like, do you think that's the that's the where we actually should be one wondering if we cannot make part in part of the other thing?

SPEAKER_03

They did a lot of catching up this year, yes. Uh the uh the hardening on npm side is also happening. I mean, we were uh we the community were asking npm to uh expand two factor authentication for publishing and to introduce staging for years now, and it's finally happened. Uh, and staging is great if you set up trusted publishing with staging, uh, and then you have to manually go and look at the package that is being released and decide, did I intend to release this package right now? This is perfect. This eliminates uh most cases where someone could uh steal some credentials and release your package. So enable staged publishing as soon as possible. And if you have many packages, uh I did you know what it's like when you're a dev and you have to do something uh multiple times, uh, you're gonna spend uh twice as long uh automating that. That's exactly what I did. So if you have to now um set up staged trusted publishing for a bunch of packages, this is gonna be helpful. I'm sharing my screen now. So if you go to Lavamote GitHub IO slash stage clicker, this is a tiny HTML file that I created uh that contains a bookmarklet that has no permissions whatsoever. It's just a script that when you collect the bookmark runs in the context of the current page. It's like you've added a bit of code in your console and nothing else. It doesn't persist in your browser, so you don't really have to trust it much. And you're in control that it's gonna run only on this page and do nothing else. Uh and you can read it, it's super short. And what it does uh is it when you run it uh on this screen, it's going to set up this box here like where normally this is like, oh, you can set up trusted publishing here. Uh it's going to set it up for you. And if you have tens of packages, it's so annoying to click the same thing so many times. Uh and in pretty much all of the cases, the main thing you have to do there is clicking three buttons and taking this string and putting it in a field in the middle. So I automated that. Uh yeah.

SPEAKER_00

Um that's where bookmarklets come in. It's still a wonderful way to actually try things out. And uh, I mean, especially with browser extensions uh being used to actually uh attack browsers, they've become a lot less powerful than they used to be. But bookmarklets is still a thing that actually works because it it injects in your own machine. But then again, there's malicious bookmarklets as well, so be afraid sometimes about it. Read your bookmarklets.

SPEAKER_03

All right. Um, yeah, so going back to Lavenote Harden, um the release is coming up, uh, but you can already try it out. And the great thing is it doesn't go into your dependencies. You just install it whichever way you want uh and run it on your project. It's going to generate some configuration. Uh and the latest thing I put in it uh is the script uh execution environment changes where it turns out every package manager lets you hook into um the mechanics of running scripts from packet JSON. In packet JSON you have scripts like build, test, lint, etc. And imagine your linter is probably using a bunch of plugins, and these are npm packages that are uh less prominent. And if someone takes over that package and decides to take the contents of your browser profile and send them somewhere, that's not great. Uh and this tool lets you uh eliminate part of that danger by uh limiting where the script from your package.json, whenever it runs node, uh, is going to access disk. Uh and with node 26, you can also use the permissions to limit network access. So you can set up your linting to be read-only disk access and uh offline, and it's just going to break if it tries to do something else. And this is the principle behind LavaMode in general. But here uh I found a way to, without uh using the whole machinery of LavaMode, uh, which requires some effort to put in place. This is pretty much effortless. You just have to make the decisions, put them in a file, uh, and this package uh sets things up in a way that npm is uh or yarn or p npm is going to run your scripts uh under these permissions, which is a nice experiment. Uh took a bit to figure out.

SPEAKER_00

So currently currently you do yarn and npm. How about bun and dino?

SPEAKER_03

Uh bun and dinu are different beasts. Uh and oh there, yeah, there's not enough uh there's not enough API surface to try to integrate with them. Also, uh they are all in one solutions, so if they want to provide this, I'm happy to work with them. Uh, but it would have to be part of uh Bun or Dino themselves.

SPEAKER_00

In general, what kind of contribution are you looking for? And are you uh are you expecting a lot of stuff to come in? Or is because right now it's three maintainers on the on the thing, but that's do you do you think it's gonna blow up?

SPEAKER_03

Um so uh Lavimotes, uh the the project itself has been going on for about five, six, six years now. Uh and we have Lavamotes uh and we have the hardened JS uh groups that are working together uh on making things fundamentally more secure. The goal is to eliminate certain classes of uh uh security risks uh entirely. Uh and the the group is larger than just the three of us. Uh that being said, we are open to contributions, uh and the best way to contribute is to test and report issues. Uh if you're uh and a more advanced user, uh we are open to all kinds of fixes uh you want to contribute. And LavaMoot Harden itself, um if you go to the repository, uh it has three files called opinion.js, one for each package manager. And if you have an opinion uh that you think applies to everyone using that package manager about how it should be configured, uh you can contribute that opinion. And we will make some decisions on how it should be announced by the wizard and if it should be part of any of the levels uh that we have, like moderate or strict, or maybe only if uh the user opts into that uh willingly in the wizard, but you can contribute uh pretty much any uh configuration for your package manager or things around it that uh many projects use uh into this package. And I will be reviewing it.

