Timeline of the xz open source attack
61–70 of 482 posts
Re: Timeline of the xz open source attack
#62Are you trying to pull an xz attack on me?
Re: Timeline of the xz open source attack
#63Earlier quoted context omitted.
The Jigar Kumar nudges are so incredibly rude. I would have banned the account, but perhaps they contributed something positive as well that isn't mentioned. I wonder if it would be possible to crowdsource FOSS mailing list moderation.
There is a good chance that everyone in that thread except the original maintainer is in on the act. It's likely that all those accounts are managed by a single person or group. Targeting just one account for rudeness isn't going to help, if that's true.
Re: Timeline of the xz open source attack
#64Earlier quoted context omitted.
The Jigar Kumar nudges are so incredibly rude. I would have banned the account, but perhaps they contributed something positive as well that isn't mentioned. I wonder if it would be possible to crowdsource FOSS mailing list moderation.
There is a good chance that everyone in that thread except the original maintainer is in on the act. It's likely that all those accounts are managed by a single person or group. Targeting just one account for rudeness isn't going to help, if that's true.
Play is just preparing for the same game but when stakes are higher?
Re: Timeline of the xz open source attack
#65Everyone wants to consume it. Nobody wants to participate.
People are upset when a company like Elastic or Mongo switches to a "non open" license. But at the same time, the market doesn't leave much choice. Companies won't be incentivized to contribute to projects when they can freeload. The market actually wants vendors, it doesn't want to participate in open source. But they don't want to _pay_ for vendors.
So I think its entirely appropriate that anyone / any entity that creates "open source" to change their license, set limits, say "no", and let users be damed unless they're willing to make it financially appealing. It's literally "Without Warranty" for a reason.
Letting your passion project becoming hijacked into determining your mental health is really depressing. F' the people who can't get on board with your boundaries, etc around it. They deserve the natural consequences of their lack of support.
Re: Timeline of the xz open source attack
#66Never allow yourself to be bullied or pressured into action. As a maintainer, the more a contributor or user nags, the less likely I am to oblige.
Re: Timeline of the xz open source attack
#67This seems very difficult to defend against. What is a project with a single burnt-out committer to do?
Re: Timeline of the xz open source attack
#68Open Source is a real tragedy of the commons. Everyone wants to consume it. Nobody wants to participate. People are upset when a company like Elastic or Mongo switches to a "non open" license. But at the same time, the market doesn't leave much choice. Companies won't be incentivized to contribute to projects when they can freeload. The market actually wants vendors, it doesn't want to participate in open source. But…
Re: Timeline of the xz open source attack
#69Re: Timeline of the xz open source attack
#70If my speculation is correct then the the exact date on which access was granted must then first be known, after that a trusted backup of the repo from before that date is needed. Ideally Lasse Collin would have a daily backup of the repo.
Although perhaps the entire repo may have to be completely audited at this point.