The Changelog: Software Development, Open Source

The insider perspective on the event-stream compromise (Interview)


Listen Later

Adam and Jerod talk with Dominic Tarr, creator of event-stream, the IO library that made recent news as the latest malicious package in the npm registry. event-stream was turned malware, designed to target a very specific development environment and harvest account details and private keys from Bitcoin accounts.

They talk through Dominic’s backstory as a prolific contributor to open source, his stance on this package, his work in open source, the sequence of events around the hack, how we can and should handle maintainer-ship of open source infrastructure over the full life-cycle of the code’s usefulness, and what some best practices are for moving forward from this kind of attack.

Join the discussion

Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!

Sponsors:

  • RollbarWe catch our errors before our users do because of Rollbar. Resolve errors in minutes, and deploy your code with confidence. Learn more at rollbar.com/changelog.
  • LinodeOur cloud server of choice. Deploy a fast, efficient, native SSD cloud server for only $5/month. Get 4 months free using the code changelog2018. Start your server - head to linode.com/changelog
  • GoCD – GoCD is an on-premise open source continuous delivery server created by ThoughtWorks that lets you automate and streamline your build-test-release cycle for reliable, continuous delivery of your product.
  • Command Line Heroes – A new podcast about the epic true tales of the developers, hackers, and open source rebels revolutionizing the tech landscape from the command line up. Presented by Red Hat.
  • Featuring:

    • Dominic Tarr – Website, GitHub, X
    • Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
    • Jerod Santo – GitHub, LinkedIn, Mastodon, X

    Show Notes:

    • The issue that kicked off everything
    • We covered the incident on Changelog News
    • Here’s Dominic’s statement that we reference repeatedly
    • Felix Krause had some on-point commentary on Twitter
    • TideLift says event-stream gets 2 million downloads per week
    • SwiftOnSecurity also chimed in on Twitter
    • Learn more about Project Xanadu
    • We discussed Reproducible Builds with Chris Lamb back in the day
    • Also check out A call for kindness in open source with Brett Cannon
    • Something missing or broken? PRs welcome!

      ...more
      View all episodesView all episodes
      Download on the App Store

      The Changelog: Software Development, Open SourceBy Changelog Media

      • 4.7
      • 4.7
      • 4.7
      • 4.7
      • 4.7

      4.7

      286 ratings


      More shows like The Changelog: Software Development, Open Source

      View all
      Software Engineering Radio by se-radio@computer.org

      Software Engineering Radio

      270 Listeners

      Software Engineering Daily by Software Engineering Daily

      Software Engineering Daily

      623 Listeners

      LINUX Unplugged by Jupiter Broadcasting

      LINUX Unplugged

      268 Listeners

      Talk Python To Me by Michael Kennedy

      Talk Python To Me

      585 Listeners

      Soft Skills Engineering by Jamison Dance and Dave Smith

      Soft Skills Engineering

      289 Listeners

      Data Engineering Podcast by Tobias Macey

      Data Engineering Podcast

      146 Listeners

      Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

      Syntax - Tasty Web Development Treats

      987 Listeners

      REWORK by 37signals

      REWORK

      210 Listeners

      Practical AI by Practical AI LLC

      Practical AI

      207 Listeners

      AWS Podcast by Amazon Web Services

      AWS Podcast

      205 Listeners

      The Stack Overflow Podcast by The Stack Overflow Podcast

      The Stack Overflow Podcast

      63 Listeners

      The Real Python Podcast by Real Python

      The Real Python Podcast

      141 Listeners

      Big Technology Podcast by Alex Kantrowitz

      Big Technology Podcast

      497 Listeners

      Training Data by Sequoia Capital

      Training Data

      40 Listeners

      The Pragmatic Engineer by Gergely Orosz

      The Pragmatic Engineer

      63 Listeners