chamomile

Wool and wool accessories

Pronounced "kæməmil"


Large sheep the size of a small sheep! Likes tea, DIY, and nerd stuff. Sysadmin, release engineer and programmer by trade.


Personal Website
bleatspeak.net/

aloe
@aloe
This page's posts are visible only to users who are logged in.

chamomile
@chamomile

This isn't hypothetical either - back in June it came out that a popular CDN hosting JS polyfills had been sold to a new provider and was distributing malware inside the legitimate scripts that sites were loading. It impacted a 6-digit number of websites and anyone who used them, and it turned out that this had been going on for months.



You must log in to comment.

in reply to @aloe's post:

at the minimum, that does work, but if you want the entire ring to remain navigable in the face of new sites entering and old ones going down you're going to need some kind of clearinghouse (mailing list? irc channel?) for maintaining the global integrity of the ring, and the temptation then becomes automating that process

i tend to think a page of links on every site is a much better idea than a "ring"