Elektrine lite

← Feed

Anant Shrivastava aka anantshri

anant@social.anantshri.info

<p>Researcher | Trainer | Security Professional | Developer | Admin</p><p>I talk about <a href="https://social.anantshri.info/tags/linux" class="mention hashtag" rel="tag nofollow noreferrer noopener" target="_blank">#<span>linux</span></a>, <a href="https://social.anantshri.info/tags/security" class="mention hashtag" rel="tag nofollow noreferrer noopener" target="_blank">#<span>Security</span></a>, <a href="https://social.anantshri.info/tags/infosec" class="mention hashtag" rel="tag nofollow noreferrer noopener" target="_blank">#<span>infosec</span></a>, <a href="https://social.anantshri.info/tags/android" class="mention hashtag" rel="tag nofollow noreferrer noopener" target="_blank">#<span>android</span></a>, <a href="https://social.anantshri.info/tags/androidsecurity" class="mention has

Posts

  • Post #2193995

    Everyone&#39;s suddenly calling dependency cooldown the grand solution to software supply chain attacks. It isn&#39;t. Cooldown helps only if the malicious payload is discovered, reported, and fixed during your cooldown window. Its success depends on someone else getting hit first, investigating first, reporting first, and cleaning up before your timer expires. I&#39;d call that outsourced blast absorption. There&#39;s a flip side. If the update contains a security fix, cooldown keeps you vul...