Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

131–140 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#131
post #97

If I were a chinese hacker trying to do something evil, why on earth would I use a chinese handler/username? Wouldn’t it be better to use an English/European name to gain (even more) trust from open source maintainers? On the other hand, if I were a non-chinese hacker trying to do evil, then using a chinese handler does make more sense (China is evil, blah blah blah)

Something I've observed as an English speaking immigrant is that in general, the US/UK is very forgiving when it comes to foreigners trying to speak English. Where certain types of phrasing and harsh words would not be tolerated with first language English speakers, the benefit of the doubt is given to 2nd/3rd language speakers because they 1. Might not have the vocabulary to express themselves correctly 2. Not under…

The English used in the commit messages I’ve seen was pretty much perfect, but unfortunately the repo has been suspended now.

Re: Xz: A microcosm of the interactions in open source projects

#132

>Our no-longer-reasonable requestor also offers a suggestions. Notice there is no offer to actually help. Help in maintainship how? Patches had already been made and were awaiting to be reviewed and merged. This was up to the maintainer to do and requestor couldn't help with it.

Collin gives his thoughts on both PRs and essentially says they just need more cross-arch testing with a focus on performance. The requester could absolutely help by doing some of those tests and providing back the results. Seems very straightforward to me what Collin is needing help with.

Re: Xz: A microcosm of the interactions in open source projects

#133
post #87

Earlier quoted context omitted.

I don’t understand this view of “If I give someone unsolicited money, they will do what I want”.

You have it backwards: The notion that open source developers can not or should not ask for monetary compensation for their work is what leads to their exhaustion and their project's demise. Of course if the developers don't want to be paid, then that's that. But otherwise, there is a very heavy atmosphere in the open source community of excommunicating anyone who dares to ask for payment as heathens of the vilest or…

> there is a very heavy atmosphere in the open source community of excommunicating anyone who dares to ask for payment as heathens of the vilest order

I fully agree that forcing payment or using dual licensing is unfortunately heavily frowned upon. But a voluntary Patreon/donation option is perfectly acceptable to the same anti-payment people.

Re: Xz: A microcosm of the interactions in open source projects

#134
post #65

Earlier quoted context omitted.

You dont need to wonder. Any long term maintainer of even semi popular open source projects will tell you that engaging with the peanut gallery is completely counter productive. Engage with people that have earned it in your eyes, whether by contributing to your project via code, assets, bug triage, writing a good and effortful bug report, whatever. Just ignore what the larger internet has to say about you and your c…

I think this is a wider social problem of the internet. Most people want to be helpful to others. This works fine when it is with a limited no of in real life interactions with mostly reasonable people. It can get wrecked by one or two unreasonable people, but the more fundamental problem is that it does not scale well, and the internet takes it to a far greater scale. It is one reason so many of us essentially work…

[deleted]

Re: Xz: A microcosm of the interactions in open source projects

#135
post #58
post #39

Earlier quoted context omitted.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

This ignores the very fact that peer pressure works and puts the entire blame on the victim. No, people react differently when pressured vs when not pressured. That's the entire reason why peer pressure works.

Peer pressure happens when someone like a teenager wants or has to be around some other peers (teenagers) but has to follow the whims of the peers in order to continue to be around them or to not be harassed by them.

The peanut gallery of non-contributors are only peers in the sense that they pretend to speak on behalf of some OSS community. And the fact that they are spokespersons is by default suspect. The attacker is a peer in the sense of being a contributor. So is he a peer pressurer? Again we come back to the teenager who has to follow the whims of his peers in order to be included. The maintainer is already inside of his own playground. So the pressure to be part of the “community” is really the incredibly abstract thing that the peanut gallery was referring to: you ought to do so-and-so in order to be whatever I think of in my head as an OSS maintainer.

This can be rejected out of hand if you really believe that maintainers don’t owe anyone anything (because of free labor).

But this gets incoherent if you want to assert both of these things:

1. There is no social contract for OSS maintainers: they can toss their PC out of the window and go on a five-year pilgrimage without telling anyone

2. There is some community which has power over the maintainer to peer pressure them

If you really want to double down on (1), the “cure” is what the OP suggested: say no and walk away.

Re: Xz: A microcosm of the interactions in open source projects

#136
post #84

I'm starting to feel that one of the lessons here is that individuals invited into trusted positions should be identifiable. Jia Tan is not a real person. We don't know who they are, so there is no way to hold them accountable.

