Hacker News new | past | comments | ask | show | jobs | submit login

If xz would have been hosted another place, what could have been prevented?



>The technical reason for not opting for such alternatives is that I will not be getting enough contributions there.

Yes.

Sudden interest from multiple people in certain pull request raise suspicions if you only have a contributions.


Sounds more like you get less eyes overall on your code. But the attacker will spend the same energy on it.


But he can't hide in the masses


Yeah I don't buy it. He was more active than most even on github.


That maybe fewer people would have even known about it and therefore decreased its importance as a target? /s




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: