Comment Re:Nobody admits it: supply chain attacks are EASY (Score 1) 26
There's another way to mitigate this, and it's ideologically difficult for a lot of Open Source people to accept...
The big problem is not ideological.
but you'll have to diverge from the tried and true path. AI makes this much easier: instead of using $popular_thing_everyone_uses, you use something else - either COTS or roll-your-own. Yes, it might be bugs, and yes, they might be security bugs, but unless they're painfully obvious issues where you didn't do your due diligence, it's going to be a more obscure target which will require more targeted attacks.
Humans are vulnerable to making the same kinds of errors, and security is hard, so you're going to either be highly likely to make predictable errors that are going to be easy to find or you're going to need to pull in some libraries to handle security.
No, this doesn't solve anything and it's 100% "security through obscurity".
IOW it's not a useful suggestion, especially now that there are exciting new tools for finding vulnerabilities rapidly.