There’s been a lot of buzz around npm ecosystem hacks lately.

It makes me wonder: is this about more attacks or simply more visibility?

It could be one (or all) of these:

1️⃣ Attackers are deliberately focusing on npm, and the ecosystem isn’t mature enough to handle it.

2️⃣ npm has enough visibility that even if issues aren’t caught immediately, vendors and the community can flag them.

3️⃣ npm is large, easier to monitor, and full of sloppy practices - so every vendor ends up catching something.

What nags me is the relative silence around RubyGems, PyPI, Maven, and other ecosystems.
Does that silence mean fewer attacks… or just less visibility?

Maybe the npm noise is only part of a bigger story.

#randomrambling #infosec #supplychainsecurity

Wanneer is werk eigenlijk “hard”? Gaat het om fysiek zwaar werk? Daarvoor halen we toch arbeidskrachten uit armere landen, die hier onder slechte omstandigheden en tegen een laag loon dat werk mogen doen dat wij “hardwerkende Nederlanders” niet willen doen? Of gaat het om veel uren per week maken? In internationaal perspectief scoren we daar niet bepaald hoog op: de “hardwerkende Nederlander” is in de praktijk wereldkampioen deeltijdwerk. https://rzondervan.eu/de-hardwerkende-nederlander/ #randomrambling
De hardwerkende Nederlander

Een milde tirade tegen een populistische stijlfiguur

Ruben Zondervan
I have been doing a fair amount of writing lately, I am by no means an author, I write stories that I would like to read, and even after writing them I read them over and over! It’s like a type of therapy for me. I will always be grateful for the life I chose, even thru the good and bad I chose a life worth living, and I fill it with things that bring me joy! #recoveryposse #randomrambling #grateful #neveralone

Right now #ai seems like magic bullet to all solutions. Preliminary success indicators also help the narrative. Its only when instead of teaching how to use ai you use it then you realize its shortcomings just like every other software in existence. Treating ai as yet another software more importantly as a solution still looking for right problem set is imho the way we need to look at things.

There are use-cases still but do they justify the compute power resources and cost. That is where the real rubber meet the road scenarios come into picture.

At this point everyone is squeezing all other funds to create or enlarge funds for r&d and use that for cloud or hardware for ai. This is the part which will hurt the most once people put it in prod and realise the true cost.

#randomrambling #aidisillusions #technology #itsecurity

#RandomRambling I was once in a band where the guitarist always had 3 guitars, all in different tunings (but not one in Standard!), and yet somehow ALWAYS managed to end up playing in the key of C! I don't even know how that's possible! Can anyone explain this? #Musician #Guitar #BassPlayerProblems