86thumbs
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
lemmyreader@lemmy.ml to Open Source@lemmy.mlEnglish · 1 year ago

Heartbleed and XZ Backdoor Learnings: Open Source Infrastructure Can Be Improved Efficiently With Moderate Funding

optimizedbyotto.com

external-link
message-square
14
fedilink
96
external-link

Heartbleed and XZ Backdoor Learnings: Open Source Infrastructure Can Be Improved Efficiently With Moderate Funding

optimizedbyotto.com

lemmyreader@lemmy.ml to Open Source@lemmy.mlEnglish · 1 year ago
message-square
14
fedilink
The XZ Utils backdoor, discovered last week, and the Heartbleed security vulnerability ten years ago, share the same ultimate root cause. Both of them, and in fact all critical infrastructure open source projects, should be fixed with the same solution: ensure baseline funding for proper open source maintenance.\n
  • Hadriscus@lemm.ee
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    1 year ago

    I got into a rabbit hole and read the story of the SolarWinds attack. Even as a total layman, what a rollercoaster.

    • lemmyreader@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Thanks

    • chebra@mstdn.io
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      @Hadriscus I wonder if anyone at SolarWinds or Mandiant would notice a 300ms delay. They didn’t even find it in June after the FBI contacted them.

      • Hadriscus@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Looks like passionate people working on open source projects are more reliable as watch dogs

Open Source@lemmy.ml

opensource@lemmy.ml

remote_follow_modal_title

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@lemmy.ml

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

  • Open Source Initiative
  • Free Software Foundation
  • Electronic Frontier Foundation
  • Software Freedom Conservancy
  • It’s FOSS
  • Android FOSS Apps Megathread

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • !libre_culture@lemmy.ml
  • !libre_software@lemmy.ml
  • !libre_hardware@lemmy.ml
  • !linux@lemmy.ml
  • !technology@lemmy.ml

Community icon from opensource.org, but we are not affiliated with them.

community_visibility: public
globe

public_blurb

  • 478 users / day
  • 1.2K users / week
  • 2.93K users / month
  • 10.4K users / 6 months
  • number_of_local_subscribers
  • 38.6K subscribers
  • 2.29K Posts
  • 36.3K Comments
  • Modlog
  • mods:
  • Evan@lemmy.ml
  • kevincox@lemmy.ml
  • CrypticCoffee@lemmy.ml
  • Lettuce eat lettuce@lemmy.ml
  • UI: unknown version
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org