See @tlhunter at our @Meetup in San Francisco
@CapitalOne
on April 4th, 6:30 pm
Talk is "Real World Attacks in the npm Ecosystem"
read about it here... https://t.co/6McJioRS5t
@rarkins@renovatebot Github diffs are useless from a security perspective. It's gotta be an npm diff, and you should be suspicious if the package is bundled before publish. Bundling should be on the package consumer
Symbols bring a few benefits to #JavaScript and are particularly useful when used as object properties. But, what can they do for us that strings cannot? And why don't they come with the same guarantees in #NodeJS? https://t.co/7TV3FRCD4y
Introducing Package Diff: A service for displaying a diff between two versions of an @npmjs package: https://t.co/88TThxl6Gt This tool was inspired by @mikeal. #nodejs
Do you maintain a #JavaScript library? Have a look at "Protecting your JavaScript APIs". Is your library resilient to each of the outlined attacks? https://t.co/eUhIAit9Cd
It’s also not the real problem. A system that relies on no one ever making a mistake to avoid a catastrophic security issue in the entire community is a fundamentally flawed system. Amazon doesn’t just hope no one uses AWS maliciously, they use *VM isolation*.
An NPM package with 2,000,000 weekly downloads had malicious code injected into it. No one knows what the malicious code does yet. https://t.co/V4rdenu7Bm
I hope you buy a solution from us but if you don't, buy a solution from *somebody*, for the love of god. I use your products and I need you to take this seriously.
Read about how @intrinsic are helping us to offer greater protection against dependency hijacking and supply-chain attacks in your #serverless functions.
https://t.co/AcFCyW9FhC
✍️ You can also sign up for early access to the beta!
Netlify Functions makes working with #serverless easier than ever before.
https://t.co/d1ENdrKEKB
And now, thanks to a partnership with @intrinsic, our enterprise customers get greater protection against dependency hijacking and supply-chain attacks.
https://t.co/AcFCyW9FhC
“Intrinsic is the best way to secure your Node.js Lambda functions, period.” — says Matthew Self of @BoxHQ
That's why we're working with @intrinsic to bring greater security to #serverless functions. More on this from @DavidWells on the @netlify blog:
https://t.co/AcFCyW9FhC
This just in: We are very excited to partner with @Netlify to offer their enterprise customers advanced runtime security for Netlify Functions. Automatically protect your code against the worst type of attacks!
Sign up for the beta: https://t.co/wN8ek5JCP0
"The typical #nodejs app is about 95% third party modules. Scrutinizing every line of third party code simply isn’t a realistic way of protecting yourself from these threats, which is why Intrinsic is here to protect you." - via @tlhunter
https://t.co/2jJgKuFriP
In this post we finally debut some of the awesome capabilities Intrinsic offers when it comes to securing #NodeJS applications! https://t.co/DlLDi2IW4R #JavaScript#security