you are viewing a single comment's thread
view the rest of the comments
[โ€“] 132 points 1 year ago (4 children)

Yup.
But in open source it CAN be noticed, by anyone determined enough to dig into its side effects.
Proprietary software? You file a regression bug that startup takes 500ms longer, and it might get looked at.

Also, backdoors that are discovered in open source software improve automated software auditing.

  • source
  • parent
  • hideshow 4 child comments
  • [โ€“] 25 points 1 year ago (1 child)

    The flaw also highlighted a social engineering exploit. Itโ€™s not the first time some vulnerability has entered open source software due to social pressure on the maintainer. Notably EventStream exploit.

    This is difficult to account for. You canโ€™t build automated tooling for social engineering exploits.

  • source
  • parent
  • hideshow 1 child comment
  • [โ€“] 6 points 1 year ago

    Yeah, you open a bug like that in proprietary software and it will immediately get rationalized away as having no business case to address, likely with a person with zero direct development responsibility writing a bs explanation like the small impact was due to a number of architectural changes.

    Speaking as someone with years of exposure to business managed issue handling.

  • source
  • parent