"open source needs more funding!"

*nation state pays for backdoor*

"not like that!"

@tenderlove

I laughed unreasonably hard at this!

Too soon, and too funny, all at the same time.

@tenderlove

To be fair, this has similar vibes:

"I need money for rent!"

"Mobster pays you to stab someone."

"Not like that!"

@tenderlove I wouldn't be too. sure it's some nation state that put together the whole scheme. It could also be a case of 2-3 friends engineers (a'la Office Space), putting together something that's eventually sellable in crime and espionage markets. From the mailing list, it seems to be a job of 2-3 ppl originally, and not just the commiter.
@eugenialoli I don't see any reason to assume it wasn't just one person with a few sockpuppets.

@eugenialoli @tenderlove From what I've heard so far it's still not clear more than one person was involved (even if more than one account was), but that certainly is possible.

Some nation states would definitely do something like this, but part of the lesson here is that it didn't take a lot of resources. It could also be someone who got laid off a couple years from an industry job and found a scheme to make some money and get back at the industry. And do the kind of programming they enjoy.

@eugenialoli @tenderlove this stinks like a Lazarus project.
@tenderlove they bought me a coffee though..
@tenderlove Hmph. All you hippie whiners acting like no struggling Sicilian church ever accepted protection from the Mafia in exchange for the priest and deacon turning a blind eye to drugs and guns being transshipped in caskets. Naïfs!
@tenderlove @dave_aitel North Korea is contributing more to the open source ecosystem than some Fortune 100 companies.
@tenderlove this reminds me of Red Flag Linux days. Ohh how young and naive we were then 🥲

@tenderlove :D

BTW nation state can out a gun on the maintainer andnforce them to release a vulnerable package.

Or put them in a prison without anyone noticing and take the ownership of the package.