but also what the xz debacle shows: open source software is really hard to secretly backdoorbecause some rando will be like “huh, this command is taking 0.5 seconds longer than it used to, let me check what’s going on here”like can you believe that tha...
-
skze :nonbinary_flag:replied to skze :nonbinary_flag: on last edited by
people actually do that. if the code is available, they are going to look at it for any number of unpredictable reasons.
-
skze :nonbinary_flag:replied to forestry-quasar on last edited by
@quasar how so?
-
forestry-quasarreplied to skze :nonbinary_flag: on last edited by@skye like, most engineers that arent red hat, microsoft whatever would see a 100x increase in latency and think "whatever, not my problem, im not paid enough for that"
-
Irenes (many)replied to forestry-quasar on last edited by
-
forestry-quasarreplied to Irenes (many) on last edited by
-
Irenes (many)replied to forestry-quasar on last edited by
-
Irenes (many)replied to Irenes (many) on last edited by
@quasar @skye behind the scenes the postgres person realized this was an inside attack of some sort and ignored the usual practice of reporting the bug to the xz project, instead reporting it to security people at distros (presumably mostly redhat), so that disclosure could be handled in a coordinated way. that was a particularly sharp move.
-
Irenes (many)replied to Irenes (many) on last edited by
-
skze :nonbinary_flag:replied to Irenes (many) on last edited by
-
skze :nonbinary_flag:replied to skze :nonbinary_flag: on last edited by
oh god my point is not “open source always secure” it’s “open source much harder to secretly backdoor than closed source”
Copyright © 2024 NodeBB | Contributors