Social engineering takeovers of open source projects
1–10 of 379 posts
Re: Social engineering takeovers of open source projects
#2https://news.ycombinator.com/item?id=30726098
https://en.wikipedia.org/wiki/Paradox_of_tolerance
https://nationalpost.com/opinion/the-tyranny-of-the-bureaucr...
Re: Social engineering takeovers of open source projects
#3It's a very serious issue. I don't really know if there is any "one solution." I suspect that each project needs to set its own bar, and that any dependency that falls out of maintenance should be removed as quickly as possible (which was good practice, beforehand, but even more important, now).
[EDITED TO ADD]
I would also think about "scoring" the sensitivity of projects. Things like cryptography and low-level drivers would be highest-rated, while user-space chrome might not be as important.
Re: Social engineering takeovers of open source projects
#4Also beware of weaponized CoCs and the paradox of tolerance. https://news.ycombinator.com/item?id=30726098 https://en.wikipedia.org/wiki/Paradox_of_tolerance https://nationalpost.com/opinion/the-tyranny-of-the-bureaucr...
Re: Social engineering takeovers of open source projects
#5Re: Social engineering takeovers of open source projects
#6Re: Social engineering takeovers of open source projects
#7Also beware of weaponized CoCs and the paradox of tolerance. https://news.ycombinator.com/item?id=30726098 https://en.wikipedia.org/wiki/Paradox_of_tolerance https://nationalpost.com/opinion/the-tyranny-of-the-bureaucr...
Re: Social engineering takeovers of open source projects
#8Anyone who has played Eve Online is familiar with this process. Gain membership, become a valued contributor to the corp, then betray it for profit.
And part of the process can be a kind of performative incredulity at the very suggestion that they are part of a campaign of hostile takeover, even if it's exactly accurate. I suppose you could even have unfortunate circumstances where parts of an open source community are unwitting advocates of being co-opted.
And I think you probably see a parallel in state-based information warfare, where part of the objective isn't just to spread misinformation, but to shift cultural norms so that the transmission of misinformation is inherently easier, which can involve sewing distrust in institutions or expertise, or normalizing a gish gallop argumentative style.
I'm perhaps stating the obvious here, but I suppose the upshot is that human psychology can be targeted in a programmatic way, and there might need to be something in the way of a normalized infosec-oriented doctrine relating to the stewardship of open source programs as an intentional countermeasure.