Hacker News new | ask | show | jobs
by gr4vityWall 343 days ago
I think bflesch's reasoning comes from the idea that the website developers may not hold their website to the same security standards as their software, and not from a trust issue. Nor from thinking the author themselves are malicious.

FWIW, I don't have a strong opinion here, besides that I like Debian's model the most. Just felt that it was worth to point out the above.

1 comments

See the codecov incident, where exactly this happened: https://about.codecov.io/security-update/