Config Files That Run Code: Supply Chain Security Blindspot

31 pointsposted 4 hours ago
by signa11

2 Comments

embedding-shape

an hour ago

Is this why Windows Defender is prompting me 2-3 times a day to submit my codex/config.toml to Microsoft for "malware analysis"? I've said no every time so far, since my first thought is "What could even be hidden there?" when I see the dialog yet again, I'm guessing Microsoft would love to see how people use their competitors' products though.

lstodd

an hour ago

You might as well click yes, since it's all been uploaded as telemetry anyways.