Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

311–320 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#311

Earlier quoted context omitted.

I think this is a wider social problem of the internet. Most people want to be helpful to others. This works fine when it is with a limited no of in real life interactions with mostly reasonable people. It can get wrecked by one or two unreasonable people, but the more fundamental problem is that it does not scale well, and the internet takes it to a far greater scale. It is one reason so many of us essentially work…

> Most people want to be helpful to others. This works fine when it is with a limited no of in real life interactions with mostly reasonable people. I don't think it has anything to do with the internet (whose scale pose many problems but not this one): anyone that founded a product/start up can tell you that people will give you “advices” and “suggestions” all the time when you talk about your project, and “don't li…

I'm always wary of people that freely give advice/suggestions because they probably:

* lack information

* have a conflicting vision

* are being dishonest

I'm not a founder but I imagine that being integral to your own vision is the way to go. Attempting to cater to the conflicting needs of a diverse set of users isn't feasible for a startup.

But anyway this isn't valid only for founders but also to life, friends and family.

Re: Xz: A microcosm of the interactions in open source projects

#312

At first I thought it was paranoid to suggest that people on the linked thread might be complicit in the attack but then I read this message: > You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs? It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Amazing how…

this was two years ago though. why rush someone when you're planning to play the long game anyway?

Because successfully creating a sense of urgency will help the maintainer make a hurried unwise decision. It's part of the whole pattern.

Re: Xz: A microcosm of the interactions in open source projects

#313
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

I'm always surprised at how much developers and maintainers will willingly put up with. For example, if you visit the Matrix feed for the Asahi Linux project, you'll see hoards of trolls and time-wasters that are regularly engaged by Asahi team members who are giving them the benefit of the doubt, when they really should be removing those posts without comment or acknowledgement. I believe this masochistic behaviour…

For me it's easy to get very excited about any attention or interest at all as meaning "This project is finally worth something and all this effort wasn't wasted!" and start thinking "the customer is always right!"

Re: Xz: A microcosm of the interactions in open source projects

#314

Earlier quoted context omitted.

The "users are mean" story is something that we can all do something about, and, honestly, I prefer stories with morals that most of us can actually put into practice.

Ah, well, I guess my thought is that we need to figure out what to do about the "take over from a burned out maintainer and then inject malware" attack. It's not obvious what to do about it to me either. Which is why I'm concerned to talk about it. That this attack was run by someone who had been participating in the project for possibly years before making the attack -- is not what i would have expected, and makes i…

> I suppose "try to get users to be less mean, by doing our part by being less mean individually" is arguably one piece of strenghtening defenses to this kind of attack, I guess, ok.

Yes, by denying cover traffic.

Re: Xz: A microcosm of the interactions in open source projects

#315

Earlier quoted context omitted.

> It genuinely looks like we’re seeing a demonstration of supply chain psyops in retrospect. Worthwhile noting: It happened in the open, archived for the world to see at any time! The attacker needed to be extra careful not to raise suspicion, both acutely and for accumulated evidence in history. Of course, easy to say "Hindsight is 20/20", but we can probably agree in actual hindsight, we easily see a lot of suspici…

There are not that many suspicious acts tbh. Randos complaining about unmaintained repos and unclosed issues is a constant in FOSS world. Sometimes it's even true, some projects really die and stop actually addressing real issues. But that's just inherent downside of the "bazaar" model. I don't think how we can "treat maintainers better" without going full corporate/without going full "cathedral".

> But that's just inherent downside of the "bazaar" model. I don't think how we can "treat maintainers better" without going full corporate/without going full "cathedral".

We now have two decades of arms-race data in OSS projects influenced by ESR's paper [1].

At least one bazaar [2] has operated for centuries.

Bazaars can develop decentralized responses to dynamic local threats.

[1] http://www.catb.org/~esr/writings/cathedral-bazaar/

[2] https://en.wikipedia.org/wiki/Grand_Bazaar,_Istanbul

Re: Xz: A microcosm of the interactions in open source projects

#316
post #96

Earlier quoted context omitted.

