logoalt Hacker News

morkalorkyesterday at 3:47 AM1 replyview on HN

You don't think bad actors don't have access to entire countries worth of stolen identities to use for supply chain attacks?


Replies

hirsinyesterday at 4:00 AM

This was largely the reason I rejected "real name verification" ideas at GitHub after the xz attack. (Especially if they are state sponsored) it's not that hard for a dedicated actor (which xz certainly was) to get a quality stolen identity.

The inevitable evolution of such a feature is a button on your repo saying" block all contributors from China, Russia, and N other countries". I personally think that's the antithesis of OSS and therefore couldn't find the value in such a thing.

show 1 reply