Politics tamfitronics Linux Foundation’s decision to ban Russian maintainers has the potential to destroy open source’s global collaboration model
By
Cliff Saran,Managing Editor
Published: 30 Oct 2024 12:20
Following the removal last week of Russian Linux kernel maintainers to comply with US policies, Linus Torvalds – the developer of the original Linux kernel – spoke about his concerns that there were lots of Russian trolls who could potentially infiltrate the Linux kernel.
The decision to block the maintainers followed a compromise of the open source XY Utils software library, which was caused by a social engineering attack targeting the maintainer of the utility.
“It’s entirely clear why the change was done. It’s not getting reverted, and using multiple random anonymous accounts to try to ‘grass root’ it by Russian troll factories isn’t going to change anything,” wrote Torvalds in a message to the Linux patch list of recipients who help maintain the kernel code.
His remarks have fielded a swathe of comments, ranging from anti-Russian sentiment to speculation that Microsoft lobbyists were behind the decision. Yet its impact has far-reaching consequences for open source, which, until now, has largely been regarded as a global community effort.
Any US sanctions to prevent people from certain countries from participating in open source projects not only has the potential to destroy global collaboration, but could also open the flood gates to wider scrutiny, involving possible background checks on software engineers working in all businesses.
Politics tamfitronics The vulnerability of open source maintainers
The ban comes just months after the XY Utils incident, where an overworked project maintainer of the XY Utils open source library took on help from a developer using the name Jia Tan, who initially joined the project and started opening pull requests for various bug fixes or improvements. The developer, having established trust and credibility, began to receive permissions for the repository. The attackers then sent spurious complaints and bugs, as a form of social engineering attack, to pressure the project’s original maintainer to give Jia Tan more control of the project, commit permissions and, eventually, release manager rights.
It seems that as part of the effort to gain these permissions, Jia Tan used an interesting form of social engineering. Fake accounts were used to send myriad feature requests and complaints about bugs to put pressure the original maintainer, eventually causing them to add Jia Tan to the repository.
One of the changes Jia Tan introduced was a sophisticated backdoor in XY Utils.
I don’t know the logic behind the decision [to block the Russian maintainers]. People are being excluded from global collaboration who are not bad actors, and that’s hugely problematic. It’s a can of worms Amanda Brock, OpenUK
However, the Russian maintainers do not appear to have done anything wrong. Amanda Brock, CEO of OpenUK, said: “I don’t know the logic behind the decision. People are being excluded from global collaboration who are not bad actors, and that’s hugely problematic. It’s a can of worms.”
The licensing of open source code means it can be used by anyone for any purpose. “In my 16 to 17 years in open source, this is the first time I’ve seen a category of people being restricted,” she added.
There are rules around export control that prevent technology, like encryption software, being exported. Earlier this year, the US Office of Foreign Assets Control issued guidance on President Joe Biden’s executive order imposing sanctions on Russia and Russian businesses. Certain categories of software and IT consulting services are covered, which means these cannot be provided in Russia. The sanctions also cover certain Russian businesses.
Although the Linux Foundation has not released any further details on the ban, it is believed that the banned Russian maintainers may have worked at these organisations.
As Brock noted, although export controls restrict the distribution of software, often, the code is available on a mirror site. “Sanctions are different,” she added. “If a business is on a sanction list, you cannot engage commercially in certain ways with that business, and what I gather from the bits of discussion [I’ve seen] is that 11 individuals have been told that they can’t be on the maintainer list.”
Brock’s understanding of why these individuals have been excluded is that their employers are subject to a US sanctions list.
Politics tamfitronics Exclusion could impact other countries of interest
“These people, to the best of my knowledge, have done nothing wrong. They are of a class of people who the US government wants to exclude because, I believe, their employer has connections to Russia, which means that they have to be excluded.”
For Brock, the decision to ban the 11 Russian maintainers has consequences for open source code, which is increasingly being subject to complex legislation and legal restrictions.
For instance, the US and the UK have imposed sanctions on Chinese tech firms, such as Huawei. Yet research suggests China has the second largest community of open source software developers in the world. The geography of open source software research paper, published in 2021, analysed developers on GitHub. While the US had the largest number of developers using GitHub, China had the second largest.
“China is particularly interesting because it’s high up the US list of countries of concern. But at the same time, it has made a decision to engage in open source at a massive scale, and this is a conscious and government-backed decision,” said Brock.
