Lemmy.World
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
codeinabox@programming.dev
cake
to Security@programming.devEnglish · 6 months ago

Minimum Release Age is an Underrated Supply Chain Defense

daniakash.com

external-link
message-square
6
link
fedilink
29
external-link

Minimum Release Age is an Underrated Supply Chain Defense

daniakash.com

codeinabox@programming.dev
cake
to Security@programming.devEnglish · 6 months ago
message-square
6
link
fedilink
Minimum Release Age is an Underrated Supply Chain Defense | Dani Akash
daniakash.com
external-link
A 7-day package delay would have blocked installs in most short-lived malicious publish attacks from the last 8 years
alert-triangle
You must log in or register to comment.
  • TomasEkeli@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 months ago

    There is some truth to this - staying on the bleeding edge exposes you to things earlier.

    Not really surprising, but maybe a consequence people who want to be on the latest version immediately did not consider. Good article!

  • _‌_反いじめ戦隊@ani.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    3
    ·
    6 months ago

    incompatible with capitalism

    • duckythescientist@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 months ago

      Did you comment this on the wrong post?

      • _‌_反いじめ戦隊@ani.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        6 months ago

        Nope.

        • duckythescientist@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 months ago

          Do you expect there to be no crime and no money if capitalism is replaced? And effort toward mitigating supply chain hacks is definitely compatible with capitalism especially with such an easy mitigation as proposed in this article.

          • _‌_反いじめ戦隊@ani.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 months ago

            But then your unsecure, cheap, and fast competitor will upload the features and solutions of your scope 14 days ahead of you, over and over again, until you’re suddenly years behind the rest. Are this unaware of the modern business deployment model?

Security@programming.dev

security@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don’t be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4 users / day
  • 37 users / week
  • 62 users / month
  • 530 users / 6 months
  • 103 local subscribers
  • 2.17K subscribers
  • 172 Posts
  • 269 Comments
  • Modlog
  • mods:
  • Vacant@programming.dev
  • UI: 0.19.20-5-ga406e80b
  • BE: 0.19.19-9-gc55dd700c
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org