Big tech security
you are viewing a single comment's thread
view the rest of the comments
[–] 31 points 1 year ago (8 children)
  1. Write an open source malware
  2. Freely publish it everywhere because everyone assumes someone checked it, because it's open source, you know?
  3. ???
  4. Profit
  • source
  • parent
  • hideshow 8 child comments
  • [–] 1 point 1 year ago (6 children)

    That's the thing though if it's open source and 99.9% don't check that 0.1% checking it will be enough.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 1 year ago (2 children)

    The trouble with smaller open source software is that there's no 0.1% checking it. And from time to time a small projects becomes widely used and everyone assumes someone already checked it; it's a widely used open source software, after all.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 year ago

    I think most early users do check further than open source licenses. It's possible they'll add things later, but if they add after it has enough users we have significant number of users to have some people check. And if the user base is small then they're probably more involved, or are reading/modifying code for their use cases.

    Of course it's not foolproof, but it has worked for a long time because of things like that

  • source
  • parent
  • [–] 1 point 1 year ago* (1 child)

    By definition in order to have . 1% then the sample size must be greater than 1,000. The vast majority of open source projects will not get to this level.

  • source
  • parent
  • hideshow 1 child comment