Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

111–120 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#111
post #77
post #73

Earlier quoted context omitted.

I didn't blame anyone; I just made some observations on how this type of thing can be avoided, partly based on my own experience doing volunteer work for the last 20 years (as open source maintainer and as scout leader), and being subject to the same pressures at times. I hate this trend of shouting "victim blaming!" once someone tries to explain things or analyse anything. Not everything needs to be a value judgemen…

Well, when you say "the victim could just not have succumbed to the pressure" I don't see how that doesn't blame the victim. I understand it's not your intention, but peer pressure works exactly because it gets around people's "wait, I don't actually want to do this" defense, and to say "just don't do it, nobody is physically forcing you to" ignores that fact. If I were in the maintainer's shoes, and was feeling ambi…

Anything can be viewed as a judgement statement if you paraphrase or stretch things enough. I don't think your paraphrasings are a fair representation of what I actually said.

But you can insert "I'm not trying to blame anyone, but here are some suggestions to modify cultural norms so these things are less likely to happen in the future" if you want. Or you can just assume good faith and take that as implied unless demonstrated otherwise.

Re: Xz: A microcosm of the interactions in open source projects

#112
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

My layperson’s opinion is that anything to do with gaming is particularly riddled with people that interact poorly with maintainers. Again, purely my opinion: gamer culture invites a particular sort of Dunning-Kruger-prone ‘power user’ type. Every gamer community carries with it a corpus of baseless, fictitious, technical information. “The developers didn’t do this because x”, “it’s ridiculous that they didn’t just y”, “They just aren’t listening to users!”

I’m not much of a gamer at all. But the once in a blue moon where I dip my toes in, it’s not that long before I’m met with a forum post or reddit comment making some technical assertion that sounds incredibly presumptuous if not downright incredibly unlikely.

Re: Xz: A microcosm of the interactions in open source projects

#113
post #86

Earlier quoted context omitted.

> Even writing it down here I'm worried I sound like I'm trying to curate a closed community of ego-boosting yes men. There's this weird trend that's been happening for some time now that tries to make non-fully-open groups look wrong, but honestly, has anything ever actually been done by such open groups? As far as I can tell, "closed community" is a necessary (but not sufficient) condition for any kind of quality c…

I think the linux kernel developement is quite open. But Linus is famous for telling people directly in not so nice words, that they are not helping. I don't think insults are the solution, but giving a clear no, is a skill many people struggle with. And if some cannot cope with that, blocking individuals also works.

My understanding was that Linus is cooling his jets a bit?

Re: Xz: A microcosm of the interactions in open source projects

#114
post #87

Earlier quoted context omitted.

No. But if the maintainer is burning out and doesn't have free time available for it, paying them so they can take time off to actually work on the thing is a nice way of fixing issues.

I don’t understand this view of “If I give someone unsolicited money, they will do what I want”.

You have it backwards: The notion that open source developers can not or should not ask for monetary compensation for their work is what leads to their exhaustion and their project's demise.

Of course if the developers don't want to be paid, then that's that. But otherwise, there is a very heavy atmosphere in the open source community of excommunicating anyone who dares to ask for payment as heathens of the vilest order.

Re: Xz: A microcosm of the interactions in open source projects

#115
post #97

If I were a chinese hacker trying to do something evil, why on earth would I use a chinese handler/username? Wouldn’t it be better to use an English/European name to gain (even more) trust from open source maintainers? On the other hand, if I were a non-chinese hacker trying to do evil, then using a chinese handler does make more sense (China is evil, blah blah blah)

At the end of the day this is such low hanging fruit that I don’t think that it’s even worth paying attention to. This was almost certainly a state actor and this detail would be blindingly obvious to all state actors capable of pulling this off. You could choose to try to dissect the 10 dimensional game of chess involved in picking fake names, or you could focus your attention on more meaningful heuristics.

