Sujet : Re: OT: Linix goes politics
De : blockedofcourse (at) *nospam* foo.invalid (Don Y)
Groupes : sci.electronics.designDate : 26. Oct 2024, 19:15:45
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <vfjbks$3qpod$1@dont-email.me>
References : 1 2 3 4
User-Agent : Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.2.2
On 10/26/2024 6:18 AM, Lasse Langwadt wrote:
And to some extend it also protects Russian contributors from being the target of being forced to add "bad things"
The problem with FOSS is the naive belief that "lots of eyes"
looking at the code *will* discover errors, bugs, etc. This
is just wishful thinking.
From "KLEE: Unassisted and Automatic Generation of High-Coverage
Tests for Complex Systems Programs":
"We also used KLEE as a bug finding tool, applying it to 452
applications (over 430K total lines of code), where it found
56 serious bugs, including three in COREUTILS that had been
---> missed for over 15 years. Finally, we used KLEE to crosscheck
purportedly identical BUSYBOX and COREUTILS utilities, finding
functional correctness errors and a myriad of inconsistencies."
So, folks have been looking at that code for "15 years" and still
didn't notice the bugs?
The failure is in thinking that someone ELSE will have found the bugs
and taken action on correcting them.
A "bad actor's" actions are, thus, largely innoculated from discovery.
And, as there is no easy way of tracking down who/what may have
already incorporated them, no easy way to "recall" those defective
products. (closed source would have such a provision as the owner
of the source will likely know which products contain which bits
of code)