2 ms·
security researchers not the ones shipping the faulty code.
by weaksauce 4mo ago
security researchers not the ones shipping the faulty code.
- teeray 4mo agoWe’re not talking about security researchers here: > there is lots to gain from being the first to write about the new malware on some registry, so *companies* are actively downloading and inspecting literally every package. (Emphasis mine)
- john_strinlai 4mo ago>We’re not talking about security researchers here: we are. "companies" in this context is "security companies" (hence why they are "downloading and inspecting every package", which would not make sense if referring to the people authoring and shipping a single package)
- weaksauce 4mo agoyeah security researchers at security companies are the ones we are talking about.