GitHub is under automated attack by millions of cloned repositories filled with malicious code.::Thanks to a combination of sophisticated methodology and social engineering, this particular attack seems to be very difficult to stop.

  • hatedbad@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    4 months ago

    a decentralized community that correctly prioritizes security would absolutely be using signed commits and other web-of-trust security practices to prevent this sort of problem

    • conciselyverbose@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 months ago

      New accounts exist and have good reason to exist. You can’t and shouldn’t ban new accounts from creating projects.

      Anyone capable of understanding what “web of trust” means is already way too sophisticated to be misled by these fake projects.