TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

"[The xz exploit] is RCE, not auth bypass"

10 点作者 maximilianburke大约 1 年前

1 comment

wolverine876大约 1 年前
&gt; This might be the best executed supply chain attack we&#x27;ve seen described in the open, and it&#x27;s a nightmare scenario: malicious, competent, authorized upstream in a widely used library.<p>&gt; Looks like this got caught by chance. Wonder how long it would have taken otherwise.<p>The IT world is lost in the fantasy that automation is the Way - there are no alternatives, nothing else exists - to scale everything including content moderation, customer service (e.g., from Google, etc.), code review, etc. If it can&#x27;t be automated, they say &#x27;it can&#x27;t be done&#x27; as if there is no alternative.<p>It can be done, but it&#x27;s more expensive and we&#x27;ll need to pay people. Automation isn&#x27;t the Way for everything. Our security, code review, etc. are awful.