4 ms·
If it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tool
by dergachev 13y ago
If it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tools like OpenSSL? What if you add blackmail to the mix?
Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.
- pasbesoin 13y agoThis is why you want some people who are not primarily motivated by money. (Neither necessarily ascetics.) In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. (E.g. an independent researcher can actually gain access to and participate in a large and reasonably priced health insurance risk pool. And where money is not the overriding, if not sole, determination of judicial proceedings.) Going very general in my comment, security is both a community effort and a personal responsibility. The more we "outsource" our own security ("Just trust us." -- Three Letter Agencies and private contractors), the more the price goes up while the quality of the results goes down. You get the government you pay for, or... if you are more concerned about a quality, effective government, the government you participate in. Hopefully, the pendulum is beginning to swing back from "pay for" to "participate in".
- deleted 13y ago[deleted]
- morganherlocker 13y ago> In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. Is financial instability really a problem for most people qualified for this type of work? I imagine most of these people are approaching or well within the 6 figure range and that accepting some sort of bribe would just be icing on top.
- judk 13y agoLuckily, open source can't include secret code. That's the point.
- brdrak 13y agoWhat about binary-only drivers? http://en.wikipedia.org/wiki/Binary_blob http://en.wikipedia.org/wiki/Binary_blob