• magic_lobster_party@kbin.run
    link
    fedilink
    arrow-up
    35
    arrow-down
    1
    ·
    8 months ago

    Closed source projects are also subject to bullying.

    Project managers pressuring developers to implement half assed features in an afternoon because sales sold a feature that doesn’t exist and have signed a deal to have it delivered tomorrow morning. Who has time to review the code and ensure there are no SQL injection vulnerabilities? Just push it!

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    2
    ·
    edit-2
    8 months ago

    Three years ago, #FDroid had a similar kind of attempt as the #xz #backdoor. A new contributor submitted a merge request to improve the search, which was oft requested but the maintainers hadn’t found time to work on. There was also pressure from other random accounts to merge it. In the end, it became clear that it added a #SQLinjection #vuln. In this case, we managed to catch it before it was merged. Since similar tactics were used, I think its relevant now

    https://social.librem.one/@eighthave/112194828562355097

    Steiner wrote this week that the original coder deleted their account as soon as F-Droid’s maintainers attempted to review the code, and that he thinks that the user’s behavior, as well as “all the attention from random new accounts” has led him to believe “it could be a deliberate attempt to insert the vuln.”

    This is pretty significant: the first documented case of these tactics being used to insert a vulnerability, apart from xz. So probably the same actors have been trying this on multiple projects.

    I hope other maintainers who have experienced similar pressure tactics will come forward, even if they’re not aware of any backdoors. For any project where this has taken place and the code was merged, the code and commit history needs to be audited.

  • nutomic@lemmy.ml
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    8 months ago

    Im a former contributor to F-Droid with various merged pull requests. Looking at the indicated pull request I really doubt that it was an intentional attack. First of all its easy to forget for a new developer to escape SQL parameters, and the docs dont even mention a risk of SQL injection attacks. And of the users pushing for the PR to be merged, one is a long-time F-Droid contributor, and the other also looks like a real human with many contributions in other repos, so no sockpuppets in sight.

    It simply looks like standard open source behaviour, for better or for worse. A new user makes a contribution for a highly demanded feature, and users want it to get merged as soon as possible. Maintainers are discussing the big picture of the change and want to avoid breaking changes, without getting into code review yet. The new contributor seems unwilling to make any design changes to his PR, and gets frustrated that it doesnt get merged as is. The potential vulnerability is only noticed half a year after the PR was opened, at which point it was already de facto abandoned. So not an attack, but simply a developer who is new to open source and doesnt understand how the process works.

  • Aquila
    link
    fedilink
    arrow-up
    9
    ·
    8 months ago

    People will always be a vulnerability. That goes for physical security too.

  • onlinepersona@programming.dev
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    4
    ·
    8 months ago

    This is why I dislike people badgering the Lemmy devs for whatever they feel is currently important to them. “Ermagerd, it’s GDPR violation!!!1!!!1!!111”. Or people flaming the developer(s) of Mastodon for not implementing quoting “Twitter has it, so you must implement it for people coming from Twitter!”. And so on and so forth.

    We should all be doing what we can to help opensource developers and that also means calling out shitty behavior from its users or external contributors towards maintainers. Maintainers aren’t messiahs and just humans too, so them being cunts isn’t nice either (obviously), but I have much more understanding for their behavior sometimes. Especially when hundreds of entitled keyboard warriors attack maintainers and write blog articles about them (like wedistribute.org) demanding stuff be done their way.

    Maintainers also need better tools and features from giants like github to shutdown annoying users on their projects. Github’s “social” features need a lot of work. It’s not possible to have moderators (human or automatic provided by the platform) for projects for example. Instead maintainers have to read all the bullshit demands people have expressed with no filter.

    When the maintainer of actix stepped down due to harrassment by rust purists (he used the unsafe keyword) and there was an outpour of support, it felt so ridiculously fake. It had been going on for a while and there were reddit threads, blog posts, tweets, and other cries on social media by the purists that amounted to harrassment, but only when the maintainer stepped down did people affected react.

    I’m by far no angel, but at least my claim to fame isn’t abusing maintainers enough for them to quit.

    CC BY-NC-SA 4.0

    • magic_lobster_party@kbin.run
      link
      fedilink
      arrow-up
      5
      ·
      8 months ago

      At least with Lemmy and Kbin, if you have a feature you want to have implemented you always have the option to fork and host your own instance. Maybe not ideal for everyone, but the option is there.

      This has happened to Kbin with the fork Mbin due to inactivity from the main Kbin maintainer. It’s not ideal that a project goes stale, but life happens and we must respect that.

    • delirious_owl@discuss.online
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      8 months ago

      what? The community finds issues like the XZ one, and the devs say they won’t be able to fix it because they have less important things to work on instead.

      Its not bullying the devs to point out to them the massive GDPR violations of their software and to give them hell for sweeping it under the rug and literally say they won’t do anything to fix it.

      I believe this is the article you refer to

      https://wedistribute.org/2024/03/lemmy-image-problem/

      Its pretty spot-on.

      • onlinepersona@programming.dev
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        2
        ·
        8 months ago

        Its not bullying the devs to point out to them the massive GDPR violations of their software and to give them hell for sweeping it under the rug and literally say they won’t do anything to fix it.

        It is. The data is in the DB and filesystem and can be manually removed. Having a button that does it is a convenience. It’s the instance operator who will be in trouble if they don’t. The code is provided with a license that literally says

        THERE IS NO WARRANTY FOR THE PROGRAM

        IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES

        You are using it and/or hosting it at your own peril.

        And the devs said this

        So there is no legal nor moral responsibility to implement any features that you personally want. However you are free to:

        • Implement the feature yourself
        • Pay someone else to implement it
        • Stop using Lemmy and use one of countless alternative platforms instead

        Then the fediverse erupted and made blog posts, toots, @'ed the devs directly, etc.

        Also Open Source Maintainers Owe You Nothing. Interalise that. They owe use fucking nothing - except maybe the respect we show them and if none is shown, they don’t owe any respect back.

        Anti Commercial AI thingy

        CC BY-NC-SA 4.0

  • rollingflower@lemmy.kde.social
    link
    fedilink
    arrow-up
    8
    arrow-down
    2
    ·
    8 months ago

    If something is free Software, there is no supply chain. There is no security and no guarantees. For sure all these volunteers are mostly trying to deliver a good product, but they are offering free labor.

    Saying “bullying is bad for the outcome of the product” is kinda ironic, as “not paying these devs” also is bad. This is just the extreme form

    • pmk@lemmy.sdf.org
      link
      fedilink
      arrow-up
      8
      ·
      8 months ago

      Maybe some inspiration from how OpenBSD handles users requesting features.
      “No one deserves anything from us. /…/ The developers in this project do the best they can”
      or
      “If you expected any of us to reply as if we are contractors or your employees, you came to the wrong place.”

        • Star
          link
          fedilink
          arrow-up
          2
          ·
          8 months ago

          Of course, but you missed part of the point. Open source devs are providing code for free, the least the user can do is provide bug reports without rude language/demands.

          • delirious_owl@discuss.online
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            8 months ago

            I agree. But that goes both ways. Devs shouldn’t be rude to contributors of bug reports. And the Lemmy devs have been real assholes to most of their contributos.

            Theres a reason they have this reputation.