Brock pointed out that Chinese companies have funded open source at scale, both in terms of contributors and investment in foundations.
Projects being driven by Chinese contributors include KubeEdge, which enables Kubernetes to be used in edge computing; Habor, a cloud-native registry for Kubernetes; and Dragonfly, a file distribution and image acceleration system.
Chinese software, based on open source technology, is also embedded in many of the smart devices in use today.
The UK government has forced mobile telecoms providers to rip out Huawei equipment from the UK’s mobile networks. Brock pointed out that the code in mobile networks is open source, and may very well have Chinese contributors, adding: “How far are we going to go with this? Where does it start and stop?”
She questioned whether the US and other governments would hold proprietary software providers to the same account, to ensure no developer code sourced from “countries of interest” is included in a commercial product. To implement such compliance would require every commercial software provider to change all of their contracts and licences, said Brock, and few organisations are large enough to fund international legal teams to ensure open source software complies with regulations in every region they operate in.
The Linux Foundation’s decision to ban the Russian developers is most likely a response to legal advice, to avert a potential clash with the US administration. With geopolitical tension heating up, there are risks that open source software developers and maintainers from other countries may find that they, too, are being dropped from contributing to and supporting open source projects.
Read more on Open source software
Linux enters the cold war
By: Cliff Saran
Russian Linux kernel maintainers blocked
By: Cliff Saran
XZ backdoor discovery reveals Linux supply chain attack
By: Rob Wright
US tech used in Russian weapons, despite export controls
Welcome to the online version of From the Politics Deska newsletter that brings you the NBC News Politics team’s latest reporting and analysis from the White House, Capitol Hill and the campaign trail.In today’s edition, Lawrence Hurley and Katherine Doyle dive into the Trump administration’s recent string of victories at the Supreme Court. Plus, I break down some historical NBC News polling data that provides further context for our deeply polarized political climate. Sign up to receive this newsletter in your inbox every weekday here.- Adam WollnerTrump is on a winning streak at the Supreme CourtBy Lawrence Hurley and Katherine DoyleWhile President Donald Trump’s aggressive use of executive power has resulted in a flurry of lawsuits, administration officials have won a series of high-profile victories at the Supreme Court in part due to careful case...
Starmer says digital ID cards an 'enormous opportunity' for UK and will make working illegally tougherKeir Starmer says plans for a new digital ID held on people’s phones will be an “enormous opportunity” for the UK and make working illegally tougher.
Digital ID will become mandatory as a means of proving the right to work under the plans, but people will not be required to carry or asked to produce it. It will be available to UK citizens and legal residents by the end of this parliament, reports the PA news agency.
Starmer said: I know working people are worried about the level of illegal migration into this country. A secure border and controlled migration are...
Mr. Peter Obi, presidential candidate of the Labour Party in the 2023 elections, has clarified his goodwill message to Oba Rashidi Adewolu Ladoja, the newly crowned traditional ruler.
Obi had referred to the monarch as his “dear brother” in a congratulatory message, a choice of words that drew criticism from some quarters who considered it a breach of protocol.
In a statement on Sunday via his X handle, Obi said his words were borne out of goodwill and not intended to cause disrespect.
His words: “I felicitated with my dear elder brother, the newly crowned, His Royal Majesty, Oba Rashidi Adewolu Ladoja.
“I have read the concerns of those aggrieved by what they considered improper addressing. I respect protocol and authority, and I try, as much as possible, to adhere to them.
“However, those who follow me would have noticed...
"Our children are being radicalized to hate our city and our country," he stated.September 29, 2025 2:32pm
Adam Gray/Getty ImagesEric Adams has officially bowed out of the 2025 New York City mayoral race, leaving the city’s political future wide open.
In a farewell video from Gracie Mansion on Sunday (Sept. 28), the mayor didn’t hold back, warning New Yorkers about a wave of “extreme” politics he says is threatening the stability of the city he’s spent a rocky first term leading.
“Extremism is growing in our politics,” Adams said. “Our children are being radicalized to hate our city and our country. Political anger is turning into political violence.” While he didn’t name names, his remarks were likely a jab at Zohran Mamdani, the 33-year-old Democratic front-runner from Queens, whose campaign includes a $9 billion plan focusing on...
