Elektrine lite

← Feed

@janpet@ruby.social

Post #3163978

2026-06-07 10:03 UTC

@pointlessone@status.pointless.one I thought the idea is that it 1) gives time to security researchers 2) when it was released by stealing tokens, it gives the organization time to notice that and rollback. But I might be wrong, and will be glad for more info.

Replies (1)

  • @janpet@ruby.social 1) It does but the research is implicit. If no one even looks cooldown will expire eventually. There's way too many packages to be examined by security researchers. And security research is not how most compromised packages are detected. xz story is much more common: a regular user (i.e. not a security researcher) investigates some weird behaviour. 2) cooldowns do not solve this issue. Cooldowns let someone else install a package before you. It somewhat limits impact on the ecosystem level but on the individual org/user level it doesn't do anything. You get infected when you install the package. The whole premise is that the first affected will raise the issue and it will get addressed within the cooldown period. In effect, cooldowns are antisocial. They don't prevent installation of a compromised package, they only let someone else be affected first. And hope they will notice and escalate the issue before it's your turn to install the package. The only good thing about cooldowns is that they're very low effort.

    Open ##3163977