Hacker News new | ask | show | jobs
by hiccuphippo 226 days ago
I'd guess one MO is to delete a malicious package/url shortly after releasing it to prevent researchers from getting to it.
1 comments

So they wouldn't make a release immutable?
Which means the tainted release doesn't matter anymore to those consumers worried about the immutable release attestation anyways. If others are worried about that, they should probably consume only attested immutable releases as well.

I'd still bet the larger portion was it was just a particularly easy path to preventing downgrade attacks or the like though. Could always be more to it as well I'm not thinking of, just feels likely.