What is Nostr?
Julien Barnoin /
npub1amd…aj67
2024-03-30 21:44:36

Julien Barnoin on Nostr: The whole situation around the #xz backdoor really demonstrates how fundamentally ...

The whole situation around the #xz backdoor really demonstrates how fundamentally broken most development practices are.

There should be two kinds of libraries we use:
- Ones whose authors we decide to trust based on their security practices and track record
- Ones for which we're willing to read and understand the code (and dependencies) each time we update it

Package managers like npm make it way too easy to import random code.

Of course, pretty much no one does this.
#programming
Author Public Key
npub1amdyvspgrzs5r0ht8aqmdc6saq2zdsqd9xznzk073d4yp8ppe7qqlfaj67