Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not the maintenance of the projects the enterprises have to fund (though that is certainly welcome if the mantainers are willing) but the slow, painful work of vetting the code.

Google does that with Project Zero but few companies are wealthy enough to afford that. The way out is economic, not technical: insurance, and mutualizing the cost of security audits. I wrote up my ideas on the subject here:

https://blog.majid.info/supply-chain-vetting/



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: