|
|
|
|
|
by jabbany
265 days ago
|
|
I think it's just because supply-chain attacks are not common enough / their attack surfaces not large enough to be worth the dev time... yet... Sneak in a malicious browser extension that breaks the permissions sandbox, and you have hundreds of thousands to millions of users as an attack surface. Make a malicious VSCode/IDE extension and maybe you hit some hundreds or thousands of devs, a couple of smaller companies, and probably can get on some infosec blogs... |
|
Attackers just have to hit one dev with commit rights to an app or library that gets distributed to millions of users. Devs are multipliers.