So next the attackers playing the long game will just set out to develop the next great everybody-uses-it open-source library, so they control it from inception? Great that we'll finally get state-sponsored open-source development :D
The ideal state is having the world's superpowers all devoting effort to improving open source libraries, but all catching each others' backdoors and at the end of the day improving security for everyone.
Social engineering takeovers of open source projects
201–210 of 379 posts
Re: Social engineering takeovers of open source projects
#202[flagged]
I can't begin to state how much of a tinfoil hat theory this is. The issues with the leadership were persistent since years. Just read the recent thread about it here people. I want to say that, just like that nixpkgs maintainer with 18.000 commits, as a non-US citizen I'd also not contribute to NixOS/nixpkgs. I in no way would support the MIC of a genocidal state.
Re: Social engineering takeovers of open source projects
#203Earlier quoted context omitted.
Probably wouldn't even need 5 Million. According the the PBS article about the 2 US Navy sailors arrested for spying around august of last year one of them was apparently only bribed $10k-15K for the year [1]. I was pretty shocked at first but it made sense that with the financial stress many face in today's market a 10K bribe would go along way and have a high return on investment especially if the potential payoff…
Even politicians are cheap these days. It astonishes me that for less than the price of a nice car, what people seem to be able to do.
I cannot find that quote now.
Re: Social engineering takeovers of open source projects
#204We've been adding features for 30+ years to open source software, they become so complex only very few people understand them anymore. Recently I looked into jfet level 2 implementation in ngspice, expecting familiar equations, but through series of small changes and maybe some DRY too, the code is almost unrecognizable. When graybeards finally retire, there will be lots of shrugs.
Your average American could quit working for 5 million dollars. They could live comfortably for the rest of their lives off that money, if well invested (read EFT for sp500) 5 million bucks is change for you average government. "Amazon made billions on my project and if I turn a blind eye to this I can retire, fuck them..." Sponsorship, for good or bad makes a lot of decisions simple.
Threatening someone's family? Who wouldn't be willing to turn their access to a project into a hack that has some possible theoretical future harm to protect their child?
Sure, the circumstances to being able to leverage someone like this are rare, but the population which is susceptible is much larger than those willing to do somethibg similar for just money.
Re: Social engineering takeovers of open source projects
#205Earlier quoted context omitted.
The ideal state is having the world's superpowers all devoting effort to improving open source libraries, but all catching each others' backdoors and at the end of the day improving security for everyone.
Web of trust, but all commits must be signed by at least 3 intelligence agencies from rival countries.
Re: Social engineering takeovers of open source projects
#206While it doesn’t eliminate the threat completely, but I can sleep soundly knowing that I need to vet one party instead of 1000.
Re: Social engineering takeovers of open source projects
#207Doesn't have to be a takeover. If I'm a state actor I'll maintain a few projects specifically so I can hide backdoors in them. When/if one gets popular and I decide to backdoor them I'll claim it was a social engineering takeover.
Re: Social engineering takeovers of open source projects
#208Re: Social engineering takeovers of open source projects
#209Of course, this won't magically increase the time spent on code review, but will at least allow currently internal reviews to be available
Re: Social engineering takeovers of open source projects
#210Would it be interesting if Github (and others) had a program where they would verify people using the same regulations the banking industry uses for KYC (know your customer)? Optional step for developers to show they are who they say they are?
No. Let's stop having these ideas of a totalitarian world. Instead, find solutions for zero-trust environments.