• Waldowal@lemmy.world
    link
    fedilink
    arrow-up
    19
    ·
    3 days ago

    In a similar vein, Heinz once used a temporary domain for a promotion accessible by scanning a QR code on their bottles. The promotion ran its course, and they let the domain name expire.

    Problem is these bottles were available on restaurant tables for much longer. Didn’t take long before scanning the Heinz QR code at your table got you some pornography.

  • towerful@programming.dev
    link
    fedilink
    arrow-up
    14
    ·
    3 days ago

    People complain about the web build tool chain, bundlers, rollups etc.
    And it has been and probably still is pretty stupid.
    But at least you can pin and deploy all your dependencies before deploying.

    This highlights why pulling in scripts at runtime from sources you don’t control is a worse idea

  • CodeMonkey@programming.dev
    link
    fedilink
    arrow-up
    11
    arrow-down
    2
    ·
    3 days ago

    This is not a supply chain attack, it is sudden extreme enshitification. according to the article, the attacker also bought the GitHub repo, so all releases should be considered tainted. The community will have to find a fork from before the acquisition and hope that there are no pre-purchase favors smuggled in.

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      3 days ago

      This is not a supply chain attack, it is sudden extreme enshitification. according to the article, the attacker also bought the GitHub repo

      I don’t see how buying the GitHub repo as well makes it not a supply chain attack but enshitification.

      They bought into the supply chain. It’s a supply chain attack.

    • sabreW4K3@lazysoci.alOP
      link
      fedilink
      arrow-up
      3
      ·
      3 days ago

      I thought Polyfill was a Google thing. I remember when they implemented it on YouTube and the Firefox performance was dire.

  • machinaeZER0@lemm.ee
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    3 days ago

    So, one would add

    * polyfill.io * block

    To their My Filters pane in ublock origin?

    • b_van_b@programming.dev
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      3 days ago

      This setting appears to work for me. It shows up as blocked in the logs. I’ve also blocked it in NoScript for good measure.