4 ms·
This is ultimately a cultural problem amongst FOSS users. Just like taking hits from the bong of unvalidated packaged imports over and over has corrupted secur
by outsomnia 5y ago
This is ultimately a cultural problem amongst FOSS users.
Just like taking hits from the bong of unvalidated packaged imports over and over has corrupted security culture in JS, Python, Rust etc.
Currently they don't want to think about where the work came from and whose hands touched it, they just want the high of being able to leech the work of others. Who did the work, what the quality really is, who touched it before you took it, and how those guys are doing are all culturally out of scope, a taboo topic even.
- phendrenad2 5y agoThe fact that people trust open-source at all is a testament to how well-managed most FOSS projects are. There are just a few bad apples that you have to look out for.