Live data from Hacker News

Being Thankful for Free Software Developers

fosspost.org

81–90 of 105 posts

Re: Being Thankful for Free Software Developers

#81
post #67
post #31

I wish it was that attractive to just switch from “expensive and evil proprietary software” as the author suggests. 1. The article claims that Microsoft Office 365 is $100 a year. In reality it's about $70, home license for up to 5 users is $80. 2. The article does not mention that every Office 365 user gets bunch of additional services. For example, a tebibyte of space in Microsoft OneDrive for each user, 60 Skype m…

> But overall, an antivirus is not necessary in modern Windows system, so you may skip on these $40. Er. . .no, that's not true. AV and AM are very important to this day. You just don't have to pay any money to get them, between things like AVG, Avast, and MalwareBytes. These aren't Free as in freedom, but they are Free as in beer for very reliable AV. And on an enterprise network, you're probably going to be pretty…

I used to be fairly neutral regarding AV's. Then I saw all the really stupid and really serious vulnerabilities Tavis Ormandy dug up in pretty much all the AV products, including the Symantec Endpoint Protection (https://googleprojectzero.blogspot.com/2016/06/how-to-compro...).

The sheer amount of incompetence and neglect displayed by AV vendors has made me strongly question third-party AV's being a net positive.

Re: Being Thankful for Free Software Developers

#82
post #67

Earlier quoted context omitted.

> But overall, an antivirus is not necessary in modern Windows system, so you may skip on these $40. Er. . .no, that's not true. AV and AM are very important to this day. You just don't have to pay any money to get them, between things like AVG, Avast, and MalwareBytes. These aren't Free as in freedom, but they are Free as in beer for very reliable AV. And on an enterprise network, you're probably going to be pretty…

I used to be fairly neutral regarding AV's. Then I saw all the really stupid and really serious vulnerabilities Tavis Ormandy dug up in pretty much all the AV products, including the Symantec Endpoint Protection ( https://googleprojectzero.blogspot.com/2016/06/how-to-compro... ). The sheer amount of incompetence and neglect displayed by AV vendors has made me strongly question third-party AV's being a net positive.

At the end of that article, the writer directly thanked the Symantec team for fixing these problems quickly.

Every company has vulnerabilities. How they respond when told about these vulnerabilities is much more important, and, at least by this account, Symantec is pretty responsible when it comes to responding to the discovery of these vulnerabilities.

And, to be clear, in the past year so, Symantec has been investing heavily into their own security. You can say "They should have done it before" all you want, but the fact that they're doing it speaks to, at the very least, the current leadership's competence.

Especially with the purchase of Blue Coat, they seem to want to bolster their offerings in a more meaningful way than "we give you virus definitions". Given Blue Coat CAS did and continues to use third party virus engines, even post purchase by Symantec, that would imply that Symantec is trying harder to improve their product.

EDIT: Full disclosure, I work heavily with Symantec products, but I do not work for them directly. It's my job to provide _support_ for Symantec products, not to sell them to people.

Re: Being Thankful for Free Software Developers

#83
post #64

Earlier quoted context omitted.

I'm all for free software. Really, I am. I just have a problem with the idea that free software is absolutely the only way to go. I have no problem with people who refuse to run non-free software. I have a problem when they insist that I'm doing it wrong by running Windows. Sent from my Fedora-running laptop.

Free software activists and advocates are often accused of "user shaming". And they often do. Generally speaking, it's difficult to both consider and balance others opinions when you have a hard-line stance on something. It's a sign of experience and empathy when you can. Not everyone can. With regards to software freedom: we wish that nobody would have to sacrifice their four freedoms to use proprietary software, bu…

Back in the day when my status as Person Who Knows Computers meant being frequently called on to (re)install computers and get rid of malware and what not, my little stance for free software was refusing to install pirated software. And once people saw what a Microsoft Office license actually costs, suddenly OpenOffice looked very attractive.

