Hacker News new | ask | show | jobs
by charcircuit 39 days ago
But how many of those attackers also had the ability to publish a github commit but didn't to remain more stealthy.
1 comments

This question is meaningless. Attackers will pick the best attack if they have more at their disposal. The fact that they didn't push a commit shows it's better not to. So closing that attack is good.
There is meaning. The difference in detection time does have meaning. If the improvement of detection time was marginal there may have been a different project time could have been invested in to make it even faster to catch such things than reproducible builds.