• 0 Posts
  • 34 Comments
Joined 3 years ago
cake
Cake day: June 14th, 2023

help-circle




  • If you can’t comprehend how site impersonation and search result manipulation aren’t relevant to the actual software vendor getting popped then you have zero comprehension of an actual kill chain.

    But sure a package manager is totally safer because you made up an irrelevant scenario!

    Nice you went back and checked with how little you cared lol


  • If you don’t see calling someone ignorant as an insult then I wish you well in a pub talking to a stranger.

    I had a chuckle when I saw NPM yet again because it was one of the examples I used that you failed to address despite totally winning that discussion.

    Hopefully manufacturing irrelevant scenarios works out for you in your career.


  • To be fair you didn’t say package managers were perfect but you also failed to provide any evidence for your claims that a package manager was more trustworthy than a known software publishers website as a distribution method.

    You were given plenty of opportunities to explain yourself and you doubled down with insults and shifting goalposts.

    Going by your logic this breach is evidence that package managers should all be avoided.