| ▲ | morkalork 6 hours ago | ||||||||||||||||||||||
You don't think bad actors don't have access to entire countries worth of stolen identities to use for supply chain attacks? | |||||||||||||||||||||||
| ▲ | hirsin 6 hours ago | parent [-] | ||||||||||||||||||||||
This was largely the reason I rejected "real name verification" ideas at GitHub after the xz attack. (Especially if they are state sponsored) it's not that hard for a dedicated actor (which xz certainly was) to get a quality stolen identity. The inevitable evolution of such a feature is a button on your repo saying" block all contributors from China, Russia, and N other countries". I personally think that's the antithesis of OSS and therefore couldn't find the value in such a thing. | |||||||||||||||||||||||
| |||||||||||||||||||||||