• magic_lobster_party@fedia.io
    link
    fedilink
    arrow-up
    22
    ·
    3 days ago

    The flaw also highlighted a social engineering exploit. It’s not the first time some vulnerability has entered open source software due to social pressure on the maintainer. Notably EventStream exploit.

    This is difficult to account for. You can’t build automated tooling for social engineering exploits.