[HN Gopher] Triaging security issues reported by third parties
       ___________________________________________________________________
        
       Triaging security issues reported by third parties
        
       Author : zdw
       Score  : 26 points
       Date   : 2025-06-19 04:27 UTC (3 days ago)
        
 (HTM) web link (gitlab.gnome.org)
 (TXT) w3m dump (gitlab.gnome.org)
        
       | tptacek wrote:
       | Wow, this is a whole thing. Like: absolutely, unpaid volunteers
       | shouldn't feel like they're on deadlines to fix security bugs in
       | open source code. They're not. But you're reading this and
       | assuming, "ok, they're getting a lot of dumb reports from random
       | bounty seekers or whatever", and, nope, he's complaining about
       | GPZ.
       | 
       | Which, again, fair enough! But the bugs he's apparently talking
       | about are presumably very serious.
       | 
       | (If maintainers of projects like libxslt stop fixing bugs, Google
       | will ultimately just fix them.)
        
         | mdaniel wrote:
         | It took me a second: "Google Project Zero" which I accept
         | responsibility for because I come to the comments before TFA
         | but I hadn't seen that initialism before
        
         | ndiddy wrote:
         | This library was originally written to parse GNOME
         | configuration XML files. It was never intended for parsing
         | untrusted data. From GNOME's perspective, if you can crash the
         | XML parser with a malformed config file, that's just a regular
         | bug. If an attacker is able to write to arbitrary files in your
         | home directory, he's already won.
         | 
         | I agree with the maintainer's perspective that it's
         | irresponsible for Apple, Microsoft, and Google to rely on this
         | library for parsing untrusted data in products that they make
         | billions of dollars off of, not provide him any monetary or
         | other support, and expect him to prioritize fixing "security
         | bugs" that don't impact security for his use case. If I was the
         | maintainer, I'd make the same decision he made.
        
           | tptacek wrote:
           | All of us agree!
        
       | runningmike wrote:
       | " These organizations are very exclusive clubs and anything but
       | open." This is so true! Many tests of the OpenSSF Scorecards do
       | not make sense when you e.g do not use github actions and have a
       | one persons project.....
        
       | cwillu wrote:
       | Proof of work captcha appears to be busted?
        
       ___________________________________________________________________
       (page generated 2025-06-22 23:02 UTC)