mattblaze,
@mattblaze@federate.social avatar

The XZ backdoor seems to have become a Rorschach test that shows whatever you already believed about the security of open source software against sabotage.

It clearly proves the inherent superiority of the open source model. Or the inherent vulnerability. One of those, definitely.

kellogh,
@kellogh@hachyderm.io avatar

@mattblaze i have a post going around (~200 boosts) pointing out how the “many eyes” is resistant against social engineering. Unfortunately, a reply thread on that post is not getting any attention, where i note that it’s a very small advantage, and that it’s actually kind of amazing that it held up. i got some heat for saying that…

ralph,
@ralph@social.tchncs.de avatar

@mattblaze It is strange, that we are so much used to hear about hacks of big companies, that we nearly do not recognize it anymore. When we have a look at how fast in this case the hack was found and fixed: That was really impressive.
And starting a reasearch because of 0.5 sec delay you cannot explain: In how many companies would you get persmission to do that?

https://www.tagesschau.de/ausland/microsoft-china-hackerangriff-100.html

mattblaze,
@mattblaze@federate.social avatar

@ralph Congratulations on finding evidence for your pre-existing beliefs!

mattblaze,
@mattblaze@federate.social avatar

If your opinion about software security fits into a catchy slogan, it's probably not that useful.

Catchy: "Many eyes make all bugs shallow"

Also catchy: "Five Eyes make all bugs shallow"

bynkii,
@bynkii@mastodon.social avatar

@mattblaze “Five Guys make all bugs full”

cigitalgem,
@cigitalgem@sigmoid.social avatar
dango_,
@dango_@mas.to avatar

@mattblaze tbh it just reminds me of when a popular Minecraft mod repository changed owners and reviews of uploaded mods degraded; and the very first week someone snuck in a trojan by using embedded binary in the source code.

Stop checking in binaries

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • rosin
  • tester
  • Youngstown
  • khanakhh
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • megavids
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • Durango
  • cisconetworking
  • anitta
  • modclub
  • cubers
  • Leos
  • provamag3
  • JUstTest
  • lostlight
  • All magazines