| ▲ | hypfer an hour ago | |||||||||||||||||||||||||
Look, man, I understand all that, but pulling the plug is something that takes at most 90s. Let's say 300s to add the "Warning: There is an attack. We're working on it. Systems are down for now" box After that, you have all the time in the world to prioritize dayjobs etc. It's not about dropping everything and fixing the root cause. It's just about taking stuff offline so that the immediate danger is mitigated. That is not too much to ask. It's not "people like me" having weird opinions there. Shut it down. Then fix whenever there is time to do so. ___ But hey. Finally a statement from someone with some amount of position in the org I guess? I wouldn't want to be in your shoes for sure, but that's beside the point. Nothing here is unreasonable other than the ostrich-style incident response lack-of-process. And I don't mean stupid corporate process. I mean "common sense adults are in the room" process. Throw waterbucket at burning server reflex. ___ I mean I can see that your userbase absolutely sucks and could imagine that one would be scared of getting roasted for "interrupting their workflow", but this is not the way. Their workflow is irrelevant. As said, I'm all here for maintainer empathy, but only after the fire is put out first. ___ Anyway, "institutional rot" is not an insult but a diagnosis. I'd love to be proven wrong on that, but I don't see it. And trust me, I do know first hand how thankless this non-job is and what hell one goes through. I have skin in the game. I just don't have a horse in the arch race. | ||||||||||||||||||||||||||
| ▲ | Tharre an hour ago | parent [-] | |||||||||||||||||||||||||
"Hey, let's take down all of npm, because there's a package that installs something malicious, and some people may install it without reviewing it first. The thousands of other people relying on this service can wait." Do you not realize how crazy of an request that is? | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||