6 ms·
Recall that the original maintainer had mental health issues and other things that likely led to the perceived need to bring on someone to help maintain xz. Th
by rmast 3y ago
Recall that the original maintainer had mental health issues and other things that likely led to the perceived need to bring on someone to help maintain xz.
This brings up some integrity questions about you and other people bringing forth accusations in order to make the original maintainer feel pressure to bring on someone else to replace the one that inserted a backdoor after several years of ostensibly legitimate commits.
Hopefully this helps you see that these sorts of accusations are a slippery slope and unproductive. Heck, you could then turnaround and accuse me of doing something nefarious by accusing you.
- thinkingemote 3y agoIt's possible that he was intentionally pressured and his mental health made bad or worse by the adversary to increase stress. The adversary would then propose to help them reduce the stress. It's probably straight out of many playbooks.
- deleted 3y ago[deleted]
- w4ffl35 3y agoAdditionally to the guy's above point, replacing him after this incident would complete that play
- w4ffl35 3y agoActually my solution as outlined on twitter was to enforce non anon commits, and i stated it is a bad idea to replace him, so try again. And, as stated above, I don't think he's malicious, it's still something that must be considered. Sweeping the possibility away is weird.
- rmast 3y agoI don’t stalk all of your social media posts, so from my perspective I don’t see any of the solutions you’ve posted elsewhere — which brings up a good point to keep in mind: none of us see the complete picture (or can read minds to know what someone else really thinks). The possibility can be kept in mind and considered even if it isn’t being actively discussed. I think in this case, most people think he is not malicious — and feel that unless new compelling evidence to show otherwise appears, potentially starting a harmful rumor based on speculation is counterproductive.
- w4ffl35 3y agoI'm not starting a harmful rumor. People are asking legitimate questions in order to paint the whole picture. Being gaslit is very weird. > I don't stalk your socials I mentioned it because you called my intent into question. Why are people running cover for the maintainer of a repo that just tried to backdoor sshd when others are asking legitimate questions?
- rmast 3y agoYou might not be trying to start a rumor, but other people could when they try to answer the questions from a place of ignorance — if you take a look at the comments on a gist summarizing the backdoor, there are quite a few comments by z-nonymous that seem to be insinuating that other specific GitHub users are complicit in things by looking at their commits in various non-xz repositories. No one is running cover, just that most information so far points to the original maintainer not knowing that the person brought on to help out had ulterior motives, and likely wasn’t even who they purported to be. If you were running an open source project and facing burnout as the sole maintainer, I’d imagine you’d exercise perfect judgement and do a full background check on the person offering to help? I think many of us would like to believe we’d do better, but the reality is, most of us would have fallen for the same trick. So now imagine having to deal with the fallout not just on the technical side, but also the never-ending questions surrounding your professional reputation that people just keep bring up — sounds like a recipe for depression, possibly even suicidal thoughts.
- w4ffl35 3y agoI am running an open source project. Yes if someone was eager to help and was making changes to things that involved security, I would make them doxx themselves and submit to a background check
- rmast 3y agoWell, good for you being one of the few exceptions who would make everyone submit themselves to a proper background check (presumably also covering the cost) before giving any write/commit access to the repo. That’s more than even most large open source projects do before giving access.