this post was submitted on 07 Apr 2024
20 points (83.3% liked)

Cybersecurity

5700 readers
145 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 6 points 7 months ago* (last edited 7 months ago)

I like the Go philosophy here: if you just need a function, copy the function, don't import the whole module. A little code duplication is fine, and it significantly narrows your attack surface.

But while I agree with your point in general, you really missed the mark here. The problem with xz wasn't pulling in sketchy dependencies, it was online bullying of a burned out FOSS dev. That's not a technical problem, but a support one.

The solution to problems like the xz vulnerability must be about supporting FOSS devs. Review code, donate money, join mailing lists, etc. Be the support these devs need, and push back against outsiders who seem to be engaging in bullying.