Keyboard Shortcuts

Keyboard shortcuts are available for common actions and site navigation.

Skip to content
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
garybernhardt's profile
Gary Bernhardt
Gary Bernhardt
Gary Bernhardt
@garybernhardt

Tweets

Gary Bernhardt

@garybernhardt

Illuminating the dark corners of programming. Destroy All Software (dense programming screencasts); Deconstruct (independent software development conference).

Seattle, WA
destroyallsoftware.com
Joined March 2007

Tweets

  • © 2018 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

  • In this conversation
    Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Gary Bernhardt‏ @garybernhardt 2h2 hours ago

    An NPM package with 2,000,000 weekly downloads had malicious code injected into it. No one knows what the malicious code does yet.https://github.com/dominictarr/event-stream/issues/116 …

    9:44 AM - 26 Nov 2018
    • 610 Retweets
    • 584 Likes
    • Thread you should've Ing. Nina Satragno Catherine | | Cathy Edwards Karen D Misha Kozik ᴅɪᴇɢᴏ ʀ. ʙ. あひい G_glop Ryan O'Boril
    17 replies 610 retweets 584 likes
      1. New conversation
      2. Gary Bernhardt‏ @garybernhardt 2h2 hours ago

        There are basically two camps in that thread. 1) This is the original maintainer's fault for transferring ownership to someone they didn't know and trust. 2) Ownership transfer was fine; it's your job to vet all of the code you run.

        4 replies 11 retweets 51 likes
        Show this thread
      3. Gary Bernhardt‏ @garybernhardt 2h2 hours ago

        Option 2 (vet all dependencies) is obviously impossible. Last I looked, a new create-react-app had around a thousand dependencies, all moving fast and breaking things.

        5 replies 14 retweets 67 likes
        Show this thread
      4. Gary Bernhardt‏ @garybernhardt 2h2 hours ago

        Option 1 (a chain of trust between package authors) seems culturally untenable given the reactions in that thread, including from well-known package authors.

        3 replies 3 retweets 44 likes
        Show this thread
      5. Gary Bernhardt‏ @garybernhardt 2h2 hours ago

        There was an option 3: don't decompose your application's dependency graph into thousands of packages. People who argued that position were dismissed as (to paraphrase heavily) old and slow. That ship has sailed, and now we're here.

        10 replies 45 retweets 161 likes
        Show this thread
      6. Gary Bernhardt‏ @garybernhardt 42m42 minutes ago

        Gary Bernhardt Retweeted

        It was cryptocurrency. Of course. https://mobile.twitter.com/joepie91/status/1067123980711198727 …

        Gary Bernhardt added,

        This Tweet is unavailable.
        4 replies 22 retweets 76 likes
        Show this thread
      7. Gary Bernhardt‏ @garybernhardt 23m23 minutes ago

        We knew that this was coming.https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5 …

        1 reply 16 retweets 45 likes
        Show this thread
      8. End of conversation
      1. New conversation
      2. Marcin Krzyzanowski‏ @krzyzanowskim 1h1 hour ago
        Replying to @garybernhardt

        Wellpic.twitter.com/jR13oY2F1D

        2 replies 12 retweets 27 likes
      3. Amy Hoy  ✨‏ @amyhoy 1h1 hour ago
        Replying to @krzyzanowskim @garybernhardt

        it’s almost like relying on unvetted free labor for millions of people’s work products is a bad idea

        1 reply 21 retweets 145 likes
      4. Posty™ #BLIZZDRAWALS /NEED [Vile Fumigator's Mask]‏ @Postsemreh 46m46 minutes ago
        Replying to @amyhoy @krzyzanowskim @garybernhardt

        See also OpenSource

        1 reply 0 retweets 3 likes
      5. Amy Hoy  ✨‏ @amyhoy 35m35 minutes ago
        Replying to @Postsemreh @krzyzanowskim

        pic.twitter.com/gB5lxC1j7C

        0 replies 0 retweets 8 likes
      6. End of conversation
      1. Christian Genco‏ @cgenco 53m53 minutes ago
        Replying to @garybernhardt

        As the prophecy foretold!https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5?gi=bd4cb2868524 …

        0 replies 4 retweets 18 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. Arc‏ @rainlife__ 1h1 hour ago
        Replying to @garybernhardt

        Ahhhh, been a while since the last npm dumpster fire

        0 replies 0 retweets 19 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. ༺ Daniel Kraft ༻‏ @frigginglorious 14m14 minutes ago
        Replying to @garybernhardt

        pic.twitter.com/jwMSPmTZIm

        0 replies 0 retweets 10 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. New conversation
      2. Greg Navis‏ @gregnavis 1h1 hour ago
        Replying to @garybernhardt

        I have a much better idea: 1. overtake a popular library, 2. relicense to require publication of the app's source code, 3. hunt down apps using it, 4. ask to publish the code or buy a custom license for a lot of money.

        1 reply 0 retweets 13 likes
      3. Michael Pumo‏ @michaelpumo 45m45 minutes ago
        Replying to @gregnavis @garybernhardt

        Wouldn’t that be locked down to the version though? You can’t just retroactively ask for money if you installed the version under a current license at that particular moment.

        1 reply 0 retweets 0 likes
      4. Nicolás Álvarez‏ @nicolas09F9 43m43 minutes ago
        Replying to @michaelpumo @gregnavis @garybernhardt

        Yes it would. Did you review the license of every dependency (transitively) last time you did an update?

        0 replies 0 retweets 1 like
      5. End of conversation
      1. hikire‏ @hikire_ 36m36 minutes ago
        Replying to @garybernhardt @flybayer

        Option 4: never transfer packages

        0 replies 1 retweet 2 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. Arthur‏ @ArthurBrussee 55m55 minutes ago
        Replying to @garybernhardt

        Turns out it's crypto of course it's crypto aaaah

        0 replies 0 retweets 3 likes
        Thanks. Twitter will use this to make your timeline better. Undo
        Undo
      1. New conversation
      2. Robert Pearce‏ @RobertWPearce 37m37 minutes ago
        Replying to @garybernhardt

        Relying on one person to shoulder the burden for a highly used package is a symptom of a systemic problem. At what point should a package have a maintainers / working group? Is it ad hoc? Is there a threshold?

        1 reply 0 retweets 3 likes
      3. 1 more reply

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2018 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info