Config Files That Run Code: Supply Chain Security Blindspot
1–10 of 28 posts
Re: Config Files That Run Code: Supply Chain Security Blindspot
#2Re: Config Files That Run Code: Supply Chain Security Blindspot
#3Re: Config Files That Run Code: Supply Chain Security Blindspot
#4Is this why Windows Defender is prompting me 2-3 times a day to submit my codex/config.toml to Microsoft for "malware analysis"? I've said no every time so far, since my first thought is "What could even be hidden there?" when I see the dialog yet again, I'm guessing Microsoft would love to see how people use their competitors' products though.
Re: Config Files That Run Code: Supply Chain Security Blindspot
#5Re: Config Files That Run Code: Supply Chain Security Blindspot
#6Re: Config Files That Run Code: Supply Chain Security Blindspot
#7Is this why Windows Defender is prompting me 2-3 times a day to submit my codex/config.toml to Microsoft for "malware analysis"? I've said no every time so far, since my first thought is "What could even be hidden there?" when I see the dialog yet again, I'm guessing Microsoft would love to see how people use their competitors' products though.
You might as well click yes, since it's all been uploaded as telemetry anyways.
Re: Config Files That Run Code: Supply Chain Security Blindspot
#8No one cares about security. People used to care for a fairly short period of time after something bad happened to them, but even that seems to have gone by the wayside as breaches, leaks, and use of exploited code has become normalized.
Re: Config Files That Run Code: Supply Chain Security Blindspot
#9It's far from a blindspot. People have been yelling about this from the rooftops for the last several years. No one cares about security. People used to care for a fairly short period of time after something bad happened to them, but even that seems to have gone by the wayside as breaches, leaks, and use of exploited code has become normalized.
The rise of editors that will own your system just by browsing to the wrong folder without opening or running anything is relatively speaking newer, but I think most people in HN audience should be able to intuit some of the risks, especially when untrusted PRs and semi-trusted LLM bots are in the mix with your "trusted" codebase.
Re: Config Files That Run Code: Supply Chain Security Blindspot
#10Earlier quoted context omitted.
You might as well click yes, since it's all been uploaded as telemetry anyways.
Citation needed
https://support.microsoft.com/en-us/windows/windows-search-a...
The final straw for me was when I saw that Microsoft Defender by default could send files to their servers for inspection, and I couldn't see what was sent previously, nor was this an opt-in option, it was on by default. I have anything from PII to highly proprietary things on my computer, I don't need them being "flagged" by Microsoft for arbitrary reasons. I have been on Linux full time for the last few years since.