Hacker News new | ask | show | jobs
by queenkjuul 133 days ago
Is there really a supply chain vulnerability of you inspect the app and never update it?

This is, for me, a "set and forget" kind of tool -- why would i need to update a script?

1 comments

Are you really inspecting every app you install, including all its dependencies, and the dependencies of those dependencies, to a level of detail sufficient to identify sophisticated and obfuscated backdoors?

In the real world, nobody does this. Instead, you make a conscious choice to trust the apps that you install. Every decision of whether to install an app is a tradeoff between (a) the risk that that trust is misplaced, and (b) the benefits of the app.