Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Suppose there is a bug in the Linux kernel. Some business runs their webservers on Linux. They have user email addresses (PII). Is Linus responsible for breaches? If so, then OSS dies. If not, then how do you intend to prove that their are no vulns in any of your dependencies for the rest of time?


This is silly. If I build my bridge with equations I find on mathoverflow, the forum is not responsible for my bridge collapsing.

If you’re using OSS for mission-critical software you must either ensure that it’s fit for purpose or pay someone to do it for you. Nothing in the Linux Kernel documentation suggests that it can/should be used for flying airplanes of securing PII without doing additional due diligence.


The person storing the data is the one responsible for securing the data. Everyone keeps trying to push data security up the stack, but the company/ individual collecting it is the responsible party.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: