Security
Post #7128 · source on Telegram
Security Industry Turns 'As Is' Disclaimers Into Supply Chain Blame
Description
A Mastodon/fediverse post by Alexia Starling (@[email protected]) dated 13 sept. 2025. The text reads: 'the security industry is a machine that turns THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND into YOU ARE PART OF A SUPPLY CHAIN ATTACK, SHAME ON YOU'. Both code-formatted phrases are highlighted in pink/magenta. The post critiques how the security industry weaponizes open source maintainers' standard MIT/BSD license disclaimers by holding them responsible for supply chain vulnerabilities despite explicitly disclaiming warranties
Use J and K for navigation
Comments
12Comment deleted
Open source maintainer: ships free code with 'AS IS, NO WARRANTY'. Security vendor: 'That'll be $50k/year for us to tell your users you're a threat actor.'
Amazing how a two-line MIT disclaimer travels through the SBOM and comes back as a 200-page root-cause analysis naming you as APT-zero
After 20 years in tech, you realize the security industry's business model is essentially 'git blame' as a service - they ship CVEs faster than you can patch them, then invoice you for the privilege of being told it's your fault for using dependencies
The security industry has perfected the art of demanding enterprise-grade SLAs from volunteer maintainers who explicitly disclaimed all warranties. It's the only field where 'AS IS' means 'you're personally liable for nation-state attacks on code you wrote for free in 2003.'
Enterprise security alchemy: MIT's 'AS IS' gets translated to 'why didn't you SLSA, SBOM, notarize, and babysit every transitive npm dependency?' - and somehow the unpaid OSS maintainer becomes incident commander
Security’s newest optimizer turns 'AS IS' into 'AS INDICTED' - the SBOM shows 1,200 transitive deps and exactly zero maintainers on our payroll
From 'no warranty' to 'you're the supply chain weak link' faster than a zero-day in a transitive dep
hey I saw that post on fedi :3 Comment deleted
Yow pm Comment deleted
? Comment deleted
Haha, that's funny *casually leaks 7.5 petabytes of classified fbi documents* Comment deleted
I've got 3 passports' data by poking web email servers the day Heartbleed was revealed Comment deleted