It's an alternative explanation all right

I've recently had to zero score SpamAssassin ENCRYPTED_MESSAGE rule as it's being exploited. Also I don't receive any encrypted messages.

> Also I don't receive any encrypted messages.

Should start giving people your public key then!

Yes, and email address.

I'd hope these other critical services at least sign their packages

Yes. But IIRC there have been attacks on Debian package fetching anyways.

Why do you want ssh if you don't have network :)

in fact i noticed this bug when ssh doesn't come up on qemu vms start on a laptop without wifi connection.

hardly Far from a 99% use case.

loopback address space is not enough for the network target

The VPN is just part of the picture (sock puppet accounts complaining about speed of dev, no meaningful history of other contributions from the dev, no trusted "personal network" for the dev, etc) that in hindsight should have raised red flags.

If they constantly are on a VPN and not willing to disclose a real location or IP then I fail to see why they should be trusted when they don’t provide anything trustworthy themselves.

new project idea: OpenBackgroundCheck

volunteer osint researchers attempt to dox any identity you submit, so you can know whether they're the Right Kind of OSS contributor or not.


I suppose they're getting at why was it important that Redis was open source to you? Under the assumption someone else would be responsible for free updates?

This accusation is not consistent with what you're replying to.

"Jigar Kumar" seems to have disappeared

true, that is suspicious as well. A person that hasn't even created any bugs or issues suddenly has a big problem with the speed of development? Especially the way this was phrased: "You ignore the many patches bit rotting away on this mailing list. Right now you choke your repo. Why wait until 5.4.0 to change maintainer? Why delay what your repo needs?"

"Why delay what your repo needs?" This sounds like scammer lingo

5% of contributions is not “mainly” from AWS

Not for redis the company if they follow mongodb’s trajectory

I think part of the issue and what the judge didn't like is he doesn't seem to have any remorse.

Sure, and that certainly means any rehabilitation would be harder, and we'd be right to be skeptical of the results of that rehabilitation (as in, is he just pretending to be rehabilitated).

