I’d argue the opposite. This happened, as how I understood it when it was explained, is that while code gets lots and lots of eyeballs, non- trivial make files get little to no real review as it’s often hard to reason about them. The exploit took advantage of going where the security was weakest. The more AI is involved in reviewing all aspects the better off the process will be, especially the tedious and boring parts of all this.
I expect we will see a spate of security bots looking at all manner of things in the process as a reaction to all this.
Ken Thompson’s issues with trust will still apply. However these issues are with us with or without AI being employed.
Fair enough. Of course, projects with few retainers will likely not have near as many eyeballs looking over the code base. I do see your point, however, in a sense nothing has really changed. Although the job of maintaining a FOSS codebase may very well become just a bit more tedious. But yes, Ken Thompson's "Trusting Trust" principles do seem to address the issue quite well. When it comes to code review, always be diligent!
Comments
I’d argue the opposite. This happened, as how I understood it when it was explained, is that while code gets lots and lots of eyeballs, non- trivial make files get little to no real review as it’s often hard to reason about them. The exploit took advantage of going where the security was weakest. The more AI is involved in reviewing all aspects the better off the process will be, especially the tedious and boring parts of all this.
I expect we will see a spate of security bots looking at all manner of things in the process as a reaction to all this.
Ken Thompson’s issues with trust will still apply. However these issues are with us with or without AI being employed.
Fair enough. Of course, projects with few retainers will likely not have near as many eyeballs looking over the code base. I do see your point, however, in a sense nothing has really changed. Although the job of maintaining a FOSS codebase may very well become just a bit more tedious. But yes, Ken Thompson's "Trusting Trust" principles do seem to address the issue quite well. When it comes to code review, always be diligent!