

1·
2 years agoYeah. Build machines should never have had internet access. Any dependencies your product uses should be downloaded once and then cached in your own artifactory. If you don’t, what you deploy in production could be different from what you tested in staging. That can allow attacks like this to happen much more easily.
Some things have gotten better, but some have gotten worse. I’ve always thought that the analogy of older flagship phones fits this perfectly.
Is your current budget android more common on the streets than a flagship from 4 years ago ever was? Yes. Does it have a comparable processor, and camera? Maybe. Is the build quality better? Hell no.