6 ms·
> 8. This sucks to say, but code reviews and handing off maintainership, at the moment, need to take into account geopolitical considerations. That won't help.
by Denvercoder9 3y ago
> 8. This sucks to say, but code reviews and handing off maintainership, at the moment, need to take into account geopolitical considerations.
That won't help. There's no evidence that Jia Tan is a real name, or even a real person for that matter. If projects stop accepting contributions from asian-sounding names, the next attack will just use Richard Jones as a name.
- lenerdenator 3y agoI think you could interpret this as "you need to know, personally, the party you're handing this off to, and make reasonable judgments as to whether or not they could be easily compromised by bad actors". Like, meeting someone at several dev conferences should be a requirement at the very least.
- redserk 3y ago1) Not everyone (current and potential future maintainers) has the time to go to dev conferences. 2) Simply meeting IRL is a terrible proxy for credibility.
- MiscIdeaMaker99 3y agoWhat would be better?
- redserk 3y agoIt's naive to believe that any form of physical presence means someone isn't going to do something nefarious in the eyes of the project. This problem can only be solved by more skilled eyes on the projects that we rely on. How do we get there? shrug.gif. Anything less is trying to find a cheap and ineffective shortcut in this trust model.
- gunapologist99 3y agoYou have a good point, but there's also a reason why companies like people to come into work and don't hire remotely as much as they should (or could). There's a reason why interviews often include a meal together. Meeting people IRL is good for building trust, on both sides.
- lenerdenator 3y ago> It's naive to believe that any form of physical presence means someone isn't going to do something nefarious in the eyes of the project. It's not the only thing, but it is something. There's a lot of social engineering that went into the xz backdoor[0]. This started years ago; Jia Tan was posting in projects and suddenly someone appeared to pressure projects to accept their code. Who's Jia Tan? Who's Jigar Kumar, the person who is pressuring others to accept patches from Jia Tan? We don't know. Probably some person or group sponsored by a state APT, but we don't know for sure, because they're currently just text on a screen. Having this person or group of people have to continually commit to the bit of publicly-known open-source maintainer who attends conferences, has an actual face, and is on security camera footage at multiple hotels and airports is far, far harder than just talking a vulnerable person into allowing maintainer access on a repository. Making them show up to different places a few times adds a layer of identity. Otherwise these "skilled eyes" could be anyone with a wide variety of motivations. [0]https://boehs.org/node/everything-i-know-about-the-xz-backdoor https://boehs.org/node/everything-i-know-about-the-xz-backdo...
- redserk 3y ago> Having this person or group of people have to continually commit to the bit of publicly-known open-source maintainer who attends conferences, This is assuming maintainers even care/want to go. > has an actual face, and is on security camera footage at multiple hotels and airports The same footage that'll get wiped a few weeks after the conference ends, and quickly becomes not useful. This is wonderful posturing in the name of security theater but doesn't solve anything.
- lenerdenator 3y ago
- gunapologist99 3y ago> 2) Simply meeting IRL is a terrible proxy for credibility. Disagree; trust your intuition, but you can never do that if you never meet IRL. Also, it's not racist or xenophobic to recognize that some countries exercise nearly complete control over their citizens (and sometimes indirectly over non-citizens), and that those people could be putting themselves at extreme personal risk by disobeying those dictates (assuming they did disagree, which doesn't seem to be a given)
- redserk 3y ago> WRT 2, no, it's not. > Trust your intuition, but you can never do that if you never meet IRL. I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. > Also, it's not racist or xenophobic to recognize that some countries exercise nearly complete control over their citizens (and sometimes indirectly over non-citizens), and that those people could be putting themselves at extreme personal risk by disobeying those dictates, if they even disagreed with them. Hold up, where did I make this claim about national origin/external pressure? I'm only suggesting if you have pets, a kid, or a project at work, conferences take a non-zero amount of time to plan to attend. Plus, what conference options even exist if you're finding other people for the xz library? Searching for #CompressionConf2024 isn't turning up much.
- lenerdenator 3y ago> I'm sure Edward Snowden also met up with colleagues in the office at least a few times. May have even passed a security clearance. And that's why we know who Edward Snowden is. That's more than we can say about Jia Tan. Say what you will about what he did and why, it is going to be very, very hard for someone to explain to a contract's security auditor why, in the year 2024, a commit from an account known to belong to Edward Snowden is in the source code of security-critical software. And that's what FOSS-based companies and orgs need to start doing after this. If I'm working for Debian/Mozilla/Apache/wherever, I'm going to start asking project maintainers more about who they are. "Hey man, we've got an all-expenses-paid trip to one of the major conferences this year, which one can we put you down for?" needs to come out of someone's mouth at some point, and excluding some very good reasons and evidence for why they can't appear at one of these events in-person (think health or long-term family obligation reasons, confirmed by multiple people who know the maintainer), they need to be at one or more meetings within a reasonable amount of time. Randomly-timed remote video meetings could work in a pinch. If they can't after a couple of years, then these projects need to inform the maintainers that they'll be forking the project and putting it under a maintainer who can be verified as a living, breathing, single person. Repeat until there's at least some idea of who's working on most of these projects that make up critical systems that society is built upon.
