Post #1398887
2026-03-24 18:36 UTC
@malwareminigun @hyc @coderanger Well, there's two parts to the JiaTan situation:
1) Attackers gained control of the project
2) Attackers (now project owners) published malware
I can't think of any way to mitigate (2), but I can think of some ways to make it slightly easier to defend against (1). I'm open to ideas though!
Replies (1)
-
@malwareminigun@infosec.exchange 2026-03-24 20:27
@chansecodina @hyc @coderanger I see no technical solutions to defend against (1). The only solution to (1) is for users of a project to somehow pay for at least 2 people to be maintainers of the thing. At the end of the day we are delegating trust to the project maintainers, and that one person delegated control of their system to someone else.