Live data from Hacker News

Open Source is one person

opensourcesecurity.io

21–30 of 184 posts

Re: Open Source is one person

#21

The title of the register article is completely disgusting > Putin on the code: DoD reportedly relies on utility written by Russian dev then in the article: > Hunted Labs told us that it didn't speak to Malinochkin prior to publication of its report today, and that it found no ties between him and any threat actor.

  The title of the register article is completely disgusting
Nearly all The Register articles are clickbaits or rage baits.

Re: Open Source is one person

#22
post #4

If they had done an activity check they would have seen that half of all projects have zero maintainers.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

Maybe we need a Linux distro based on "inactive" software and look how reliably it performs.

Re: Open Source is one person

#23

Earlier quoted context omitted.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

Maybe we need a Linux distro based on "inactive" software and look how reliably it performs.

s/inactive/stable/

Well, when you talk about a distribution there's a different issue.

The entire Linux ecosystem is constantly shifting with each package releasing new versions, and therefore everything else must be updated to accommodate the changes in the dependency tree.

You could get away with some stuff being only stable versions, but things like mesa, x11, chrome, etc... would still be constantly changing as would their dependency trees.

Re: Open Source is one person

#25
I feel like there's a lot of misunderstanding of this issue in the software community, because primarily, supply chain risk isn't a software or engineering issue. It's a governance issue.

Someone doesn't have to be a bad actor for a project to have supply chain risk. Nor do all who evaluate supply chain risk have the same security posture and evaluate risks the same as others might. The DoD likely has a very different set of risks they evaluate against for their security posture than you do.

Most supply chain risks are not an indictment of somebody's code or somebody's character. A lot of one person projects are risky just because they're only one person. Having a bus factor of one is a supply chain risk in and of itself.

And while most people don't prepare for war while choosing their packages, it's not unreasonable for a military to do so. During a war, the ability for people to govern themselves and their own projects often changes dramatically, even in democratic countries. It is entirely routine for countries to require cooperation by the force of law in war time, even the US can and has forced private companies to cooperate with war efforts. This is probably not in the security posture calculation for most of us. But it is for some.

Re: Open Source is one person

#26

The title of the register article is completely disgusting > Putin on the code: DoD reportedly relies on utility written by Russian dev then in the article: > Hunted Labs told us that it didn't speak to Malinochkin prior to publication of its report today, and that it found no ties between him and any threat actor.

The title of the register article is completely disgusting Nearly all The Register articles are clickbaits or rage baits.

They're also from Great Britain which seems to have the most irrational hatred for everything Russian.

Re: Open Source is one person

#27

I've heard good things about work done by this guy Linus. I'm pretty sure that I've used his work. I think he comes from a country that borders Russia, so should we be worried? I've done OSS for decades; mostly by myself, but sometimes, in teams of volunteers. If anyone has any experience, working in teams of volunteers, it can be ... challenging . It can definitely work, but not as often as you'd think. If it works,…

(Off topic.)

Not only that, but Linus's parents were politically active communists and young Linus was a pioneer (like a boy scout but for communists). His father also lived in Moscow for several years on two separate occasions.

Re: Open Source is one person

#28
post #4

If they had done an activity check they would have seen that half of all projects have zero maintainers.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

Under a microscope, maybe.

But if you had a "perfect" piece of software that used Log4j in 2020, it wouldn't have been perfect for long.

Unfortunately, there's a lot of reasons that software needs maintenance, even if it was thought to be perfect when it was originally written.

Hardware changes. The software landscape changes. Dependencies are deprecated, or are found to have their own problems. Vulnerabilities are discovered. Vulnerabilities are found that aren't even the fault of your software, maybe they are a flaw in the hardware your software runs on, and the only way to fix it is via a software mitigation. These are all real things that happen to otherwise perfect software.

Re: Open Source is one person

#30

Earlier quoted context omitted.

Aren't Russian developers on average more susceptible to the "wrench attack" though?

Many of them don't live in Russia. Some of the best engineers that I've worked with (in the US and Europe) are Russian. I've also been quite impressed with other former Iron Curtain developers. A lot of Chinese folks I've worked with have been good. I know that some nations are known for threatening the relatives of expats, to get them to work on their behalf. Not very nice. But state-sponsored Russian (or other nati…

> Many of them don't live in Russia.

Well Malinochkin does. His GitHub profile says he is located in a suburb 30 minutes from the Kremlin.

Of course, there's a lot of smart software engineers in major cities all around the world.

Post reply on HN