Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
lemmyreader@lemmy.ml to Open Source@lemmy.mlEnglish · 1 year ago

Heartbleed and XZ Backdoor Learnings: Open Source Infrastructure Can Be Improved Efficiently With Moderate Funding

optimizedbyotto.com

external-link
message-square
14
link
fedilink
96
external-link

Heartbleed and XZ Backdoor Learnings: Open Source Infrastructure Can Be Improved Efficiently With Moderate Funding

optimizedbyotto.com

lemmyreader@lemmy.ml to Open Source@lemmy.mlEnglish · 1 year ago
message-square
14
link
fedilink
The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.\n
  • Hadriscus@lemm.ee
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    1 year ago

    I got into a rabbit hole and read the story of the SolarWinds attack. Even as a total layman, what a rollercoaster.

    • chebra@mstdn.io
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      @Hadriscus I wonder if anyone at SolarWinds or Mandiant would notice a 300ms delay. They didn’t even find it in June after the FBI contacted them.

      • Hadriscus@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Looks like passionate people working on open source projects are more reliable as watch dogs

    • lemmyreader@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Thanks

Open Source@lemmy.ml

opensource@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@lemmy.ml

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

  • Open Source Initiative
  • Free Software Foundation
  • Electronic Frontier Foundation
  • Software Freedom Conservancy
  • It’s FOSS
  • Android FOSS Apps Megathread

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !libre_culture@lemmy.ml
  • !libre_software@lemmy.ml
  • !libre_hardware@lemmy.ml
  • !linux@lemmy.ml
  • !technology@lemmy.ml

Community icon from opensource.org, but we are not affiliated with them.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 172 users / day
  • 1.49K users / week
  • 2.75K users / month
  • 10.5K users / 6 months
  • 1 local subscriber
  • 37.2K subscribers
  • 1.87K Posts
  • 27.3K Comments
  • Modlog
  • mods:
  • Evan@lemmy.ml
  • kevincox@lemmy.ml
  • CrypticCoffee@lemmy.ml
  • Lettuce eat lettuce@lemmy.ml
  • UI: unknown version
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org