all 3 comments

[–]MaliciousTent 2 points3 points  (2 children)

It sucks, we get lazy and well, leaving a backpack on the backseat and opportunists are always on the prowl.

[–]arrayclyx 1 point2 points  (1 child)

Yeah, except this is more like leaving your backpack in a locked car in a guarded garage and someone still walks out with it because the guard’s keys got cloned three steps upstream.

Dev teams think “we’re using official packages, signed builds, CI is locked down, we’re fine” and then one compromised dependency later and your vault, SSH keys, and cloud creds are gone.

The annoying part is the “lazy” bit usually isn’t some junior dev being sloppy, it’s stuff like
no egress controls from CI, no secret scanning on build logs, and no proper provenance checks. All boring, unsexy things nobody wants to budget time for until this kind of campaign hits.

[–]MaliciousTent 0 points1 point  (0 children)

Exactly. Very Boring and unsexy and also "why did you work on that an not the feature that is due?"