• 0 Posts
  • 408 Comments
Joined 1 year ago
cake
Cake day: June 15th, 2023

help-circle






  • It highlighted some pretty glaring weaknesses in OSS as well. Over worked maintainers, unvetted contributers, etc etc.

    The XZ thing seems like we got “lucky” more than anything. But that type of attack may have been successful already or in progress elsewhere. It’s not like people are auditing every line of every open source tool/library. It takes really talented devs and researchers to truly audit code.

    I mean, I certainly couldn’t do it for anything semi advanced, super clever, or obfuscated the way the XZ thing was.

    But I agree, that the fact we could audit it at all is a plus. The flip side is: an unvetted bad actor was able to publish these changes because of the nature of open source. I’m not saying bad actors can’t weasel their way into Microsoft, but that’s a much higher bar in terms of vetting.







  • The article even states this is a thinly veiled ad for some other “method”.

    The agile manifesto is fantastic. Scrum can work wonders as a means for providing a framework to hang “agile principles” onto.

    Most organizations don’t do “scrum” well or quickly lose sight of the “why” behind it.

    Companies are gonna company at the end of the day. Process + bureaucracy + buzzwords + ill-informed management + vendors promises + shit customers/product owners = late projects.

    Agile done right, works. The benefit agile has over waterfall(the process it replaced in a lot of places), imo, is that it’s predicated on working software, responding to change and working collaboratively/iteratively.



  • I agree with a lot of this sentiment. My goal is to try to “be the change I want to see in the world”.

    So I occasionally challenge the dumb group think I see on here. Sometimes it well received but not always.

    One thing Ive noticed is how reactionary and un-nuanced a lot of posts are. I guess it makes sense since a majority of the users here self-selected to leave a site in protest. There is a bias towards being “reactionary”.

    But the vibe feels off on Lemmy and I can’t put my finger on exactly why, but I certainly don’t feel like a lot of my people are here. Don’t get me wrong, I love hearing different opinions and viewpoints but the way a lot of them are presented here feel very “well ackshually!” or sanctimonious. It’s less like that on mastodon, but still there. Maybe less “fun” and hearted. It’s almost too serious, but even the less serious stuff isn’t as fun/funny.

    Hacker news feels better. Almost reminds me of old school reddit or even forums.

    I think the fediverse and Lemmy would have been better if it was designed where each “subreddit”/channel was an instance. Basically federate the small communities but don’t make a bunch of small “reddits” where it’s fragmented and watered down.

    There could be hubs with curated channels or apps that let you curate channels but each channel is effectively independent.

    Anyway, I don’t know that that would even fix the vibe problem with the fediverse but I think it would help communities grow, evolve, and mature better.