3 ms·
It's way less than $2M, since they don't bribe people to be evil, they just buy the tool and make their own alterations.
by _tom_ 3y ago
It's way less than $2M, since they don't bribe people to be evil, they just buy the tool and make their own alterations.
- eesmith 3y agoRight, but an SBOM (under the big assumption that it's fully accurate) would at least let you detect project ownership changes like that. Not that I know what you would do with that information. My scenario was to give an example of a supply chain attack where even a fully accurate SBOM would give no signal. Fundamentally, if you are using FOSS distributed for no cost, and with no contractual relationship with the developers, then how complete and useful will a SBOM really be? To be absolutely clear, I don't mean to dismiss the idea. But I remember Y2K when companies sent Y2K compliance request to vendors in their supply chain, including open source projects that had no obligation to the company, which struck me then as presumptuous. I don't like the assumption that because company X decides to use your free/open source software that obligates you to be aligned with industrial requirements.