Politics tamfitronics Linux Foundation’s decision to ban Russian maintainers has the potential to destroy open source’s global collaboration model
By
Cliff Saran,Managing Editor
Published: 30 Oct 2024 12:20
Following the removal last week of Russian Linux kernel maintainers to comply with US policies, Linus Torvalds – the developer of the original Linux kernel – spoke about his concerns that there were lots of Russian trolls who could potentially infiltrate the Linux kernel.
The decision to block the maintainers followed a compromise of the open source XY Utils software library, which was caused by a social engineering attack targeting the maintainer of the utility.
“It’s entirely clear why the change was done. It’s not getting reverted, and using multiple random anonymous accounts to try to ‘grass root’ it by Russian troll factories isn’t going to change anything,” wrote Torvalds in a message to the Linux patch list of recipients who help maintain the kernel code.
His remarks have fielded a swathe of comments, ranging from anti-Russian sentiment to speculation that Microsoft lobbyists were behind the decision. Yet its impact has far-reaching consequences for open source, which, until now, has largely been regarded as a global community effort.
Any US sanctions to prevent people from certain countries from participating in open source projects not only has the potential to destroy global collaboration, but could also open the flood gates to wider scrutiny, involving possible background checks on software engineers working in all businesses.
Politics tamfitronics The vulnerability of open source maintainers
The ban comes just months after the XY Utils incident, where an overworked project maintainer of the XY Utils open source library took on help from a developer using the name Jia Tan, who initially joined the project and started opening pull requests for various bug fixes or improvements. The developer, having established trust and credibility, began to receive permissions for the repository. The attackers then sent spurious complaints and bugs, as a form of social engineering attack, to pressure the project’s original maintainer to give Jia Tan more control of the project, commit permissions and, eventually, release manager rights.
It seems that as part of the effort to gain these permissions, Jia Tan used an interesting form of social engineering. Fake accounts were used to send myriad feature requests and complaints about bugs to put pressure the original maintainer, eventually causing them to add Jia Tan to the repository.
One of the changes Jia Tan introduced was a sophisticated backdoor in XY Utils.
I don’t know the logic behind the decision [to block the Russian maintainers]. People are being excluded from global collaboration who are not bad actors, and that’s hugely problematic. It’s a can of worms Amanda Brock, OpenUK
However, the Russian maintainers do not appear to have done anything wrong. Amanda Brock, CEO of OpenUK, said: “I don’t know the logic behind the decision. People are being excluded from global collaboration who are not bad actors, and that’s hugely problematic. It’s a can of worms.”
The licensing of open source code means it can be used by anyone for any purpose. “In my 16 to 17 years in open source, this is the first time I’ve seen a category of people being restricted,” she added.
There are rules around export control that prevent technology, like encryption software, being exported. Earlier this year, the US Office of Foreign Assets Control issued guidance on President Joe Biden’s executive order imposing sanctions on Russia and Russian businesses. Certain categories of software and IT consulting services are covered, which means these cannot be provided in Russia. The sanctions also cover certain Russian businesses.
Although the Linux Foundation has not released any further details on the ban, it is believed that the banned Russian maintainers may have worked at these organisations.
As Brock noted, although export controls restrict the distribution of software, often, the code is available on a mirror site. “Sanctions are different,” she added. “If a business is on a sanction list, you cannot engage commercially in certain ways with that business, and what I gather from the bits of discussion [I’ve seen] is that 11 individuals have been told that they can’t be on the maintainer list.”
Brock’s understanding of why these individuals have been excluded is that their employers are subject to a US sanctions list.
Politics tamfitronics Exclusion could impact other countries of interest
“These people, to the best of my knowledge, have done nothing wrong. They are of a class of people who the US government wants to exclude because, I believe, their employer has connections to Russia, which means that they have to be excluded.”
For Brock, the decision to ban the 11 Russian maintainers has consequences for open source code, which is increasingly being subject to complex legislation and legal restrictions.
For instance, the US and the UK have imposed sanctions on Chinese tech firms, such as Huawei. Yet research suggests China has the second largest community of open source software developers in the world. The geography of open source software research paper, published in 2021, analysed developers on GitHub. While the US had the largest number of developers using GitHub, China had the second largest.
“China is particularly interesting because it’s high up the US list of countries of concern. But at the same time, it has made a decision to engage in open source at a massive scale, and this is a conscious and government-backed decision,” said Brock.
Brock pointed out that Chinese companies have funded open source at scale, both in terms of contributors and investment in foundations.
