7 Matching Annotations
  1. Apr 2024
    1. This is not the first time an open source package has been hijacked after a maintainer was added – it actually happens all the time in Python repositories and such, and has been one of the leading causes of infostealers and coin miners in development pipelines. It is absolutely not a surprise that somebody is targeting open source compression libraries that systemd loads.. and it is also sadly not a surprise that people online bully the creators of these libraries, either.

      Wrt [[XZ open source kwetsbaar door psyops 20240331083508]] and examples referred to here, the author focuses on technology fixes to reduce risks. Whereas most of the problems highlighted are social aspects, for which no other solution is suggested than paying OSS devs who maintain stuff. That may well alleviate some of the social aspects that became an attack surface, but does nothing to look at Q of connections between devs and knitting those into relationships that are more resistant to social engineering and psyops. That and more transparency both on the social side of things and the chains. OSS is open source wrt the piece of software in front of you only.

  2. Nov 2019
    1. The thing is that each UI decision depends on countless other UI decisions. A simple example is keybindings. On UNIX/Linux, it’s nearly impossible to pick reasonable default bindings for global desktop navigation because they all conflict with bindings that some app is using. On Windows, the desktop navigation bindings are hardcoded, and no app uses them, because apps know for sure which bindings to avoid.
  3. Oct 2018
  4. Nov 2017
  5. Feb 2016