Skip to content

Comment on The many (many) ways I've backdoored your dependencies and other supply chain atparent

Comments

Ultimately, enough money/political capital will be lost such that the deciders will move towards Capability-based security[0] stances... oh, who am I kidding? It'll just be the Certification Game round NaN.

[0] That really is the only fail-closed way to do it. Everything else is theater... good theater, but theater.

EDIT: Btw, I do not mean to be dismissive towards lower-level/higher-sophistication security issues like side-channels, etc... but that's peanuts to ordinary Bad Guys. (Nation states might be more interested in advanced things). Most Interweb Bad Guys use very simple techniques, like bad writing in a scam email.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.