90
Supply chain attack on arrayref
(blog.rust-lang.org)
Welcome to the Rust community! This is a place to discuss about the Rust programming language.
Credits
I just wanted to ask, how do they build C libraries in JAVA world? And if the answer is they don't, they just ship binaries, then that's infinitely worse. And you just confirmed that's the case 😲😄.
Yep, it's all binaries.
In reality it very rarely happens that native binaries are needed for Java. I’m not even sure what libraries might use them nowadays - I would guess mostly commercial closed source.
I don’t think it’s “infinitely worse”, but it does mean you require builds for whatever platform you are on or you need to manually build it from source as a separate project.
JVM, ELF, Mach-O,.... binaries are infinitely worse when the attack vector is "compromised dev machine".
I'm not sure how anyone would even try to argue against that.