Comment Re:Nobody admits it: supply chain attacks are EASY (Score 2) 24
There's another way to mitigate this, and it's ideologically difficult for a lot of Open Source people to accept... but you'll have to diverge from the tried and true path. AI makes this much easier: instead of using $popular_thing_everyone_uses, you use something else - either COTS or roll-your-own. Yes, it might be bugs, and yes, they might be security bugs, but unless they're painfully obvious issues where you didn't do your due diligence, it's going to be a more obscure target which will require more targeted attacks.
No, this doesn't solve anything and it's 100% "security through obscurity". Perhaps I'm just missing something, but it seems like sound practice.