Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

221–230 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#221
post #99

Earlier quoted context omitted.

100% this. I don’t know why this obvious angle is being ignored. The other puppet accounts had Indian and German names - it’s very clear they were trying to obscure their real origins.

The hacker's name "Jia Cheong Tan" actually includes phonics from both variants of Chinese from China, Singpore and Hong Kong region, hence no way it is a name of a real person, so the name probably don't indicate anything. However, since the Hong Kong and Singapore variants is rarely used, the group behind the hacker probably has good knowledge of Chinese linguistics. Either way, the fact that the hacker's account s…

> that the hacker's activity is mostly in Southeast Asia working hours (read GMT+8)

Opposite is true. His activity is focused around midnight in UTC+0800, with significant activity at 2AM in that timezone.

Re: Xz: A microcosm of the interactions in open source projects

#223
post #65

Earlier quoted context omitted.

You dont need to wonder. Any long term maintainer of even semi popular open source projects will tell you that engaging with the peanut gallery is completely counter productive. Engage with people that have earned it in your eyes, whether by contributing to your project via code, assets, bug triage, writing a good and effortful bug report, whatever. Just ignore what the larger internet has to say about you and your c…

I think this is a wider social problem of the internet. Most people want to be helpful to others. This works fine when it is with a limited no of in real life interactions with mostly reasonable people. It can get wrecked by one or two unreasonable people, but the more fundamental problem is that it does not scale well, and the internet takes it to a far greater scale. It is one reason so many of us essentially work…

> Most people want to be helpful to others. This works fine when it is with a limited no of in real life interactions with mostly reasonable people.

I don't think it has anything to do with the internet (whose scale pose many problems but not this one): anyone that founded a product/start up can tell you that people will give you “advices” and “suggestions” all the time when you talk about your project, and “don't listen to random suggestions from people you've just met” is one of the first advice you're being given when you're talking to other founders.

It doesn't even need to scale above a handful of people to be a nuisance that harm your project if you listen to them.

Re: Xz: A microcosm of the interactions in open source projects

#224

As a maintainer of a security-oriented open source library, the paranoia of "is this person trying to help or to exploit?" weighs down on me every time I have to read a PR (EDIT: even though the libraries are by no means as widely used), regardless of whether it's from a long-time contributor or someone new. I think accepting a slower pace of development is the only viable solution (as I'm not interested in making th…

> As a maintainer of a security-oriented open source library, the paranoia of "is this person trying to help or to exploit?"

That's an excellent mind set when reviewing code, no matter security or not. But especially for security. How could this be wrong? What are the corner cases? How could anyboy break this? What do we need to test? That kind of scrutiny is crucial for keeping the quality of your code base high, no matter who posts the PR.

Re: Xz: A microcosm of the interactions in open source projects

#225
post #110

Earlier quoted context omitted.

> Help in maintainship how? Pay.

Pay is not the only thing regarding maintainership. Time is another factor. It takes time to maintain software, improve the codebase, add features, etc. Then there are the other tasks such as answering questions, reviewing PRs, triaging bugs and feature requests, etc. So getting more contributors, people to assist with bugs and bug investigations, etc. is arguably more important. Especially projects developed by a si…

>So getting more contributors, people to assist with bugs and bug investigations, etc. is arguably more important.

Pay is how you get more contributors.

Re: Xz: A microcosm of the interactions in open source projects

#226
post #71

Earlier quoted context omitted.

> It made it to production, for a long time Did it? At least in Debian, where it was found in the first place, it only existed in sid/unstable and I think perhaps in testing. It never made it into stable which is the only thing you should be running on a production system. I think in Fedora it was also only in a testing or RC of the next stable version but I'm not sure. Also unsure about others. I have seen several d…

I don't know specifics either, but Debian stable has years-old packages, so I'm not sure if it's a good indicator of how widespread this got. If it's in the latest Ubuntu release, I'd say it's pretty successful.

I don't personally know anyone who would run any Debian release that's not stable on production systems. On your desktop? Fine. I do it myself. On a server, with ports open to the public Internet that's a big nope.

There's nothing wrong with Debian stable having years-old packages either. In any case:

> The current "stable" distribution of Debian is version 12, codenamed bookworm. It was initially released as version 12.0 on June 10th, 2023 and its latest update, version 12.5, was released on February 10th, 2024.

https://www.debian.org/releases/

That's just over 1 year. Sure, packages themselves will be older than that since they take some time soaking frozen in testing before they become part of stable but that's generally a good thing.

