this post was submitted on 31 Mar 2024
258 points (98.1% liked)

Open Source

31140 readers
318 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 35 points 7 months ago (2 children)

If anything it highlights how great open source actually is when it comes to security. People saw it and immediately flagged it.

[–] [email protected] 24 points 7 months ago (1 children)

I don't think this one counts as a big win to be honest It was just freakish luck

[–] [email protected] 13 points 7 months ago (2 children)

It's definitely freakish luck but at least it got found out. A closed source software would have gone through unnoticed.

[–] [email protected] 11 points 7 months ago

the fact that it was found by luck, not methodically, to me implies that there probably are other backdoors we didn't get lucky with.

[–] [email protected] 5 points 7 months ago

Or found out in corporate code review / pentest. We just don't know. I get that we want to say FOSS is great due to the "many eyes/shallow bugs" thing, but that didn't work for OpenSSL or log4j. The fact that it did now is great, but let's not get carried away. It was just pure luck.

[–] [email protected] 21 points 7 months ago (2 children)

Dude, the issue was found purely by coincidence, it very nearly made it through

[–] [email protected] 27 points 7 months ago (1 children)

Yes, but it didn’t. Has it made it through on closed software? Who knows?

[–] [email protected] 19 points 7 months ago (3 children)

My takeaway is more like: This one almost made it through and was caught by accident. How much more backdoors actually were not caught and made it through? I would bet some money on it being more than 0 :(

[–] [email protected] 2 points 7 months ago

Yep for sure. But open source at least let's you examine every part of the ecosystem.

No software is perfect even if all contributors have good intentions and do all due diligence.

Throw some malice and there is a chance something will get through.

[–] [email protected] 1 points 7 months ago

Im not sure why it being caught by accident is a factor here.

If devs knew what the pitfalls were before coding, there wouldn't be security risks in software.

Hackers do the same thing. They pen test, and if by chance they find something, they exploit it.

[–] [email protected] 1 points 7 months ago

Yes, probabky, but also might be possible to now find.

[–] [email protected] 9 points 7 months ago

Also this was a multi year effort that employed very complex knowledge. And still didn't get thru.

If it's multi year and very complex it's telling that this is what it takes. The bar is very high.