Software is becoming more interdependent, and that’s a big security problem

by Reima Budd on Jun 28, 2022 Software 222 Views

O

n 16 March, 20 days after Russia invaded Ukraine, users of the Vue.js development framework were panicking. Vue is a set of tools that makes it easier for developers to build interfaces for websites and web applications, including at companies like Facebook, Netflix and Nintendo. According to BuiltWith, it powers 19.8 per cent of the world’s biggest 10,000 websites.

So, what does a popular programming tool have in common with the war in Ukraine? Under the hood, Vue, like all tools of its kind, relies on a bundle of other software packages that it automatically downloads. Software packages make it easier for programmers to add functionality to their applications without having to code it from scratch.

In this case, Vue included a dependency on a package called “node-ipc”, whose developer decided to add a small amount of code that would create a text file containing anti-war messages on the desktops of those who use it. But if the package was installed on a device with a Russian or Belarussian IP address, it would also start wiping files from the device and replacing them with a heart emoji.

This was not the first incident of its kind. Earlier this year, the developer of two other popular packages sabotaged them by modifying them to produce gibberish text instead of their expected output.

These incidents show how software developers rely on an increasingly large ecosystem of third-party packages. While these packages can greatly simplify and speed up development, they also have wide security implications.

Read more about the blog in-depth here.

 

Article source: https://article-realm.com/article/Computers/Software/24139-Software-is-becoming-more-interdependent-and-that-s-a-big-security-problem.html

Reviews

Guest

Overall Rating:

Comments

No comments have been left here yet. Be the first who will do it.
Safety

captchaPlease input letters you see on the image.
Click on image to redraw.

Statistics

Members
Members: 16307
Publishing
Articles: 66,152
Categories: 202
Online
Active Users: 1209
Members: 14
Guests: 1195
Bots: 6337
Visits last 24h (live): 2937
Visits last 24h (bots): 16732

Latest Comments

Good work! we can apply all the major keypoints for our business. Kindly share some more about trendy distribution points for the business holders. Will back soon on ur work page after wind up my...
For more information on how to download and use the Chinese version of Telegram, please visit our external blog link: Telegram下載   
FNF is an entertaining rhythm game that tests players' musical skills with catchy tracks that appeal to the gaming audience.
Companies that aspire to adapt and succeed in the business are leveraging the benefits of emerging trends.
Designer handbags have long been synonymous with sophistication, status, and impeccable craftsmanship. These fashion staples are more than just accessories; they are investments in artistry,...