this post was submitted on 07 Apr 2024
96 points (98.0% liked)

Open Source

30221 readers
244 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
top 14 comments
sorted by: hot top controversial new old
[–] [email protected] 25 points 5 months ago (2 children)

Imagine if the governments were to fund open source projects when they need and as such the benefit is available to everyone if they have no money.

In such scenario all governments/citizens would have access to software that is good.

[–] [email protected] 15 points 5 months ago (1 children)

But but think about those poor (for profit) corporations. How can they ever afford to pay upper management million dolla paychecks without milking us dry :)

And think about the children

/s

[–] [email protected] 4 points 5 months ago

Ohh yeah, gotta think about children's safety online.

[–] [email protected] 2 points 5 months ago

My country has non profits that lobby for citizens , I wonder if there is enough motivation in the community to set something like that for FOSS, I don't think existing non profits (FSF, OSI) will want to deal with that kind of stuff .

[–] [email protected] 10 points 5 months ago (1 children)

It's always impressive to me that instead of sending billions of dollars to Microsoft, the US government could have had an entire operating system that caters exactly to them. They could have then given back in the form of commits improving the software for the rest of us too.

[–] [email protected] 5 points 5 months ago

Vote Pirate Party

Anti Commercial AI thingyCC BY-NC-SA 4.0

[–] [email protected] 9 points 5 months ago* (last edited 5 months ago) (1 children)

It was a huge fluke of luck that the XZ backdoor didn’t go in any actual Linux distribution releases.

It did get into a few, just not the ones corporations are likely to be using.

[–] [email protected] 9 points 5 months ago (1 children)

I doubt it would have been discovered this fast and easily if it was closed source.

[–] [email protected] 14 points 5 months ago (1 children)

it's safe to assume there are similar issues in closed source. A big part of the snowden leaks was about how NSA could access lots of data at will. It wouldn't surprise me if they also could execute code.

Also there is stuxnet. But I am not sure, if there were intentional backdoors, or only some "natural occuring" RCE.

[–] [email protected] 7 points 5 months ago

It wouldn't surprise me if they also could execute code.

They sat on external blue for 5 year before it was stolen and they disclosed the vulnerability to Microsoft.

https://en.wikipedia.org/wiki/EternalBlue

I don't see why we wouldn't assume there is always something similar in their armoury.

[–] [email protected] 7 points 5 months ago* (last edited 5 months ago) (2 children)

I got into a rabbit hole and read the story of the SolarWinds attack. Even as a total layman, what a rollercoaster.

[–] [email protected] 1 points 5 months ago
[–] [email protected] 1 points 5 months ago (1 children)

@Hadriscus I wonder if anyone at SolarWinds or Mandiant would notice a 300ms delay. They didn't even find it in June after the FBI contacted them.

[–] [email protected] 1 points 5 months ago

Looks like passionate people working on open source projects are more reliable as watch dogs