Sopuli
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
𝗧𝗼𝗮𝘀𝘁𝗲𝗿 *𝑣𝑒𝑟𝑦 𝑝𝑢𝑠ℎ𝑒𝑑 𝑑𝑜𝑤𝑛@slrpnk.net to Open Source@lemmy.mlEnglish · 1 year ago

Bullying in Open Source Software Is a Massive Security Vulnerability

www.404media.co

external-link
message-square
35
link
fedilink
  • cross-posted to:
  • foss@beehaw.org
  • technology@lemmy.world
171
external-link

Bullying in Open Source Software Is a Massive Security Vulnerability

www.404media.co

𝗧𝗼𝗮𝘀𝘁𝗲𝗿 *𝑣𝑒𝑟𝑦 𝑝𝑢𝑠ℎ𝑒𝑑 𝑑𝑜𝑤𝑛@slrpnk.net to Open Source@lemmy.mlEnglish · 1 year ago
message-square
35
link
fedilink
  • cross-posted to:
  • foss@beehaw.org
  • technology@lemmy.world
The Xz backdoor and a near miss on the F-Droid app store show how the entitled attitude of some people in the open source community can be used to push malicious or insecure code.
  • rollingflower@lemmy.kde.social
    link
    fedilink
    arrow-up
    8
    arrow-down
    2
    ·
    1 year ago

    If something is free Software, there is no supply chain. There is no security and no guarantees. For sure all these volunteers are mostly trying to deliver a good product, but they are offering free labor.

    Saying “bullying is bad for the outcome of the product” is kinda ironic, as “not paying these devs” also is bad. This is just the extreme form

    • magic_lobster_party@kbin.run
      link
      fedilink
      arrow-up
      5
      ·
      1 year ago

      This person has never worked in a company where customer service has full access to user’s passwords because no one bothered to hash them.

    • delirious_owl@discuss.online
      link
      fedilink
      arrow-up
      4
      arrow-down
      2
      ·
      1 year ago

      What? Its literally a transparent supply chain, and therefore much safer than the supply chain of non-free software.

      • rollingflower@lemmy.kde.social
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        https://www.softwaremaxims.com/blog/not-a-supplier

Open Source@lemmy.ml

opensource@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@lemmy.ml

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

  • Open Source Initiative
  • Free Software Foundation
  • Electronic Frontier Foundation
  • Software Freedom Conservancy
  • It’s FOSS
  • Android FOSS Apps Megathread

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !libre_culture@lemmy.ml
  • !libre_software@lemmy.ml
  • !libre_hardware@lemmy.ml
  • !linux@lemmy.ml
  • !technology@lemmy.ml

Community icon from opensource.org, but we are not affiliated with them.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 99 users / day
  • 1.13K users / week
  • 3.16K users / month
  • 10.1K users / 6 months
  • 408 local subscribers
  • 36.7K subscribers
  • 3.31K Posts
  • 37.9K Comments
  • Modlog
  • mods:
  • Evan@lemmy.ml
  • kevincox@lemmy.ml
  • CrypticCoffee@lemmy.ml
  • Lettuce eat lettuce@lemmy.ml
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org