Verify the identity of developers
Verify the identity of developers
Posted Mar 30, 2024 17:04 UTC (Sat) by marcH (subscriber, #57642)In reply to: Verify the identity of developers by pizza
Parent article: A backdoor in xz
This already happened a while ago but that wasn't my main point. My main point is: how was 20% better compression enough to "lure" projects into adding some bad dependency? _This_ is when projects should "slow down" and take the time to weight all the pros and cons, including future maintenance headaches
https://cacm.acm.org/practice/surviving-software-dependen...
> The amount of collective effort to remove xz from production dwarfs the effort of maintaining xz. By multiple orders of magnitude.
This is comparing apples and oranges because it's not the same people. There's no "collective" either: each project should manage its dependencies independently.
I'm surprised that switching to a different compression is so expensive because many projects offer such a choice at configuration time which hints at comparable APIs.
> "maintained" doesn't mean it can be trusted.
Indeed but "unmaintained" cannot be trusted _for sure_. Same as testing: it can only "prove the existence of bugs, not their absence". Quality is not black or white.
> Meanwhile, as this mess demonstrates,
If anything, this mess demonstrated a lack of maintenance.
