Who's going to pay to fix open source security?
Who's going to pay to fix open source security?

Who's going to pay to fix open source security?

Saintedyfy59

21 min0 plays0 favorites
Business & Finance
Play

Description

<p>Will no one think of the maintainers? As <a href="https://thenewstack.io/log4j-is-one-big-i-told-you-so-for-open-source-communities/"><i>The New Stack</i> points out</a>, watching millions of projects fail because of a bug in an open source library has become common enough that  we shrug and reply, "Told you so." It's gotten so bad, big tech companies are visiting the White House to discuss the issue as a matter of national security.</p><p>There is a great <a href="https://thenewstack.io/log4j-is-one-big-i-told-you-so-for-open-source-communities/">post</a> up on the Stack Overflow blog examining  this issue, but it's not about color.js, it's about Log4J.  Traffic to questions on this logging library grew more than 1000% percent after the recent revelations about a new vulnerability. </p><p>Also discussed in this episode: cryptographer and Signal creator Moxie Marlinspike stepped down from his role as CEO of the encrypted messaging service.  That's news, but he actually made bigger waves in tech circles with an unrelated <a href="https://moxie.org/2022/01/07/web3-first-impressions.html">blog post</a> detailing  his first experience with Web3. Spoiler alert: it's not as decentralized or divorced from Web2 as you might have thought.</p><p>You can find Cassidy Williams on <a href="https://twitter.com/cassidoo?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor">Twitter</a> and her <a href="https://cassidoo.co/">website</a>.</p><p>Ben Popper can be found on Twitter <a href="https://twitter.com/benpopper">here</a>.</p><p>Ryan Donovan can be found on <a href="https://twitter.com/rthordonovan">Twitter</a>, or writing for the Stack Overflow <a href="https://stackoverflow.blog/author/rdonovan/">blog</a>.</p><p> </p>

Creators

danny.street

danny.street

Creator