(no title)
exacube | 1 year ago
I would think a "real identity" should be required by linux distros for all /major/ open source projects/library committers which are included in the distro, so that we can hold folks legally accountable
exacube | 1 year ago
I would think a "real identity" should be required by linux distros for all /major/ open source projects/library committers which are included in the distro, so that we can hold folks legally accountable
rsc|1 year ago
Google's Know, Prevent, Fix blog post floated the idea of stronger identity for open source in https://security.googleblog.com/2021/02/know-prevent-fix-fra... and there was very significant pushback. We learned a lot from that.
The fundamental problem with stronger identity is that spy agencies can create very convincing ones. How are distros going to detect those?
kashyapc|1 year ago
I realize, it's a hard problem. (And, thanks for the link to the "Know, Prevent, Fix" post.)
PS: FWIW, I "win my bread" by working for a company that "does" open source.
Edit: Some projects I know use in-person GPG key signing, or maintainer summits (Linux kernel), etc. None of them are perfect, but raises the bar for motivated anonymous contributors with malicious intent, wanting to become maintainers.
nrvn|1 year ago
But you have a point. As an agency you can seed two jiatan's to serve diligently for a couple of years following the strict 2-person code reviews and then still poison the project. On the other hand, if the xz build process was automated and transparent and release artifacts were reproducible and verifiable even in this poor condition of xz-utils as a project it would have been much harder to squeeze in a rogue m4/build-to-host.m4
delfinom|1 year ago
Source code is provided without warranty and this statement is clear in the license.
Putting an verified identity behind the source code publish is basically starting to twist said said no-warranty. Fuck that.
in3d|1 year ago
mapmeld|1 year ago
tamimio|1 year ago
tester457|1 year ago
asvitkine|1 year ago
gquere|1 year ago