|
|
|
|
|
by georgyo
809 days ago
|
|
I'm not saying political forces won't try legislating the problem away, but that won't even help here. A supply chain attack can happen in hardware or software. Hardware has firmware, which is software. What makes this XZ attack so scary is that it was directly from a "trusted" source. A similar attack could come from any trusted source. At least with software it is much easier to patch. |
|
Open sources days of declaring “use at your risk” have become a liability in this hyper networked society. It’s now becoming part of the problem it was imagined up to solve.