Great that we'll finally get state-sponsored open-source development :D
Great that we'll finally get state-sponsored open-source development :D
At first you'd get emails from like, pewdiepie@outlook.com instead of pewdiepie@gmail.com. But you could usually check the YouTube about page to find the real business email and compare it.
So eventually the scammers started creating their own YouTube channels. They'd steal videos from other channels and reupload them, then get bots to add views and subscribers. Now the email matches the one on their channel.
One remaining tell tended to be the lack of comments, but it's been a few years since I had a game that was getting those kind of emails, and I wouldn't be surprised if they have good fake video comments these days too.
Here are a couple of examples of fake channels I have saved from a few years ago:
I think I have a good eye for these things and worryingly they just look like the normal low effort youtube chaff but I wouldn't have thought fake/scamming.
- Weird view counts. Strangely consistent, random sudden dropoff to near zero views, etc.
- No voice commentary. Can't steal videos from different channels if your "voice" changes I guess.
- A whole set of videos uploaded at once. This was more obvious when the linked channels were still active since you'd see like two rows of "2 days ago", then a bunch "1 week ago", then a bunch "3 weeks ago" etc.
- Social media etc links either missing or super basic.
- Few and generic comments vs. amount of views.
- Channel description generic, sometimes copied from other channels.
- The two I linked haven't done it, but some I saw were uploading long-plays of games split into many parts, I guess to easily pad out their total number of videos.
Another thing they were doing at the time, was changing their channel name and banner after a few weeks or months and then emailing again pretending to be a whole new channel. Easy to spot if you still had the old link and it was the same.
The second one I linked also mysteriously turns Russian if you scroll back far enough. Bit unusual for someone with their location listed as USA.
At least 2 rival legal Jurisdictions/Alliances/Spheres
At least 2 rival state intelligence Agencies per Sphere
At least 2 rival corporations per Sphere
TOTAL: 2*(2+2) = 8
Widely used OSS projects are contested spheres of collaboration.Maybe just ignore Hostile, try to find enough competitors to ensure at least one will review, require a couple unaligneds and friendlies, and then consider “too friendly” to be the same as your own country.
Like from a US point of view, if the US and the UK agree on something… I mean, that only counts as one point, right? We are too close. But if like half of the EU and India agree, there’s enough competing self-interest to let it through (keeping in mind that it is all open source, nobody wants to be caught doing something sketchy). And if China, the US, and any other non-5-eyes country agree on something, it must be fine. (I picked these countries because I think they are pretty uncontroversial, I’m definitely not going to try and list who’d be in the hostile group, that’s just asking for unproductive political squabbling).
Multiple possible paths, no veto.
But I have no idea how to fix the problem of: some countries look more or less trustworthy from others’ point of view; I think we can easily suggest a plan from the US point of view, but I have no idea how to get everyone to agree on what the actual state of a single source code repository is, since commits have dependencies. Maybe it needs to be more like a package manager.
* Bruce Schneier writing about the NSA: https://www.theguardian.com/commentisfree/2013/sep/05/govern...
* https://en.wikipedia.org/wiki/Bullrun_(decryption_program)
Suspicions are very old: "Report of FBI back door roils OpenBSD community" (2010)- https://www.cnet.com/news/privacy/report-of-fbi-back-door-ro...
OpenSSF members: https://openssf.org/about/members
2021, $10MM, https://openssf.org/press-release/2021/10/13/open-source-sec...
> Financial commitments from Premier members include Amazon, Cisco, Dell Technologies, Ericsson, Facebook, Fidelity, GitHub, Google, IBM, Intel, JPMorgan Chase, Microsoft, Morgan Stanley, Oracle, Red Hat, Snyk, and VMware. Additional commitments come from General members Aiven, Anchore, Apiiro, AuriStor, Codethink, Cybertrust Japan, Deepfence, Devgistics, DTCC, GitLab, Goldman Sachs, JFrog, Nutanix, StackHawk, Tencent, TideLift, and Wind River.
2022, $5MM for 10,000 OSS projects, https://openssf.org/press-release/2022/02/01/openssf-announc...
> Following a meeting with government and industry leaders at the White House, OpenSSF is excited to announce the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated security testing. Microsoft and Google are supporting the Alpha-Omega Project with an initial investment of $5 million.. “Omega” will identify at least 10,000 widely deployed OSS projects where it can apply automated security analysis, scoring, and remediation guidance to their open source maintainer communities.
2022+2023, $4.8MM disbursed to ten (not 10K?) OSS projects, https://openssf.org/blog/2024/02/16/alpha-omega-2023-annual-... & https://openssf.org/blog/2022/12/14/alpha-omega-project-firs...
Eclipse $1,150,000
NodeJS $579,000
Rust $920,000
Homebrew $175,000
jQuery $350,000
OpenSSL $127,968
OpenRefactory $50,000
Prossimo (ISRG) $530,000
Python $400,000
Linux Kernel $620,000- DBeaver (very widely used to connect to production databases)
- STM32Cube IDE (for embedded development in all sorts of devices)
But protecting dev environments makes sense. Think how many supply chains an attacker can compromise if they can get at random dumb developer machines...
Any implementation would be vulnerable.
This already happened.
*cough* React *cough*
Ask yourself, why would rogue AI and famous human impersonator Mark (short for Mark Zero Ai) Zuckerberg make an open-source UI library for everyone to use? /tinfoil
That said, who knows, maybe it already happened.