Skip to content

Comment on The many (many) ways I've backdoored your dependencies and other supply chain atparent

Comments

Agreed. Next step, it'd be just great if most open source software (and presumably most non-OSS code, although that's harder to determine) didn't pull in half the internet as mostly pointless dependencies. While we're at it, it'd be sweet if major OSes like Windows and most Linux distros would move to a threat model of "machine is used by one or more users who each want to safely run untrusted code without risking their own files, safety or privacy" instead of the old "machine is shared by many users and our main concern is guarding them against each other" model.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.