Quote · The a16z Show
The Reality of AI-Powered Cyberattacks | Truffle Security & Socket
Where this was said
Funding Open Source Security: The $25K–$50K Solution
At 19:28 · chapter starts 19:17
The episode's pragmatic climax. Feross argues that switching programming languages for security reasons is impractical, but funding is not. The math is simple: a few companies each writing $25K or $50K checks to an underfunded registry could fund one, two, five additional security professionals who would make a decisive difference. He urges companies to sponsor the software they actually use, especially the registries. Joel de la Garza adds a wry coda that will resonate with any security practitioner: virtually every conversation about securing a company ends with the question of how to do it cheaply. The industry's reluctance to fund its own foundational infrastructure is itself a security vulnerability. [1] — Feross Aboukhadijeh "Funding open-source registries: $25K–$50K: Feross Aboukhadijeh argued that relatively small sponsorship amounts of $25K–$50K from enterpris…" 19:17
Feross Aboukhadijeh argued that relatively small sponsorship amounts of $25K–$50K from enterprises could meaningfully fund security staff at under-resourced open-source package registries.
Feross Aboukhadijeh declared 2026 the year of the software supply chain, noting supply chain attacks have broken into mainstream business press coverage for the first time.