Elektrine lite

← Feed

@JasonDJ@lemmy.zip

Post #1811131

2026-04-22 16:31 UTC

There’s been a notable uptick in supply chain attacks coming from the odd FOSS dependency. Fortunately the FOSS environment as a whole, ironically, reflects the best aspects of a “free market” in the capitalist sense. If a package is no longer maintained, or poorly maintained, or the maintainer is a douche/Russian asset, it forks and many users jump ship to the newer package. Users have full transparency into how the sausage is made. Everybody does. So if exploitable code is discovered, it can just as well be discovered first by a defensive researcher (non-inclusive term: white-hat) or offensive researcher (black-hat). And if an offensive researcher discovers it first, they have a choice: Use it and risk being spotted. Once discovered in the wild, patching is only a matter of time. Sit on it and hope a defensive researcher doesn’t find it. Submitting bad code to a project in itself though. Some new user with no reputation is going to be heavily scrutinized putting a PR on a large/popular project. And even with a good reputation, you’re still putting the exploit code out there in the open and hoping none of the reviewers or maintainers catch it.

Replies (1)

  • @Tonava@sopuli.xyz 2026-04-23 08:11

    non-inclusive term: white-hat Uh, sorry to comment besides the subject, but could someone explain why white-hat is non-inclusive? I’m not trying to argue it is not, but I had not heard that and I can’t find any answers by searching about it

    Open ##1811130