Too few attackers understood it well enough? Or were other attack vectors easier?
Too few attackers understood it well enough? Or were other attack vectors easier?
It has resulted in a major thinking shift for me. Mostly initiated by a malicious nodejs package being quietly pulled in.
I am fortunate that my own contributions only require that.
The tradeoff isn't simple, and will be different for each company. I think everyone can point at a couple of components that are complex and massively benefit from the work poured into them and the large install base finding all the edge cases. Equally everyone can name a couple of dependencies that anyone could rewrite in a couple hours, and maybe even improve on the way.
Note that I’m not saying “never use libraries”, which your points seem mainly aimed at. Code reuse is great! I’m just not sold on automatic, unmonitored updates to libraries.
1. one or more major package hubs
2. one package manager, or at least, a package standard
3. easy to consume/build (source code to binary)
4. easy to publish
5. easy to download (one liner in your build script, e.g. package.json, vcproj, cargo.toml, build.gradle etc.)
At the moment C++ only really has 5. - easy to download: cmake, conan, vcpkg, build2, can all download easily.
1-4 are a work in progress for C++, but are far better than 10 years ago.
Perhaps the reason is package managers for C are called distro maintainers (for Linux/BSD)
Eventually, due to a lot of factors, threat landscapes start shifting and attackers start moving their targets and tooling. One of the bigger shifts would be the huge, rapid improvement to both OS and browser security that occurred within a few years, radically increasing the cost of attacking desktop users via malicious websites. Another would be crypto, where 'account takeover' attacks that could lead to wallet access are now easier to monetize + crypto itself as a tool for transfers.
With regards to supply chain, enough of these changes occurred that some attackers took the leap and have started looking at this area. There are probably a lot of reasons why - prevalence of dependencies, increased interest in tech companies, etc.
If it continues to prove viable (it's obviously viable from an attack perspective, unclear if it's something attackers will rally around to monetize) we'll see it escalate and get better tooling around the attacks.
EDIT: It's much like building a tower. Upper floors depends on lower floors. Taller the construction more unstable it gets.