• HumanPerson@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    4 days ago

    Someone used a hammer to smash a window and steal stuff. Quick, ban hammers!!!

    Getting rid of the tools to exploit vulnerabilities doesn’t get rid of the vulnerabilities, and security by obscurity is not security.

    • kristoff@infosec.pub
      link
      fedilink
      arrow-up
      0
      ·
      2 days ago

      Concerning this particular article, perhaps the vulnerability here are not a mallicious software packages, but the management of these software repo’s.

      Should it be possible to upload a package on a repo with 99% of the same name as one that already exists without some additional checks?