Chris Heilmann, Daniel Cranney & Zbyszek Tenerowicz

WeAreDevelopers LIVE - Node and Package Security

Even a harmless linter plugin can be hijacked to exfiltrate your environment variables. Here's how to stop malicious post-install scripts before they execute.

WeAreDevelopers LIVE - Node and Package Security
#1about 9 minutes

Exploring the past and future of mobile phone technology

A discussion on the history of open source mobile operating systems like Firefox OS and the design challenges of modern foldable and modular phones.

#2about 7 minutes

Navigating the new EU law for labeling AI-generated content

The EU now requires clear labeling for deepfake and AI-generated content to combat misinformation, raising questions about enforcement and impact.

#3about 8 minutes

Balancing AI assistance with human-curated content quality

Using AI for research and summarization can be effective, but maintaining quality requires significant human curation and editorial oversight.

#4about 7 minutes

The push to eliminate frustrating cookie consent banners

A new EU proposal aims to replace cookie banners by relying on browser-level privacy settings, addressing user frustration and malicious compliance.

#5about 6 minutes

Showcasing unique web tools and creative data projects

A look at several clever web projects, including an anti-scraper font, a Wikipedia image sticker generator, and an IKEA assembly complexity index.

#6about 7 minutes

Understanding password cracking and quantum computing threats

An analysis of password strength shows how quickly they can be cracked, while projects like ECDSA.fail advance algorithms for future quantum attacks.

#7about 7 minutes

Playing a game of real vs fake tech news headlines

A fun segment challenges guests to distinguish between actual technology news stories and fabricated, plausible-sounding headlines.

#8about 7 minutes

Securing your project with the Lavamoat Harden tool

Lavamoat Harden is a new tool that automates optimal security configurations for npm, pnpm, and yarn to protect against supply chain attacks.

#9about 10 minutes

Limiting script permissions for enhanced project security

Lavamoat Harden can restrict package.json scripts by limiting their disk and network access, preventing malicious behavior from dependencies like linters.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles

From learning to earning

Jobs that call for the skills explored in this talk.