6 ms·
Geez, his last commit is making security reports worse: https://git.tukaani.org/?p=xz.git;a=commitdiff;h=af071ef7702debef4f1d324616a0137a5001c14c;hp=0b99783d63f
by fcanesin 3y ago
Geez, his last commit is making security reports worse: https://git.tukaani.org/?p=xz.git;a=commitdiff;h=af071ef7702debef4f1d324616a0137a5001c14c;hp=0b99783d63f27606936bb79a16c52d0d70c0b56f https://git.tukaani.org/?p=xz.git;a=commitdiff;h=af071ef7702...
- eacapeisfutuile 3y agoWhy is that accepted? Serious question
- foooorsyth 3y agoBecause nobody’s really paying attention. “LGTM!”
- eacapeisfutuile 3y agoGenerally yes, but ripping all conditions out of SECURITY.md should at least raise an eyebrow?
- indrora 3y agoNobody was watching. Plain and simple. If you have commit access to it, and nobody is there to see, nothing stops you.
- eacapeisfutuile 3y agoYes but if that’s the sentiment how is this not as problematic as the npm ecosystem.
- snazz 3y agoIt’s similarly problematic but on a somewhat smaller scale and with fewer levels of nested dependencies.
- eacapeisfutuile 3y agoI’m not sure this would be smaller scale? At least probably too early to tell?
- snazz 3y agoI just mean fewer total packages and fewer maintainers. Linux libraries and packages don’t have the culture of making a package out of a single small function and importing it everywhere, which is part of the reason why NPM is a good case study in opportunities for supply chain attacks.
- eacapeisfutuile 3y agoYes but the distribution likely depends on it, making it wider spread even without the middleman dependencies.
- kristjansson 3y agoHe had unfettered access to xz’s git?
- eacapeisfutuile 3y agoIsn’t it a bit ironic with how much code everyone depends on that can freely be altered by some unknown party, while so much time goes into code reviews to verify internal changes at most companies.
- cookiengineer 3y agoSome might say RMS was right all along.
- darthrupert 3y agoI would actually say that he is completely wrong in this case. Open source created this problem.
- cookiengineer 3y agoAnd you think proprietary code doesn't have this problem? Can you prove it? Where's the evidence? ;)
- eacapeisfutuile 3y agoLack of proof in any direction is approaching the core issue here.
- SAI_Peregrinus 3y agoThe problem niver would have been fixed in proprietary software. And it's unlikely the problem would have been considered anything more than a 0.5s startup delay in some situations if xz were proprietary; it would have been reported as a performance issue to the malicious maintainer, who would have treated it as such and improved the startup time.
- maxdamantus 3y agoPresumably because they're one of the two maintainers: https://web.archive.org/web/20240329182607/https://xz.tukaani.org/ https://web.archive.org/web/20240329182607/https://xz.tukaan...