Linked by Thom Holwerda on Wed 21st Sep 2011 22:06 UTC, submitted by kragil
Thread beginning with comment 490337
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[5]: Comment by OSbunny
by lemur2 on Thu 22nd Sep 2011 10:09
in reply to "RE[4]: Comment by OSbunny"
You say "it is not possible" to add such a thing to an open source project.
That would be a bit naive.
It is like saying: it is not possible to be struck by lightning.
It is possible, just not very likely.
That would be a bit naive.
It is like saying: it is not possible to be struck by lightning.
It is possible, just not very likely.
An "open source project" typically has dozens, sometimes hundreds, of independent developers, in countries all over the world, pouring over the code.
Useful malware would take many hundreds or thousands of lines of source code.
How exactly would you propose that a malicious individual hides hundreds or thousands of lines of code in plain sight as a submission to an open source project being worked on by dozens of others?
It is just not credible that this could happen.
More to the point, in over a decade of open source software development over thousands and thousands of projects, it never has happened.
The proof, as they say, is in the pudding.
RE[6]: Comment by OSbunny
by Lennie on Thu 22nd Sep 2011 10:55
in reply to "RE[5]: Comment by OSbunny"





Member since:
2007-09-22
You say "it is not possible" to add such a thing to an open source project.
That would be a bit naive.
It is like saying: it is not possible to be struck by lightning.
It is possible, just not very likely.