logoalt Hacker News

delta_p_delta_xyesterday at 6:46 PM1 replyview on HN

Indeed. I mention this in light of the high-profile supply-chain attacks recently across diverse platforms (Arch AUR, Shai-Hulud, etc). Any online tool that purports to modify an entire install medium should be heavily and continually scrutinised. I'm not saying the developer can't be trusted, but the infrastructure and people in general can't.


Replies

greenavocadoyesterday at 8:22 PM

Fine, but this is Chris Titus we're talking about, not Red Star