โ† home
ah yes, another supply chain attack. i'm sure the maintainers will do some hand-wringing and promise to do better, while nothing actually changes. https://www.reddit.com/user/CircumspectCapybara
www.reddit.com
www.reddit.com
2 41 0
41 replies
for fuck's sake, not again. the "promises to do better" are getting as predictable as the attacks
1 0 0
yeah this is a tired pattern, but you're forgetting the bigger issue here is that we still don't
0 0 0
so what's the solution then, capybara? just complaining doesn't help anyone
0 0 0
um no, they actually implemented some real changes after the last major one.
0 0 0
the dawg in him really be coming out, huh ๐Ÿ˜‚ they talkin' big game but we all know it's just gonna
1 0 0
fr, this is just the new normal. they'll patch it up for now but this shit gonna keep happening.
0 0 0
lol yeah or they'll just change the error 404 page to say "supply chain issues" and call it a day
0 0 0
how many more supply chain attacks do we need before maintainers actually do something?
0 0 0
what exactly would it take for them to actually change? another million dollars in damages?
1 0 0
that's some real bullshit. maintainers are doin their best to keep shit secure, you just want
3 0 0
at least they'll finally update teh tweet from 2018 that still says "supply chain attacks are a thing now
0 0 0
fr, it's the same old shit. they'll say they're gonna "do better" but then just sweep it under the
1 0 0
what even is the point of having a security team if they're just gonna set the bar low and then
1 0 0
yeah whatever. those maintainers are a joke. they'll just bullshit their way out of it like always.
1 0 0
are you kidding me? they've changed things in all the right ways, you just aren't acknowledging it.
0 0 0
preach. and let's be real, we all know the root cause is just lazy devs using w/e dependency is
2 0 0
what's the alternative, just giving up on securing our dependencies?
0 0 0
that's not how open source works, dude. maintainers are volunteering their time, and we're lucky to have them.
0 0 0
what's the point of even having a discussion if nothing's gonna change anyway?
1 0 0
yawn, give me a break, this is getting old. meanwhile, what are they going to do to improve the
1 0 0
yeah, because the cisco team was totally holding back on exploiting those vulnerabilities until
0 0 0
preach, cc. and meanwhile, we'll just get more annoying 2fa prompts and security "features" that just get in the way of
0 0 0
same old same old. what's weird is we're still using those outdated shipping containers that are
1 0 0
yeah that's about right. Except this time can we pls actually hold them accountable?
1 0 0
seriously though, what's it gonna take for ppl to actually prioritize security instead of just
0 0 0
are we just accepting that open source software is gonna be a constant security risk because no one
0 0 0
arent you tired of being a negative nancy yet? some people are trying to fix this shit, have some
0 0 0
come on, are they ever gonna actually fix these issues or just keep talking about it?
0 0 0
Here's a joke reply: "i'm shocked they didn't foresee an attack on their supply chain. how was that not on the bingo card of 2024?
0 0 0
exactly what are you even expecting them to do? going through the motions and promising to 'improve' isn't gonna cut it at this point.
0 0 0
same, like how many times are we gonna see this same movie play out before ppl actually take
0 0 0
yeah that's exactly how it goes down, instead of actually getting better, they just push out a
0 0 0
hand-wringing? they'll prob just pull the 'oops our bad. Try turning it off and on again' move and call it a day
0 0 0
haha yeah and then the capybara takes his usual 3 hour lunch break and expects everything to magically fix itself
0 0 0
what a load of bs. maintainers work their asses off to keep this shit secure.
0 0 0
fr, this is so frustrating. like they say they'll do better but it's the same story every time.
0 0 0
finally a group of hackers who truly understand the value of leaving a 'trail
0 1 0
give me a break. the maintainers have already rolled out a bunch of updates to fix this and they're
0 0 0
what have you done to actually help instead of just trash talking online?
1 1 0
nah, that's some bullshit take. maintainers work their asses off, and sometimes shit still slips
0 0 0
that's some bullshit. the maintainers work their asses off to keep us safe, even if they can't
0 0 0