4 ms·
I've argued in a blog post [1] that we need to delineate between "open source developer" and "supplier". If we don't do that, calling thankless unpaid volunteer
by CiPHPerCoder 2y ago
I've argued in a blog post [1] that we need to delineate between "open source developer" and "supplier". If we don't do that, calling thankless unpaid volunteers and hobbyists a "supply chain" is kind of insulting [2].
I don't believe that "identity verification" for F/OSS developers is a good idea. Suppliers? Sure. That can be a contract negotiation when you decide how much you pay for it.
Also, I don't think identity verification helps when your adversary is a nation state, which can just falsify government identification if it suits them.
[1] https://scottarc.blog/2024/04/04/open-source-supply-chains-and-bears-oh-my/ https://scottarc.blog/2024/04/04/open-source-supply-chains-a...
[2] https://crankysec.com/blog/supply/ https://crankysec.com/blog/supply/
- xcrunner529 2y agoJust because it can by beaten doesn’t mean making it harder isn’t useful. This person/team used a VPN. Masking your location is a big red flag for just dev work like this. These things could be exposed in UI.
- mbs159 2y agoNot everyone dev that uses a VPN or something like Tor is doing so due to some malicious reasons. Some people face challenges regarding privacy.
- CiPHPerCoder 2y ago> Just because it can by beaten doesn’t mean making it harder isn’t useful. Fair. > This person/team used a VPN. Masking your location is a big red flag for just dev work like this. These things could be exposed in UI. I disagree strongly, and am surprised to hear this argument on Hacker News of all places.
- ogurechny 2y agoPeople are so used to see artificial bureaucratic structures as more real than their real counterparts that they constantly invent such naive solutions. “Just make the gub'ment provide an official paper (with a stamp) that Joe Random Dude is a real developer, a father of two, not a fan of satanic metal music, and the project will be safe”.
- xcrunner529 2y agoPeople already do this in a general sense for authenticating a person and deciding if they’re trustworthy.
- ogurechny 2y agoNot “trustworthy”, but “able to play their role in certain scenes”. When you're outside of that structure, those decorated clothes lose any meaning.
- jamespo 2y agoThe VPN is just part of the picture (sock puppet accounts complaining about speed of dev, no meaningful history of other contributions from the dev, no trusted "personal network" for the dev, etc) that in hindsight should have raised red flags.
- markhahn 2y agonew project idea: OpenBackgroundCheck volunteer osint researchers attempt to dox any identity you submit, so you can know whether they're the Right Kind of OSS contributor or not. /s
- xcrunner529 2y agoIf they constantly are on a VPN and not willing to disclose a real location or IP then I fail to see why they should be trusted when they don’t provide anything trustworthy themselves.
- asveikau 2y agoMost people you interact with electronically, you don't even bother trying to see if they're using a VPN or make any attempt to geolocate them.
- xcrunner529 2y agoSure but GitHub could have that as a badge to provide useful info that can help with vetting someone who wants to be a maintainer.