Live data from Hacker News

Mitigating Memory Safety Issues in Open Source Software

security.googleblog.com

1–10 of 244 posts

Re: Mitigating Memory Safety Issues in Open Source Software

#3
What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools.

Correct me if I’m wrong, but that’s my understanding of the rather terse article.

I would rather have the original maintainers funded and still in control of the many pieces that form the basis of the major Linux distributions.

Re: Mitigating Memory Safety Issues in Open Source Software

#4
post #3

What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools. Correct me if I’m wrong, but that’s my understanding of the rather terse article. I would rather have the original maintainers funded and still in control of the many pieces that form the basis of the major Linux distribut…

Yeah, it sounds a lot like Google is going to "hijack" popular open source projects for the sake of "security".

It'll be interesting to watch how this plays out. But I pity the projects where Google's gaze falls upon.

Re: Mitigating Memory Safety Issues in Open Source Software

#5
post #3

What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools. Correct me if I’m wrong, but that’s my understanding of the rather terse article. I would rather have the original maintainers funded and still in control of the many pieces that form the basis of the major Linux distribut…

They specifically mention rust based backends for curl where the author of curl was funded to integrate as a starting point. I don't see any mention of funding being exclusively for organisations other than the author(s)?

Re: Mitigating Memory Safety Issues in Open Source Software

#7
post #3

What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools. Correct me if I’m wrong, but that’s my understanding of the rather terse article. I would rather have the original maintainers funded and still in control of the many pieces that form the basis of the major Linux distribut…

Agreed 100%.

Sadly everyone expressing concerns like this will be dismissed and everyone is going to once again hail google for being community friendly and supportive of FOSS.

Re: Mitigating Memory Safety Issues in Open Source Software

#9
Would not be cheaper to fix those unsafe languages, such as C, and offer safe mechanisms that could be used upon need?

Why spend thousands, if not millions of dollars, on rewriting existing codebases when they could help fixing the existing toolset and make it safer?

I don't get it.

Re: Mitigating Memory Safety Issues in Open Source Software

#10
post #3

What is left out of the title is that they do not provide funding to the current authors/maintainers of these open source projects. Instead, they fund an organization that will rewrite these tools. Correct me if I’m wrong, but that’s my understanding of the rather terse article. I would rather have the original maintainers funded and still in control of the many pieces that form the basis of the major Linux distribut…

Yeah, it sounds a lot like Google is going to "hijack" popular open source projects for the sake of "security". It'll be interesting to watch how this plays out. But I pity the projects where Google's gaze falls upon.

I’m not sure “hijack” is the right word. They are using money to entice projects to rewrite in memory safe languages.
Post reply on HN