Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously.

I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously.

Scheduled Pinned Locked Moved Uncategorized
8 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote last edited by
    #1

    RE: https://infosec.exchange/@ifin/116605052950779161

    I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

    shadowfetchai@mastodon.socialS luxliquida@critter.cafeL argv_minus_one@mastodon.sdf.orgA mk30@tilde.zoneM bovaz@misskey.socialB 6 Replies Last reply
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

      RE: https://infosec.exchange/@ifin/116605052950779161

      I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

      shadowfetchai@mastodon.socialS This user is from outside of this forum
      shadowfetchai@mastodon.socialS This user is from outside of this forum
      shadowfetchai@mastodon.social
      wrote last edited by
      #2

      @mttaggart Gives me the chills. As a solo dev, my entire livelihood is tied to the integrity of my toolchain, and there's only so much I can realistically audit myself.

      1 Reply Last reply
      0
      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

        RE: https://infosec.exchange/@ifin/116605052950779161

        I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

        luxliquida@critter.cafeL This user is from outside of this forum
        luxliquida@critter.cafeL This user is from outside of this forum
        luxliquida@critter.cafe
        wrote last edited by
        #3

        @mttaggart I'm sure vibe coding will make securing the supply chain easier and not harder /s

        1 Reply Last reply
        0
        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

          RE: https://infosec.exchange/@ifin/116605052950779161

          I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

          argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
          argv_minus_one@mastodon.sdf.orgA This user is from outside of this forum
          argv_minus_one@mastodon.sdf.org
          wrote last edited by
          #4

          @mttaggart

          “Taking supply chain security seriously” involves laying off the productivity obsession and allowing programmers to remain calm, focused, and vigilant.

          I don't think we're anywhere near that tipping point, unfortunately. Companies and politicians still think we can solve this problem with audits, regulations, and hoop jumping.

          I discussed this in another thread earlier today: https://mastodon.sdf.org/@argv_minus_one/116602229559669722

          1 Reply Last reply
          0
          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

            RE: https://infosec.exchange/@ifin/116605052950779161

            I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

            mk30@tilde.zoneM This user is from outside of this forum
            mk30@tilde.zoneM This user is from outside of this forum
            mk30@tilde.zone
            wrote last edited by
            #5

            @mttaggart @peter that github news seems bad! 😳

            1 Reply Last reply
            0
            • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

              RE: https://infosec.exchange/@ifin/116605052950779161

              I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

              bovaz@misskey.socialB This user is from outside of this forum
              bovaz@misskey.socialB This user is from outside of this forum
              bovaz@misskey.social
              wrote last edited by
              #6
              @mttaggart@infosec.exchange my fear is it's going to lead to more expensive and annoying policies from companies, bothering developers, so that compromised stuff is immediately deployed at company-scale.
              mttaggart@infosec.exchangeM 1 Reply Last reply
              0
              • bovaz@misskey.socialB bovaz@misskey.social
                @mttaggart@infosec.exchange my fear is it's going to lead to more expensive and annoying policies from companies, bothering developers, so that compromised stuff is immediately deployed at company-scale.
                mttaggart@infosec.exchangeM This user is from outside of this forum
                mttaggart@infosec.exchangeM This user is from outside of this forum
                mttaggart@infosec.exchange
                wrote last edited by
                #7

                @bovaz You know, I think the constant compromise of their repositories and credentials is something of a bother in and of itself

                1 Reply Last reply
                0
                • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                  RE: https://infosec.exchange/@ifin/116605052950779161

                  I'm really hoping this, and the last few weeks, are a tipping point toward taking supply chain security seriously. Initial access appears to be a compromised VS Code extension.

                  epic_null@infosec.exchangeE This user is from outside of this forum
                  epic_null@infosec.exchangeE This user is from outside of this forum
                  epic_null@infosec.exchange
                  wrote last edited by
                  #8

                  @mttaggart Not that we know which one and can check our own extensions to make sure we aren't compromised. That would be too much to ask!

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups