Live data from Hacker News

Social engineering takeovers of open source projects

openssf.org

201–210 of 379 posts

Re: Social engineering takeovers of open source projects

#201
post #175

So next the attackers playing the long game will just set out to develop the next great everybody-uses-it open-source library, so they control it from inception? Great that we'll finally get state-sponsored open-source development :D

The ideal state is having the world's superpowers all devoting effort to improving open source libraries, but all catching each others' backdoors and at the end of the day improving security for everyone.

This has been quietly happening for a good while...

Re: Social engineering takeovers of open source projects

#202

[flagged]

I can't begin to state how much of a tinfoil hat theory this is. The issues with the leadership were persistent since years. Just read the recent thread about it here people. I want to say that, just like that nixpkgs maintainer with 18.000 commits, as a non-US citizen I'd also not contribute to NixOS/nixpkgs. I in no way would support the MIC of a genocidal state.

I looked into the "issues with the leadership", and everything I found was all a bunch of crap. The head of NixOS made a mistake stepping down, he should have told the SJW losers to get fucked.

Re: Social engineering takeovers of open source projects

#203

Earlier quoted context omitted.

Probably wouldn't even need 5 Million. According the the PBS article about the 2 US Navy sailors arrested for spying around august of last year one of them was apparently only bribed $10k-15K for the year [1]. I was pretty shocked at first but it made sense that with the financial stress many face in today's market a 10K bribe would go along way and have a high return on investment especially if the potential payoff…

Even politicians are cheap these days. It astonishes me that for less than the price of a nice car, what people seem to be able to do.

After Abscam in the late 1970s/early 1980s, one of the quote going expressed surprise not that politicians could be bought, but that they were so cheap.

I cannot find that quote now.

Re: Social engineering takeovers of open source projects

#204
post #5

We've been adding features for 30+ years to open source software, they become so complex only very few people understand them anymore. Recently I looked into jfet level 2 implementation in ngspice, expecting familiar equations, but through series of small changes and maybe some DRY too, the code is almost unrecognizable. When graybeards finally retire, there will be lots of shrugs.

Your average American could quit working for 5 million dollars. They could live comfortably for the rest of their lives off that money, if well invested (read EFT for sp500) 5 million bucks is change for you average government. "Amazon made billions on my project and if I turn a blind eye to this I can retire, fuck them..." Sponsorship, for good or bad makes a lot of decisions simple.

Money isn't the motivator I worry about. Money requires people to make rational decisions about what they think they can get away with.

Threatening someone's family? Who wouldn't be willing to turn their access to a project into a hack that has some possible theoretical future harm to protect their child?

Sure, the circumstances to being able to leverage someone like this are rare, but the population which is susceptible is much larger than those willing to do somethibg similar for just money.

Re: Social engineering takeovers of open source projects

#205
post #175

Earlier quoted context omitted.

The ideal state is having the world's superpowers all devoting effort to improving open source libraries, but all catching each others' backdoors and at the end of the day improving security for everyone.

Web of trust, but all commits must be signed by at least 3 intelligence agencies from rival countries.

Russia, China, Iran and NK cock-block development for years, because the MR “doesn’t represent their interests”.

Re: Social engineering takeovers of open source projects

#207

Doesn't have to be a takeover. If I'm a state actor I'll maintain a few projects specifically so I can hide backdoors in them. When/if one gets popular and I decide to backdoor them I'll claim it was a social engineering takeover.

Exactly, pick something that is expensive right now, make it free and people will use it.

Re: Social engineering takeovers of open source projects

#209
Seems like this would mostly raise suspicion for little gain, wasn't there a more robust solution of signed distributed reviews so you could simply pin the dependency at a state where reviewers you've explicitly added as trusted review code (and similarly after you review you can express that for the others to rely on)

Of course, this won't magically increase the time spent on code review, but will at least allow currently internal reviews to be available

Re: Social engineering takeovers of open source projects

#210
post #199

Would it be interesting if Github (and others) had a program where they would verify people using the same regulations the banking industry uses for KYC (know your customer)? Optional step for developers to show they are who they say they are?

No. Let's stop having these ideas of a totalitarian world. Instead, find solutions for zero-trust environments.

How is that totalitarian? Bureaucratic - yes, totalitarian- hardly.
Post reply on HN