Re: Xz: A microcosm of the interactions in open source projects

#116
post #99
post #97

If I were a chinese hacker trying to do something evil, why on earth would I use a chinese handler/username? Wouldn’t it be better to use an English/European name to gain (even more) trust from open source maintainers? On the other hand, if I were a non-chinese hacker trying to do evil, then using a chinese handler does make more sense (China is evil, blah blah blah)

100% this. I don’t know why this obvious angle is being ignored. The other puppet accounts had Indian and German names - it’s very clear they were trying to obscure their real origins.

The hacker's name "Jia Cheong Tan" actually includes phonics from both variants of Chinese from China, Singpore and Hong Kong region, hence no way it is a name of a real person, so the name probably don't indicate anything. However, since the Hong Kong and Singapore variants is rarely used, the group behind the hacker probably has good knowledge of Chinese linguistics. Either way, the fact that the hacker's account shows GMT+8 and that the hacker's activity is mostly in Southeast Asia working hours (read GMT+8) would only make sense if the hacker is originated from Asia countries. I doubt that group of people behind the hack can consistently stay late night for 2+ years just to fake the timezone.

Re: Xz: A microcosm of the interactions in open source projects

#117
post #63

Earlier quoted context omitted.

> The most consequential (rightly or wrongly) technologists of our time are failing to properly think about trust. It is implicit in your statement that you know some "proper" way to think about trust. If it is the case, please do share with us your thoughts on trust.

I didn't read it that way. I read it as in "actually giving it thought" as opposed to just barely acknowledging it or even at all. So, not so much a judgement of the quality of the thought but rather of its existence in the first place.

Yes, exactly this. I certainly don't claim to have any big answers, but at the same time I think these problems with trust were very clear very early on.

Re: Xz: A microcosm of the interactions in open source projects

#118
post #39

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

This is incredibly naive. Anyone that thinks that pressure doesn’t work is exactly who I’d personally put top of my list to try to social engineer. Everyone is human. Nobody has infinite strength against persistent pestering. Everyone is capable of finding oneself in a scenario where they feel unsolicited responsibility. All you’re saying here is that you haven’t personally experienced it.

Re: Xz: A microcosm of the interactions in open source projects

#119

Some random thoughts: - every Fortune 500 company tracks exactly which FOSS code it includes in its ecosystem (usually code scanning and fingerprinting - can’t remember the usual Provider of such) - this is essentially the software BOM that Biden signed a while back. - this (made public) would give a real time map of the dependancies of all organisations - and linking that to things like the above thread (“cry for he…

Agreed it’s a decent way to create a “map” of vulnerable projects. But it’s over-fitting the MO of adversaries - plugging an arbitrary hole.

Why not play into the strengths of OSS instead of trying to replicate frictionous trust models from elsewhere?

Like, listen to ourselves. We are admitting here that open source software is not feasible to audit? Like did we just accept that an adversary can basically smuggle exploit payloads in plain sight?

Can we at least try to simplify and reduce the messiness of checked in generated code, irreproducible builds, and magical binary blobs, conditional compilation, “ifuncs”? Wtf? Granted I’m not a domain expert in this area, but I’m horrified by all the complexity for what I understand to be a compression library.

I would much rather play whack-a-mole with obscurity, which as a side effect is great for software quality overall.

Re: Xz: A microcosm of the interactions in open source projects

#120
post #111
post #77

Earlier quoted context omitted.

Well, when you say "the victim could just not have succumbed to the pressure" I don't see how that doesn't blame the victim. I understand it's not your intention, but peer pressure works exactly because it gets around people's "wait, I don't actually want to do this" defense, and to say "just don't do it, nobody is physically forcing you to" ignores that fact. If I were in the maintainer's shoes, and was feeling ambi…

Anything can be viewed as a judgement statement if you paraphrase or stretch things enough. I don't think your paraphrasings are a fair representation of what I actually said. But you can insert "I'm not trying to blame anyone, but here are some suggestions to modify cultural norms so these things are less likely to happen in the future" if you want. Or you can just assume good faith and take that as implied unless d…

But what's the advice here? "When people are trying to peer pressure you, don't accept?"
Post reply on HN