3 ms·
I think there are huge factors that push things both for and against open source here. Yes, you get more eyes and people like Andres Freund. However, if this
by creato 3y ago
I think there are huge factors that push things both for and against open source here.
Yes, you get more eyes and people like Andres Freund.
However, if this had been a mole in a company, he wouldn't be able to hide behind a possibly anonymous fake persona and (likely) be immune from any consequences/fallout from this attack. It would be harder to gain entry in the first place, he would have needed a real identity. Background checks may not be a big hurdle, but they're at least something more than signing up for a GitHub account. He also wouldn't have had his posse of anonymous sock puppet accounts to add pressure to the original maintainer.
I also think that just being able to ramp up on liblzma and its dependencies to undertake this effort in the first place is a huge head start vs. trying to execute the same attack on a closed source corporate product.
At the same time, there are probably lower hanging fruits to attack if you really do get a mole inside a company, in addition to there being fewer eyes/opportunities for the attacks to be discovered as you pointed out.
I honestly don't know how all of these factors add up. I expect the argument opposite to yours to be raised (again) in the wake of this incident. I'd personally be hesitant to raise this argument (not that it matters here on HN).
- A1kmm 3y ago> However, if this had been a mole in a company, he wouldn't be able to hide behind a > possibly anonymous fake persona and (likely) be immune from any consequences/fallout from > this attack. It would be harder to gain entry in the first place, he would have needed a > real identity. Lots of companies hire remote workers sight unseen, and not all require proof of identity, and where they do, that proof can possibly be easily faked by someone willing to break the law. Larger Open Source projects - e.g. Debian Developers, also have real-identity verification through chain of trust. > Background checks may not be a big hurdle, but they're at least something more than > signing up for a GitHub account. GitHub doesn't allow more than one free account per person. Companies might not look for employees sharing an IP address as much as GitHub does. > He also wouldn't have had his posse of anonymous sock > puppet accounts to add pressure to the original maintainer. Depending on the software, it might not be that hard to be a customer (or even pretend to be an employee of a known customer, if they aren't validating incoming requests claiming to be from customers enough) and add pressure for features that will provide cover for a backdoor, or even for a product that isn't a commercial success to be handed over to an external developer.
- WesolyKubeczek 3y agoAnd yet industrial espionage in companies is quite common, by both competition and, if you’re big and important enough, state (yours or enemy). The means are different, though.
- nonrandomstring 3y agoOrganisations shield moles and infiltrators very effectively. They are rarely alone. It may be harder to get in as an outsider, but once in they've protections a lone wolf does not enjoy. You can save a lot of time reading John LeCarre novels and take a short summary like this one of Adam Curtis [0]. If you watched the recent Oppenheimer film you'll know the name Klaus Fuchs. But what about Guy Burgess, Kim Philby and Anthony Blunt? If MI5, MI6 and GCHQ are. almost by tradition stacked to the rafters with defectors and spies, enclaves of enemies within, and enemies within enclaves of enemies... how does anyone expect a commercial company motivated by money and with such a weak perimeter as a "job market", to do better? Trust does not have an organisational solution. [0] https://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9-3149-963f-47bea720b460 https://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9...
- barcist 3y agoIn a corporate proprietary code base this is REALLY easy. Just commit a bug. Happens every day, everywhere. Just that normally these are mistakes. You can easily mask a deliberately inserted exploitable bug as a mistake. Make the code a bit convoluted, leave out a crucial corner case from your test, slip this in in a moment when your code reviewers have time pressure and/or are stressed somehow, and even if you are caught, the plausible deniability is convincing. How many eyes will see it after the fact? None.