Live data from Hacker News

Social engineering takeovers of open source projects

openssf.org

361–370 of 379 posts

Re: Social engineering takeovers of open source projects

#361
post #22

I'm a maintainer (one of many) of an open source project, and this topic has been on my mind a lot lately as I review PRs. I am more suspicious of PRs from new contributors by default now. Of course I keep these suspicions to myself, but besides simply reviewing code for all the regular things, I now ask myself "what sort of sneaky thing could they be doing that appears benign on the surface?"

Consider this comment: "But the xy story taught us, that every contributor is dangerous, the most dangerous ones are probably the most helpful and most skilled contributors."

What is "xy"?

It's tempting to classify this as a typo but y is a long way from z on the keyboard, while the x and z keys are adjacent.

I type xz on a regular basis because it is so often used in place of gz for compressing tarballs. I cannot imagine calling it "xy" unless I rarely used it.

Re: Social engineering takeovers of open source projects

#362
I think we need to philosophize. Is some software “infrastructure” and some even “critical infrastructure”? Or maybe they should be new classes of public goods? There are huge risks that society needs to address and I don’t think the non-profit (open source) market is providing it. And maybe not even the for-profit market.

I don’t think open-source project leaders have the resources to fight this risk on their own. We should discuss if there is a role for government, just the way government pays for security (police) and protects critical infrastructure.

Re: Social engineering takeovers of open source projects

#363
post #213

Earlier quoted context omitted.

I don't see how blocking contributions from people in Russia etc will help. Malicious actors can simply falsely claim to be American. Is GitHub going to start verifying citizenship? Even if GitHub did that, it likely wouldn't be too hard to fake.

> Is GitHub going to start verifying citizenship? As an American company they must presumably already do this to avoid violating sanctions, and least for anyone giving them money. It’s not a huge stretch to imagine they could also do so for free tier users.

I don't think they need to verify citizenship. I think IP geolocation is sufficient to comply with sanctions. That's not going to stop a malicious actor though.

Re: Social engineering takeovers of open source projects

#365

Earlier quoted context omitted.

Are you saying codes of conduct make the transmission of misinformation is inherently easier, e.g by sewing distrust in institutions or expertise, or normalizing a gish gallop argumentative style? Are you saying Linus Torvald's behaviour prevented those problems?

It has not occurred to me before, but I don't see why the cancel culture surrounding such matters couldn't be used as an attack vector. Basically, target key maintainers who are vulnerable to this (white, male, history of questionable interactions etc) and push until you force them out one way or another. Then when project gets in trouble because of the lack of qualified manpower, pitch your own agent as replacement.…

This is exactly what I was thinking. Thank you for expressing it so much better.

Re: Social engineering takeovers of open source projects

#366
post #325
post #295

Earlier quoted context omitted.

> Your choice of language in your comments (in this thread, not in general) isn’t bolstering your argument. Yeah, you're probably not wrong. I've had this argument a few times now, and it's the same dismissive "we don't know what we don't know" every time. Well, you can say that for everything and given the complexities of the xz attack that seems a bit unlikely to me, which is then again countered with "but we don't…

Thanks for your thoughtful reply. > "Every contributor is dangerous" is spectacularly toxic type of attitude. I view this from the lens of "How well can people reason about probabilities?" and research has shown, more or less, "not very well". In the short term, therefore, it is wise to tailor communications so as to avoid predictable irrational reactions. In the medium term, we need to _show_ people how to think abo…

In the end you can never fully trust anyone, including yourself. This has always been true for anything: people get drunk, have psychotic episodes or have other mental health issues, things like that. It happens. Remember that Malaysian pilot flying the passenger plane in the ocean?

Every pilot in the world will agree that we need to think about risk management to prevent that sort of thing. I think a lot of them will have issues if we start saying things like "every pilot is dangerous" and (in a follow-up) "long-term good faith pilots are maybe even more dangerous than new maintainers". Then you've gone from "risk management" to just throwing shade.

Re: Social engineering takeovers of open source projects

#367
post #328

Earlier quoted context omitted.

> This was never a nuanced conversation about risk management to start with. This is not the type of community I've worked for all this time. I'm not quite following the second sentence. What kind of community have you worked for? Do you mean "worked for" as in e.g. "the spirit of your comments on HN"? Or something else?

I think they are using community to refer to F/OSS projects as a monolithic entity, rather than a million separate and often competing and disagreeing fiefdoms that have always had issues with toxic assholes worming their way into too much power.

Communities are rarely monolithic; but do tend to have some vague set of shared ideas and values (even if there's ton of internal disagreement).

But yes, that's what I meant, roughly.

Re: Social engineering takeovers of open source projects

#368
post #150

Earlier quoted context omitted.

What I'm argueing against is absolutist fear-mongering statements such as "every contributor is dangerous". I'm not confident about anything, but anything could happen or have happened all the time. We need to operate on the reality that exists, not the reality that perhaps maybe possibly could perhaps maybe possibly exist. And we certainly shouldn't be treating anyone sending you a patch as a dangerous hostile actor…

You seem to think that vetting contributors or reviewing all code commits for malicious actions or code is some unreasonable ask. That should be standard practice. If someone is getting angry that you actually check their code for vulns, or that you don't let them make changes to certain core areas of a large app without establishing some credibility first, you probably don't want them working on your project. You ca…

It has been standard practice for decades. Sometimes this goes wrong, because everything can go wrong. It happens. Casting doubt on any contributor, any maintainer, and any long-term maintainer with fantastical stories is just throwing shade. Of course no one can be trusted absolutely; that has always been true for anything from software to child care to launching nuclear bombs. Anyone and anything can become suspect if you analyse things with enough of a suspicious mindset.

Re: Social engineering takeovers of open source projects

#369

Earlier quoted context omitted.

I'm sorry but this is a huge copout. At least the big companies and governments have the money to solve all these problems. They have literally teams of lawyers on retainer and they can hire a few more people for all the other self created bureaucracy. None of the things mentioned here are laws, of nature or otherwise.

I'm not sure what you are proposing. You declare cop-out, but then fail to describe a mechanism. Who exactly would initiate this change? Shareholders? Board members? C-suite? Employees? What do you propose an initiator should argue to convince colleagues? Why should an initiator spend political capital on this rather than on themselves? Of course they have the money to give to random OSS projects for no return. What…

> Shareholders? Board members? C-suite?

Yup these three. Its been too long that we give passes to executives for their bad behavior. If a company is using a tool they should be thinking about paying back. If they are not, they are being bad members of society (and yes companies also live in a society). It is not hard if there were good people in charge. Who's only lookout isn't to make the share price go up every quarter.

Re: Social engineering takeovers of open source projects

#370
post #331

Earlier quoted context omitted.

> one of the Internet’s last remaining high trust spaces is being destroyed One of the Internet's last remaining high trust spaces is being attacked . What happens next is still unwritten.

From what I know of today's developer culture the solution will be for one company, probably Microsoft given their ownership of GitHub, to step in and become undisputed king and single point of failure for all open source development. Developers will say this is great and will happily invite this, with security people repeating mantras about how securing things is "hard" and "Microsoft has more security personnel tha…

It can be a stepping stone towards a world in which we use sandboxing and (formal) verification to safeguard against cultural degradation. There's no alternative, too many bad actors are roaming about. I hate that as much as the next guy :(
Post reply on HN