4 ms·
Supply chain attack is a trust issue. I don't know what these tools do but if it's software then there is one more link you must trust in supply chain. Soluti
by _int3_ 4y ago
Supply chain attack is a trust issue. I don't know what these tools do but if it's software then there is one more link you must trust in supply chain.
Solution is to go the other way , you don't bloat your software with too many dependencies. That way you minimize your attack surface.
- drewcoo 4y agoYes, it's about trust. But what aspects? Is it just "I trust that and there's not much there, ok we're secure?" It's a little more complicated. The stuff in the article is about leaving audit trails to verifiable identities taking known actions. To quote Ronald Reagan, tongue in cheek, "trust but verify."