3 ms·
“Given enough underfunded maintainers, all security is shallow.”[0] 0. https://en.wikipedia.org/wiki/Linus%27s_law https://en.wikipedia.org/wiki/Linus%27s_law
by irdc 3y ago
“Given enough underfunded maintainers, all security is shallow.”[0]
0. https://en.wikipedia.org/wiki/Linus%27s_law https://en.wikipedia.org/wiki/Linus%27s_law
- lenerdenator 3y agoI wouldn't say "funding" is necessarily the problem. Most maintainers do it because they like doing it. Their main limiting factor is time. I can drop a million dollars an hour into a maintainer's lap; that doesn't mean they can dedicate every waking moment to a project. They still have human needs that money can't buy like sleep, family obligations, and health concerns. And that's making the assumption that the maintainer uses that million/hr to quit their job. No, the problem is a lack of trustworthy candidates for maintainership and a lack of time. There are components of a GNU userland that are now too complex for a single human to both maintain and enhance at the same time. We now need to target multiple distros (really, more than are necessary, strictly speaking) and ISAs. Most are written in systems programming languages like C that are more complex than the average software engineer in 2024 works with. We need consolidation, simplification, maintainer redundancy, and a trust/governance framework for packages.
- mikrotikker 3y agoWe need to utilise a specialised AI to scan through the code looking for bugs and security holes. Imagine if openai donated server time to this.