• 0 Posts
  • 342 Comments
Joined 1 year ago
cake
Cake day: June 15th, 2023

help-circle






  • It highlighted some pretty glaring weaknesses in OSS as well. Over worked maintainers, unvetted contributers, etc etc.

    The XZ thing seems like we got “lucky” more than anything. But that type of attack may have been successful already or in progress elsewhere. It’s not like people are auditing every line of every open source tool/library. It takes really talented devs and researchers to truly audit code.

    I mean, I certainly couldn’t do it for anything semi advanced, super clever, or obfuscated the way the XZ thing was.

    But I agree, that the fact we could audit it at all is a plus. The flip side is: an unvetted bad actor was able to publish these changes because of the nature of open source. I’m not saying bad actors can’t weasel their way into Microsoft, but that’s a much higher bar in terms of vetting.







  • The article even states this is a thinly veiled ad for some other “method”.

    The agile manifesto is fantastic. Scrum can work wonders as a means for providing a framework to hang “agile principles” onto.

    Most organizations don’t do “scrum” well or quickly lose sight of the “why” behind it.

    Companies are gonna company at the end of the day. Process + bureaucracy + buzzwords + ill-informed management + vendors promises + shit customers/product owners = late projects.

    Agile done right, works. The benefit agile has over waterfall(the process it replaced in a lot of places), imo, is that it’s predicated on working software, responding to change and working collaboratively/iteratively.