Hacker News new | ask | show | jobs
by TheCabin 1928 days ago
Many people here say that slowing down is a must -- and I agree it's probably the best solution -- but surely there are more approaches we could think of:

* Not allowing packages with similar names to popular ones

* Not allowing packages creation to be anonymous (in the extreme case you would require to validate your passport or similar)

* Automatic detection of malicious code

* Central auditing organization ...

This is just on top of my head, there must be many more ideas.