{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"[Dev]olution","title":"Open Source Security: The Eyeballs Were Never Enough","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/8fb67233\"></iframe>","width":"100%","height":180,"duration":824,"description":"6,000 vulnerabilities but only 97 fixed. Nicky Pike can't stop thinking about a stat that a machine found in the open-source code your company almost certainly runs.\nIt all started with 90 seconds of a much longer conversation. A few weeks back, Nicky sat down with Gene Kim for a full episode on citizen developers and the outer loop. Near the end, Gene described a moment from an Erik Meijer talk that stuck with them both: the suggestion that running open source at all might be crazy, that it's coupled to code nobody's actually accountable for.\nIn this minisode, Nicky goes back through 25 years of the open source eyeballs promise and tests it against what happened this year. An AI model was pointed at open-source code and returned thousands of vulnerabilities. Maintainers, already buried, received more bug reports and barely any hands to fix them. Nicky lays out why the gap between finding a problem and fixing it, not the finding itself, has been the real issue the whole time.\nIf your team runs open source and you've never asked who actually fixes it when something breaks, this one will change how you look at that dependency list.\nIn this episode, you'll learn:\n1. Why cURL went from weekly bug reports to one every 18 hours\n2. How a stolen npm credential targeted the exact AI coding tools you use\n3. Why a signed, verified package still shipped malicious code untouched\nThings to listen for:\n(00:00) The stats that proved the risks of running open source\n(00:53) The 90 seconds with Gene Kim that changed everything\n(01:37) What this episode is not saying\n(02:23) Linus's law and Gene’s law\n(03:16) How the XZ Utils backdoor got in\n(04:14) An npm attack aimed at AI configs\n(05:09) An AI model gets pointed at open source\n(06:12) The wolfSSL bug nobody explained\n(07:06) A 27-year-old claim no one can verify\n(07:58) Why the fix counter stopped moving\n(08:50) The maintainer drowning in bug reports\n(09:41) Why more eyeballs never meant safer code\n(10:30) What to actually check...","thumbnail_url":"https://img.transistorcdn.com/NGioKOB49N-k877AC-twbJMVPLxekfS0gRkeRbVCBog/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MTRi/MGJkNDYxN2ZlY2Rm/ODM2MjQyYjJmNGEy/NTY1Ny5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}