HN user

nibbleshifter

1,825 karma
Posts0
Comments781
View on HN
No posts found.

those doing supply chain attacks are often at least somewhat professional and take precautions.

Not really.

The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.

Yes, even the shit tier supply chain attacks count :)

Customs in the EU have massively cracked down on imports from China in the last couple of years, with new regulations regarding import charges etc.

Every single package I've ordered since then across four different EU countries and multiple Chinese suppliers has resulted in it being held until a fee was paid.

Previously, stuff below a certain value was "free".

The only downside is: extremely limited device support by design (ease of support).

Has tonnes of hardening though.

In the UK it was such a routine thing (landlord not giving your deposit back) that I just stopped paying the last months rent before moving out.

The UK does have a supposedly mandatory deposit protection scheme, but a lot of dodgy landlords aren't compliant with it, and the dispute process is a fucking nightmare.