Earlier quoted context omitted.
> Help in maintainship how? Pay.
Huh? So anyone who asks/says something in OSS, should just throw money into the ring to have an opinion?
Xz: A microcosm of the interactions in open source projects
21–30 of 353 posts
Re: Xz: A microcosm of the interactions in open source projects
#22Considering how kind(naive) our open source projects maintainers are, backdoors are probably already everywhere.
Re: Xz: A microcosm of the interactions in open source projects
#23Re: Xz: A microcosm of the interactions in open source projects
#24Considering how kind(naive) our open source projects maintainers are, backdoors are probably already everywhere.
Re: Xz: A microcosm of the interactions in open source projects
#25The Jigar Kumar account should be treated with extreme suspicion. It seems like it was part of a social engineering attack.
Re: Xz: A microcosm of the interactions in open source projects
#26Earlier quoted context omitted.
Enabled by customers who don’t pay or donate.
Are these customers or additional attackers who have never posted before and will never post again?
Even if we say "no payment, no customer," it won't prevent determined attackers from paying significant amounts of laundered money in order to be treated as customers.
Re: Xz: A microcosm of the interactions in open source projects
#27Re: Xz: A microcosm of the interactions in open source projects
#28Earlier quoted context omitted.
> Help in maintainship how? Pay.
That assumes the maintainer wants to be paid. There are plenty of us who maintain FLOSS projects that do it for other reasons and any monetary exchange would burden us, since it might pressure one that this is now a job and you have to execute on tasks - there are enough headaches handling other things as it is.
Re: Xz: A microcosm of the interactions in open source projects
#29Re: Xz: A microcosm of the interactions in open source projects
#30So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
The tiredness or other problems of the developer seems an easy narrative, but did anything actually happen that wouldn't in any understaffed open source project? A contributor shows up and does work for 2 years, I feel most projects would have given the person full project developer status by then.
But important software needs to be identified and proportionally more scrutinized by multiple independent parties, that's the lesson. Identification is the hard part. You can't easily determine that half of the world relies on this particular piece of software, or that it enables access to desirable targets.