4 ms·
I think the point was that open-sourced apps aren't vulnerable to an attack vector like this, which is true. Of course, not everything can be open-sourced, but
by aaronyarborough 2y ago
I think the point was that open-sourced apps aren't vulnerable to an attack vector like this, which is true. Of course, not everything can be open-sourced, but the poster's point still stands.
- Hamuko 2y agoExcept that it's not really true, since open-sourced applications can and most definitely have changed maintainers. And even if they don't, there's still a risk. Do I need to remind everyone of the xz incident when it's so recent?
- Aurornis 2y agoOpen sourced apps are absolutely vulnerable to this “attack vector” Did you already forget about the back door in xz utils?