Hacker Talks
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
codeinabox@programming.dev to Security@programming.devEnglish · 18 days ago

Minimum Release Age is an Underrated Supply Chain Defense

daniakash.com

external-link
message-square
6
link
fedilink
29
external-link

Minimum Release Age is an Underrated Supply Chain Defense

daniakash.com

codeinabox@programming.dev to Security@programming.devEnglish · 18 days ago
message-square
6
link
fedilink
Minimum Release Age is an Underrated Supply Chain Defense | Dani Akash
daniakash.com
external-link
A 7-day package delay would have blocked installs in most short-lived malicious publish attacks from the last 8 years
alert-triangle
You must log in or # to comment.
  • TomasEkeli@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    13 days ago

    There is some truth to this - staying on the bleeding edge exposes you to things earlier.

    Not really surprising, but maybe a consequence people who want to be on the latest version immediately did not consider. Good article!

  • _‌_反いじめ戦隊@ani.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    3
    ·
    17 days ago

    incompatible with capitalism

    • duckythescientist@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      17 days ago

      Did you comment this on the wrong post?

      • _‌_反いじめ戦隊@ani.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        17 days ago

        Nope.

        • duckythescientist@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          16 days ago

          Do you expect there to be no crime and no money if capitalism is replaced? And effort toward mitigating supply chain hacks is definitely compatible with capitalism especially with such an easy mitigation as proposed in this article.

          • _‌_反いじめ戦隊@ani.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            16 days ago

            But then your unsecure, cheap, and fast competitor will upload the features and solutions of your scope 14 days ahead of you, over and over again, until you’re suddenly years behind the rest. Are this unaware of the modern business deployment model?

Security@programming.dev

security@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don’t be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 269 users / week
  • 391 users / month
  • 640 users / 6 months
  • 1 local subscriber
  • 2.06K subscribers
  • 98 Posts
  • 111 Comments
  • Modlog
  • mods:
  • Vacant@programming.dev
  • UI: unknown version
  • BE: 0.19.17
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org