Well, it's been 2/3 of a year since the xz attack.
Is software safer now?
Serious question.
What improvements have we made?
@rsc personally I really like this take:
"In any other course of life, this is not normal behavior and it would not be tolerated. Open source has gotten to the point that normal behavior is so toxic that literal state actors posing as toxic people on mailing lists went undetected and could have brought upon an international security incident upon us."
@leon_p_smith This was a great talk. Thanks.