Post #498190
2026-02-07 00:12 UTC
We need better tools for uncovering phantom binary dependencies. Not having these tools makes our global tech infrastructure less secure, and puts a strain on the Open Source maintainers we rely on.
I collected some resources on this topic in this new post.
https://vlad.website/binary-dependencies-identifying-the-hidden-packages-we-all-depend-on/
Replies (3)
-
@vladh@merveilles.town 2026-02-07 00:13
Huge thanks to @andrewnez@mastodon.social and @sethmlarson@mastodon.social for their help 🙏
-
@jbm@infosec.exchange 2026-02-09 07:44
@vladh@merveilles.town me embedded caveman. Lot of C. This good. Me like.
-
@jbm@infosec.exchange 2026-02-10 07:43
@vladh@merveilles.town more seriously, a couple of things: Actually, embedded people do not care that much about _binary_ stuff, because we build everything from sources. In long and complex supply chain of providers, for 10+ years products, this was not necessarily the case in _some_ industries. But as for me, it's been 25 years of source code only... ...except for very small payloads, in the order of kbytes, for drivers chipsets (wifi, bluetooth,...).