Projects being driven by Chinese contributors include KubeEdge, which enables Kubernetes to be used in edge computing; Habor, a cloud-native registry for Kubernetes; and Dragonfly, a file distribution and image acceleration system.
Chinese software, based on open source technology, is also embedded in many of the smart devices in use today.
The UK government has forced mobile telecoms providers to rip out Huawei equipment from the UK’s mobile networks. Brock pointed out that the code in mobile networks is open source, and may very well have Chinese contributors, adding: “How far are we going to go with this? Where does it start and stop?”
She questioned whether the US and other governments would hold proprietary software providers to the same account, to ensure no developer code sourced from “countries of interest” is included in a commercial product. To implement such compliance would require every commercial software provider to change all of their contracts and licences, said Brock, and few organisations are large enough to fund international legal teams to ensure open source software complies with regulations in every region they operate in.
The Linux Foundation’s decision to ban the Russian developers is most likely a response to legal advice, to avert a potential clash with the US administration. With geopolitical tension heating up, there are risks that open source software developers and maintainers from other countries may find that they, too, are being dropped from contributing to and supporting open source projects.
Read more on Open source software
Linux enters the cold war
By: Cliff Saran
Russian Linux kernel maintainers blocked
By: Cliff Saran
XZ backdoor discovery reveals Linux supply chain attack
By: Rob Wright
US tech used in Russian weapons, despite export controls
Article content
In this week’s video, host John Ivison was joined by guests Ian Brodie and Gene Lang to review the tumultuous year in Canadian politics and to look at what might be ahead.THIS CONTENT IS RESERVED FOR SUBSCRIBERS
Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles including the New York Times Crossword.Support local journalism.SUBSCRIBE FOR MORE ARTICLES
Enjoy the latest local, national and international news.Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.Unlimited online access to National Post.National Post ePaper, an...
HYDERABAD: Union minister of state for home Bandi Sanjay Kumar accused the Congress leadership of turning the Jubilee Hills byelection campaign into a religious contest, ignoring development issues that truly affect the constituency.
Sanjay claimed the real fight was between the BJP and Congress, criticising what he termed “opportunistic alliances” between the Congress, AIMIM and the BRS. He alleged that government agencies had ignored complaints about the mysterious death of Jubilee Hills MLA Maganti Gopinath and alleged that Chief Minister A. Revanth Reddy and BRS working president K.T. Rama Rao were eyeing the late MLA’s properties.
“If the Chief Minister has courage and integrity, let him order a thorough probe into Gopinath’s death,” Sanjay said, showing copies of what he claimed were official complaints regarding the case. He also questioned the nomination of Gopinath’s wife,...
Former Secretary to the Government of the Federation (SGF), Babachir Lawal, has made a fresh revelation about President Bola Tinubu and former President Muhammadu Buhari.
Speaking on Channels Television’s Politics Today on Monday, Lawal claimed that Tinubu, Buhari, and other APC leaders were the first to brief the United States government about the alleged killing of Christians in Nigeria during Goodluck Jonathan’s administration.
According to him, “Trump might be right, might not be right, but don’t forget, there was a delegation that first went to the United States to tell Obama then that Christians were being slaughtered in Nigeria. It included this man. Which man? The president (Tinubu). That APC delegation. I saw the picture. Buhari was there. Amaechi was there. I think he was the one even sitting close to the president where they went to...
Marketing in 2026 Audiences, Costs, and Smarter AI Marketing in 2026 Audiences, Costs, and Smarter AI Marketing in 2026 Audiences, Costs, and Smarter AI Marketing in 2026 Audiences, Costs, and Smarter AI As brokers eye B2B business and compete with fintechs and crypto exchanges alike, marketers need to act wisely with often limited budgets. AI can offer scalable solutions, but only if used properly. Join seasoned marketing executives and specialists...
Alec Hogg speaks with Graham Soden, CEO of Steenkampskraal Mine, about the growing geopolitical significance of rare earth elements and South Africa’s potential role in this global race. Soden reflects on his journey in mining, the promise of the Steenkampskraal project, and the rising demand for thorium and radium. He also addresses misconceptions about radioactivity, the challenges of attracting investment, and the importance of strategic partnerships in navigating a politically sensitive environment.Sign up for your early morning brew of the BizNews Insider to keep you up to speed with the content that matters. The newsletter will land in your inbox at 5:30am weekdays. Registerhere.
Support South Africa’s bastion of independent journalism, offering balanced insights on investments, business, and the political economy, by joining BizNews Premium. Registerhere.
If you preferWhatsAppfor updates, sign up to the BizNews channelhere.
The African Democratic Congress (ADC) has criticized the Federal Government for keeping silent over the alleged attempted coup involving some military officers, saying its failure to clarify the matter is heightening public anxiety and creating room for dangerous speculation. Speaking on Channels Television’s Politics Today on Tuesday, the party’s National Publicity Secretary, Bolaji Abdullahi, described the government’s inaction as “deeply concerning,” especially in a democracy still recovering from the scars of past military interventions. Recall that on October 18, the Defence Headquarters (DHQ) dismissed as false and misleading reports by an online medium alleging that activities marking Nigeria’s 65th Independence Anniversary were cancelled due to an attempted coup plot. The DHQ, in a statement by its Director of Defence Information, Brigadier General Tukur...
‘Describing these things as left wing reflects the way in which our politics is being twisted.’Former Liberal prime minister Malcolm Fraser (Image: Private Media)
We are currently witnessing the death throes of the Liberal Party. To a good chunk of the electorate who voted for the current government, that doesn’t matter… except that it leaves Labor in full power with no meaningful opposition.
A decade ago, former Liberal prime minister Malcolm Fraser predicted this moment would come, and he spent his final years working on the answer: a new political party, built on traditional liberal values but without the now-toxic name.Bernard Keane joins the podcast to revisit Fraser’s plan to replace the Liberal Party. The detailed “Renew Australia” manifesto remains remarkably relevant, and takes a surprisingly progressive stance on issues like immigration, our relationship with the...
I first realized the extent of the internet’s takeover of U.S. politics while standing in the lobby of a drab hotel convention center, listening to an elderly gentleman rattle off a list of fringe conspiracy forums he frequented.
“Prison Planet,” he told me, and “Infowars.”
“Wow,” I said. In the conference room behind us, a man distributed papers watermarked with a custom edit of Pepe, a cartoon frog that achieved infamy as an unofficial mascot of the too-online, 4chan-dwelling alt-right of the 2010s.
I wasn’t at an alt-right conference. Nor was I at a meetup of tech-savvy trolls. I was at the 2018 Flat Earth International Conference in Aurora, Colorado. The hundreds of globe denialists who’d gathered included friendly retirees, mother-daughter duos,...
Democratic congresswoman criticizes Trump's comments about a third termRashida Tlaib, Michigan’s Democratic representative, has criticized comments from Steve Bannon after the former White House aide said that Donald Trump plans to run for a third term.
On Monday, Tlaib took to X and wrote: “Despite what the Constitution says, Bannon vows Trump will be president for a third term. But they all start crying when we call them fascists. No way in hell we’re going to let that happen.”While on his Asia tour, Trump told reporters on Monday that he “would love to do” an unconstitutional third term but ruled out the option of running as a vice-president, saying “Because it’s too cute.”Today brought news...
Natacha Akide, known as Tacha, is a reality TV star and social media influencer.She has expressed interest in potentially entering politics.Tacha’s motivation for considering politics is her desire to help Nigerians.Reality TV star and social media influencer Natacha Akide, popularly known as Tacha, has revealed that venturing into politics could be a path she might consider.
In a recent interview with BBC Pidgin, Tacha expressed her interest in engaging in political matters, citing her desire to help Nigerians as a motivating factor.
She explained, “I feel that if you constantly complain about issues, it makes sense to step in and contribute to decisions that could improve people’s lives. People always say that after God comes politics, and it’s true government policies can significantly impact our lives. So, getting involved is logical.”
Tacha apart, “I’m passionate about politics, but...
Elections this week in Ireland and the Netherlands were disrupted by AI deepfakes as the post-truth future that experts have long warned about came one step closer.
Newly elected Irish President Catherine Connolly survived a doctored video showing her supposed withdrawal from the election on the eve of voting, while Dutch firebrand Geert Wilders was forced to apologise for a fabricated video distributed by two of his party’s MPs depicting centre-left opponent Frans Timmermans being arrested.Since deepfakes first emerged in 2017 as “incel-produced nonconsensual porn”, concerns have “snowballed into panic” when their political consequences became apparent, said The Guardian. AI “slopaganda” is here to stay and promises to influence our lives “for better or for worse”.The WeekEscape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.
SUBSCRIBE & SAVESign up for The...
The movie “One Battle After Another” expands on issues from the novel it is based on, Thomas Pynchon’s “Vineland.” Jason Dick discusses the book with Pynchon scholar Sean Carswell on the latest Political Theater podcast. (Jason Dick/CQ Roll Call)
...