94
you are viewing a single comment's thread
view the rest of the comments
[-] Cypher@aussie.zone 9 points 2 weeks ago

It doesn't matter if the software is delivered via a publishers website or via a package repository if the supply chain has been compromised.

Clearly you're not aware of any recent cyber security news or you'd know that the NPM package manager has suffered numerous attacks: https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/

I guess you should trust NPM though because its a package manager!

You're just encouraging people to blindly use and trust repos with no understanding of the pros or cons, and without understanding how you can verify and test software yourself to reduce risk. This is especially an easy conversaion when we talk closed source vs open source and you failed to even bring that up.

Repeating nonsense claims instead of actually considering the entirely reasonable question only highlights that you're victim to the Dunning-Kruger effect.

You could have had a conversation and learned something from an actual cyber security professional and instead you've acted like a clown.

this post was submitted on 11 Apr 2026
94 points (100.0% liked)

cybersecurity

6106 readers
36 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 2 years ago
MODERATORS