Samuel Attard Profile
Samuel Attard

@MarshallOfSound

Followers
974
Following
416
Media
59
Statuses
1K

Building at @AnthropicAI | Former Desktop at @SlackHQ, Eng @ @NotionHQ | Creator of GPMDP | Helping build @electronjs | Contributing to Node, Chromium and OSS

Vancouver, British Columbia
Joined September 2013
Don't wanna be here? Send us removal request.
@MarshallOfSound
Samuel Attard
1 month
@martinwoodward The fact this keeps happening is great for @SocketSecurity, what @feross & team have built is amazing. But surely as an ecosystem we can be doing more to stop this kind of token compromise from even starting. GitHub owns the registry and the majority source of publishes (GHA). .
1
2
3
@MarshallOfSound
Samuel Attard
1 month
Who do I need to talk to to make any of these happen @martinwoodward? Heck if you sign me up as a contractor for $1 I'll build some of them for you.
1
0
2
@grok
Grok
8 days
Generate videos in just a few seconds. Try Grok Imagine, free for a limited time.
416
686
3K
@MarshallOfSound
Samuel Attard
1 month
* Allow npm developers to _advertise_ what level their npm package is secured with (2fa-only, publish-token, any-token). All of these would meaningfully move the needly in both ecosystem and enterprise security for the npm registry.
1
0
1
@MarshallOfSound
Samuel Attard
1 month
* Any package published with GHA based provenance _ever_ should require a manual 2FA invention on the first subsequent deploy that does not have provenance.
1
0
1
@MarshallOfSound
Samuel Attard
1 month
* Enforce 2FA globally, not just specific accounts.* New tokens should not be allowed to publish till approved via email on the same IP that requested them.
1
0
1
@MarshallOfSound
Samuel Attard
1 month
When is GitHub going to step up as the current stewards of npm and enforce 2FA globally. This keeps happening, and the answer is always "developers should enable 2FA" and not "the registry needs to change drastically". There are steps that be taken very quickly to make npm safer.
@SocketSecurity
Socket
1 month
🚨 Active supply chain attack on #npm: Multiple Prettier tooling packages were compromised through the phishing campaign we published about just hours ago. Watch out for more compromised accounts and malicious packages. Follow-up post: #nodejs.
1
3
8
@MarshallOfSound
Samuel Attard
2 years
Is it still a sub tweet if you tweet it early
@electronjs
Electron
2 years
Earlier today, the Electron team was alerted to several recent CVEs filed against an Electron Fuse setting. These reports are incorrect, and seem to be filed in bad faith. More information here:
0
0
3
@MarshallOfSound
Samuel Attard
2 years
I don't know who needs to read this, but it isn't remote code execution if you have to run a command in a shell to do it. That's physically local, and in the majority of cases is not a critical CVE. Good reference from the Chrome security team.
1
0
9
@MarshallOfSound
Samuel Attard
2 years
Who do I talk to about 500kb of undici taking up 2MB in the node executable. @ArrowoodTech 👀
Tweet media one
4
0
3
@MarshallOfSound
Samuel Attard
2 years
This is important for anyone building electron apps to read. * Make sure you're up to date.* Don't turn the sandbox off.
@electronjs
Electron
2 years
In the wake of CVE-2023-4863, here's an overview from @felixrieseberg on why it's a good idea to use Electron's process sandbox, and how to enable it in your own app:
0
3
11
@MarshallOfSound
Samuel Attard
3 years
RT @JasonEtco: Thinking of starting a YouTube channel in which I review PC cases from the perspective of "cat comfort" - how easy it is to….
0
6
0
@MarshallOfSound
Samuel Attard
4 years
M1 Max is gamechanging for people doing excessive amounts of compilation (read "work on Chromium"). My old fully specced out i9 macbook took 23 minutes to build Electron from source (using our distributed build + cache). The M1 Max does the same thing in 9 minutes flat. .
4
12
60
@MarshallOfSound
Samuel Attard
4 years
RT @george_xuuu: Browsing in incognito mode at work so when I screen share w my mentor they wont see me googling “how to center a div”.
0
2
0
@MarshallOfSound
Samuel Attard
5 years
Today I discovered I've spelled "tenant" wrong in a project for the last 4 years. I think the correct thing to do here is click the "add to dictionary" button 😅
Tweet media one
0
0
11
@MarshallOfSound
Samuel Attard
5 years
Tracking down the commit I originally wrote some code in, hoping Past Sam left me a clue as to my intentions. I don't know why I even bother anymore 😂
Tweet media one
3
0
12
@MarshallOfSound
Samuel Attard
5 years
Couple of months of hard work, but we're here and ready for the future of Macs.
@SlackEng
Slack Engineering
5 years
Our friends at @Apple are building the future of Macs with Apple-designed processors and we're excited to be along for the ride. Today, Slack for macOS Beta supports Apple silicon without emulation. Get it at – we're looking forward to your feedback!.
0
0
9
@MarshallOfSound
Samuel Attard
5 years
RT @eevee: oracle is bustling with excitement and activity as entire boardrooms of executives try to figure out how to charge tiktok users….
0
90
0
@MarshallOfSound
Samuel Attard
5 years
This one contains a nice surprise for anyone out there with a DTK.
Tweet media one
0
2
11
@MarshallOfSound
Samuel Attard
5 years
Fun thing I got working earlier this week. We have launch-able dev builds of @electronjs for Apple Silicon. Decent way to go still but this is great early progress.
Tweet media one
1
5
45