• gravitas_deficiency
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    4 days ago

    But the main point is that good and well-written code doesn’t need this sort of misdirection, nor would the authors generally engage in this sort of thing

    • David J. Shourabi Porcel@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 days ago

      You seem to imply bad programmers use these services to star-boost their otherwise mediocre code. That might be the case, but there are other –at least conceivable, if not yet proven– use cases for these star-boosting services, such as typosquatting, the promotion of less secure software as part of supply chain attacks (with organizations sticking to vulnerable libraries or frameworks in the erroneous belief that they are more popular and better maintained than alternatives, for example) and plain malware distribution.

      • gravitas_deficiency
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 days ago

        I mean… I was sort of taking “good” code to imply “not malicious”, in addition to it being written well. But yeah, I completely agree, in the context of attack vectors you mention.