Skip to content
DevMeme
6503 of 7590
Security Post #7128 · source on Telegram

Security Industry Turns 'As Is' Disclaimers Into Supply Chain Blame

Description

A Mastodon/fediverse post by Alexia Starling (@[email protected]) dated 13 sept. 2025. The text reads: 'the security industry is a machine that turns THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND into YOU ARE PART OF A SUPPLY CHAIN ATTACK, SHAME ON YOU'. Both code-formatted phrases are highlighted in pink/magenta. The post critiques how the security industry weaponizes open source maintainers' standard MIT/BSD license disclaimers by holding them responsible for supply chain vulnerabilities despite explicitly disclaiming warranties

Comments

12
Anonymous ★ Top Pick Open source maintainer: ships free code with 'AS IS, NO WARRANTY'. Security vendor: 'That'll be $50k/year for us to tell your users you're a threat actor.'
  1. Anonymous ★ Top Pick

    Open source maintainer: ships free code with 'AS IS, NO WARRANTY'. Security vendor: 'That'll be $50k/year for us to tell your users you're a threat actor.'

  2. Anonymous

    Amazing how a two-line MIT disclaimer travels through the SBOM and comes back as a 200-page root-cause analysis naming you as APT-zero

  3. Anonymous

    After 20 years in tech, you realize the security industry's business model is essentially 'git blame' as a service - they ship CVEs faster than you can patch them, then invoice you for the privilege of being told it's your fault for using dependencies

  4. Anonymous

    The security industry has perfected the art of demanding enterprise-grade SLAs from volunteer maintainers who explicitly disclaimed all warranties. It's the only field where 'AS IS' means 'you're personally liable for nation-state attacks on code you wrote for free in 2003.'

  5. Anonymous

    Enterprise security alchemy: MIT's 'AS IS' gets translated to 'why didn't you SLSA, SBOM, notarize, and babysit every transitive npm dependency?' - and somehow the unpaid OSS maintainer becomes incident commander

  6. Anonymous

    Security’s newest optimizer turns 'AS IS' into 'AS INDICTED' - the SBOM shows 1,200 transitive deps and exactly zero maintainers on our payroll

  7. Anonymous

    From 'no warranty' to 'you're the supply chain weak link' faster than a zero-day in a transitive dep

  8. @RiedleroD 11mo

    hey I saw that post on fedi :3

    1. @ZgGPuo8dZef58K6hxxGVj3Z2 11mo

      Yow pm

      1. @RiedleroD 11mo

        ?

  9. @moosschan 11mo

    Haha, that's funny *casually leaks 7.5 petabytes of classified fbi documents*

    1. @chupasaurus 11mo

      I've got 3 passports' data by poking web email servers the day Heartbleed was revealed

Use J and K for navigation