Post #3446766
2026-06-28 06:09 UTC
Replies (5)
-
@bagder@mastodon.social 2026-06-28 09:27
@icing@chaos.social yeah, there's a lot of creativity in coming up with different ways except actually funding or assisting projects for real...
-
@flyingpenguin@infosec.exchange 2026-06-28 10:59
@icing@chaos.social there's a lot in that article that runs without any context. I know it's all been said before so I wonder why the journalists are still fluffing up the weakest logic. huge output of potential vulns? yeah, but what's the ratio to valid and severe? should be the next sentence after raw outputs. and the refactoring claim is nice, but then it creates a new attack surface with a new set of its own vulns too. self licking ice cream cone is not supposed to be a business model. we've had the "it's getting hotter in here" for decades. saying frontier alone is turning up the heat this summer is just obviously wrong. like saying the Ukraine and Iran war caused this summer's heat wave.
-
@totoroot@ibe.social 2026-06-28 09:37
@icing@chaos.social Someone from Chainguard has cold-messaged me on LinkedIn because I followed them to see their marketing announcements. I had previously looked into them and their product, as hardened container images with minimal dependencies, build-time SBOMs and signatures sounds reasonable and something that many likely should incorporate in their #DevOps pipelines. Then I stumbled across this bullshit post and noticed that their marketing is just disingenuous fearmongering like so much of the AI-pilled industry engages in. Told them what I think about it in a response and they responded with something along the lines of "Duh, it's obviously exaggerated, but just admit that we are cool." Unfollowed them after.
-
@Di4na@hachyderm.io 2026-06-28 09:42
@icing@chaos.social here is my offer. We stop caring about these things and we actually spend money into making build systems and dependencies update works better, so that maintainers have the time to work on security one day. I would love to see research on how much time of hobbyists maintainers is spent updating dependencies, dealing with these breakages.... and the same thing with build systems...
-
@jpl@norden.social 2026-06-28 11:19
@icing@chaos.social "Affected projects are rebuilt as private, hardened versions available to Athena members through Chainguard Libraries before vulnerabilities are publicly disclosed a month later" That sounds like a GPL violation...