While all of this is of course quite serious, we also need to remember that these types of things are actually fairly rare. Last major one was that JS event-stream thing, and that was in 2018 (5 and a half years ago). I don't think this is really a structural problem requiring these kind of sweeping changes; it's just an occasional rare incident.

No, the problem is that we don’t know how common it is.

We only know about the ones found.

Re: Xz: A microcosm of the interactions in open source projects

#137
post #39

Earlier quoted context omitted.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

This is incredibly naive. Anyone that thinks that pressure doesn’t work is exactly who I’d personally put top of my list to try to social engineer. Everyone is human. Nobody has infinite strength against persistent pestering. Everyone is capable of finding oneself in a scenario where they feel unsolicited responsibility. All you’re saying here is that you haven’t personally experienced it.

The GP did not state that pressure does not work. They stated how to they think one should think about people trying to pressure. Or about contributions. They named the industry's self inflicted problems.

Re: Xz: A microcosm of the interactions in open source projects

#138
post #54

I'm under no illusions that this is a totally new thought, but for me first with cryptocurrencies, then "AI", and now this, the fundamental issue that the biggest problems come back to is one of trust. Cryptocurrencies try to code around it, LLM boosters try to dazzle you into it, and the attacker here half-succeeded in laundering it. The most consequential (rightly or wrongly) technologists of our time are failing t…

> The most consequential (rightly or wrongly) technologists of our time are failing to properly think about trust.

Because that's an insanely hard problem that's outside our area of expertise.

Consider how much money governments spend on all the red tape they add to increase trust. If there was naturally perfect objective alignment and trust I bet any infrastructure project would cost about 10% of what it does.

Re: Xz: A microcosm of the interactions in open source projects

#139
post #111

Earlier quoted context omitted.

Anything can be viewed as a judgement statement if you paraphrase or stretch things enough. I don't think your paraphrasings are a fair representation of what I actually said. But you can insert "I'm not trying to blame anyone, but here are some suggestions to modify cultural norms so these things are less likely to happen in the future" if you want. Or you can just assume good faith and take that as implied unless d…

But what's the advice here? "When people are trying to peer pressure you, don't accept?"

More or less, yes. Also see my other post: https://news.ycombinator.com/item?id=39883598

Also: as far as I'm concerned there is no "peer pressure" here because these people aren't "peers". They're just some random people who, as near as I can tell, have done fuck all. There is not even an attempt to help out. Not even the question on how to help out. These people are supposed to be the maintainer's peers? Yeah nah. They're just shouty entitled internet nobodies that have not even attempted to contribute anything constructive or signal any willingness to do so (not even "I have been using the patch in production for half a year without problems", which would actually be a small but useful way to help out).

When it comes to these types of things you need to accept that you can't change every person in the world; you can only change yourself. If you cycle a lot you better learn to anticipate assholes doing asshole things. Is that fair? No. But it beats being run over and getting hospitalized, or worse.

Re: Xz: A microcosm of the interactions in open source projects

#140
post #61
post #38

Earlier quoted context omitted.

This is why OSS can be more secure. How much software has the build scripts, the code, all of it, locked away and hidden behind propriety software? Instead of lots of eyes, just 2 DEVs? Yes, this almost succeeded... but can you imagine how many scenarios where someone such as Andres Freund would have found irregularities, but then.. what? Just had to report it to some webpage's contact page? Without being able to eve…

I think there are huge factors that push things both for and against open source here. Yes, you get more eyes and people like Andres Freund. However, if this had been a mole in a company, he wouldn't be able to hide behind a possibly anonymous fake persona and (likely) be immune from any consequences/fallout from this attack. It would be harder to gain entry in the first place, he would have needed a real identity. B…

Organisations shield moles and infiltrators very effectively. They are rarely alone. It may be harder to get in as an outsider, but once in they've protections a lone wolf does not enjoy.

You can save a lot of time reading John LeCarre novels and take a short summary like this one of Adam Curtis [0].

If you watched the recent Oppenheimer film you'll know the name Klaus Fuchs. But what about Guy Burgess, Kim Philby and Anthony Blunt? If MI5, MI6 and GCHQ are. almost by tradition stacked to the rafters with defectors and spies, enclaves of enemies within, and enemies within enclaves of enemies... how does anyone expect a commercial company motivated by money and with such a weak perimeter as a "job market", to do better?

Trust does not have an organisational solution.

[0] https://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9...

Post reply on HN