Latest Blog Post: Software Library Security is Scary
Michael Biancardi
Posted March 28, 2024; Last Updated March 28, 2024
I published a package on pip and learned that software library security is scary...
Interesting Quote:
Even though we don't know which companies the NSA has compromised – or by what means – knowing that they could have compromised any of them is enough to make us mistrustful of all of them. This is going to make it hard for large companies like Google and Microsoft to get back the trust they lost. Even if they succeed in limiting government surveillance. Even if they succeed in improving their own internal security. The best they'll be able to say is: "We have secured ourselves from the NSA, except for the parts that we either don't know about or can't talk about.