Apple, Google, AWS, Microsoft, ... I would call it criminal neglect using hobby software like libxml2 written in a memory-unsafe language (to cite the maintainer) to process untrusted input in systems that need to protect personal data or are even safety-relevant.
So what's the alternative? Microsoft has a longer history than many open source components. Nobody could see the source, but it was proven continuously that it was highly insecure. Less than hobbyist quality, but closed source so nobody could see the (lack of) quality explicitly. Some might claim 20 years later they would produce better software. Maybe marginally, but not fundamentally I'd dare to claim.
WhereIsTheTruth · 3h ago
Should we rewrite everything in Ada?
anotherhue · 4h ago
Good for him, I just wish he made it more obvious how a cash rich but time poor BigTech product owner could help him.
usr1106 · 4h ago
Hire him full time for a Silicon Valley salary? Employ a team of testers using state of the art test automation, fuzzing, static analysis?
anotherhue · 4h ago
"Paid support contracts are available starting at $50k per year"
Is more what I had in mind. Maybe he's already rich :)
msla · 4h ago
Unsustainable what? The title got cut off.
gessha · 4h ago
“Burden” is missing but I feel like the title is descriptive enough.
So what's the alternative? Microsoft has a longer history than many open source components. Nobody could see the source, but it was proven continuously that it was highly insecure. Less than hobbyist quality, but closed source so nobody could see the (lack of) quality explicitly. Some might claim 20 years later they would produce better software. Maybe marginally, but not fundamentally I'd dare to claim.
Is more what I had in mind. Maybe he's already rich :)