84 points by batch12 3 days ago | 30 comments | View on ycombinator
jl6 about 19 hours ago |
Shank 1 day ago |
woodruffw about 23 hours ago |
AdrienPoupa about 24 hours ago |
feross about 12 hours ago |
Disclosure: I’m the founder of Socket.
swq115 about 21 hours ago |
duckmysick about 15 hours ago |
How do you simultaneously revoke all credentials of all your accounts spanning multiple services/machines/users?
snailmailman 1 day ago |
I only clicked on a handful of accounts but several of them have plausibly real looking profiles.
MilnerRoute 1 day ago |
"Trivy Supply Chain Attack Spreads, Triggers Self-Spreading CanisterWorm Across 47 npm Packages"
https://it.slashdot.org/story/26/03/22/0039257/trivy-supply-...
4riel about 19 hours ago |
RS-232 1 day ago |
robutsume 1 day ago |
qkitzero about 16 hours ago |
Of course, every entity is ultimately accountable for its own security, including assigning a level of trust to any dependencies, so it’s ultimately no excuse, but getting hit by a supply chain attack does evoke a little more sympathy (“at least I did my bit right”), and I feel like the ambiguous wording of the title is trying to access some of that sympathy.