SPEAKER_00

Excellent. I like that you did that instead of doing a template, uh uh a pull request template that gives you opinions, you just put a file in there called opinion.js so people have to edit the files. So that's that's another interesting way of getting contributions in there and not having to worry about too many pull requests coming in. Well, I mean, I hope there will be a lot of pull requests coming in. I hope that people will use it because it seems to be uh solving a real issue that we have at the moment. And um, yeah, good luck on the 1.0 release. That's always a that's always a uh a worrying thing to do. I mean, it was more worrying when I did it in Microsoft than for a project like that, but it's still it's it's it feels good to have a 1.0. Yeah. It feels like a very uh step done.

SPEAKER_03

The 0.6 version I released before uh this meeting uh is uh a release candidate effectively. So it has all the features that I intended for 1.0. Uh and now how much can I change in two weeks? Probably not much. Mostly human readable text is gonna change. Uh but other than that, this is uh yeah, this is what I intended to give people. So take it and run it.

SPEAKER_00

Cool. Well, thanks very much. This was uh uh this was a great, interesting uh uh concept. We we we covered a lot of stuff today, uh, and it's interesting to see that uh there's so many uh security things happening right now, and especially also regulation things that uh people are confused about. So hopefully we manage to confuse them even more uh and get some more information out there for people to choose and read. So this we are developers live. Any last words uh for people out there, uh, CB? Anything you want people to do or not to do?

SPEAKER_03

Stay safe.

SPEAKER_01

How about you, Josh? No, I got I got nothing to add. Uh you know, thanks for having me and glad to join anytime.

SPEAKER_00

So well, we can we can make we can make it, we can make it we can make it a common thing. I mean, like we you're in the office, we're in the office. So um uh next week we're gonna be actually in the Silicon Valley. So I don't know if the show is gonna happen or not, or if we're gonna pre-record it. Uh so we'll see, because this time the Silicon Valley is not a good time to have it. I also find it fascinating. The the scroller down there, the marquee that's happening here. We wrote San Jose with an uh uh with an accent, which is not actually the city, like we made it even more Spanish than it is like that's debatable.

SPEAKER_01

That's actually debatable. I mean, I come from California, and that was my first feedback when I joined the company. But apparently, uh the city of San Jose, that's their branding choice. So if you go to the city of San Jose's website, they have that listed there. So that uh I growing up in San Francisco, I knew it was San Jose without the eh. Yeah, exactly.

SPEAKER_00

I mean, the the Wikipedia page, uh the Wikipedia page doesn't have it, and that's the source of truth for me.

SPEAKER_01

But it's it's a branding effort by the city, so um yeah, it's I mean it I'm surprised.

SPEAKER_00

Having lived to Silicon Valley and worked in there as well, it cracks me up that everything is a sand, this or that or other in California. Like, I mean, you start with sand and you do an autocomplete when I wrote Yahoo maps, not fun. Like, I mean, that's like that's a big request. Like, it's out of it. Oh, my favorite is when you have El Camino Real, the road, and people are like, Oh, I'm almost there. I'm on El Camino Real. And you're like, this is like 220 miles long, that sort of road or something, it just goes through the whole of California. So now you're not here yet. Like, I'm quite sure. Which is the number that you want, is the interesting bit. Cool. Well, thanks very much for listening. I hope we had something for you. Uh, you can also play uh uh play uh truth or dare almost said you can play uh fake on news yourself as well if you want to. And I hope to see you in September in uh in the Silicon Valley in San Jose. Uh I just took my tickets, so uh now I have to argue with my wife that I'm gonna be not available on those days. But yeah, we're gonna be seeing you in the Silicon Valley doing the same thing we did in Berlin, a bit smaller, but uh with excellent partners. So hopefully there will be good stuff to be heard and to be played with. So thanks very much. This was Weird Developers Live for today, and we see you maybe next Wednesday, and if not the Wednesday after. So thanks, Josh. Thanks, Eevee. This was great. Bye bye.

SPEAKER_03

See ya.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Stack Overflow Podcast Artwork

The Stack Overflow Podcast

The Stack Overflow Podcast