In any case, if there's pressing need for some newer packages, it's always possible to use apt pinning to pull those on top of a stable base.

Re: Xz: A microcosm of the interactions in open source projects

#227
post #128

Earlier quoted context omitted.

I don’t think that’s a good application of Occam. Does it really seem parsimonious to think that someone who shows up with no prior history or subsequent activity is really just a random open source user who cares deeply about new maintainers for a low-level library they’re otherwise silent about?

But the point of the article, which matches my own observations, is that comments pouring guilt onto maintainers is commonplace. The depth of feeling it invokes in the maintainer is likely orders of magnitude more than the depth of caring on the part of the commentator. The normal commentator who complains is probably not malicious, probably not aware of the pain they might cause, is probably just not even thinking o…

Yes, I think that’s what made this attack so effective: that kind of abuse is normalized in much of the tech world so it’s very easy to miss that in this targeted case it was coming from accounts with no prior involvement in the community. I like the open feel we’ve had for the last 3 decades but I do think this will likely mean a lot of projects becoming less open, which is warranted but going to suck for people trying to start a career.

Re: Xz: A microcosm of the interactions in open source projects

#228
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

Apologies in advance for the swear words, but this deserves swear words.

WHO FUCKING GRANDSTANDS ENDLESSLY ABOUT CYBERTHREATS AND THE NEED FOR BETTER SECURITY?

WHO FUCKING SITS ON BILLIONS IF NOT TRILLIONS OF DOLLARS IN FUNDING?

That would be the FUCKING GOVERNMENTS OF THE FIRST WORLD. Whose modern economies increasingly rest on open source to a degree they possibly don't understand.

Yes I understand part of this comes from funding from another part of these governments. Oh well, cat and mouse. Once we wrung our hands over these governments having power over these. Well, these days we are facing far more totalitarian state threats and totalitarian wannabes in the private sector.

Government save me, as the less totalitarian option!

Linux and BSD the operating systems should UNQUESTIONABLY be funded to the degree of multiple billions per year by, I'll just put it, "NATO". Here's the true value of open source in this model: it is the perfect public record, unlike untold other aspects of government output.

You must produce public vetted code in Linux/BSD.

This person should not have been "a person". This should have been 5 people, funded likely at least 10-50k/year for their roles.

The described "hit" by the intel services of course is frighteningly easy. But what is most horrid is that this poor person is being subject to very common abuse that comes from non-state-actor manipulation. The article says it:

"this is where our software comes from" -- this poor dude that is trying to help and being abused by state actors on one hand, and ridden thanklessly and for no monetary or fame benefit by massively deep pocketed corporations, governments, and billionaires.

For all of Linus's famous swearing abilities, he hasn't used it to address this publicly. He should be dressing down all corporations and governments at this point that need Linux. There isn't a "going back" from Linux at this point to some closed source option.

Linus and Linux have massive sway here. They could threaten to stop work on the kernels.

I guess fundamentally, this makes me angry because this is basically bullying the nerd in high school to get his homework/answers. The nerds need to realize their power here.

Other vulnerabilities snuck through the commit chain? I get that, usual spy stuff. They actually kind of messed up here. Usually it is within the "cordiality" of things, just quietly ride the overworked unpaid nerd to benefit. Here they inadvertently exposed the real truth of everything: the hidden contempt we treat these people with as a society.

Re: Xz: A microcosm of the interactions in open source projects

#229
post #71

Earlier quoted context omitted.

I don't know specifics either, but Debian stable has years-old packages, so I'm not sure if it's a good indicator of how widespread this got. If it's in the latest Ubuntu release, I'd say it's pretty successful.

I don't personally know anyone who would run any Debian release that's not stable on production systems. On your desktop? Fine. I do it myself. On a server, with ports open to the public Internet that's a big nope. There's nothing wrong with Debian stable having years-old packages either. In any case: > The current "stable" distribution of Debian is version 12, codenamed bookworm. It was initially released as version…

I didn't say there's anything wrong, I meant that choosing the OS distribution with the oldest packages isn't an indication for how widespread the distribution of this package was.

Re: Xz: A microcosm of the interactions in open source projects

#230
The multi-entity (sock puppet or not hard to say) social engineering attack that was apparently two years in the making (?), is to me a much more salient story than "users are often mean." Although it's true that the expectation of mean users let the attack fit right in, I guess.
Post reply on HN