Hacker News new | ask | show | jobs
by Kalium 1732 days ago
You're absolutely right! You can trust that a community, given sufficient time, will act to protect itself in the long-term and thus individual users. This just might not always be the same as every user being maximally safe at every point in time.

Case in point that gets at both: malicious python and npm packages stealing credentials. They were caught and handled, but not before hitting some people.