logoalt Hacker News

TZubiritoday at 2:56 AM1 replyview on HN

No I don't think so either, nor do I think that my rule is a hard rule, it's more of a correlation:

If you pay for software, your supply chain risk is reduced, if you don't pay for software, your risk is increased.


Replies

asdfasgasdgasdgtoday at 3:20 AM

Okay, so we agree that everyone who uses open source is at risk, regardless if of they're a contributor.

But maybe we disagree about this other thing. I'm not certain that closed source/paid software is less of a risk either. There have been high profile incidents lately that suggest this is not a sufficient defense.

Personally I just think you're barking up the wrong tree with this pay/contribute=>reduced risk link. I don't think there's anything there. I will grant that you are at slightly less risk from software you know well and contribute to directly, but that's only of any help for very low level stuff that doesn't have many dependencies.