Elektrine lite

← Feed

@malwareminigun@infosec.exchange

Post #1398841

2026-03-23 20:35 UTC

@chansecodina @coderanger The problem is that web of trust would have done nothing against JiaTan. They were the upstream maintainer and had permission at a project level to mint the release they minted so they would have had the right keys.

Replies (2)

  • @coderanger@cloudisland.nz 2026-03-23 20:39

    @malwareminigun Presumably in a WoT world, the original maintainers would have checked who vouched for this new guy before adding them as a maintainer. Which just moves the problem from "socially engineer a project owner" to "... someone a project owner trusts, directly or indirectly". This is kind of an improvement but not in a hugely meaningful way.

    Open ##1398842

  • @chansecodina@sunny.garden 2026-03-23 21:12

    @malwareminigun @coderanger You can't expect to solve all social problems with technical tools. That said, if a group of accounts, all with zero external relationships in the web of trust, mounts an influence campaign to get one of their own members made into a project maintainer it's going to look fishy.

    Open ##1398862