It all seems a bit hopeless, I refuse to believe anyone who claims to audit everything and every update - and would they have caught xz's backdoor anyway?
It all seems a bit hopeless, I refuse to believe anyone who claims to audit everything and every update - and would they have caught xz's backdoor anyway?
[0] That really is the only fail-closed way to do it. Everything else is theater... good theater, but theater.
EDIT: Btw, I do not mean to be dismissive towards lower-level/higher-sophistication security issues like side-channels, etc... but that's peanuts to ordinary Bad Guys. (Nation states might be more interested in advanced things). Most Interweb Bad Guys use very simple techniques, like bad writing in a scam email.
my 2 cents are that it is not theoretically possible to handle and actually fight the problem of _too many dependencies_. we all need them to move quickly.
But, there must be a balance.
remark: just look at the FE framework / packages world (eco system), this is too much, and most are not needed.
It's more like a "hope to" than an actual solution