YOUR AD GOES HERE

2024-07-10 supply chain on the brain

Published 10, Jul 2024

dorian taylor


Description:
Thinking about how the practice of piling on two dozen domains serving JavaScript is bad practice that is just going to get worse. Also thinking about how since memory-safe languages are getting more prevalent, attackers are going to start focusing more on injecting malware into the supply chain.

The books I mentioned (or rather didn't):

• The Enigma of Reason, Hugo Mercier and Dan Sperber (https://www.amazon.com/dp/067423782X?tag=doriantaylor-20 )
• How Infrastructure Works, Deb Chachra (https://www.amazon.com/dp/0593086597?tag=doriantaylor-20)

Mentioned:

• Why Do Humans Reason? https://www.dan.sperber.fr/wp-content/uploads/2009/10/MercierSperberWhydohumansreason.pdf
• NoScript: https://noscript.net/
• The Polyfill exploit: https://therecord.media/polyfill-cloudflare-trade-barbs-supply-chain-attack
• The Egyptian Predator exploit: https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/
• The XZ exploit: https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/

Erratum: At some point (03:50) I say that there isn't a lot you can do with JavaScript which isn't entirely accurate. Arbitrary code execution in the VM is of course a once in a while thing but the main hazard of JS is stuff like key logging and credential stealing, also stuff like crypto mining and annoying spam/popup whatever.

00:00 - tried to buy some books
01:21 - reminded me of namecheap
02:37 - actually do get me started about the security implications
03:45 - the hazards of javascript
04:14 - you're saying trust these guys forever
05:05 - how did it get this bad?
05:33 - badguys are moving to supply chain
07:20 - xz is the new standard for badness

Releted More Videos

  • Sorry!!! Nothing to show

You May Also Like

YOUR AD GOES HERE

YOUR AD GOES HERE