Hacker News new | ask | show | jobs
by yearolinuxdsktp 17 days ago
That’s a bold claim to make about HNers. Au contraire, security companies have absolutely missed supply chain attacks.

Example:

https://snyk.io/blog/node-gyp-supply-chain-compromise-self-p...

Before that we had event-stream, then we had XZ compromise.

It’s not exceptionally hard to delay reaching out to external sites until after a cooldown period.