tomw,
@tomw@mastodon.social avatar

xz is not a "trusting trust" attack, it is a "your build tools are too complex for you to understand all the input and output" attack.

And guess what: that's very relevant to web development...

tomw,
@tomw@mastodon.social avatar

People worry about backdoored compilers and undetectable exploits and then go and install 100MB of node modules that we assume someone out there is probably checking idk

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tester
  • magazineikmin
  • khanakhh
  • InstantRegret
  • thenastyranch
  • Youngstown
  • everett
  • mdbf
  • slotface
  • ngwrru68w68
  • DreamBathrooms
  • kavyap
  • osvaldo12
  • rosin
  • JUstTest
  • Durango
  • tacticalgear
  • modclub
  • cubers
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • cisconetworking
  • Leos
  • megavids
  • provamag3
  • anitta
  • lostlight
  • All magazines