Hacker News new | ask | show | jobs
by bitwize 775 days ago
Jonathan Blow ranted about the susceptibility of open source to supply chain attacks from state actors, which discussion recently became germane again in light of the xz backdoor.

What he didn't discuss was how vulnerable proprietary vendors (including, but by no means limited to, Microsoft) are to "rubber-hose vulnerability injection".

Anyway, it's good to see Microsoft actually participating in the open source process.