Earlier quoted context omitted.
You mean like the US blocks all efforts to ban putting weapons in space?
[flagged]
Social engineering takeovers of open source projects
341–350 of 379 posts
Re: Social engineering takeovers of open source projects
#342Earlier quoted context omitted.
Honestly, a good PR should have a very clear description of the idea and a sample implementation, and then a trusted core contributor re-implements the fix on his own. But Github users are entitled and spoiled by Github-marketed commercial software, so they will rage at this.
Sounds like you're describing an issue, not a PR.
Re: Social engineering takeovers of open source projects
#343I'm a maintainer (one of many) of an open source project, and this topic has been on my mind a lot lately as I review PRs. I am more suspicious of PRs from new contributors by default now. Of course I keep these suspicions to myself, but besides simply reviewing code for all the regular things, I now ask myself "what sort of sneaky thing could they be doing that appears benign on the surface?"
It's not the new contributors you have to watch, it's the sleeper contributor who has built up a solid reputation and then is "activated". At least that's how I understand XZ.
Re: Social engineering takeovers of open source projects
#344Earlier quoted context omitted.
theres definitely improvements ofcourse. apple is not wrong trying to have more of the chain as a single vendor. i would hope amd/intel and such places might offer more help also to implement their devices easily. (implementing amd64 is really difficult imho, only acpi has some good code from the vendor and thats such a small part of whats needed). we know kot to build a house on a bad foundation, but somehow built o…
> we know not to build a house on a bad foundation, but somehow built our techstack on a flimsy one Good analogy. Extending it further, homebuilders have liability and regulation for safety, while software has been a contest of incentives for creation, extraction and influence. With the convergence of "cyber" and physical reality, liability is coming to software development. Alan Kay's VPRI has a few papers on new ap…
Re: Social engineering takeovers of open source projects
#345Earlier quoted context omitted.
That's great that you are considering this more now. But the xy story taught us, that every contributor is dangerous, the most dangerous ones are probably the most helpful and most skilled contributors. If someone barely get's a PR accepted, they probably lack the skills to add a sophisticated backdoor. Another thing that was not talked about a lot: There are many ways to compromise existing maintainers. Compromising…
> Another thing that was not talked about a lot: There are many ways to compromise existing maintainers. Also not talked about a lot - there are many ways to compromise existing software engineers who are paid to work on proprietary software systems.
But, source-not-available proprietary systems are just totally hopeless from this point of view, of course an intelligence agency could slip something on. A bored developer at the company could too. Users of this sort of proprietary system have just chosen to have 100% faith for some incomprehensible reason.
Re: Social engineering takeovers of open source projects
#346Earlier quoted context omitted.
>> And I think you probably see a parallel in state-based information warfare, where part of the objective isn't just to spread misinformation, but to shift cultural norms so that the transmission of misinformation is inherently easier, which can involve sewing distrust in institutions or expertise, or normalizing a gish gallop argumentative style. TikTok springs to mind when reading this...
Re: normalization of gish gallop The speed reading shit they do in competitive debate was in my opinion 100% caused by clandestine elements who wanted to keep the future “revolutionary” intelligentsia class obsessed with ivory tower elitism so that they don’t get too close to doing actually subversive things. I have no other explanation for how otherwise smart people think that speed reading lacanian psychoanalysis i…
Re: Social engineering takeovers of open source projects
#347Earlier quoted context omitted.
It was not difficult because you actually had the recovery codes. How many people have them? Also you're supposed to print them. Where? How many people own a printer? If you print them in a shop they can be considered compromised.
We're talking about software developers, right? I would hope that when a software dev sees a widget that says "these are your recovery codes, write them down or copy them to a secure location or you may lose access to your account ", they do exactly that. Except for codes which protect my money (which go onto paper, which goes in a safe), I put them in a password vault. TOTP offers protection against getting shoulder…
Yes software developers are known for never making any mistake.
Re: Social engineering takeovers of open source projects
#348Earlier quoted context omitted.
Web of trust, but all commits must be signed by at least 3 intelligence agencies from rival countries.
Russia, China, Iran and NK cock-block development for years, because the MR “doesn’t represent their interests”.
Maybe just ignore Hostile, try to find enough competitors to ensure at least one will review, require a couple unaligneds and friendlies, and then consider “too friendly” to be the same as your own country.
Like from a US point of view, if the US and the UK agree on something… I mean, that only counts as one point, right? We are too close. But if like half of the EU and India agree, there’s enough competing self-interest to let it through (keeping in mind that it is all open source, nobody wants to be caught doing something sketchy). And if China, the US, and any other non-5-eyes country agree on something, it must be fine. (I picked these countries because I think they are pretty uncontroversial, I’m definitely not going to try and list who’d be in the hostile group, that’s just asking for unproductive political squabbling).
Multiple possible paths, no veto.
But I have no idea how to fix the problem of: some countries look more or less trustworthy from others’ point of view; I think we can easily suggest a plan from the US point of view, but I have no idea how to get everyone to agree on what the actual state of a single source code repository is, since commits have dependencies. Maybe it needs to be more like a package manager.
Re: Social engineering takeovers of open source projects
#349Earlier quoted context omitted.
"What companies pay for" is anything they cannot get for free. If the value of an OSS project is mostly in its code, then any license that allows it to be used commercially will mean lots of free-riding.
Companies want to have their cake and eat too: the code is free, but they're complaining there's no warranty. If companies want better guarantees, then they should contribute more.
Re: Social engineering takeovers of open source projects
#350Earlier quoted context omitted.
A kind of similar thing happened with game key scammers. People will email the devs of hundreds of Steam games pretending to be a popular YouTuber, asking for keys for themselves and usually a few extra "for a giveaway". If they get the keys, they'll try to resell them for a profit. At first you'd get emails from like, pewdiepie@outlook.com instead of pewdiepie@gmail.com. But you could usually check the YouTube about…
How do you know those two channels are "fake" or "scammers"? I think I have a good eye for these things and worryingly they just look like the normal low effort youtube chaff but I wouldn't have thought fake/scamming.
- Weird view counts. Strangely consistent, random sudden dropoff to near zero views, etc.
- No voice commentary. Can't steal videos from different channels if your "voice" changes I guess.
- A whole set of videos uploaded at once. This was more obvious when the linked channels were still active since you'd see like two rows of "2 days ago", then a bunch "1 week ago", then a bunch "3 weeks ago" etc.
- Social media etc links either missing or super basic.
- Few and generic comments vs. amount of views.
- Channel description generic, sometimes copied from other channels.
- The two I linked haven't done it, but some I saw were uploading long-plays of games split into many parts, I guess to easily pad out their total number of videos.
Another thing they were doing at the time, was changing their channel name and banner after a few weeks or months and then emailing again pretending to be a whole new channel. Easy to spot if you still had the old link and it was the same.
The second one I linked also mysteriously turns Russian if you scroll back far enough. Bit unusual for someone with their location listed as USA.