29 ms·
Insane, yes, but I guess it's just never really been that much of a problem until now. Hopefully something good will come out of this..
by henrikfr 11y ago
Insane, yes, but I guess it's just never really been that much of a problem until now. Hopefully something good will come out of this..
- smt88 11y ago> it's just never really been that much of a problem until now That's a reasonable excuse in the 90s, before automatic updates over HTTP were common. Our industry now has decades of experience securing HTTP updates and package managers, with various Linux solutions demonstrating good practices.
- CorpOverreach 11y agoYou would think this is part of security 101 for these things... And people wonder why big enterprises are scared of touching open source stuff.
- nyan4 11y ago> And people wonder why big enterprises are scared of touching open source stuff. some open source stuff. Most enterprises dig distributions, especially with LTS.
- cyphar 11y agoMany big enterprises run on free software. Just because this particular free software project is a shit-show doesn't make all free software projects this bad.
- gst 11y agoSomething similar is (or at least was) true for Github: I changed my username a couple of years ago and I recently found out that another user is now using my original username. Less of an issue due to the much longer timeframe, but I think not allowing username re-use would be a safer choice.
- FranOntanaya 11y agoModule repositories have been a thing for decades. Even a platform as crusty-old as WordPress doesn't allow repository take-overs for plugins. Surely someone had some experience outside npm to think about this.