We are now at t+26h. Please compare how much we knew about the xz-attack after less than a day with what we know about the chain of events of giant outage yesterday.

If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    134
    arrow-down
    3
    ·
    4 months ago

    If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

    No we won’t. I refer to HeartBleed, Log4J, and Eternal Blue, and Solar winds. None of those affected applications have been banned and never will. Congress bans are based on political aspects not technical ones.

    Huawei ban is because of the ties to China, kaspersky was banned because of Russian ties.

    • Artyom@lemm.ee
      link
      fedilink
      arrow-up
      24
      ·
      4 months ago

      Security vulnerabilities are a big deal in the tech world, but no one really cares outside of that. The CrowdStrike bug was big because it was user-facing and shut down systems. The truth is we haven’t seen any user-facing bugs from open source software to compare CrowdStrike to.

    • uis@lemm.eeOP
      link
      fedilink
      arrow-up
      17
      arrow-down
      24
      ·
      edit-2
      4 months ago

      I refer to HeartBleed, Log4J, and Eternal Blue, and Solar winds.

      None of those took down half of world. “something similar” in context of cyberstrike means something like cyberstrike.

      Congress bans are based on political aspects not technical ones.

      You realize that any policy is political by its nature? Including any bans?

      • HubertManne@moist.catsweat.com
        link
        fedilink
        arrow-up
        14
        ·
        4 months ago

        Solar winds was a pretty big deal and I would say bigger than the current thing. Although that just strengthens your argument given orion was not open source and they were hacked and the malevolent code was injected into their system essentially internally and had been tested for a bit by the hackers which if their code had been viewable might have allowed it to be caught before becoming such a big deal.

        • uis@lemm.eeOP
          link
          fedilink
          arrow-up
          3
          arrow-down
          12
          ·
          4 months ago

          And? We are not talking about malware here.

          Although I guess congress probably did ban Wannacry.