pull down to refresh

That is what I was thinking. For all the people who are saying the error was novice, the commit notes were shit, and the warning signs were being waved, I sure didn't hear anything too bad about coldcard until a few days ago (except the open source shit).

I don't often make github commits, so I'm not sure what is acceptable there, but things like dusty's article make me feel like apparently absolutely no one looked at their repo before now. But I see that Sjors was a contributor as well as Portland Hodl and Xavier Fiechter, Na Ava Chow and Pythcoiner. These are all serious people who are listed as contributors on Coldcard's github. Am I to believe that they all somehow missed these now glaring process errors and amateur code?

686 sats \ 6 replies \ @Kruw 2 Aug

A "Contributor" to a project does not incur any obligation to review existing code. It is the maintainer's responsibility to assure nothing bad gets merged and deployed.

reply

Sure, but presumably, in the process of making their contribution they might have peeked at the existing CC code...

reply

No. That is not a reasonable assumption.

reply

I didn't realize this. Thanks for the clarification.

reply

Just think of it this way: we're both contributors to SN code. Did you review the code I wrote for opentimestamps and see any strange things there?

reply
127 sats \ 1 reply \ @Scoresby 2 Aug

Ah, that does make sense.

As a non dev, I think that it is likely many people have the same faulty understanding of what "contributor" implies.

Not sure that there is really anything to be done about that, but thanks to your comment, I at least will not make that error again.

reply

It's a fairly common thing so don't take that as criticism. I think that it is caused by people, most often not the actual subjects, that like to assign meaning to work and people, often more than is due. Create a framework where there is some kind of order that only exists in the mind of the narrator, not reality. We see this often when we hear accusations against groups of devs too; always from outsiders.

When you review something, you'll use git blame a lot, to try and find context. I rarely look at the name. I just need the commit. And go. The name is useful if you're working off a huge codebase and you wanna send an email to the author about it. But otherwise it has no meaning.

Most commits (what GH counts) I've done as an independent contributor (hundreds) were focused on very narrow things. In fact, I've had bigger proposals declined with "sorry you're not the maintainer and this changes too much" - which imho is still a bit eww, but if no one is going to review it, might as well not work on it. I rarely propose large things since a decade or so. The best change is removing 10 lines and adding 2.

reply

Think of the Contributors section as an exhaustive list made automatically by GitHub, not those behind the repo. Example: once I did one minor commit for work, did not do anything else, never really took a look at the entire repo and yet was added.

Same for Ledger, I saw someone blaming them but they are not paid to review the code of Coinkite, probably they looked for a vulnerability on the hardware only.

reply
Am I to believe that they all somehow missed these now glaring process errors and amateur code?

It's easy to in hindsight label something amateur code. If you didn't say it before the breach, your words do not have meaning. There is learning to be done. For all of us.

reply