@norootcause honestly, I'm really hoping we eventually learn what mitigations they put in place. It's all well and good for us to say you should have secondary access channels or automated rollbacks or whatever else. But that's a hard enough problem in userspace application code. How do you even do these things in the bootloader?
Conversation
Notices
-
Embed this notice
Jenniferplusplus (jenniferplusplus@hachyderm.io)'s status on Saturday, 20-Jul-2024 09:51:57 JST Jenniferplusplus -
Embed this notice
Lorin Hochstein (norootcause@hachyderm.io)'s status on Saturday, 20-Jul-2024 09:51:58 JST Lorin Hochstein I have no information about how this incident came to be but I can confidently predict that people will blame it on greedy execs and sloppy devs, regardless of what the actual details are. And they will therefore learn nothing from the details.
Blaise Pabón - controlpl4n3 repeated this.
-
Embed this notice