George E. 🇺🇸♥🇺🇦🇵🇸🏳️🌈🏳️⚧️<p>"Just because a piece of software is <a href="https://bofh.social/tags/OpenSource" rel="nofollow noopener" target="_blank">#OpenSource</a> it does <b>not</b> mean the software is <i>secure</i>." --<i>me</i><span><br><br>I've been saying that for years and it really bothers me to hear developers and users alike quip that because a package is open source it automatically means it's more secure than a comparable package that is closed-source.</span></p><blockquote>As EricS. Raymond, one of the people behind open source, said in Linus's Law, "Given enough eyeballs, all bugs are shallow." If no one is looking, though -- as appears to be the case here — then simply because a codebase is open, it doesn't provide any safety or security at all.</blockquote><a href="https://www.zdnet.com/article/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant-and-devs-are-worried/" rel="nofollow noopener" target="_blank">https://www.zdnet.com/article/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant-and-devs-are-worried/</a><span><br><br></span><a href="https://developers.slashdot.org/story/25/07/26/0352242/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant" rel="nofollow noopener" target="_blank">https://developers.slashdot.org/story/25/07/26/0352242/hacker-slips-malicious-wiping-command-into-amazons-q-ai-coding-assistant</a><span><br><br></span><a href="https://bofh.social/tags/amazon" rel="nofollow noopener" target="_blank">#amazon</a> <a href="https://bofh.social/tags/hacker" rel="nofollow noopener" target="_blank">#hacker</a> <a href="https://bofh.social/tags/hacking" rel="nofollow noopener" target="_blank">#hacking</a> <a href="https://bofh.social/tags/github" rel="nofollow noopener" target="_blank">#github</a> <a href="https://bofh.social/tags/PullRequest" rel="nofollow noopener" target="_blank">#PullRequest</a> <a href="https://bofh.social/tags/patch" rel="nofollow noopener" target="_blank">#patch</a> <a href="https://bofh.social/tags/vulnerability" rel="nofollow noopener" target="_blank">#vulnerability</a> <a href="https://bofh.social/tags/ComputerSecurity" rel="nofollow noopener" target="_blank">#ComputerSecurity</a> <a href="https://bofh.social/tags/InformationSecurity" rel="nofollow noopener" target="_blank">#InformationSecurity</a> <a href="https://bofh.social/tags/ITSecurity" rel="nofollow noopener" target="_blank">#ITSecurity</a> <a href="https://bofh.social/tags/MaliciousCode" rel="nofollow noopener" target="_blank">#MaliciousCode</a> <a href="https://bofh.social/tags/aws" rel="nofollow noopener" target="_blank">#aws</a> <a href="https://bofh.social/tags/q" rel="nofollow noopener" target="_blank">#q</a> <a href="https://bofh.social/tags/ai" rel="nofollow noopener" target="_blank">#ai</a> <a href="https://bofh.social/tags/agent" rel="nofollow noopener" target="_blank">#agent</a> <a href="https://bofh.social/tags/vscode" rel="nofollow noopener" target="_blank">#vscode</a><p></p>