{"id":11486,"date":"2024-07-19T20:24:30","date_gmt":"2024-07-20T03:24:30","guid":{"rendered":"https:\/\/mattfife.com\/?p=11486"},"modified":"2024-12-31T21:24:33","modified_gmt":"2025-01-01T04:24:33","slug":"open-source-has-some-big-questions-ahead","status":"publish","type":"post","link":"https:\/\/mattfife.com\/?p=11486","title":{"rendered":"Open Source has some big questions ahead"},"content":{"rendered":"\n<p>There&#8217;s no doubt that open source software makes up the majority of the world&#8217;s internet services. However, some recent, and not so recent problems are starting to shine the light on some of the problems facing the open source communities.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Malicious maintainers and contributors &#8211; xz compression backdoor that went for an amazingly long time before it was detected. The backdoor was added by a contributor Jia Tan who had been making contributions for 2 years. <a href=\"https:\/\/thenewstack.io\/linux-xz-backdoor-damage-could-be-greater-than-feared\/\" data-type=\"link\" data-id=\"https:\/\/thenewstack.io\/linux-xz-backdoor-damage-could-be-greater-than-feared\/\">The level of obfuscation and sophistication was unprecedented. It was only discovered by a very astute senior Microsoft engineer<\/a>.<\/li>\n\n\n\n<li><a href=\"https:\/\/arstechnica.com\/security\/2024\/05\/ssh-backdoor-has-infected-400000-linux-servers-over-15-years-and-keeps-on-spreading\/\" data-type=\"link\" data-id=\"https:\/\/arstechnica.com\/security\/2024\/05\/ssh-backdoor-has-infected-400000-linux-servers-over-15-years-and-keeps-on-spreading\/\">Hacking of open source maintainers\/distro servers<\/a> &#8211; Kernel.org was infected and&nbsp;<a href=\"https:\/\/www.theregister.com\/2011\/08\/31\/linux_kernel_security_breach\/\">came to light<\/a>&nbsp;in 2011, when kernel maintainers revealed that 448 accounts had been compromised after attackers gained root system access to servers connected to the domain. There&#8217;s no evidence source was changed, but it just as easily could have.<\/li>\n\n\n\n<li>Open source burnout &#8211; The <a href=\"https:\/\/jyn.dev\/the-rust-project-has-a-burnout-problem\/\" data-type=\"link\" data-id=\"https:\/\/jyn.dev\/the-rust-project-has-a-burnout-problem\/\">burnout levels among Rust developers spawned an interesting article<\/a> (<a href=\"https:\/\/www.theregister.com\/AMP\/2024\/01\/22\/rust_project_burnout\/\" data-type=\"link\" data-id=\"https:\/\/www.theregister.com\/AMP\/2024\/01\/22\/rust_project_burnout\/\">and another<\/a>) that really speaks to general burnout problems. Honestly, this is just one more example of <a href=\"https:\/\/mattfife.com\/?p=6198\" data-type=\"link\" data-id=\"https:\/\/mattfife.com\/?p=6198\">why &#8216;passion&#8217; jobs are bad for you<\/a> and what you really want is a <a href=\"https:\/\/mattfife.com\/?p=10247\" data-type=\"link\" data-id=\"https:\/\/mattfife.com\/?p=10247\">job you work 8-5 and then unplug from completely<\/a>.<\/li>\n<\/ol>\n\n\n\n<p>That&#8217;s by no means the entire list. Open source is now the backbone of our modern computer infrastructure &#8211; and is under attacks from more threats than it has ever faced. From ransomware hacker groups, for-profit botnets, all the way to the increasing occurrences of state-sponsored hackers\/infiltrators. The attacks and manipulations can now be combined with AI actors and code to create nearly limitless attack vectors and attackers. <\/p>\n\n\n\n<p>Combine this with unpaid contributors that need to police themselves and this represents some serious threats.<\/p>\n\n\n\n<p>The New Stack has a <a href=\"https:\/\/thenewstack.io\/open-source-is-at-a-crossroads\/\" data-type=\"link\" data-id=\"https:\/\/thenewstack.io\/open-source-is-at-a-crossroads\/\">great article describing the new challenges facing open source development<\/a>.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s no doubt that open source software makes up the majority of the world&#8217;s internet services. However, some recent, and not so recent problems are starting to shine the light on some of the problems facing the open source communities. That&#8217;s by no means the entire list. Open source is now the backbone of our modern computer infrastructure &#8211; and is under attacks from more threats than it has ever faced. From ransomware hacker groups, for-profit botnets, all the way&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/mattfife.com\/?p=11486\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[28,9],"tags":[],"class_list":["post-11486","post","type-post","status-publish","format-standard","hentry","category-ai","category-cool"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4WECr-2Zg","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/11486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11486"}],"version-history":[{"count":2,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/11486\/revisions"}],"predecessor-version":[{"id":12942,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/11486\/revisions\/12942"}],"wp:attachment":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}