睇埋佢其他reply, 其實佢以為open source = 個個可以edit, 係理解錯個新聞
xz入backdoor個個係co-maintainer, 所以先有right, 佢唔係任何人, 佢係得到原本developer既「信任」
即係而家最大個問題其實唔係edit right
而係identify 唔到呢個co-maintainer嘅真實身份
呢單野令我諗起EU想通過嗰條cyber resilience act
如果通過咗,個maintainer可能破產都唔掂
係,如果個software 係employee edit only, 咁就比較大機會捉到凶手
但大份部份open source software都係anonymous,依個絕對唔係佢嘅缺點嚟。但我會擔心囉
其實有唔少人講返故事, 個hobby project冇心機理, 交左比D熱心人, 會發生咩事
有一個反而係個熱心人搞大左個project, 又有拿左個project之後就踢走左個原作者
有辣有唔辣, 所以交權比個anonymous既人搞本來就係open source既精神
因為有部分hacker想exploit呢個遊戲, That's why we can't have nice things