Remix.run Logo
loloquwowndueo 5 hours ago

Depending on those vaunted “security researchers” to take point and find all vulnerabilities in all packages is also fairly naive. That process costs money and produces a fairly valuable result - why would they give it away for free? So this will inevitably evolve into targeting only the high-value most popular packages and the exploiters will retreat to the long tail of less-popular ones. Lower payoff? Sure, but beats zero payoff.

shengpuerh 5 hours ago | parent [-]

Finding vulns in popular OSS and disclosing is probably good for your reputation as a security researcher, even if it's not immediately profitable.

Hackbraten 4 hours ago | parent [-]

How is that sustainable?

Are security researchers going to be doing free labor for you indefinitely for exposure?

stephantul 4 hours ago | parent [-]

They sell their products using the credentials they gained.

I’d never heard of socket until they found and reported shai hulud hiding in pytorch lightning. It pays off.

Hackbraten 4 hours ago | parent [-]

What happens after a couple of players have obtained marketshare and the market has consolidated?

I think there are diminishing returns to be had.