GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Yellow Flag (wpalant@infosec.exchange)'s status on Thursday, 19-Oct-2023 23:10:27 JSTYellow FlagYellow Flag

    The Ubuntu debacle just shows that quality of localization is an underappreciated problem. For most projects, there are only a handful languages with enough contributors to catch the most glaring issues. And what do you do about the rest of them?

    Even without malicious contributors, translation issues are common. There are too literal translations, translations missing the context and your regular translation mistakes. But I’ve also seen bogus automated translations being submitted way too often.

    And that isn’t only an issue with open source projects that rely on volunteer contributors. Some of the worst translations I’ve seen came from translation agencies, even those promising to have translation checks in place. Presumably, they pay employees for quantity, not quality. And bad translations are rarely noticed, so there are no consequences.

    Back in the day I’ve been juggling 40+ languages, reviewing changes and attempting to recognize translation issues without speaking the language. It was a time-consuming and complicated job. I didn’t like doing it, but at least I would definitely have recognized malicious submissions like the ones Ubuntu tripped over.

    Most projects barely review translations or skip reviews completely. Instead, they rely on end users to report issues, which almost never happens. Worse yet: it is very typical to allow HTML injection via translations, so malicious translations can cause real security trouble.

    https://www.bleepingcomputer.com/news/security/ubuntu-discovers-hate-speech-in-release-2310-how-to-upgrade/

    In conversationThursday, 19-Oct-2023 23:10:27 JST from infosec.exchangepermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.