4 ms·
I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applie
by greenwich26 5y ago
I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar?
Since the Linux kernel is installed on many millions of computers, it is obviously pretty important that it doesn't have bugs in it. Certainly not malicious bugs. And if all it takes is a couple grad students and an assistant prof to get them in...well, that reflects very poorly on the state of kernel maintenance, to me. Which seems far more important and deserving of attention, than endlessly arraigning three clueless guys at some university.
I'm not in a position to be more specific about what should be fixed. But, what would your answer be to your query? Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it? How is that going to help when the CCP tries to insert surveillance into the kernel? Or when Russian hackers try to get exploits and ransomware in there?
- shkkmo 5y ago> assumption that every single contributor is honest. There is no such assumption and it has been well known for a long time that such an assumption would be harmful. > if all it takes is a couple grad students and an assistant prof to get them in There were 0 malicious commits that made it through the review process (since the paper was incompetent as well as unethical.) You seem to be missing some basic facts here. Filling in those gap would help you partipate more productively in the conversation.
- bronson 5y ago> I just don't understand why open source software can continue with the assumption that every single contributor is honest It doesn't. They've been on the lookout since before 2003: https://lwn.net/Articles/57135/ https://lwn.net/Articles/57135/ (there are other examples, this is just the earliest I know of) > Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it? This sounds overly dramatic which makes discussion difficult. My answer would be that the kernel maintainers have known about this threat vector for a very long time and seem to be doing a reasonable job of repelling it.
- anonymousab 5y ago> I just don't understand why open source software can continue with the assumption that every single contributor is honest It's not a bare assumption of honestly, it's an established relationship of trust. If you have zero trust then you cannot have any collaboration with other humans; it would be definition take as much or more effort than any creation to verify that the creation is fully safe in an current and future potential contexts. That trust with the university was broken, and in doing so their work has been reviewed and oft rejected.