Elektrine lite

← Feed

@coderanger@cloudisland.nz

Post #1398870

2026-03-23 21:32 UTC

@malwareminigun @chansecodina It would help a little, it would have created a new roadblock to this kind of attack. But in the end all that roadblock does is force an attacker to spend extra time finding a weak point somewhere in the strong-set, one person who is indirectly trusted but does a bad job vetting new friends. Maybe that adds a year to the timeline but we have 100% proof that these attackers are extremely patient so I don't feel much better overall. And of course the next time this happens, a human won't have been doing anything for that year, it will be some horrible LLM conglomeration spinning a loop with minimal oversight.

Replies (2)

  • @coderanger In this case the xz maintainer 'organization' was one person, and that one person is also who gave JiaTan access.

    Open ##1398873

  • @chansecodina@sunny.garden 2026-03-23 22:32

    @coderanger @malwareminigun All we can *ever* hope to do is make the attacker's job harder. Right now we can tell people "Hey, you should vet new contributors to your projects" and they'd (correctly!) ask "How should I vet them?". I think a web of trust could be one part of "how you vet people". In my mind we're talking about two "problems" right now: 1) As a group, we're still assuming good intentions of Internet strangers and that's no longer warranted 2) We don't have good tools for *easily* visualizing relationships, so it's annoying to try and vet newcomers to a project A web of trust doesn't solve (1), but I think it could be a part of (2).

    Open ##1398875