> Why cooldowns? Most npm (or pypi) compromises were taken down within hours,
But won't more people on cooldown mean less likelihood to catch the bug, thus extending the need for cooldowns?
But won't more people on cooldown mean less likelihood to catch the bug, thus extending the need for cooldowns?
It's inevitable that a false negative will slip through one day, and when that happens, it will compromise everyone who installs it, no matter if on day one or day eight.
I just hope that the companies who currently perform security scans for free/for exposure have a sustainable business model. Once such a company gains reputation, there's diminishing returns in headlines currency.