schwa,
@schwa@mastodon.social avatar

deleted_by_author

  • Loading...
    heckj,
    @heckj@mastodon.social avatar

    @schwa I fell down the same rabbit hole yesterday evening. Quite the story

    schwa,
    @schwa@mastodon.social avatar

    deleted_by_author

  • Loading...
  • schwa, (edited )
    @schwa@mastodon.social avatar

    deleted_by_author

  • Loading...
  • schwa,
    @schwa@mastodon.social avatar

    deleted_by_author

    pgor,
    @pgor@mastodon.social avatar

    @schwa My concern is that if they were playing such a long game, they weren’t/aren’t just doing it with xz.

    zleap,
    @zleap@qoto.org avatar

    @schwa

    In the UK, despite background checks, police checks, references, etc bad people still get to work or volunteer with children and go on to abuse. This applies to the police, NHS, which has seen recent horrific incidences. Lucy Letby, Wayne Couzens et al.

    I don't think we can mitigate against this 100 percent, what works is the fact people act on their instinct and raise concerns, the first step in finding out what is going on.

    I think the same applies to free software contributions, we value contributors, but there are lots of checks / balances in place, in this case the concern was a drop in performance, and thank fully it raised a red flag for further investigation.

    Could be a newbie programmer making an error, or an experienced programmer making an error, or a bad actor with malicious intent.

    We are human can't catch everything, we can do our best to though.

    Let's not aim blame, but learn from this. Which I AM very confident the community will learn from this.

    schwa,
    @schwa@mastodon.social avatar

    deleted_by_author

  • Loading...
  • NilaJones,
    @NilaJones@zeroes.ca avatar

    @schwa @zleap

    Child rape is not an honest mistake, either. schwa seems to miss the point here

    zleap,
    @zleap@qoto.org avatar

    @NilaJones @schwa

    Agreed, I did see a reply on here that suggested what happened in this case may have been malicious, I can't find the reply, but we simply don't seem to know at this point.

    schwa,
    @schwa@mastodon.social avatar

    deleted_by_author

  • Loading...
  • mwyman,
    @mwyman@mastodon.social avatar

    @schwa I suspect in the coming years we are going to learn a whole host of critical OSS packages are maintained by essentially one person as that person struggles to find someone to take over so they can retire. Or worse.

    jumbanho,
    @jumbanho@mas.to avatar

    @schwa do many distros uses maintainers' binaries?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • megavids
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines