Tom Walker on Nostr: xz is not a "trusting trust" attack, it is a "your build tools are too complex for ...
xz is not a "trusting trust" attack, it is a "your build tools are too complex for you to understand all the input and output" attack.
And guess what: that's very relevant to web development...
Published at
2024-03-31 10:30:06Event JSON
{
"id": "12a530740ced5633594f591ad20ee257ebec88c2cbe9a6ba387f27271e5ac083",
"pubkey": "01cf6009dc9a2a2a7029452898cbdcb50c91449ce757443f7472094cd9f44f31",
"created_at": 1711881006,
"kind": 1,
"tags": [
[
"proxy",
"https://mastodon.social/users/tomw/statuses/112189833631285213",
"activitypub"
]
],
"content": "xz is not a \"trusting trust\" attack, it is a \"your build tools are too complex for you to understand all the input and output\" attack.\n\nAnd guess what: that's very relevant to web development...",
"sig": "c30509c96ab476161c7121e3aa3cc4e37b929a7da397a2936c3588ddb879ce1e2b96080f5783f68476e3838609c4a5157f3e625432620c43a947fdc9c861950c"
}