Skip to content

Comment on Ubuntu 24.04 (and Debian) removed libsystemd from SSH server dependenciesparent

Comments

What could be done to prevent supply chain attacks more broadly?

The UNIX philosophy was right all along - each tool does one simple thing.

I can't tell if this is sarcasm or not.

Most things we want to do are necessarily complex, so dogmatically adhering to "one simple thing" necessarily drives you towards a towering heap of composed dependencies.

If you want to get rid of the supply chain, you want everything specifically to be non-composable, so that everything has to be reinvented from scratch for that specific solution.

Try that supply chain attack on dropbear running as ssh server on devuan. Simple utility on a simple system made of simple utilities

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.