Skip to content
DevMeme
3705 of 7590
Security Post #4044 · source on Telegram

The 'Many Eyes' Fallacy of Open Source Security

Description

This meme uses the 'Shut Up Seagull' format, where a large yellow emoji-style hand pinches a seagull's beak closed, silencing it. The background is dark and indistinct. Text at the top reads, 'Open Source Software is more secure because absolutely anybody could audit the'. At the bottom, aligned with the silencing action, is the single word 'shut'. The image includes a small watermark 'imgflip.com' in the bottom-left corner. The meme humorously cuts short a common but naive argument in favor of open-source security. The technical context, especially given the post date of December 2021, points directly to the Log4j (Log4Shell) vulnerability crisis. It satirizes the 'many eyes' theory, where the theoretical possibility of anyone auditing the code is supposed to guarantee its security. Experienced engineers know that 'could' doesn't mean 'does,' and critical, widely-used libraries can go unaudited for years, leading to massive security vulnerabilities. The joke resonates with senior developers who understand that the security of the software supply chain often rests on underfunded and under-maintained open-source projects

Comments

57
Anonymous ★ Top Pick The 'many eyes' on that critical OSS dependency turned out to be one unpaid maintainer who burned out in 2017 and a CVE that just says 'good luck'
  1. Anonymous ★ Top Pick

    The 'many eyes' on that critical OSS dependency turned out to be one unpaid maintainer who burned out in 2017 and a CVE that just says 'good luck'

  2. Anonymous

    Sure, the repo is public - right next to the 1,237 other tabs every "potential auditor" swears they'll read after the sprint retro

  3. Anonymous

    After 20 years in tech, I've learned that 'many eyes make all bugs shallow' actually translates to 'everyone assumes the other guy already looked at it' - just like how we all assumed someone was auditing OpenSSL before Heartbleed, or Log4j before... well, you know

  4. Anonymous

    'Given enough eyeballs, all bugs are shallow' - turns out the eyeballs were all on the README, while the JNDI lookup sat unreviewed for eight years

  5. Anonymous

    Ah yes, the classic 'many eyes make all bugs shallow' argument - conveniently ignoring that those eyes are usually skimming Stack Overflow at 2 AM, not performing rigorous security audits of your dependency tree's dependency tree. Turns out 'anybody could audit it' and 'anybody actually does audit it' are separated by approximately 10,000 unpaid volunteer hours and a critical CVE that's been sitting there since 2015

  6. Anonymous

    Linus’s Law works - until you realize those “many eyes” are GitHub stars, not reviewers, and the xz backdoor still ships

  7. Anonymous

    Open‑source security model: infinite reviewers in the spec, a bus‑factor‑1 maintainer in production

  8. Anonymous

    Many eyes make bugs shallow - until those eyes are glued to Jira tickets instead of the codebase

  9. @Roman_Millen 4y

    And what's actually wrong here?

    1. P S 4y

      I think its refering to log4shell.

    2. dev_meme 4y

      people claim that open source is better because anyone can audit, but no one guartantees that the code will be checked

      1. @AlihatorU 4y

        So you should check it by yourself

    3. dev_meme 4y

      Memes don’t need to be fun. They also may teach us something. It’s DevMeme, not fun meme, you know🤔

  10. P S 4y

    Well if it were to be a real Backdoor, not a bug, it could be found far more easy.

  11. @maxuslum 4y

    Original please

  12. dev_meme 4y

    let it be the original

  13. Deleted Account 4y

    I use arch btw

    1. dev_meme 4y

      thanks to arch linux my netbook can handle 10 fps on low graphics minecraft (compared to 2 fps on winxp)

      1. @Infinitelineman 4y

        Win xp supports minecraft?

        1. dev_meme 4y

          winxp supports java 8, thats enough for 1.12.2, which was tested

          1. @Infinitelineman 4y

            How old is 1.12.2?

            1. dev_meme 4y

              4.5 years (summer 2017)

        2. P S 4y

          Well Minecraft is Java.

      2. @RiedleroD 4y

        thanks to arch linux and optifine, I get 60fps on my pentium shitshow

        1. P S 4y

          Is OF faster than vanilla?

          1. dev_meme 4y

            sometimes

          2. @RiedleroD 4y

            if you turn all the settings down, yes, massively.

    2. @arpanetus 4y

      u woman, u do not

      1. Deleted Account 4y

        D:

        1. @ZgGPuo8dZef58K6hxxGVj3Z2 4y

          Lol

  14. @Bitals 4y

    Well, this vulnerability was found because the open source code was audited, so the problem was patched...

    1. @Bitals 4y

      That's the idea behind the phrase. Free software is not magically better with less bugs, community just has a way to actually discover and fix them.

      1. @asoteric 4y

        i dont see how that is a bad thing?

        1. @Bitals 4y

          Maybe because it's not.

  15. @Infinitelineman 4y

    Ah i see. Necromancy

  16. dev_meme 4y

    i don't think so, at least because 1.16 crashed under java 8

  17. P S 4y

    I thought OF is just bringing better Graphics...

    1. @RiedleroD 4y

      you need extra shaders for the real meat

  18. dev_meme 4y

    optifine eats 2x ram... (allocate 4GB for minecraft, optifined minecraft uses 7GB)

    1. @RiedleroD 4y

      I have 4GB RAM, stop shitting me

  19. @RiedleroD 4y

    I that

  20. dev_meme 4y

    only 32x resource packs, BUT same settings with and without OF

  21. dev_meme 4y

    pics will be soon

    1. dev_meme 4y

      Optifined minecraft 1.17.1 Private bytes for java: 3.1GiB Allocates: 2.1GiB -Xmx 4g from where 1GiB?

      1. @RiedleroD 4y

        > why xp > how big is the render distance > openjdk or oracle java?

        1. dev_meme 4y

          openjdk 16

        2. dev_meme 4y

          31 render

          1. @RiedleroD 4y

            31 render distance? holy shit no wonder lmao

            1. @RiedleroD 4y

              I got like 2 or 4 chunks render distance btw, not ideal, but I have to take what I can get with my 1.9GHz Pentium

              1. dev_meme 4y

                how can i set render distance below 2 chunks

                1. @RiedleroD 4y

                  impossible afaik

                  1. @RiedleroD 4y

                    maybe with mods

        3. dev_meme 4y

          NOT xp, but xp-styled win7

          1. @RiedleroD 4y

            still bad

      2. dev_meme 4y

        No optifine 1.17.1 allocated 2.4GiB private bytes 3.4GiB maybe it is not reproducible now, because I updated versions?

  22. dev_meme 4y

    firefox uses 28GiB virtual memory, but i meant not virtual

  23. @cptnBoku 4y

    Hahahahahaa

Use J and K for navigation