Intrinsic
@intrinsic
Stop trusting code. Secure your Node.js apps from bugs and malicious code. #Security #NodeJS
ID: 833502229235585024
https://intrinsic.com/ 20-02-2017 02:23:11
71 Tweet
215 Followers
0 Following
Here's @[email protected]'s talk, Property Descriptors, Getters/Setters, and Proxies, given at Node Summit 2018: nodesummit.com/prior-video/no… #NodeJS #JavaScript
"The typical #nodejs app is about 95% third party modules. Scrutinizing every line of third party code simply isn’t a realistic way of protecting yourself from these threats, which is why Intrinsic is here to protect you." - via @[email protected] medium.com/intrinsic/secu…
Rhys Arkins Renovate Bot Github diffs are useless from a security perspective. It's gotta be an npm diff, and you should be suspicious if the package is bundled before publish. Bundling should be on the package consumer
I loved working with Eran Hammer on a prototype pollution attack that can impact Node applications: github.com/hapijs/hapi/is… < Check it out.
See @[email protected] at our Meetup in San Francisco Capital One on April 4th, 6:30 pm Talk is "Real World Attacks in the npm Ecosystem" read about it here... bit.ly/2Oy6DID