Live data from Hacker News

Welcome to the Strip Mining Era of OSS Security

metabase.com

1–10 of 94 posts

Re: Welcome to the Strip Mining Era of OSS Security

#2
Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days?

One of the benefits of Open source has been that there are more eye balls on the source, leading to more secure code/better quality. I think given enough time the bug reports will plateau and we will be back to a normal cadence - once the tsunami is over, hopefully things will settle at a more manageable cadence .

Re: Welcome to the Strip Mining Era of OSS Security

#4

Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…

This benefit you speak of is actually just a meme.

Source that is unmaintained is dead. Nobody is looking at it, even the maintainer has something better to do.

Do you know whats even more powerful than "eyeballs"? Money.

Re: Welcome to the Strip Mining Era of OSS Security

#5

Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…

I'm not sure that the benefit of many eyes helps here. So much of this bulk scanning is low-effort, and if you're a smart person developing closed source software you get the benefits of bulk scanning, but _at the time of your choosing_ .

OSS has always had tradeoffs and I sadly think this one is going straight to the "Cons" column. We still think the Pros outweigh the Cons, but this is NotGreat.

Re: Welcome to the Strip Mining Era of OSS Security

#6

Good luck getting anyone who values their time to even triage the results. I would rather lick the bottom of a NYC dumpster that a rat had just died in.

That was true last year -- things changes.

Ignore (admittedly low-effort LLM generated) reports at your own peril.

Re: Welcome to the Strip Mining Era of OSS Security

#7

Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…

Lets be honest, LLM with fuzzers are going to pound any llvm generated binary right in the hubris.

Won't matter if is closed source, signed, and or obfuscated. =3

Re: Welcome to the Strip Mining Era of OSS Security

#8

Good luck getting anyone who values their time to even triage the results. I would rather lick the bottom of a NYC dumpster that a rat had just died in.

That was true last year -- things changes. Ignore (admittedly low-effort LLM generated) reports at your own peril.

Software will eventually become "unmaintainable due to lack of interest", because of this very thing. People not invested in this are not "in peril" in any way.
Post reply on HN