32-bit x86 Position Independent Code - It's that bad https://ewontfix.com/18/ (makes a compelling argument for private-by-default I think)
miniblog.
Related Posts
One big challenge of open source is that the number of users (and bug reports) is entirely independent of the number of maintainers. Both users and maintainer capacity can fluctuate wildly.
A new speculative execution vulnerability in CPUs: https://www.theregister.co.uk/2019/03/05/spoiler_intel_processor_flaw/
Attacks only get sophisticated over time, and this is a great example of other researchers finding similar issues. This vulnerability is independent of Spectre.
Google is setting up an independent committee for the AMP standard: https://www.theverge.com/2018/9/18/17871666/google-amp-open-source-committee-governance-instant-article