You've been blocked by network security.To continue, log in to your Reddit account or use your developer token
If you think you've been blocked by mistake, file a ticket below and we'll look into it.Log in File a ticket
Honest, paywall-free news is rare. Please support our boldly independent journalism with a donation of any size.As officials with Hamas say they will respond “soon” to President Trump’s ceasefire proposal to end Israel’s nearly two-year war on Gaza, brokered with Middle East envoy Steve Witkoff, we look at the many other deals Witkoff and his family are involved with. A New York Times investigation reveals that when Witkoff, a real estate developer and longtime friend of Trump, began his new position as a diplomat in the Middle East, his son Alex took over his company, the Witkoff Group. Since then, not only has the Witkoff Group continued to ink major deals with investors in...
A clash over the Affordable Care Act that has led to a shutdown of the federal government has ramifications for public health as agencies cease some services. The Trump administration vows mass layoffs during the impasse.
The shutdown centered largely on a disagreement over the Obama-era health law. Democrats want a further extension of enhanced subsidies that reduce ACA health insurance premiums, but GOP lawmakers insist any debate wait until after a budget deal is reached to keep the federal government afloat.
With the sides far apart, federal funding ran out at midnight Oct. 1 after Congress failed to pass even a stopgap budget. The issue now is how long the deadlock will continue.
In a KFF poll released today, more than three-quarters — 78% — of the public say they want Congress to extend the enhanced tax...
The Trump administration will start mass layoffs of federal workers if the president decides negotiations to end the government shutdown are “absolutely going nowhere,” a senior White House official has said.
Kevin Hassett told CNN he still saw a chance that Democrats would back down, but added that Trump was “getting ready to act” if he has to.
No tangible signs of negotiations have emerged between congressional leaders since Trump met with them last week. The shutdown began on 1 October, after Senate Democrats rejected a short-term funding measure that would keep federal agencies open through to 21 November. Democrats are demanding that funding include healthcare measures for low-income Americans.
“They’ve refused to talk with us,” Senate Democratic leader Chuck Schumer told CBS, saying the impasse could be solved only by further talks between Trump and the four...
In a nation as diverse as Nigeria, where faith often intersects with politics and daily life, questions about the spread of extremist ideologies demand urgent attention. The notion of a “Quran Atlantic” evokes fears of radical Islamic influence expanding beyond borders, potentially fueling jihadist agendas aimed at dominating non-believers.
This concern stems from ongoing violence that many see as part of a broader strategy to impose strict interpretations of religious law on secular societies. In Nigeria, the integration of Sharia law into the constitution since 1999 has sparked debates about fairness and equality.
While intended to govern personal matters in northern states, its application often appears selective, targeting the vulnerable while sparing the powerful. Residents in these areas complain that poor individuals face harsh punishments for minor offenses, such as theft or adultery, leading to amputations or...
One party has held court over Welsh politics for more than a century.
Welsh Labour MPs have been the largest group sent to Westminster in every general election since 1922 - and the party has been in government in the country for more than a quarter of a century.
But if the polls are accurate, Labour's long-standing grip on politics in Wales is fading.
Politics latest - follow live
Plaid Cymru and Reform UK are running almost neck and neck, while Labour trails significantly. A recent YouGov poll put Plaid Cymru on 30%, Reform UK on 29% and Labour at 14%.
Plaid Cymru, heading into its conference this weekend, can sense the mood for change in Wales - and intends to show it is ready for government. ...
Welcome to the online version of From the Politics Deska newsletter that brings you the NBC News Politics team’s latest reporting and analysis from the White House, Capitol Hill and the campaign trail.In Friday’s edition, four of NBC News’ reporters in Washington dig into the next phase of the government shutdown standoff: layoffs ordered by the Trump administration. Plus, “Meet the Press” moderator Kristen Welker dives into Trump’s direction of the prosecution of old political adversaries.Sign up to receive this newsletter in your inbox every weekday here.— Scott BlandTrump's latest shutdown move: 'Substantial' federal layoffsBy Sahil Kapur, Yamiche Alcindor, Monica Alba and Laura StricklerThe Trump administration announced Friday that it has begun “substantial” layoffs of federal workers, as the government remains shut down due to the inability of Congress to reach a funding deal. “The...
True colours: The writer suggests that there needs to be an attitude change within the structures of South African political parties, putting emphasis on ethics and leadership training for candidates. Photo: Delwyn Verasamy On 14 September,...
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.