Welcome to the Strip Mining Era of OSS Security
metabase.com
Welcome to the Strip Mining Era of OSS Security
1–10 of 94 posts
Re: Welcome to the Strip Mining Era of OSS Security
#2One of the benefits of Open source has been that there are more eye balls on the source, leading to more secure code/better quality. I think given enough time the bug reports will plateau and we will be back to a normal cadence - once the tsunami is over, hopefully things will settle at a more manageable cadence .
Re: Welcome to the Strip Mining Era of OSS Security
#3Re: Welcome to the Strip Mining Era of OSS Security
#4Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…
Source that is unmaintained is dead. Nobody is looking at it, even the maintainer has something better to do.
Do you know whats even more powerful than "eyeballs"? Money.
Re: Welcome to the Strip Mining Era of OSS Security
#5Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…
OSS has always had tradeoffs and I sadly think this one is going straight to the "Cons" column. We still think the Pros outweigh the Cons, but this is NotGreat.
Re: Welcome to the Strip Mining Era of OSS Security
#6Good luck getting anyone who values their time to even triage the results. I would rather lick the bottom of a NYC dumpster that a rat had just died in.
Ignore (admittedly low-effort LLM generated) reports at your own peril.
Re: Welcome to the Strip Mining Era of OSS Security
#7Clearly for commercial oriented opensource software, security through obscurity is one way to keep the pace in the short term. Not an option for proper open source software. Will this be the case that people who use open source software that is easily detectable will also start to shy away from using them for the fear of zero-days? One of the benefits of Open source has been that there are more eye balls on the sourc…
Won't matter if is closed source, signed, and or obfuscated. =3
Re: Welcome to the Strip Mining Era of OSS Security
#8Good luck getting anyone who values their time to even triage the results. I would rather lick the bottom of a NYC dumpster that a rat had just died in.
That was true last year -- things changes. Ignore (admittedly low-effort LLM generated) reports at your own peril.