
Who's going to pay to fix open source security?
About this episode
Will no one think of the maintainers? As The New Stack points out, watching millions of projects fail because of a bug in an open source library has become common enough that we shrug and reply, "Told you so." It's gotten so bad, big tech companies are visiting the White House to discuss the issue as a matter of national security.
There is a great post up on the Stack Overflow blog examining this issue, but it's not about color.js, it's about Log4J. Traffic to questions on this logging library grew more than 1000% percent after the recent revelations about a new vulnerability.
Also discussed in this episode: cryptographer and Signal creator Moxie Marlinspike stepped down from his role as CEO of the encrypted messaging service. That's news, but he actually made bigger waves in tech circles with an unrelated blog post detailing his first experience with Web3. Spoiler alert: it's not as decentralized or divorced from Web2 as you might have thought.
You can find Cassidy Williams on Twitter and her website.
Ben Popper can be found on Twitter here.
Ryan Donovan can be found on Twitter, or writing for the Stack Overflow blog.
See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Get every episode summarized
Each time The Stack Overflow Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Stack Overflow Podcast

Connecting the dots for accurate AI
The Stack Overflow Podcast

AI giveth and AI taketh CPU
The Stack Overflow Podcast

What (un)exactly do you mean by semantic search?
The Stack Overflow Podcast

Time is a construct but it can still break your software
The Stack Overflow Podcast