Presentation: Making Npm Install Safe
This presentation is now available to view on InfoQ.com
Watch videoAbstract
There’s a JavaScript package for everything. But installing a random package is a security nightmare: the installed package can access your data and send it over the network without anyone ever knowing.
But there’s hope! This talk will discuss how to minimize the risks of running third-party JavaScript. We’ll go over POLA, the Principle of Least Authority, and how object capabilities can help us grant specific, limited resources to third-party code. We’ll also cover the current efforts to enforce security boundaries in JavaScript: SES (Secure ECMAScript) and Realms.
Similar Talks
Pick Your Region: Earth; Cloudflare Workers
Core Rust Team @RustLang
Ashley Williams
License Compliance for Your Container Supply Chain
Open Source Engineer @VMware
Nisha Kumar
Optimizing Yourself: Neurodiversity in Tech
Consultant @Microsoft
Elizabeth Schneider
[CANCELLED] Balancing Priorities: Revenue Generation vs. Revenue Protection
Director of Digital Transformation @Tasktop
Dominica DeGrandis
Mapping the Evolution of Socio-Technical Systems
Agile Methods Coach & Advocate for Woman in Tech
Cat Swetel
Coding without Complexity
CEO/Cofounder @darklang
Ellen Chisa
CI/CD for Machine Learning
Program Manager on the Azure DevOps Engineering Team @Microsoft
Sasha Rosenbaum
Observability in the Development Process: Not Just for Ops Anymore
Cofounder @honeycombio
Christine Yen
5 Simple Tools to Unlock Innovation
Director of Engineering @GravityPymts