3 ms·
I can make an argument that money will make it even worse, as people will full-time make even more useless features that just increase the attack surface. This
by throwaway47292 5y ago
I can make an argument that money will make it even worse, as people will full-time make even more useless features that just increase the attack surface.
This particular class of problems (same as the sqlite fts tokenizer exploit and most of openssl exploits, even lots of the sendmail exploits) are just obscure unused features. It happens even in CPUs themselves. (e.g. https://www.youtube.com/watch?v=lR0nh-TdpVg https://www.youtube.com/watch?v=lR0nh-TdpVg)
Removing code is twice harder than adding code, why do you think paid maintainers would improve anything? Just look at the code written in FAANG or any enterprise, and those maintainers are very well paid, imagine this code being public, we will have 1 new exploit per day per company... and that is assuming non malicious developers that can be shipping trojan code https://lwn.net/Articles/874951/ https://lwn.net/Articles/874951/ (it is also hard to assume all millions of developers are non malicious, even if we assume 1 in 100000, things look really bad)
Less code is the one solution. Regardless if open source or enterprise code.
We are stuck, and change is needed, but money is not a solution, and might even be the cause of the problem. (incentive to write more code)