Live data from Hacker News

Social engineering takeovers of open source projects

openssf.org

91–100 of 379 posts

Re: Social engineering takeovers of open source projects

#91
post #89

Earlier quoted context omitted.

> Compromising people is the core competency of intelligence, happens all the time, and most cases probably never come to public knowledge. Yea. It would almost be strange if security service didnt consider the route of getting "kompromat" on a developer to make them "help" them.

> consider the route of getting "kompromat" on a developer to make them "help" them I suppose that’s an option, but it also introduces an additional risk of exposure for your operation as it doesn’t always work and makes it much more complicated to manage even when it does work.

Does it matter though? They don’t have to say “I am so and so of the Egyptian intelligence service and would like to blackmail you”

Re: Social engineering takeovers of open source projects

#92
post #6

Anyone who has played Eve Online is familiar with this process. Gain membership, become a valued contributor to the corp, then betray it for profit.

Rudi Dutschke's long march through the institutions. Marcuse endorsed it -- because it works.

Re: Social engineering takeovers of open source projects

#93

There's an awkward reckoning in open source software about inclusivity and protecting the long-term security of projects coming. Authors from several countries were already suspicious, such as Iran. Anyone from Russia and China or unknown places are all potential risks now. Combined with recent inclusive ideologies, it’s gonna cause hard conversations. There will be a furthering in segmenting the Internet. Why fight…

this is a wild prediction to make and disturbingly regressive

FOSS is one of the most beautiful examples of supranational collaboration, and is in my experience much more integrated than the web at large, in a way that has nothing to do with "recent inclusive ideologies"

Re: Social engineering takeovers of open source projects

#94
post #71

Earlier quoted context omitted.

[flagged]

[flagged]

If the news articles about Instagram extortion are anything to go by, adding weapons to an extortion situation is more likely to lead to a suicide than the extortionist being dissuaded.

Re: Social engineering takeovers of open source projects

#95

Earlier quoted context omitted.

>> And I think you probably see a parallel in state-based information warfare, where part of the objective isn't just to spread misinformation, but to shift cultural norms so that the transmission of misinformation is inherently easier, which can involve sewing distrust in institutions or expertise, or normalizing a gish gallop argumentative style. TikTok springs to mind when reading this...

Re: normalization of gish gallop The speed reading shit they do in competitive debate was in my opinion 100% caused by clandestine elements who wanted to keep the future “revolutionary” intelligentsia class obsessed with ivory tower elitism so that they don’t get too close to doing actually subversive things. I have no other explanation for how otherwise smart people think that speed reading lacanian psychoanalysis i…

In Europe, the most popular high school and university debate format is British Parliamentary in which spreading is not popular because you only have 15 minutes to prepare and weakly justified arguments don't require responses.

https://youtu.be/XyIK_Cg_8jc?t=327

British culture certainly has plenty of ivory tower elitism, yet has passed by this. I don't think it's a special revolutionary pedagogy, just a different interpretation of how to deal with subjectivity in debate.

Re: Social engineering takeovers of open source projects

#98
post #22

I'm a maintainer (one of many) of an open source project, and this topic has been on my mind a lot lately as I review PRs. I am more suspicious of PRs from new contributors by default now. Of course I keep these suspicions to myself, but besides simply reviewing code for all the regular things, I now ask myself "what sort of sneaky thing could they be doing that appears benign on the surface?"

the attitude remindes me of maintaining game-servers and looking out for cheaters; once we had a handful of folks looking out for cheaters, it turned the community against itself calling everybody a cheater... i think it is good to be cautious; but overall it's the same cat and mouse game we've seen before. i can only say good luck on not letting it stress you out second guessing other folks actions and intent - and hope we continue writing code for humans to read vs the cryptic, obstrufcated, even "elegant" code (not to dive into the skill issue rabbit hole lol)

Re: Social engineering takeovers of open source projects

#99

Which of the suggested "Steps to help" would have helped prevent the xz infiltration? For a single-maintainer project, adding bureaucracy can only make things worse.

Seems just being aware of it. Doesn’t hurt to have people be more alert. Although that alertness can quickly become fear and anxiety.

Which can eventually evolve into paranoia.

Re: Social engineering takeovers of open source projects

#100
post #71
post #33

Earlier quoted context omitted.

That's great that you are considering this more now. But the xy story taught us, that every contributor is dangerous, the most dangerous ones are probably the most helpful and most skilled contributors. If someone barely get's a PR accepted, they probably lack the skills to add a sophisticated backdoor. Another thing that was not talked about a lot: There are many ways to compromise existing maintainers. Compromising…

[flagged]

If someone gets stabbed in the eye, we find out about it. So our statistics on eye-stabbing are probably accurate.

We literally have no idea how many xz-style compromises are out there in the wild. We got really lucky with xz - it was only found because the backdoor was sloppy with performance and a microsoft employee got curious. But we have no data on all the times we got unlucky. How many packages in the linux ecosystem are compromised in this way? Maybe none? Maybe lots? We just don't know.

Post reply on HN