3 ms·
What's your suggestions on how oss maintainers can fend off state actor attacks? Always need two people to sign off on a patch? I strongly agree that supply ch
by squaresmile 5y ago
What's your suggestions on how oss maintainers can fend off state actor attacks? Always need two people to sign off on a patch?
I strongly agree that supply chain attack is a huge deal and worse attacks will come to light eventually but what should be done at the level of oss maintainers?
Like you said, I feel like Open source projects by random solo maintainers that the security of almost everyone on the internet relies on... can't do a lot of things.
- lrvick 5y agoDual cryptographic sign off is exactly what I recommend and have been prototyping tools to make this easier: https://github.com/distrust-foundation/sig https://github.com/distrust-foundation/sig