The Ledger

Every statement that passed quotation and attribution checks. Mix any filter with any other: certainty 1/5, debate potential 5/5, or both at once.

clear all ✕

why aren't all 6 resolved? a statement only gets an assessment when the public record can support or contradict it. opinions and what-ifs never can, and 0 checkable ones are still open, waiting for their date. predictions held up or didn't; assertions are supported or contradicted. on every card: ▮▮▮▮▮ certainty · ▮▮▮▮▮ debate potential. speakers are clickable

Assertion Supported
Eghbal: OpenSSL had only one paid maintainer when Heartbleed hit
“There was, like, a very critical bug that was found in OpenSSL, and the question Was, well, why did nobody find this before? And the answer was, because there are, like, two, there's one paid person, and there's, like, 10 volunteers that are working on this.”
Nadia Eghbal Jan 2, 2019 ▶ 21:00 a16z Podcast | The Changing Culture of Open Source
Assertion Not checkable as stated
Yahya: OpenSSL Heartbleed stemmed from open source's failure to capture value
“And this has been historically a big problem in open source, like, for example, in the world of which is generally open source, like for example, the Heartbleed bug in SSL is interesting because even though SSL is a critical piece of infrastructure, and is use…”
Ali Yahya Jan 2, 2019 ▶ 24:22 a16z Podcast | Cryptonetworks and Cities -- Analogies
Insight
Eghbal: Open-source popularity and project health are separate metrics
“So you can have projects like OpenSSL might be a project that was really, really popular. Lots of people use it, but not actually healthy. Until we separate those things out, then you have the problem of people saying, well, if it's, you know, if no one's main…”
Nadia Eghbal Jan 2, 2019 ▶ 7:36 a16z Podcast | The Changing Culture of Open Source
Assertion Not checkable as stated
Vitalik: OpenSSL underfunding directly caused the Heartbleed bug
“Bottom-level protocols are something that's been, like, so horribly underfunded. You know, like, in the mainstream world, if you look at even something like the hard bleed bug, which happened in large part because OpenSSL security research was just, like, so h…”
Vitalik Buterin Jan 2, 2019 ▶ 38:20 a16z Podcast | Ethereum, App Coins, and Beyond
Assertion Not checkable as stated
Hindawi: Tanium queries enterprise OpenSSL versions across all endpoints in 15 seconds
“Our customers literally could ask an English language question. Tell me all the machines and versions of open SSL for every machine that's got open SSL across the environment and get an answer back in 15 seconds.”
Orion Hindawi Jan 2, 2019 ▶ 13:55 a16z Podcast | When Large Scale Gets Really Massive -- Managing Today’s Enterprise Networks
Assertion Not checkable as stated
Ali Yahya: OpenSSL underfunding highlights open-source value capture failure
“Even though SSL is a critical piece of infrastructure and is used by sort of every single person in the world who connects to the internet only a couple of people were really in charge of maintaining the implementation of OpenSSL. And so, not enough of the val…”
Ali Yahya Jul 26, 2018 ▶ 23:29 Cryptonetworks and Cities: Analogies
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.