Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, yeah. There’s no package police that’ll stop you from installing malware. The argument has never revolved around that; the argument is solely that cooldowns are effective if you use them, and timely detection by third parties is strong evidence of that.


>and timely detection by third parties is strong evidence of that

Do you have an example of those things you're alleging?


I gave Shai Hulud as an example above. If you want precise timeline examples that demonstrate the efficacy of cooldowns, here’s some examples I collected last year[1].

(See the “Window of opportunity” column in the table.)

[1]: https://blog.yossarian.net/2025/11/21/We-should-all-be-using...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: