oss-sec mailing list archives

Re: Some Changes to GNOME Security Tracking


From: Yves-Alexis Perez <corsac () debian org>
Date: Mon, 03 Aug 2026 10:19:25 +0200

On Fri, 2026-07-31 at 12:42 -0400, Eli Schwartz wrote:
Projects that reject truthful security reports are putting their users at
risk.


Correction: Linux Foundation stakeholders such as OpenAI, Anthropic,
Microsoft, Google, Facebook, NVIDIA, Oracle, etc. are putting GNOME (and
other project) users at risk.

I heard that the Linux Foundation has declared the danger of "AI
vulnerabilities" is so great that they are founding a group called
Akrites, devoted to coordinating security incident response. Members can
pay their dues in LLM compute credits. If projects don't fix their
software "fast enough", Akrites will declare themselves the "maintainer
of last resort" to publish a fixed version.


Yes, that's right, not "we will provide the fiscal support you've been
lacking for 20 years that resulted in you being so sick and tired of
slaving away for free that you declared Enough Is Enough and drew a
moral line in the sand about what constitutes harassment and bullying".

Instead, the Linux Foundation will fork your project and declare
themselves the new maintainers and "fix it without you".

Hey,

I heard about Akrites but missed the fine prints about this. Could you point
us to where they talk about this (I assume it's not written exactly like this
but still I'd be interested in reading it).

Regards,
-- 
Yves-Alexis


Current thread: