Xz: A microcosm of the interactions in open source projects
robmensching.com
Xz: A microcosm of the interactions in open source projects
1–10 of 353 posts
Re: Xz: A microcosm of the interactions in open source projects
#2Culpability also must be laid at RedHat's feet for sanctioning the practice of side loading libraries into such a critical service's address space. Their drive to cellularize systems management has overtaken their common sense.
The idea that they could not be bothered to answer the call of the sole maintainer of a library used in such a critical path in his time of need is, well, astonishing.
Re: Xz: A microcosm of the interactions in open source projects
#3Re: Xz: A microcosm of the interactions in open source projects
#4Funny. I was just saying the same thing to one of my partners just 4 hours ago. Culpability also must be laid at RedHat's feet for sanctioning the practice of side loading libraries into such a critical service's address space. Their drive to cellularize systems management has overtaken their common sense. The idea that they could not be bothered to answer the call of the sole maintainer of a library used in such a c…
2) A potential explanation for "why now" is that systemd DID prevent these dependencies from loading automatically in a patch one month ago [0], and the patches to lzma enabling the backdoor merged a few days later, followed by (as we know) an immediate and somewhat heavy push to get distros to upgrade driven by sockpuppets. It could be a total coincidence, or it could be that the attacker jumped to pull the trigger before the window of vulnerability started closing on them
[0] https://github.com/systemd/systemd/pull/31550#issuecomment-1...
I think it's a bit cheap to blame systemd here, and systemd does not equate directly to Red Hat either.
Re: Xz: A microcosm of the interactions in open source projects
#5awkward, but heard very recently that open source is not "vc backable, go away". maybe it will change now, after the infrastructure pillars of the modern world ruins in front of those many saas/ai/web3/cloud/whatever investors
The SaaS/cloud/etc. companies themselves should fund the projects they depend on. They actually know what those are and don't have to force their own monetization/growth models onto the projects.
Re: Xz: A microcosm of the interactions in open source projects
#6Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.
Re: Xz: A microcosm of the interactions in open source projects
#7>Our no-longer-reasonable requestor also offers a suggestions. Notice there is no offer to actually help. Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.
Pay.
Re: Xz: A microcosm of the interactions in open source projects
#8>Our no-longer-reasonable requestor also offers a suggestions. Notice there is no offer to actually help. Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.
> Help in maintainship how? Pay.
Re: Xz: A microcosm of the interactions in open source projects
#9awkward, but heard very recently that open source is not "vc backable, go away". maybe it will change now, after the infrastructure pillars of the modern world ruins in front of those many saas/ai/web3/cloud/whatever investors
Why should VCs back oss infrastructure directly? It doesn't help the VCs and only creates perverse incentives for the oss projects. The SaaS/cloud/etc. companies themselves should fund the projects they depend on. They actually know what those are and don't have to force their own monetization/growth models onto the projects.
There is a bit of a free rider problem it seems.