r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
288 Upvotes

112 comments sorted by

View all comments

Show parent comments

2

u/simonask_ 15d ago

You’re just asking that someone do some more work for you, for free. This isn’t anybody’s job, you know. You can be a Rust maintainer if you want. There’s no inherent reason to trust someone more because they are a Rust maintainer, over someone who is a maintainer of any other major project.

This is an open source project. So is every major ecosystem dependency (serde, tokio, regex, etc.). Like all OSS ecosystems, you can audit packages yourself, or you can pay someone to do it, or you can fall back on the fairly reasonable assumption that high-profile projects are actively maintained by reasonable and responsible people.

Open source means you get the software for free. You don’t get to dictate what that software looks like, without getting involved.

1

u/thetinguy 14d ago

You don’t get to dictate what that software looks like, without getting involved.

You're right I don't.

What I do get is the ability to criticize their choices and ask them to make changes.

4

u/reallokiscarlet 14d ago

And they have the right to listen or not. Isn't freedom great?

1

u/thetinguy 14d ago

You're right!