• Scrubbles@poptalk.scrubbles.tech
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 hours ago

    Yeah they claim it’s safe because it’s through their store, but isn’t this a direct path to a supply chain attack? One app using electron has one bad npm dependency and it auto installs and updates on every machine? This seems like a security nightmare scenario.

    Bu hey marketing gets to put their shit in front of everyone’s eyes so who cares.