xz has shown how a dependence on unpaid volunteers can cause major problems
twitter.com
twitter.com
I'm very frustrated by all of the "this has shown how fragile FOSS is" hot takes I see appearing. I think it has shown us how awesome FOSS is: If this were all closed source software, chances are we'd never have known about the issue, nor would an entire community now be able to have an open conversation about how to mitigate it in the future, applying their combined brain power to the problem.
And there's a fair amount of obvious steps to take now:
- Re-visit the pro/con of anonymous contributions. Re-visit identity verification. Maybe do a SPDX-like thing for governance/contribution work flow mechanisms for project to report how they work and what stance they take, to allow downstreams to risk-rate. Some projects will very much want to continue to allow anonymous contribs for excellent reasons, and that's fine.
- Phase out build and module systems that drive published tarballs differing from repo tags.
- Have distributions verify that tarball contents match repo tags on import of new versions. Yes, this requires that projects have a repository that is reachable online. I think for critical SW that's OK.
- Don't accept build systems that silently disable security features when dependencies are unavailable. Not building a security feature should always be a decision point and manual opt-out.
- Come up with better metrics for maintainer burnout and heartbeat signals.
Moreover, identities on the internet are fairly easy for motivated individuals (or moneyed organizations) to fake.
Finally, who's going to build and maintain everything you've proposed?
Companies need to sponsor work done on FOSS. FOSS maintainers need to reject requests that don't benefit the broadest possible audience unless they're receiving a sponsorship to do it. And that's just at a bare minimum. Without aligned incentives, I personally think any attempts at fixing things will be ineffective.
I'm adamant on thinking that first and foremost there is a smorgasbord of crazy designs at play: a build system so messy you can slide in binary injections, an init system with dependencies, an execution chain where you can easily rewrite whatever else's functions. It's fine if somewhere down the drain someone churns garbage, the priority has to be that it should be easy to detect it, I find that it's dumb and sub-par to rely on a fragmented and laggy circle of reviews, pre-releases and releases, (yeah, everything handled by thankless and lone volunteers makes it worse), for protecting our systems.
It always made me wonder how many such cases don't get caught, since code review isn't consistently thorough.
Also, being unpaid implies that one has to do other things to get money, so that leaves limited time and energy to put towards the free project. So when pressure starts coming in from outside, the maintainer(s) don’t have time for real reviews and accept code without fully vetting it.
If maintaining this code was part of a paid day job, there would be more time, energy, and incentive to review it more completely.
American programming at least is centered around a few hubs where the programmers make great wages. They work for companies which make a lot, lot of money. Much of the complaining is about professional programmers who do OSS as a hobby.
So none of the parties are lacking in resources. And no one is being coerced.
I bring this up because some problems are about exploitation and coercion. Then the soft (unreliable) solution is about morality (don’t exploit), while the hard (reliable) solution is about laws and law enforcement.
But Ethics doesn’t seem to be the appropriate domain. And not Philosophy in general.
I’ve wondered for years now: where are the economists? This is a problem of assigning resources. It’s a problem of incentives. It’s a problem of dependable and proper bus-factored maintenance. Isn’t this a kind of problem that they are trained to solve? Concretely: you have an unreliable (volunteer, small) resource and large entities that rely on it. How do you bolster that resource?
And I don’t mean in the vulgar sense of “give X and Y more money”. I mean: the current status quo is apparently unreliable, so how should things be organized in order to promote more reliability? That does not have to involve money.
This isn’t some academic exercise. Real money is apparently on the line, indirectly. The stakeholders are powerful. Why can’t the relevant professionals solve this?
Don’t get me wrong. I’m the kind of annoying person who believes that a lot of economics is mostly about propaganda. But how is this not a problem that economists can solve?
In this case at least reading through the timeline it sounds like the bulk of the discovery of the vulnerability came through paid folks though.
"shoulda put a ring on it"
Microsoft are being the twats here, not the ffmpeg devs
To be honest it has also shown that it wasn't all too wise at all to introduce a completely needless dependency on a rube-goldberg piece of software in what was otherwise something created by security-minded people.
openbsd -> openssh
vs: systemd Linux distros -> openssh -> (lib)systemd -> endless potential venues for backdoors (oh, look, we just found one)
I'd give Theo de Raadt a thumb up and Poettering a thumb down here, again.Seriousy, why the fuck did Linux have to be polluted with that gigantic squid that systemd is, throwing is tentacles about just everywhere. I know, I know, there are distros out there not using systemd but they're rare.
I find it very weird that so many people keep downplaying the role of libsystemd here (makes me wonder what their agenda is).
Poettering didn't talk distros into patching openssh to call libsystemd's sd_notify(), and if you look at the PR for dropping libsystemd's linking of liblzma you can also see him take a stance against the dependency there.
For some reason, people want to only interact with text on a screen. Who's taking this crypto? Who cares? Who's managing this website or forum? Who cares? Who's maintaining this software package? Who cares?
We're semi-hairless apes with brains adapted to living in social groups of 150-300 people, and now we have placed so many of the daily transactions of life into this system that could theoretically make the social group the size of humanity. We've fooled ourselves into thinking that if we just make anonymity a feature of the system, bad actors can't hurt us.
If this had happened and someone's livelihood or next promotion was on the line, the amount of forensics and publicity would likely have been so much less open than it has been in a product driven by community and done in the open.
I knew people would be reactionary, but not "unwind most of the free software movement ideals" reactionary.
1. After $EVENT, we are in a horrible state of affairs. Something must be done.
2. $THING is something.
3. Therefore, we must do $THING.
(We don't examine whether $THING could've prevented or alleviated $EVENT - there is no time.)