Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

331–340 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#331

Earlier quoted context omitted.

An issue is that the maintainer may have other priorities. By sponsoring an item you "force" them to look at that sooner.

Probably, it is their choice to fix the issue and collect. An unresolved issue in the agreed timeline automatically refunds the money. Maintainer has the option to request more time. Donors can accept or reject. Ideally multiple people would sponsor an issue, so some percentage of funding would back out as deadlines are missed, but not all funding. Incentive is more delay, less reward.

What happens here is inevitably someone puts up $5 and harasses the maintainer for not taking the bounty.

Re: Xz: A microcosm of the interactions in open source projects

#332
post #60

Earlier quoted context omitted.

"I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. that's much harder than it sounds. having someone fork your project can give you the feeling of loosing control over the project as potentially all your users might go with the fork. that fear is often strong enough to push yourself to do things that will avoid a fork. it's a desire for harmony and a fear of conf…

I'm reminded of this recent post about the Redis fork to be maintained by Drew Devault: https://andrewkelley.me/post/redis-renamed-to-redict.html > Redict is a Finished Product > Drew is a controversial person (he's been rude/mean in the past) xz should be pretty much finished as well, major overhauls like the "ifunc" feature to inject alternate function implementations are not really justified. Beware of busybodies…

xz sees continual improvement to e.g. make it faster. ifuncs are an important part of that. If you want to use the garbage slow version of xz that’s up to you but I don’t think most people would want this.

Re: Xz: A microcosm of the interactions in open source projects

#333
post #58

Earlier quoted context omitted.

This ignores the very fact that peer pressure works and puts the entire blame on the victim. No, people react differently when pressured vs when not pressured. That's the entire reason why peer pressure works.

Peer pressure happens when someone like a teenager wants or has to be around some other peers (teenagers) but has to follow the whims of the peers in order to continue to be around them or to not be harassed by them. The peanut gallery of non-contributors are only peers in the sense that they pretend to speak on behalf of some OSS community. And the fact that they are spokespersons is by default suspect. The attacker…

Maintainers have an obvious contract with their users, even for open source projects. Everyone thinks what “Jia Tan” is unacceptable, even though he’s an open source maintainer! You have an obligation to not cause harm to people who use your software.

Re: Xz: A microcosm of the interactions in open source projects

#334

Earlier quoted context omitted.

Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. I don't think the maintainer is at fault to any degree here. Sure, this could have been avoided if the ma…

> Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. All the pro-social benefits with a side-dish of the nuclear option. That’s coherent I have to admit. In…

> In real life volunteering you don’t get random drive-by input from outsiders.

Sure you do: everyone likes to comment on whether your volunteering work is an effective use of time and resources or not.

Re: Xz: A microcosm of the interactions in open source projects

#335

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

I often debate if I should go into the hacking world, best case I get bug bounties, worst case I get rich and I contribute immoral actions. I think its far easier to make $3,000,000 as a hacker than a worker/entrepreneur. Its way easier to find flaws/bugs than to do the entire Capitalism thing correctly. Then I see that half of these major attacks required social engineering.... Maybe being a hacker is significantly…

Security engineer here. Your viewpoint is exceptionally skewed to the point of being wildly inaccurate. Being good at security work is like any other skill and has a payout distribution more akin to being a star performing artist than a 9-to-5 job. That is, everyone hears about the people that make millions, but they’re actually missing that most people make far less than that, even when they’re good at their jobs. And in your case the people who are not good at their jobs also end up in jail. And just like learning to play music, you can get really good at it if you practice for 10 years–but most people won’t, and even then if you’re in the top 1% but not the top 0.1% the difference in pay might be several orders of magnitude. Just being a software engineer is a far more reliable way to be well off.

Re: Xz: A microcosm of the interactions in open source projects

#336

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

Here's the deliciousness: Let's take on face value that it was the Chinese, and that China is communist. I mean, "Kumar" and "Tan"? Maybe it wasn't, but it doesn't matter for my purposes: They took an overworked peon of the capitalist enemy that provides a ... ... do I even need to expound? well it's fun ... ... collectively and idealistically produced common operating system "for the people" ... that is exploited an…

> Let's take on face value that it was the Chinese, and that China is communist.

Let’s not.

Re: Xz: A microcosm of the interactions in open source projects

#337
post #260

Earlier quoted context omitted.

> I think the idea this was HUMINT operation by a state sponsored intelligence service is more likely. It's not an either/or proposition. I definitely think it was state sponsored, AND one method used was social engineering a burned out maintainer.

It seems to me that people are very much exaggerating how "professional" this attack was. Yes, it doesn't look like the actions of a single bored teenager but I don't think the government of a country like the USA or China would deliberately permit their employees to get involved with crap like this. Any backdoor they try to insert would look exactly like an innocent bug. So my (uninformed) guess would be that this i…

Which "employees"? The anonymous guys in an nondescript office building somewhere?

This is absolutely something Russia could have done.

Re: Xz: A microcosm of the interactions in open source projects

#338

Earlier quoted context omitted.

It sounds to me like you're trying to seek a correlation too eagerly. It's not obvious whether it's more implausible that he's a lazy Chinese programmer with very good English, or a lazy native English-speaking programmer who wants to pretend to be Chinese.

The former is more implausible because Chinese people with that level of English are quite rare, whereas English people able to create a fake Chinese username are not.

There's a lot of Chinese people, though.

And China has been enticing ethnic Chinese who grew up in the West to "come back to the Motherland" with promises of riches for a long time now. Quite a few made the switch, too. I very much doubt that finding a native English speaker is a problem if it's the PRC govt.

It does make it less likely to be Russia, though. Although of course this could always just be subcontracted.

Re: Xz: A microcosm of the interactions in open source projects

#339

Earlier quoted context omitted.

> Many maintainers want to please their users, and be helpful (which is admirable, and more power to them), which means #2 applies. Sure, the maintainer is entitled to say "fuck you, I want to sit on my project and you can fork it if you want", but he was, presumably, trying to be helpful and succumbed to pressure. All the pro-social benefits with a side-dish of the nuclear option. That’s coherent I have to admit. In…

> In real life volunteering you don’t get random drive-by input from outsiders. Sure you do: everyone likes to comment on whether your volunteering work is an effective use of time and resources or not.

Not in my experience. People don’t complain about people doing pro-social volunteer work (IME).

Re: Xz: A microcosm of the interactions in open source projects

#340

Earlier quoted context omitted.

Probably, it is their choice to fix the issue and collect. An unresolved issue in the agreed timeline automatically refunds the money. Maintainer has the option to request more time. Donors can accept or reject. Ideally multiple people would sponsor an issue, so some percentage of funding would back out as deadlines are missed, but not all funding. Incentive is more delay, less reward.

What happens here is inevitably someone puts up $5 and harasses the maintainer for not taking the bounty.

They already do while putting up $0. Nothing really changes there. Also, maybe money should be refunded if maintainer does not accept in a reasonable time after funding goal is reached. Maintainer can always reject sooner. Maintainer has final word.
Post reply on HN