Elektrine lite

← Feed

@joshbressers@infosec.exchange

Post #4243639

2026-07-30 14:42 UTC

I wrote a blog post You don't have a supply chain, you have a supply soup This is something I want to spend some time investigating in the future, it's all vastly more complicated and weird than we think it is https://opensourcesecurity.io/2026/07-supply-soup/

Replies (5)

  • @joshbressers@infosec.exchange “If your first thought was software can’t cause explosive diarrhea you have never tried to debug C++.” LOL

    Open ##4243850

  • @joshbressers@infosec.exchange definitely infuriating that the startups are getting gigabucks to shit on the repos while the repos themselves only get an occasional crumb

    Open ##4252506

  • @icing@chaos.social 2026-07-30 19:25

    @joshbressers@infosec.exchange That was a nice post! But i guess even the soup metaphor is giving business too much credit. No one is planning or strategizing anything. It‘s all. just a shot from the hip, hoping to be John Wayne riding into the sunset.💁🏻‍♂️

    Open ##4263441

  • @Di4na@hachyderm.io 2026-07-30 20:40

    @joshbressers@infosec.exchange good post. I like the metaphor. I have thought like that for a long time. Here is my personal take. Accept it as an immutable fact. You cannot beat it. The complexity and recursive aspect of it is what fundamentally make it works. The more we accept the constraints, the more we can find a solution. Because once you eliminated the impossible, what is left is the only thing that make sense. And that, to me, means that we are going to start realising that our boundary is _every single machine used by a FOSS maintainer_. You cannot secure just your own engineers machines. You cannot secure your perimeter. That ships sailed away somewhere in the 00s. So now, what we need, is that we need to make every machine that could end up being used by a FOSS Maintainer far more secure.... Time to invest in some thinking for the CLI and all these packages you mentioned.

    Open ##4263447

  • @StaticRocket@defcon.social 2026-07-31 01:12

    @joshbressers@infosec.exchange https://www.youtube.com/watch?v=sfYNyZha0vw

    Open ##4263449