GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    ✨buff dog himbo✨ (itsmeholland@mastodon.social)'s status on Sunday, 31-Mar-2024 08:23:25 JST ✨buff dog himbo✨ ✨buff dog himbo✨

    @astraleureka I'm sorry, I thought the entire point of "open source" was that it's vastly easier to audit than closed source/most proprietary software. Isn't the discovery of this backdoor a good thing, because it means the open source model is working? (To catch threats and weaknesses in a collaboratively developed system?)

    Maybe I'm underinformed, but if it took a long time to be discovered then maybe FOSS community needs to be more aggressive & thorough with auditing FOSS software. 🤷

    In conversation Sunday, 31-Mar-2024 08:23:25 JST from mastodon.social permalink
    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Wolf480pl (wolf480pl@mstdn.io)'s status on Sunday, 31-Mar-2024 08:24:11 JST Wolf480pl Wolf480pl
      in reply to

      @itsmeholland @astraleureka
      It's not that it took long to discover, it's that it took an incredibly lucky coincidence, and a mistake on the attacker's part.

      There could be 50 more backdoors like this that we don't know about and there's no reason for them to be caught.

      Part of the problem is that some parts of open-source software (eg. build scripts) are often hard to audit despite being open-source (this is fixable).

      Another part is insufficient amount of people wants to audit software.

      In conversation Sunday, 31-Mar-2024 08:24:11 JST permalink
      Haelwenn /элвэн/ :triskell: likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.