Kind reposts

 Repost

Reposted Terence Eden (@Edent@mastodon.social)
Post details
I wrote this ⬆️ a few years ago. As the fallout from the #XZ hack reverberates, expect to see people calling for a "real name" policy for contributors to critical infrastructure. But, as I explain, there are several practical problems with that. https://shkspr.mobi/blog/2021/02/whats-my-name-again/ That's before we get to the ethical and privacy issues. Oh, and making it *easier* for attackers to target named individuals.

 Repost

Reposted cathos (@cathos@merveilles.town)
Post details
Maintenance is more important than innovation. This xz debacle is a symptom of a system that prioritizes lots of things above maintenance. Take this as a reminder to rest, to mend things & pay attention to what needs mending in yourself. Do the radical thing of working slowly and making all things more whole.

 Repost

Reposted yossarian (1.3.6.1.4.1.55738) (@yossarian@infosec.exchange)
Post details
my only contribution to the xz discourse: absolutely none of the supply chain stuff we're currently doing, including the things i like, would have stopped this. the only things that can stop this are (1) compulsively treating all code as untrusted, and (2) way, way stronger capability checks and restrictions in running systems. (1) is economically infeasible (the world runs on free labor from OSS), and (2) has had only very limited practical success.

 Repost

Reposted Geoffrey Thomas (@geofft@mastodon.social)
Post details
@glyph @eb@social.coop I'm frustrated that big tech's efforts to increase core library security are "your project is too popular, you must use 2FA" and "the best reverse engineers in the world will find your bugs and put you on a 90 day disclosure deadline" and not "here is $100K/year and benefits to keep doing what you're doing at your own pace."

 Repost

Reposted Glyph (@glyph@mastodon.social)
Post details
@eb@social.coop I really hope that this causes an industry-wide reckoning with the common practice of letting your entire goddamn product rest on the shoulders of one overworked person having a slow mental health crisis without financially or operationally supporting them whatsoever. I want everyone who has an open source dependency to read this message https://www.mail-archive.com/xz-devel@tukaani.org/msg00567.html

 Repost

Reposted danielle 🏳️‍🌈 (@endocrimes@toot.cat)
Post details
It’s not surprising that a major security vulnerability is once again caused by maintainer burnout and someone stepping in to take over. We’ve all been talking about that risk for years. Sadly it’s also unsurprising that OSS teams still are going to need to plead with management to stay funded, and paid OSS maintainers will still do unpaid overtime to work with volunteers. 🙃.

 Repost

Reposted Rob Ricci :real: (@ricci@discuss.systems)
Post details
Hey, with people in the news getting sentenced to prison, facing the possibility of prison time, etc., just a reminder: it is not desirable, nor funny, that violence in prison (including sexual violence), be a part of someone's punishment. Even people you really, really do not like who have done really super bad things. It is to the United State's shame that violence in prison is part of our carceral system, and we should not celebrate it, ever. We should seek to eliminate it.

 Repost

Reposted The Seven Voyages Of Steve (@sinbad@mastodon.gamedev.place)
Post details
I feel like subscriptions have generally made software quality worse. There was an argument that having to make paid upgrades to generate revenue to pay salaries put pressure on companies to change things that didn’t need changing, just to get that upgrade money, and subs reflected the holistic task of careful maintenance better. But in practice what’s often happened is the subscription props up bad decisions on product direction, because subs have to keep paying either way.

 Repost

Reposted Eloy (@eloy@hsnl.social)
Post details
@noracodes@tenforward.social IMHO you should pay for open source if you are making a profit on it. Lots of companies are reselling proprietary software and are paying for licenses without having specific feature wishes for the software, they just pay for the maintenance.

 Repost

Reposted JimmyB (he/him) (@JimmyB@mas.to)
Post details
@aral@mastodon.ar.al My little lad had a bad leukaemia when he was 20 months - in 2002. He had care at Great Ormond St - I calculated at the time (I’m an accountant) at somewhere between £250k and £500k, entirely free to us. And he lived. The US families sometimes didn’t fare so well. After they’d drained all insurance & resources their kids often died of something entirely treatable. Folks need to think very hard before voting for either #Tories or #Labour. @nhsactivistrn

 Repost

Reposted Baldur Bjarnason (@baldur@toot.cafe)
Post details
I’ll let you in on a secret: I love sporadically updated weblogs. I subscribe to over 1200 feeds and most of them are sporadic or even technically “inactive”. Months often pass between updates It means that every post published was important to the writer Back in the days of snail mail, letters that began with “It’s been a while since I last wrote to you” were the ones people cherished the most You don’t need to post every day or even every week to have a blog that matters

 Repost

Reposted Miah Johnson (@miah@hachyderm.io)
Post details
Remember folks. When VC is funding Corporation that releases a Open Source project its only a matter of time until they take it back. Their goal is to get their product embedded into your organization and abuse you for free work in the hopes they can eventually sell their corporation and cash out. Its always good for them, and rarely good for you.

 Repost

Reposted Sara Safavi (@sara@hachyderm.io)
Post details
Attached: 1 image Ok I’m doin the thread I said I wanted to do last week. (feel free to mute unless you enjoy a little second-hand drama as a Monday morning treat) Attn #devrel people! Are you job hunting? Does this pic of search results look familiar? Have you ever seen a bunch of job postings like this from Canonical and thought “gee I should apply to one of these”? I’m here to tell you: IT’S A TRAP! 🧵

 Repost

Reposted SwiftOnSecurity (@SwiftOnSecurity@infosec.exchange)
Post details
Y’all realize everyone in Helpdesk at your job can just import your browser cookies into their machine remotely and browse your Facebook at their leisure, right? Like, you understand what Administrator means? It means unquestioned god from anywhere. It’s not your machine IT’S THEIRS. All you do, all your access, it’s stored to be stolen. Anything hackers can do to ruin your life, IT can do better.

 Repost

Reposted Ryan💋 (@ryanhoulihan@mastodon.social)
Post details
They’re children. And their government is keeping them from doctors who practice a type of medicine that cures suicidal ideation at near miracle rates. If those kids do find relief, it'll be via their parents paying exorbitant out of pocket costs or by covertly ordering those drugs online with cryptocurrencies from sketchy overseas labs. Please don't play the Harry Potter video games and it defend it by saying they brought *you* childhood joy. https://www.thepinknews.com/2024/03/12/trans-puberty-blockers-nhs-england-prescribe-gender-affirming-healthcare/

 Repost

Reposted Thomas 🔭✨ (@thomasfuchs@hachyderm.io)
Post details
“But AI is cheap!” It’s not, it has horrendous hardware, server housing and water and power requirements; it’s just that VCs are financing it now so you get in on the hype and later they will charge you rent and it will cost you way more—with inferior results—than, you know, hiring the writers and artists it’s stealing from, but those will be gone by then.