Live data from Hacker News

Several Russian developers lose kernel maintainership status

lwn.net

61–70 of 314 posts

Re: Several Russian developers lose kernel maintainership status

#61

Earlier quoted context omitted.

[flagged]

Who is the “our” that owns Linux? It is a human project and any human should be able to be maintainer. Liberalism is what makes our society great, not paranoia and securitization.

> Who is the “our” that owns Linux?

Well, the Linux Foundation which owns the Linux® trademark and employs the primary maintainer is based in the US:

* https://en.wikipedia.org/wiki/Linux_Foundation

Some of the most active contributer employers are Intel, Google, Linaro, AMD, Red Hat, SuSE, Meta, Oracle, Qualcomm, IBM, NVIDIA, TI, Arm, Microsoft:

* https://lwn.net/Articles/972605/

* https://kernelnewbies.org/DevelopmentStatistics

which are based in countries that have Russia on a sanctions list. The main contributer employer based in a country that doesn't have Russia on some list is Huawei.

So given those folks contribute the most code to Linux, they may not want possible complications with regards to possible legal issues.

Re: Several Russian developers lose kernel maintainership status

#62
post #31

Strongly opposed to any sort of sanction regime that results in this.

Let me spell it out for you: If Project P in Country A is identified by Country B as a potential target for planting cyber-attack-enabling backdoors, Country B has an incentive to find people to put a backdoor in P. If Country B is a free country with rights and ethics, they will say "Help us put a backdoor in P. We'll pay you very well for services rendered," or try to get someone who already works for Country B int…

Really appreciate informative comments like this, basically explaining from first principles and not assuming people are idiots for not immediately understanding the implications.

It also made me realise what a cushy, insular world I live in not having to worry about those threats when I write software. Made me more aware of what others might face.

Re: Several Russian developers lose kernel maintainership status

#63

Earlier quoted context omitted.

[flagged]

did banning plastic straws in a few US cities fix climate change and pollution? >The access Russia currently enjoys is the equivalent of Goebbels being allowed to anonymously publish front-page editorials in the Times there's absolutely nothing you can do about this to prevent this. troll farms can afford residential VPNs and can network with the US/EU via neighboring neutral countries or their overseas agents. >whil…

[deleted]

Re: Several Russian developers lose kernel maintainership status

#64

Earlier quoted context omitted.

So they can fork it and roll their own version of Linux. Russia-ux.

Not sure if you are joking or not, but BRICS certainly have enough developers for that effort, especially if it is encouraged and financed by the member states. I would not be surprised if this happens.

Even North Korea runs their own Linux Distribution ( https://en.wikipedia.org/wiki/Red_Star_OS )

Re: Several Russian developers lose kernel maintainership status

#65
How convoluted, insidious, and camouflaged can a hidden backdoor or exploitable intentional defect be?

If hacking or subversion is possible, it has been tried and will be again. If anyone is going to try it, chances are Putin's people will.

It's by far the sneakiest, most advanced cheating and infiltration apparatus humanity has ever known. It inherited a large "meddling war chest" from the Soviet Union, then invested heavily into it for 25 years. The Internet increased its opportunities a million-fold. Its semitransparent tentacles are now embedded into nearly every consequential organization on the planet.

Consider the xz episode as a baseline. It was fairly sneaky, but it was introduced by a newcomer to the project and affected mostly existing code. A more elaborate exploit might be submitted with a new feature by an established maintainer.

Re: Several Russian developers lose kernel maintainership status

#70
post #31

Earlier quoted context omitted.

Let me spell it out for you: If Project P in Country A is identified by Country B as a potential target for planting cyber-attack-enabling backdoors, Country B has an incentive to find people to put a backdoor in P. If Country B is a free country with rights and ethics, they will say "Help us put a backdoor in P. We'll pay you very well for services rendered," or try to get someone who already works for Country B int…

Cool. Which country owns the Linux kernel? Not that I disagree with the move 100%, but I don't think it's that clear cut.

Linux foundation is 501(c)(6) organization based in US.of.A
Post reply on HN