A backdoor in xz
A backdoor in xz
Posted Apr 2, 2024 16:12 UTC (Tue) by GNUtoo (guest, #61279)In reply to: A backdoor in xz by rra
Parent article: A backdoor in xz
The issue here is the side effects. For instance what would prevent companies from writing extremely used software with poor security track record and try to get money to fix things after the fact when the design is bad, or that even bigger foundations than the design is bad (use cases impossible to secure, etc).
And if it somehow works it could also make very secure software that go in conflict with freedom or other things we care about (like inclusiveness, making old hardware continue to work, etc).
A slightly better approach would be to look at the NLnet approach and somehow adapt it for improving security maintenance.
Micro-grants for small period of time are probably not ideal to fund long term maintenance, so that could probably be adapted/changed, along with the metrics to decide when not to pay (it's probably easier to look if a specific task is done than assert the usefulness of maintenance tasks), but the fact that highly competent people decide what to fund and not to fund and have a strategic vision for FLOSS is probably something that we need.
This could avoid the most problematic perverse incentives, and the cost here would probably be the subjectivity of the people that decide what to fund or not to fund, and here having diverse people could help but probably won't fix everything.
But at least it would be better than the other models mentioned here before.
