I don't think that's what the commenter is claiming. I think they want to be able to sue the companies who indirectly benefit from this kind of spam, which is pretty ridiculous.
However, crypto has become such a menace to society that it's time that governments do something about it, if they even can at this point.
Can we please stop pretending that Ruby/Rails is in any way a good choice for software that needs to be safe?
I do understand that it is what it is and GitLab has to deal with it, but going forward, can we stop pretending a language and framework that prioritizes cleverness and hidden control flow is better than something more boring?
If I sound overly-annoyed it's because I have to work on a production Ruby codebase where I can absolutely see a scenario in which we have similar issues just waiting to be exploited, because someone thought seventeen layers of abstraction made the code super extensible.
What are the chances the United States (and others) follow suit? For startups, I assume most will continue to live on the App Store lest they force their users into two different experiences based on their location.
I just love how we can have a critical study about a failure that could have possibly led to the death of dozens if not 100+ people, a failure in something as routine and critical as flying in an airplane, and the article is behind a paywall.
We're getting very close to the point where the combination of the competency crisis and the greed crisis are going to start causing more people to think twice about doing things that were once common, like flying commercial.
Personally, I cancelled my flight later this month and am going to start getting in the habit of doing long road trips again.
Just-as-if-not-more dangerous? Maybe, but at least I have a higher chance of my fate being in my own hands (swerving out of the way of an oncoming truck vs being sucked out from a fuselage plug failing).
Older generations wonder why younger generations are "quiet quitting" and using all this anti-capitalist rhetoric when in the same breath they're sending HR goons (great term for it) to do their dirty work.
It's funny that they're using peer-to-peer to literally mean sending payments from one person to another, rather than it being the technical definition.
I wonder if it's a marketing gimmick to make people think it's more libertarian/secure/private than it actually is.
Why would people want to send payments over Twitter (I understand it's X, but I'm using Twitter to emphasize that the product is still, exclusively, a microblogging platform with some audio features).
Is it to donate to personalities? I can see that use-case, but whenever I see these kinds of headlines it seems the vision to create an "everything app" means that "peer-to-peer" payments means adding something like Venmo or Cashapp. Do people add their IRL friends on Twitter? If so, why would they use Twitter for that sort of thing as opposed to Venmo or Cashapp?
I'm genuinely curious, but to me it seems like it's a play to get hordes of cash flowing into the platform so that X can rake in interest on it for use in their own debt payments.
The entire reason this is a big deal is that people don't know what their dependencies are. The left-pad incident wasn't a big deal because it was pulled, it was a big deal because no one could easily fix their builds and didn't even know they were depending on it, because it was a dependency of a dependency of a dependency.
While it's ridiculous to expect that people will audit every single dependency and sub-dependency, it's not ridiculous to expect tooling to do the same.
Packages should be given an overall quality rating (and honestly it might be great for an ecosystem as large, diverse, and welcoming-to-beginners as JS/TS), part of the score comes from the number of different dependencies/sub-dependencies -- a social package score if you will. If a package causes the dependency graph to explode, give a warning before installing it.
Then, if you're NPM, you don't need all of these convoluted and exploitable policies around un-publishing.
Usually the sweet spot is somewhere in the middle of both, which is what the United States is (though some may argue we've begun to slide towards the extremes)