2007 was 17 years ago, and it was another world. This time 17 years ago, the iPhone had not been released. Facebook was still new and hot, the first big operation to be unashamedly built on PHP (!). GitHub didn't exist , opensource happened on mailing lists, Sourceforge, private Subversion repos. It was definitely another world. I do agree that maintainership issues were already there, but I think they were smaller i…

MySpace, Yahoo! Mail, eBay and probably other large scale operations were all built on PHP long before Facebook and I don’t think any of them were particularly ashamed about it.

I doubt eBay was originally built with PHP - when it was founded in 1995, the very first PHP version had been available for barely 3 months. I expect the original EBay was mostly Perl, which was the standard at the time.

The others I don't know, but MySpace was not a particularly big operation. Before WordPress, most sites started as PHP at some point were expected to migrate to something else, because maintainability of PHP3/4 projects was a big challenge (hence the "shame"). Facebook was the first company that simply refused to do that, and focused on improving PHP instead.

Re: Xz: A microcosm of the interactions in open source projects

#317
post #75

Some random thoughts: - every Fortune 500 company tracks exactly which FOSS code it includes in its ecosystem (usually code scanning and fingerprinting - can’t remember the usual Provider of such) - this is essentially the software BOM that Biden signed a while back. - this (made public) would give a real time map of the dependancies of all organisations - and linking that to things like the above thread (“cry for he…

> “here are three interns doing two years in gov.uk. They will help for the next 2 years Having temp workers come and go into all kinds of various open source projects.. does that help? :)

Does two years count as temp? What if one in five stays on for “life”

I am not claiming I have perfect solutions, just that we need to be more mindful of our supply chains. And when we are we start demanding things of those supply chains - and if we are sensible we support those suppliers

Re: Xz: A microcosm of the interactions in open source projects

#318
post #119

Some random thoughts: - every Fortune 500 company tracks exactly which FOSS code it includes in its ecosystem (usually code scanning and fingerprinting - can’t remember the usual Provider of such) - this is essentially the software BOM that Biden signed a while back. - this (made public) would give a real time map of the dependancies of all organisations - and linking that to things like the above thread (“cry for he…

Agreed it’s a decent way to create a “map” of vulnerable projects. But it’s over-fitting the MO of adversaries - plugging an arbitrary hole. Why not play into the strengths of OSS instead of trying to replicate frictionous trust models from elsewhere? Like, listen to ourselves. We are admitting here that open source software is not feasible to audit? Like did we just accept that an adversary can basically smuggle exp…

I have to admit that is a good point - myself I think there is some other goal here - I am trying to build reproducible workstations and servers (nix os). And until right now I have not even considered can I put all the source code I am sitting on in one place.

God knows if I could. It that has to be the first place to start

Re: Xz: A microcosm of the interactions in open source projects

#319

> This is the way it works. It needs to change. Well, it’s on you to set your boundaries. "Feel free to submit a PR" works wonders.

Be careful what you wish for. Someone will eventually take you up on that challenge. The responsibility will lie with you when they do make that pull request. Is that something you actually want? I gotta ask because it seems there's lots of people out there who are saying that but don't actually want it to happen. Look I get it, it's a great line, it instantly weeds out anyone who can't code, it even filters out thos…

I like (and upvoted) how you replied, but disagree with you.

What's the problem, honestly? Telling someone that you don't like / want their code / direction / feature?

It just takes a modicum of emotional maturity to do that.

Re: Xz: A microcosm of the interactions in open source projects

#320
post #279

Earlier quoted context omitted.

I have never seen a Code of Conduct that emphasized that the overriding goal of all social interactions under the domain of project is to deliver a quality product

The conversation is about trust in software systems, not some code of conduct grievance you want to wedge in here.

as I wrote originally, trust implies discernment which contradicts egalitarianism. Most codes of conduct take egalitarianism for granted. If one does not treat all comers equally, one will eventually be accused of violating someone’s code of conduct.

In my book, software quality is much more important than emotions.

Post reply on HN