|
|
|
|
|
by otterley
2051 days ago
|
|
I would very much like to see prevention advice tacked on to analyses like these. It's very interesting to see how the vulnerabilities were exploited, but I think it would be extremely valuable to understand how to prevent future attacks such as this. What were the root causes of the vulnerability, and how can the community prevent similar ones from being created in the future? (Ideally with some automated tooling, too.) |
|
2. Don’t homogenize all the platforms.
3. Reproducible builds; in all likelihood the build server was compromised.