Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

291–300 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#291
post #54

I'm under no illusions that this is a totally new thought, but for me first with cryptocurrencies, then "AI", and now this, the fundamental issue that the biggest problems come back to is one of trust. Cryptocurrencies try to code around it, LLM boosters try to dazzle you into it, and the attacker here half-succeeded in laundering it. The most consequential (rightly or wrongly) technologists of our time are failing t…

I think the biggest problems come from single points of failure. This wouldn't be as problematic if _everyone_ didn't use the same libraries. I guess you could argue that's similar to trust.

In any case, I agree technologist aren't thinking about it because the only way to extract massive amount of wealth is by centralization/monopoly. Hard problem though, the appropriate amount of redundancy is hard to know.

Re: Xz: A microcosm of the interactions in open source projects

#292
post #97

If I were a chinese hacker trying to do something evil, why on earth would I use a chinese handler/username? Wouldn’t it be better to use an English/European name to gain (even more) trust from open source maintainers? On the other hand, if I were a non-chinese hacker trying to do evil, then using a chinese handler does make more sense (China is evil, blah blah blah)

> If I were a chinese hacker trying to do something evil, why on earth would I use a chinese handler/username?

1) Why not?

2) You'd likely want a relatively common-sounding name, I suppose. Chinese names are relatively common-sounding.

Re: Xz: A microcosm of the interactions in open source projects

#293

At first I thought it was paranoid to suggest that people on the linked thread might be complicit in the attack but then I read this message: > You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs? It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Amazing how…

Also the authors of these messages never interacted on that mailing list before or after. They only turned up to put pressure on the original maintainer.

Re: Xz: A microcosm of the interactions in open source projects

#294
post #282
post #35

Sadly, this is how it works in many large social systems, left unchecked. The “reasonable consumers” drain the kind contributors until they cannot do this anymore. The curse of kindness strikes in software and other industries alike.

This is all due to the ongoing attempt to convert FOSS into an obligation. The original idea behind FOSS was to code to scratch your itch and then leave it out there for anyone to find, modify and use. Instead we now treat FOSS code like commercial projects with performance goals and expectations. Why? My guess is that this new culture is promoted to extract free labor from hobby developers. Take for example, Github.…

> Why?

Well, also a lot of people get into FOSS for altruistic reasons. They want to pay it forward and make the world a better place.

For these people, applying good operations principles allows them to more efficiently do good -- just like it allows a commercial company to deliver more end-user value for lower cost.

Running an efficient operation in FOSS isn't necessarily bad. Sometimes it takes an obligation viewpoint to get there. It can be unhealthy, but it can also give us crazy levels of neat software, as we see proof of daily.

Re: Xz: A microcosm of the interactions in open source projects

#295
post #39

Earlier quoted context omitted.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

This is harsh but tree, but it's not simple. People are different. Some shrug off things naturally, others try to be empathetic almost to a fault. I've learned to be the former, but when I was younger was much more the latter. I try not to act like it's easy because it took me a while to have that skill. And it is a skill and not built in to me, I still feel the urge but built up the skill of saying "no"

true*

Re: Xz: A microcosm of the interactions in open source projects

#296
post #270

Earlier quoted context omitted.

If you think peer pressure is most relevant to teenagers, you really need to sit down and rethink peer pressure.

It is certainly the most obvious and kind of archetypal kind of peer pressure, which doesn’t mean that it’s exclusive to teenagers.

That's still thinking of it the wrong way.

Peer pressure among adults is far more widespread and powerful than the limited peer pressure among teenagers.

Re: Xz: A microcosm of the interactions in open source projects

#297

Serious question, but what is your expectations for linux and all these libraries/dependencies after 20-40+ years when most of old school or current devs are retired? How can anyone guarantee reliable continuity by good actors in all these dependencies?

Steve Jobs said that someone needs to be the keeper and maintainer of the vision. I think that’s the key to the making of anything great over the long run: there needs to be a Benevolent Dictator For Life who has the vision, competence, energy, passion, and caring to consistently iterate the thing well. The best case scenario for a project that loses its BDFL(s) is to hold on maybe as decently as Apple has under Tim…

Someone has to step up. Someone's got to care. Someone this. Someone that.

Who if not you? When if not now? Be someone.

Re: Xz: A microcosm of the interactions in open source projects

#298
User Hakkin made an interesting observation: The "consumers" are likely sock puppets controlled by the attacker.

I did not independently verify the claim, but it seems reasonable to me.

Post with Hakkin's reply: https://news.ycombinator.com/item?id=39869703

(But yeah, I've seen some entitled idiots trying to push their demands on FOSS maintainers and being irritated by the harsh reaction...)

Re: Xz: A microcosm of the interactions in open source projects

#299

At first I thought it was paranoid to suggest that people on the linked thread might be complicit in the attack but then I read this message: > You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs? It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Amazing how…

this was two years ago though. why rush someone when you're planning to play the long game anyway?

Re: Xz: A microcosm of the interactions in open source projects

#300

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

I often debate if I should go into the hacking world, best case I get bug bounties, worst case I get rich and I contribute immoral actions. I think its far easier to make $3,000,000 as a hacker than a worker/entrepreneur. Its way easier to find flaws/bugs than to do the entire Capitalism thing correctly. Then I see that half of these major attacks required social engineering.... Maybe being a hacker is significantly…

I think your worst case is a bit off. Worst case you go to prison for a very long time?

And if you do make that $3m as a hacker, now you have to spend your time worrying about whether someone will eventually catch you because of that one time you logged into a service without using enough VPNs.

Post reply on HN