Earlier quoted context omitted.
An issue is that the maintainer may have other priorities. By sponsoring an item you "force" them to look at that sooner.
Probably, it is their choice to fix the issue and collect. An unresolved issue in the agreed timeline automatically refunds the money. Maintainer has the option to request more time. Donors can accept or reject. Ideally multiple people would sponsor an issue, so some percentage of funding would back out as deadlines are missed, but not all funding. Incentive is more delay, less reward.
Xz: A microcosm of the interactions in open source projects
331–340 of 353 posts
Re: Xz: A microcosm of the interactions in open source projects
#332Earlier quoted context omitted.
"I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. that's much harder than it sounds. having someone fork your project can give you the feeling of loosing control over the project as potentially all your users might go with the fork. that fear is often strong enough to push yourself to do things that will avoid a fork. it's a desire for harmony and a fear of conf…
I'm reminded of this recent post about the Redis fork to be maintained by Drew Devault: https://andrewkelley.me/post/redis-renamed-to-redict.html > Redict is a Finished Product > Drew is a controversial person (he's been rude/mean in the past) xz should be pretty much finished as well, major overhauls like the "ifunc" feature to inject alternate function implementations are not really justified. Beware of busybodies…
Re: Xz: A microcosm of the interactions in open source projects
#333Earlier quoted context omitted.
This ignores the very fact that peer pressure works and puts the entire blame on the victim. No, people react differently when pressured vs when not pressured. That's the entire reason why peer pressure works.
Peer pressure happens when someone like a teenager wants or has to be around some other peers (teenagers) but has to follow the whims of the peers in order to continue to be around them or to not be harassed by them. The peanut gallery of non-contributors are only peers in the sense that they pretend to speak on behalf of some OSS community. And the fact that they are spokespersons is by default suspect. The attacker…
Re: Xz: A microcosm of the interactions in open source projects
#334Earlier quoted context omitted.
Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. I don't think the maintainer is at fault to any degree here. Sure, this could have been avoided if the ma…
> Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. All the pro-social benefits with a side-dish of the nuclear option. That’s coherent I have to admit. In…
Sure you do: everyone likes to comment on whether your volunteering work is an effective use of time and resources or not.
Re: Xz: A microcosm of the interactions in open source projects
#335So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
I often debate if I should go into the hacking world, best case I get bug bounties, worst case I get rich and I contribute immoral actions. I think its far easier to make $3,000,000 as a hacker than a worker/entrepreneur. Its way easier to find flaws/bugs than to do the entire Capitalism thing correctly. Then I see that half of these major attacks required social engineering.... Maybe being a hacker is significantly…
Re: Xz: A microcosm of the interactions in open source projects
#336So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.
Here's the deliciousness: Let's take on face value that it was the Chinese, and that China is communist. I mean, "Kumar" and "Tan"? Maybe it wasn't, but it doesn't matter for my purposes: They took an overworked peon of the capitalist enemy that provides a ... ... do I even need to expound? well it's fun ... ... collectively and idealistically produced common operating system "for the people" ... that is exploited an…
Let’s not.
Re: Xz: A microcosm of the interactions in open source projects
#337Earlier quoted context omitted.
> I think the idea this was HUMINT operation by a state sponsored intelligence service is more likely. It's not an either/or proposition. I definitely think it was state sponsored, AND one method used was social engineering a burned out maintainer.
It seems to me that people are very much exaggerating how "professional" this attack was. Yes, it doesn't look like the actions of a single bored teenager but I don't think the government of a country like the USA or China would deliberately permit their employees to get involved with crap like this. Any backdoor they try to insert would look exactly like an innocent bug. So my (uninformed) guess would be that this i…
This is absolutely something Russia could have done.
Re: Xz: A microcosm of the interactions in open source projects
#338Earlier quoted context omitted.
It sounds to me like you're trying to seek a correlation too eagerly. It's not obvious whether it's more implausible that he's a lazy Chinese programmer with very good English, or a lazy native English-speaking programmer who wants to pretend to be Chinese.
The former is more implausible because Chinese people with that level of English are quite rare, whereas English people able to create a fake Chinese username are not.
And China has been enticing ethnic Chinese who grew up in the West to "come back to the Motherland" with promises of riches for a long time now. Quite a few made the switch, too. I very much doubt that finding a native English speaker is a problem if it's the PRC govt.
It does make it less likely to be Russia, though. Although of course this could always just be subcontracted.
Re: Xz: A microcosm of the interactions in open source projects
#339Earlier quoted context omitted.
> Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. All the pro-social benefits with a side-dish of the nuclear option. That’s coherent I have to admit. In…
> In real life volunteering you don’t get random drive-by input from outsiders. Sure you do: everyone likes to comment on whether your volunteering work is an effective use of time and resources or not.
Re: Xz: A microcosm of the interactions in open source projects
#340Earlier quoted context omitted.
Probably, it is their choice to fix the issue and collect. An unresolved issue in the agreed timeline automatically refunds the money. Maintainer has the option to request more time. Donors can accept or reject. Ideally multiple people would sponsor an issue, so some percentage of funding would back out as deadlines are missed, but not all funding. Incentive is more delay, less reward.
What happens here is inevitably someone puts up $5 and harasses the maintainer for not taking the bounty.