• corsicanguppy@lemmy.ca
    link
    fedilink
    English
    arrow-up
    9
    ·
    11 hours ago

    Supply chain attacks are what scare me.

    As a former OS security pro, this is the right answer. Not because of the exploit itself, but because young (unmentored) coders readily trust some really bad patterns of pulling in random junk from the web and running it. THIS is how the LPE becomes essentially an RCE-level problem.