Hacker News new | ask | show | jobs
by woodruffw 16 days ago
I generally try not to name the companies directly, because I don’t want to give them free advertising. But you can look up e.g. the recent Shai Hulud campaign.

> Just post one link of a "supply chain" problem that was prevented by any of these companies before it went into the wild and affected users.

This is not the claim being made, since cooldowns are not widely adopted at the moment.

1 comments

I see. So, it has never happened before.
Well, yeah. There’s no package police that’ll stop you from installing malware. The argument has never revolved around that; the argument is solely that cooldowns are effective if you use them, and timely detection by third parties is strong evidence of that.
>and timely detection by third parties is strong evidence of that

Do you have an example of those things you're alleging?

I gave Shai Hulud as an example above. If you want precise timeline examples that demonstrate the efficacy of cooldowns, here’s some examples I collected last year[1].

(See the “Window of opportunity” column in the table.)

[1]: https://blog.yossarian.net/2025/11/21/We-should-all-be-using...