zlacker

[parent] [thread] 1 comments
1. 112233+(OP)[view] [source] 2026-02-04 13:04:08
> increasingly trust code they haven't personally reviewed

while the problems you describe are valid, my personal experience is fully opposite — trust is decreasing. I do not remember anyone worrying about supply chain 15ish years ago — windows was where the viruses lived, and unix people were installing distros, compiling kernel modules and building tarballs without auditing anything.

replies(1): >>the_ha+Mh4
2. the_ha+Mh4[view] [source] 2026-02-05 17:05:10
>>112233+(OP)
Hmm that's actually a good reframe. You're right that awareness is way up - nobody was talking about supply chain attacks 15 years ago and now it's a whole discipline.

I think what I was getting at is more that the volume of unreviewed code is increasing faster than our ability to review it. We're more aware of the risks, but we're also running `npm install` on packages with 200 transitive dependencies and now asking AI to write whole features. The awareness went up but so did the attack surface, and I'm not sure the first is keeping pace with the second.

[go to top]