What is Nostr?
yossarian (1.3.6.1.4.1.55738) /
npub1srp…h23s
2024-03-29 23:20:19

yossarian (1.3.6.1.4.1.55738) on Nostr: my only contribution to the xz discourse: absolutely none of the supply chain stuff ...

my only contribution to the xz discourse:

absolutely none of the supply chain stuff we're currently doing, including the things i like, would have stopped this. the only things that can stop this are (1) compulsively treating all code as untrusted, and (2) way, way stronger capability checks and restrictions in running systems. (1) is economically infeasible (the world runs on free labor from OSS), and (2) has had only very limited practical success.
Author Public Key
npub1srpm3cp2mnr5efng42p2ae594h3al2xhw0u87ef27q7x23u9cj4q3uh23s