- Denvercoder9 3y ago> Like, meeting someone at several dev conferences should be a requirement at the very least. This is utterly and completely unfeasible. Most open source maintainers, especially those that are struggling and are pressured to hand-off maintenance, don't have the time, means and will to travel to meet up with prospective co-maintainers, not just once but multiple times. In practice it would just result in projects getting abandoned, the prospective co-maintainer starting a fork, and everyone switching to use the fork.
- lenerdenator 3y agoReally, it starts before things get bad. This thing where - in the famous XKCD example - a single guy is thanklessly maintaining a project for 20 years in Nebraska needs to stop. Software libraries like these are no longer a one-person job. They can't be for the bus factor alone. Major projects like Linux distros or bigger foundations like Apache or Mozilla need to start harping on people hard to contribute to important libraries. We'll get to whatever the buzzword of the day is once we do the important work first. Find a way to make it happen. Sorry, "I just can't" isn't going to cut it after this.
- Denvercoder9 3y agoI agree we need to stop depending on the 20-year hobby project of the guy in Nebraska, but adding barriers (which requiring travel and in-person meetings is) to sharing the load is not the solution. What these projects need is the necessary resources (mostly money) for multiple people to work on it professionally.
- nerdponx 3y agoWhat I don't understand is, where are all the code and security contributions from Big N and other multi-billion-dollar international scale and users? Do they all have their own internal fork of every major library? If not, you would think that they would be their own financial interest to keep somebody on payroll to maintain fundamental libraries like this.
- 3y ago
- markus_zhang 3y agoThis is almost impossible for remote OSS maintainers. Do you want people to upload passports? And what if a three agency can easily produce whatever material you want?
- lenerdenator 3y agoSounds like it's time for someone to either pay a few visits to the remote maintainer or give them a scholarship for attending a few conferences.
- markus_zhang 3y agoThe big companies can do that. But then there is also the question of -- how many of these critical OS libraries are there in the wilderness?
- lenerdenator 3y agoI feel a census coming on. There needs to be a reckoning of who is doing what where on this sort of thing. After this whole fiasco you'll probably see more contracts wanting to know who's working on these things, and that will, in turn, have people auditing their software's packages.
- to11mtm 3y agoThe reality of such criteria is that it will be a ladder-pull for any new entrants. Not a workable option, full stop.
- clnhlzmn 3y agoThis is really not the responsibility of unpaid developers.
- lenerdenator 3y agoBig vendors should pay to get to know them, because they're the ones making the money off of the developers' work, but "I don't want to meet anybody and want to just manage the project" is the FOSS version of "just trust me bro".
- xign 3y agoThat's not what the above commenter said. This may be your interpretation but the above commenter is essentially saying "don't work with Chinese-sounding developers" and is the completely wrong take here. Jia Tan may or may not be Chinese but the core issue is the lack of basic vetting to make sure he/she/they are a real person.
- rebolek 3y agoI don't think that #8 implies that projects should stop accepting contributions from Asian-sounding names. To me it means that people should be more careful who they give access. It doesn't matter if it was China or some other state or organization pretended to be China, the problem is that people don't expect that open source contributor wouldn't act in altruistic way, but can be a malicious entity.
- glenstein 3y agoAnd to build on your point (hopefully), one way of understanding #8 is that it's not out of the question that bad actors have the time resource and patience to coordinate long-term campaigns of significant subtlety, the type of which is more easily pulled off by a state actor. Facts such as those should inform our presumptions about when and where people enjoy the benefit of the doubt.
- bombcar 3y agoFor example, we hope that Linus is not a long-term agent of the Suojelupoliisi - but how would you prove it? Ideally, the "proof is in the code" and the review setup is strong enough that it could handle a Compromised Linus™, even if it couldn't handle multiple compromises.
- glenstein 3y agoI mean I would hope that there's a way to separate out the Linuses from the Jia Tans. But it's no longer out of the question that a campaign can build up an account or accounts with long-term histories of good standing that really challenge our intuitions. But I suppose you are right, the best backstop is for the proof to be in the code.
- AndrewKemendo 3y agoThis is why things like kyc exist in other contexts The problem with any social test is that it’s biased by default towards whomever is controlling access
- rmbyrro 3y agoThis is so obvious that needing to say it shows how prejudice can blind people.