7 ms·
I think its much more likely this was not a bad actor, given their long history of commits. It's a known fact that China will "recruit" people to operate them.
by port443 3y ago
I think its much more likely this was not a bad actor, given their long history of commits.
It's a known fact that China will "recruit" people to operate them. A quote:
> They talk to them, say my friend, I see you like our special menu. Are you from China? Are you here on a VISA? Do you have family back there? Would you like your family to stay alive? Is your loyalty to this temporary employer or is your loyalty to your motherland? You know, a whole bunch of stuff like that. That’s how Chinese intelligence operations acts...
This just gives feelings of less "compromised account" and more "Your account is now our account"
- Johnny555 3y agoIsn't that still a "bad actor" even if they are coerced into it?
- foobiekr 3y agoYes.
- deleted 3y ago[deleted]
- Terr_ 3y agoFor the purposes of security discussions, I would say yes. You often don't know their real identity let alone their motivations and tribulations. However if we were critiquing characters in a book-- especially ones where narrative voice tells us exactly their true motivations--then maybe not, and they get framed as a "dupe" or "manipulated" etc.
- Almondsetat 3y ago"bad actor" doesn't mean "bad faith", it's not a value judgement
- ip26 3y agoI believe your parent is trying to make a distinction that the handle's history may not be suspect, only recent activity, positing a rubber-hose type compromise.
- zeroCalories 3y agoI think we should seriously consider something like a ts clearance as mandatory for work on core technologies. Many other projects, both open and closed, are probably compromised by foreign agents.
- Meetvelde 3y agoThat's hard to do when the development of these libraries is so international. Not to mention that it's already so hard to find maintainers for some of these projects. Given that getting a TS clearance is such a long and difficult process, it would almost guarantee more difficulty in finding people to do this thankless job.
- zeroCalories 3y agoIt doesn't need to be TS for open source(but for closed, I'm leaning yes). But all code for these core technologies need to be tied to a real person that can be charged in western nations. Yes, it will make it harder to get people, but with how important these technologies are, we really should not be using some random guys code in the kernel.
- guinea-unicorn 3y agoDon't forget that the NSA bribed RSA (the company) to insert a backdoor into their RNG. Being in western jurisdiction doesn't mean you won't insert backdoors into code. It just changes whom you will target with these backdoors. But they all equally make our technology less trustworthy so they are all equally despicable.
- zeroCalories 3y agoIt will significantly cut down on Russian and Chinese back doors, which is still an improvement, Mr. Just Made an Account.
- rwmj 3y agoThat just means the bad actors will all have clearance while putting in a bunch of hurdles for amateur contributors. The only answer is the hard one, constant improvement in methods to detect and mitigate bugs.
- okasaki 3y agoA quote from... your arse?
- joveian 3y agoThat is what I thought too but it wasn't hard to find: https://darknetdiaries.com/transcript/21/ https://darknetdiaries.com/transcript/21/
- threeseed 3y agoIt's also a known fact that China will coerce people by threatening family and friends. Seen this happen to friends here in Australia who were attending pro-Taiwan protests.
- dang 3y agoWe detached this subthread from https://news.ycombinator.com/item?id=39867106 https://news.ycombinator.com/item?id=39867106.