Comment on Analysis of supply-chain attack on UltralyticsparentComments−ashishbijlani1yIf the tech is open-sourced, then an attacker can keep trying in private until they find an exploit, and then use it.So you'd rather assume that if something is obscure, it is secure?−amelius1yI'm just pointing out a huge downside of the approach and that more measures such as pen testing are really needed. I don't want to be right, I want a secure PyPI <3
Comments
So you'd rather assume that if something is obscure, it is secure?
I'm just pointing out a huge downside of the approach and that more measures such as pen testing are really needed. I don't want to be right, I want a secure PyPI <3