4 ms·
If he's right about the incentive for internal code sabotage, I wonder if this will strengthen the security perceptions of open source software. Particularly s
by bsaunder 14y ago
If he's right about the incentive for internal code sabotage, I wonder if this will strengthen the security perceptions of open source software. Particularly strongly curated open source software.
He somewhat alludes to this with his comment:
"No commercial vendors perform the level of code review that would be necessary to detect, and prove mal-intent for, this kind of sabotage."
- deleted 14y ago[deleted]
- shabble 14y agoHave a look at the Underhanded C contest[1] and see which of those entries (suitably scaled up, possibly spread over several commits by different people) would be likely to be spotted by OSS maintainers or contributors. I'm not sure the 'all bugs are shallow...' applies to actively malicious contributions. In some sense, proprietary software might be more secure, exactly because it doesn't accept contributions from anyone, and can much more easily background-check the people who do work on it. I'm not sure how common OSS projects that don't accept contributions are, but I'm sure they exist. [1] http://underhanded.xcott.com/ http://underhanded.xcott.com/