this post was submitted on 11 Apr 2024
486 points (96.0% liked)

Programmer Humor

35192 readers
115 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 5 years ago
MODERATORS
 

transcriptScreenshot of github showing part of the commit message of this commit with this text:

Remove the backdoor found in 5.6.0 and 5.6.1 (CVE-2024-3094).

While the backdoor was inactive (and thus harmless) without inserting
a small trigger code into the build system when the source package was
created, it's good to remove this anyway:

  - The executable payloads were embedded as binary blobs in
    the test files. This was a blatant violation of the
    Debian Free Software Guidelines.

  - On machines that see lots bots poking at the SSH port, the backdoor
    noticeably increased CPU load, resulting in degraded user experience
    and thus overwhelmingly negative user feedback.

  - The maintainer who added the backdoor has disappeared.

  - Backdoors are bad for security.

This reverts the following without making any other changes:

The sentence "This was a blatant violation of the Debian Free Software Guidelines" is highlighted.

Below the github screenshot is a frame of the 1998 film The Big Lebowski with the meme caption "What, are you a fucking park ranger now?" from the scene where that line was spoken.

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 1 year ago

Best part to me is "The maintainer who added the backdoor has disappeared." implying it was removes because there's nobody left to maintain it

[–] [email protected] 4 points 1 year ago

reminds me of the infamous NSA backdoor patch blog for Notepad++

[–] [email protected] 22 points 1 year ago (1 children)

Backdoors are bad for security.

No shit....

[–] [email protected] 1 points 1 year ago

You've gotta wonder what else you'd write though

Especially given the urgency guy's probably not gonna sit there and ponder

[–] [email protected] 13 points 1 year ago (1 children)

Nobody fucks with the Linux

[–] [email protected] 4 points 1 year ago

This guy Archs! Am I right!? You know I'm right!

[–] [email protected] 31 points 1 year ago (4 children)
[–] [email protected] 18 points 1 year ago (2 children)

Its like saying bank robbery is against bank’s gun carrying policy.

Sure its true, but thats not really the problem being addressed. The massive, notorious security vulnerability is.

[–] [email protected] 3 points 1 year ago

I got that part, which is funny. The movie below tho, I don't think is

[–] [email protected] 5 points 1 year ago

Oh the big lebowsky part, i dont get it either

[–] [email protected] 42 points 1 year ago

I can excuse attempting to compromise millions of computer systems worldwide for nefarious purposes but I draw the line at violating the contributor guidelines of an opensource project.

[–] [email protected] 16 points 1 year ago (1 children)

Yep, probably because it's not funny or clever. My guess is that you look for funny and/or clever in your jokes.

[–] [email protected] 5 points 1 year ago (1 children)

Someone explained it, turns out it's just not my kind of joke. I get it now tho

[–] [email protected] 2 points 1 year ago (1 children)

I'm still lost... I've been following the XZ thing since it broke, so I get the context, but I'm not sure how the meme at the bottom is connected?

[–] [email protected] 7 points 1 year ago (2 children)

On the photo you see a violation of rules listed as one of the reasons this commit is made. Because it's at the top the meme creator is presuming that's their main priority.

And they disagree with that, so they're calling them a "park ranger". I'm guessing they're alluding to an old but common media presentation of park rangers being childish about rules.

I get the joke with that it looks a bit odd to put that reason at the top of the list, but their response I find more unkind than funny

[–] [email protected] 12 points 1 year ago (2 children)

As the image transcript in the post body explains, the image at the bottom is a scene from a well-known 1998 film (which, according to Wikipedia, was in 2014 selected for preservation in the United States National Film Registry by the Library of Congress as being "culturally, historically, or aesthetically significant").

This meme will not make as much sense to people who have not seen the film. You can watch the referenced scene here. The context is that the main character, The Dude (played by Jeff Bridges) has recently had his private residence invaded by a group of nihilists with a pet marmot (actually portrayed by a ferret) and they have threatened to "cut off his Johnson". In an attempt to express sympathy, The Dude's friend Walter (played by John Goodman) points out that, in addition to the home invasion and threats, the nihilists' exotic pet is also illegal. The Dude's retort "what, are you a fucking park ranger now" is expressing irritation with that observation, because it is insignificant compared with the threat of the removal of his penis.

This meme attempts to draw a parallel between this humorous scene and XZ developer Lasse Collin's observation that the XZ backdoor was also a violation of Debian's software licensing policies.

Thank you for reading my artist's statement.

[–] [email protected] 2 points 1 year ago

I just don't like derogatory jokes

[–] [email protected] 2 points 1 year ago

I don't think I've seen that movie, so that explains why I missed the joke

[–] [email protected] 10 points 1 year ago (1 children)

It's a scene from The Big Lebowski, right after The Dude got tortured with a marmot by German nihilists. Walter focuses on the legality of keeping a marmot as a pet, which is obviously not the main issue.

[–] [email protected] -1 points 1 year ago (1 children)

Yea, I've seen that kind of humour in my grandpa's movies sometimes too. Not my thing

[–] [email protected] 4 points 1 year ago

The Big Lebowski is the pinnacle of humour! Now get off my lawn!

[–] [email protected] 4 points 1 year ago
[–] [email protected] 6 points 1 year ago (1 children)

Well, I think they should revoke that guy's PGP key

[–] [email protected] 2 points 1 year ago (1 children)

Isn't the point of PGP/GPG that there's no central database?

[–] [email protected] 2 points 1 year ago

Yes, he will always be able to prove that's it's him. But if they revoke the permissions of that key he can't do any more damage

load more comments
view more: next ›