Egregoros

Signal feed

Timeline

Post

Remote status

Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

Replies

10

@feld @mhoye @sun@shitposter.world @mischievoustomato

I think we're talking past the point here - say you run your whole dev environment in a VM - sure, *your* OS is fine, but the packages you've trusted for years that you're including as dependencies have just been fucked, and that's what you're shipping to *me*, the end user.

Did I "deserve it"? I put it to you that I don't. I also don't think "everyone should just run everything in a container because someone wants to use some LLM agent in their gitforge" is the same as "don't install a random exe from a random warez site".

How did I deserve to have my box popped because you, a trustworthy dev, used a package that's trustworthy for years? This thinking makes no sense.