And it's not an isolated case, this happens pretty much always when some issues attracts attention on GH.
Can't we respect the project and give the people there space to work, and leave the peanut gallery commenting to reddit/hn/twitter/whatev.
And it's not an isolated case, this happens pretty much always when some issues attracts attention on GH.
Can't we respect the project and give the people there space to work, and leave the peanut gallery commenting to reddit/hn/twitter/whatev.
What are you sitting on, if not an arm chair? We all agree that the xz attack was of unparalleled sophistication and complexity, spread carefully over years, funded by a State. Many people were taken in so how is it helpful to pile on Jia Tan's primary victims?
> but calls to safe_fprintf were replaced with calls to the unsafe fprintf. The diff doesn't make this obvious due to the removal of a newline in a parameter list.
It wasn't noticed because it was specifically designed not to be obvious.
Anyone who has maintained large/complex software like this knows that name recognition is worth a ton, and it kind of has to be that way. It's just not practical at all to scrutinize every commit/change as though the committer is an adversary, and particularly when you know the person it is not a reasonable ask. I would bet the truth is basically "yes, we knew him so it didn't get full scrutiny," and honestly that's an honest (but hard to give) answer.
I do hope (perhaps naively) that this (security code reviews) is something AI can get really good at in the future, because that would be a real value add IMHO.
It's like Where's Wal(do|ly): once you know where to look, it's obvious, but if you don't even know you're supposed to be looking for it, you may never find it
Sure, that's not how it's SUPPOSED to happen, but I'll eat my hat if at least 95% of people who've approved a PR at some point couldn't have been walked down that path by a dedicated attacker over time. Hopefully this has been enough of a jolt to make that less likely the next time someone tries it.
People often cite death and taxes as the only certainties in life-- we could easily include human fallibility.
What was it ... 80% of aviation accidents due human error?
In the years I worked as a nightclub bouncer, dozens or hundreds of people would try to fool me every night... and sometimes they did! I had a lot of experience foiling them, but they had a lot more time on their hands to scheme whatever thing they were scheming than I had to pay attention to them, individually.
As people pointed out, this was a technically simple attack-- the meat of the attack was psychological and emotional. In practice, particularly smart people are more susceptible to attacks like this because they subconsciously assume they'll catch everything that comes at them, and make a lot of assumptions about the attack vectors of problems based on what they're good at, like the classic XKCD about cryptography vs a wrench.
It would offer a good solution, and one that would scale.-
(Until, of course, the AI systems themselves become compromised or weaponized ...
But that is a few arms race cycles away yet.-
Sometimes you gamble and lose. The bank doesn’t care that “well there was a good chance I was going to be fine” when it comes time to pay your mortgage.
“But I’m the only one that knows the floor plan!” doesn’t quite cut it. Exit the premises and get some therapy.
so akcheually some people are sitting on a block of concrete!
theorizing that it was wrong to merge in itself is not victim blaming. but of course piling up in GH discussions and issues unconstructively, and just expressing opinions is bullying.
Raising competent empathic well balanced individuals is difficult, to say the least. And it’s not like the so called world leader elites really show they are some paragons of these traits.
So I say they are getting exactly what they wanted to get.
This is exactly the problem. If you want your resort be vandalized, build a nice road to it.
And some orgs are even eager to fuel this with things like Hacktoberfest.
Maintainers can 'lock down' the issue to just projects members, but that's very much an after-the-fact thing.
So, they have comment minimization by assigned moderators. Or you can just delete / edit comments and issues. Obviously not as powerful as a pre-screening queue. Less work tho!
PS. And, for some people it might undoubtedly be *all* their "social" ...I guess the argument for it is that it lets people easily "get involved"? Seems like there's some merit to making it easy for users to leave feedback. Maybe thumbs-up or thumbs-down on an issue really is valuable feedback in some situations. I'm torn between saying the social features are bad because they lower the barrier for low quality engagement, and saying that even low quality engagement can lead to valuable insights.
https://web.archive.org/web/20081216011059/https://github.co...
Which changed to "social coding" later:
https://web.archive.org/web/20110217073759/https://github.co...
"social coding" eventually moved to the page title, and disappeared from the page itself:
https://web.archive.org/web/20120202143623/https://github.co...
"Social code hosting" and "social coding" are not on the front page anymore, but they definitely kept all the social features.