i don’t understand how people see the xz incident and conclude that open source is insecure. That level of social engineering could easily have worked on a company as well, but it was detected *because* it was open source. All other mechanisms failed, and it was just some random guy poking around that discovered it. That kind of scrutiny doesn’t happen on closed source systems
@kellogh I'm also not comfortable with the "by chance" aspect of the find, despite what the person who found it says.
Open source is full of quirky, obsessive, neurodiverse, people who will say "that little thing that doesn't bother other people, it bothers me, so I'm going to fix it". In corporate environments they beat that out of you very quickly (or you resign)