my only contribution to the xz discourse:

absolutely none of the supply chain stuff we're currently doing, including the things i like, would have stopped this. the only things that can stop this are (1) compulsively treating all code as untrusted, and (2) way, way stronger capability checks and restrictions in running systems. (1) is economically infeasible (the world runs on free labor from OSS), and (2) has had only very limited practical success.

@yossarian @encthenet
How about (3) create social systems surrounding OSS that don’t put a single person in a position of absolute and unsupervised trust like this. To me this is a “single point of failure” story, but about •human• dependencies, not code dependencies.