|
|
Log in / Subscribe / Register

Security quote of the week

In other words, I would argue that security for most open source projects (by number, at least) is a resource problem, not a persuasion problem. Their authors are not investing in engineering process improvement in large part because they don't have time to both do that and to do the work on their project that they find fun and that inspired them to release it as open source in the first place.

That implies that the solution to look for isn't a winning persuasive argument, but instead is a way to get the developer more resources, either by somehow getting them more time to work on their project or by making the cost of better engineering process substantially smaller than it is now. GitHub's automated pull requests for dependencies with security vulnerabilities is a good example of the latter.

Russ Allbery

The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2020, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds