Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

271–280 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#271
post #17

Earlier quoted context omitted.

The tiredness or other problems of the developer seems an easy narrative, but did anything actually happen that wouldn't in any understaffed open source project? A contributor shows up and does work for 2 years, I feel most projects would have given the person full project developer status by then.

It's not like organizations writing proprietary software are magically immune to sleeper agents either. Social engineering is not a software or tech problem in general. Trust is required to get anything done, and can also be abused to hell and back by a sufficiently motivated actor. But important software needs to be identified and proportionally more scrutinized by multiple independent parties, that's the lesson. Id…

True, but organizations tend not to accept online-only identities.

Re: Xz: A microcosm of the interactions in open source projects

#272
post #63
post #54

I'm under no illusions that this is a totally new thought, but for me first with cryptocurrencies, then "AI", and now this, the fundamental issue that the biggest problems come back to is one of trust. Cryptocurrencies try to code around it, LLM boosters try to dazzle you into it, and the attacker here half-succeeded in laundering it. The most consequential (rightly or wrongly) technologists of our time are failing t…

> The most consequential (rightly or wrongly) technologists of our time are failing to properly think about trust. It is implicit in your statement that you know some "proper" way to think about trust. If it is the case, please do share with us your thoughts on trust.

Trust is a lot easier if real-life identities and real-life consequences are involved.

Unfortunately the Open Source community has a long history of ties to anonymity culture, which is fundamentally untrustworthy.

Re: Xz: A microcosm of the interactions in open source projects

#273
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

My layperson’s opinion is that anything to do with gaming is particularly riddled with people that interact poorly with maintainers. Again, purely my opinion: gamer culture invites a particular sort of Dunning-Kruger-prone ‘power user’ type. Every gamer community carries with it a corpus of baseless, fictitious, technical information. “The developers didn’t do this because x”, “it’s ridiculous that they didn’t just y…

I think what you said is true but the major reason is simpler: there are way more gamers than developers.

So if your project's audience is gamers, of course it's going to attract more people which also means lower quality community almost automatically.

Re: Xz: A microcosm of the interactions in open source projects

#274
post #241

Earlier quoted context omitted.

Steve Jobs said that someone needs to be the keeper and maintainer of the vision. I think that’s the key to the making of anything great over the long run: there needs to be a Benevolent Dictator For Life who has the vision, competence, energy, passion, and caring to consistently iterate the thing well. The best case scenario for a project that loses its BDFL(s) is to hold on maybe as decently as Apple has under Tim…

44% of active open source projects have only one maintainer. Out of all maintainers, 60% would describe themselves as unpaid hobbyist. They already are BDFL for themselves or one other person. The problem is a chronic deficiency of maintainers, which is at the root of this attack. Your comment implies there is a wide pool of peoplecwho want to do that, along with mythical "someone". Here is a little story: There was…

> Your comment implies there is a wide pool of peoplecwho want to do that, along with mythical "someone".

I don’t know where you got that? I didn’t say there are a lot of people who can or would step up. It’s the opposite: competent, motivated people are rare… and why would they step in to maintain someone else’s project?

I was implicitly hinting at this by saying you need a Steve Jobs. We all know how rare such people are.

Re: Xz: A microcosm of the interactions in open source projects

#275
post #214

Earlier quoted context omitted.

> I think this is why I don't do social media any more Guess what you’re doing here, buddy.

IMO, it's not social media unless there's a social graph. HN has no way to follow or otherwise establish some relationship with specific users, so it's just a forum, not social media.

Classic phpBB style forums had smaller populations, there might not have been a follow feature, but the relationships formed naturally. HN doesn’t really feel like one.

I don’t really know how I’d classify the differences specifically…

Re: Xz: A microcosm of the interactions in open source projects

#276

At first I thought it was paranoid to suggest that people on the linked thread might be complicit in the attack but then I read this message: > You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs? It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Amazing how…

> It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect.

Worthwhile noting: It happened in the open, archived for the world to see at any time! The attacker needed to be extra careful not to raise suspicion, both acutely and for accumulated evidence in history. Of course, easy to say "Hindsight is 20/20", but we can probably agree in actual hindsight, we easily see a lot of suspicious acts around the issue. An individual incident may be chance, but as a whole things become clear more easily.

So, I think there is a teachable moment here: When something seems just a tiny bit fishy, do a background check, investigate. You may not catch all something, but you probably won't miss everything.

Now, looking at the level of sophistication and risk sneaking people and code into open infrastructure, imagine chances of getting caught infiltrating a large company writing closed source binary blobs for drivers, firmware, ...

Re: Xz: A microcosm of the interactions in open source projects

#277
post #270

Earlier quoted context omitted.

Peer pressure happens when someone like a teenager wants or has to be around some other peers (teenagers) but has to follow the whims of the peers in order to continue to be around them or to not be harassed by them. The peanut gallery of non-contributors are only peers in the sense that they pretend to speak on behalf of some OSS community. And the fact that they are spokespersons is by default suspect. The attacker…

If you think peer pressure is most relevant to teenagers, you really need to sit down and rethink peer pressure.

It is certainly the most obvious and kind of archetypal kind of peer pressure, which doesn’t mean that it’s exclusive to teenagers.

Re: Xz: A microcosm of the interactions in open source projects

#278

At first I thought it was paranoid to suggest that people on the linked thread might be complicit in the attack but then I read this message: > You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs? It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Amazing how…

> It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Worthwhile noting: It happened in the open, archived for the world to see at any time! The attacker needed to be extra careful not to raise suspicion, both acutely and for accumulated evidence in history. Of course, easy to say "Hindsight is 20/20", but we can probably agree in actual hindsight, we easily see a lot of suspici…

There are not that many suspicious acts tbh. Randos complaining about unmaintained repos and unclosed issues is a constant in FOSS world.

Sometimes it's even true, some projects really die and stop actually addressing real issues.

But that's just inherent downside of the "bazaar" model. I don't think how we can "treat maintainers better" without going full corporate/without going full "cathedral".

Re: Xz: A microcosm of the interactions in open source projects

#279
post #154

Earlier quoted context omitted.

I have never seen a code of conduct that would prevent a polite rejection of whatever new suggestion or help to a project.

I have never seen a Code of Conduct that emphasized that the overriding goal of all social interactions under the domain of project is to deliver a quality product

The conversation is about trust in software systems, not some code of conduct grievance you want to wedge in here.

Re: Xz: A microcosm of the interactions in open source projects

#280

Earlier quoted context omitted.

The English used in the commit messages I’ve seen was pretty much perfect, but unfortunately the repo has been suspended now.

I agree. Either native English or very very good second language. Given the weird laziness of some parts of the attack I'd put my money on native English.

It sounds to me like you're trying to seek a correlation too eagerly. It's not obvious whether it's more implausible that he's a lazy Chinese programmer with very good English, or a lazy native English-speaking programmer who wants to pretend to be Chinese.
Post reply on HN