Re: Being Thankful for Free Software Developers

#84
post #70
post #51

Inspired by this I went over to donate money to Arch Linux, since I've just been getting nothing but joy from using it for the last 2 years. They use Click2Pledge which, frankly, is a UX which is a tad frightening, but I'm not a snob so I carry on. And then I find that of all the countries in the world they seem to have left Ireland out (Eire, Republic of Ireland, no, nothing). I mean they have the Isle of Man - but…

Careful with re-invention. I was going to suggest SPI, but funny enough they're already on the list at: https://www.spi-inc.org/projects/ I see the arch linux web page links to "click to pledge" service as reported, which apparently is extremely limited in legal coverage area, but the SPI Inc web page for arch links to a paypal link, and paypal seems to "work" in most countries on the planet. Back when it took 5000 b…

Oh that's great. I'll do it there now. They really should link straight to that page instead of the Click2Pledge...

Re: Being Thankful for Free Software Developers

#85
post #51

Inspired by this I went over to donate money to Arch Linux, since I've just been getting nothing but joy from using it for the last 2 years. They use Click2Pledge which, frankly, is a UX which is a tad frightening, but I'm not a snob so I carry on. And then I find that of all the countries in the world they seem to have left Ireland out (Eire, Republic of Ireland, no, nothing). I mean they have the Isle of Man - but…

>So what all these guys need is a separate FOSS organisation exclusively dedicated to fund-raising.

Not sure if totally FOSS, but non-commercial and tranparent: https://opencollective.com/

Re: Being Thankful for Free Software Developers

#86

Earlier quoted context omitted.

>this is capitalism at it's finest If by capitalism, you mean: >an economic and political system in which a country's trade and industry are controlled by private owners for profit, rather than by the state. Then no, because FOSS is not private or for profit.

Read the other comments in this thread. No shortage of profits. Monetary, and otherwise.

Indeed there can be profits gained from FOSS but they are required, and FOSS still doesn't meet the "private" ownership qualification of capitalism.

Re: Being Thankful for Free Software Developers

#87
post #47
post #28

The should be thankful, but they do not know. FOSS doesn't spend money on PR. Few know that free Linux lurks under Android, and OS/X an iOS have large parts of BSD in them.

> free Linux lurks under Android Not only that, but the GUI is also FOSS: https://source.android.com/ > OS/X an iOS have large parts of BSD in them. I think this gives the wrong impression. The interesting parts of macOS and iOS are GUI and drivers, which are proprietary.

The interesting parts of macOS and iOS are GUI and drivers, which are proprietary.

The best parts of OSX are brew, iTerm2, and FileMerge.

(Edit in reply to below: Yes, that's my point. brew and iTerm2 are FOSS, FileMerge is part of XCode)

Re: Being Thankful for Free Software Developers

#88
post #47

Earlier quoted context omitted.

> free Linux lurks under Android Not only that, but the GUI is also FOSS: https://source.android.com/ > OS/X an iOS have large parts of BSD in them. I think this gives the wrong impression. The interesting parts of macOS and iOS are GUI and drivers, which are proprietary.

The interesting parts of macOS and iOS are GUI and drivers, which are proprietary. The best parts of OSX are brew, iTerm2, and FileMerge. (Edit in reply to below: Yes, that's my point. brew and iTerm2 are FOSS, FileMerge is part of XCode)

Those aren't part of OSX though.

Re: Being Thankful for Free Software Developers

#89
post #82

Earlier quoted context omitted.

I used to be fairly neutral regarding AV's. Then I saw all the really stupid and really serious vulnerabilities Tavis Ormandy dug up in pretty much all the AV products, including the Symantec Endpoint Protection ( https://googleprojectzero.blogspot.com/2016/06/how-to-compro... ). The sheer amount of incompetence and neglect displayed by AV vendors has made me strongly question third-party AV's being a net positive.

At the end of that article, the writer directly thanked the Symantec team for fixing these problems quickly. Every company has vulnerabilities. How they respond when told about these vulnerabilities is much more important, and, at least by this account, Symantec is pretty responsible when it comes to responding to the discovery of these vulnerabilities. And, to be clear, in the past year so, Symantec has been investi…

> Every company has vulnerabilities. How they respond when told about these vulnerabilities is much more important, and, at least by this account, Symantec is pretty responsible when it comes to responding to the discovery of these vulnerabilities

How about eliminate the attack vector in the first place? No third-party AV, no problems.

The more they extend their offerings, the more features they add, the more they extend the attack surface. And the attack surface of an average AV product is HUGE.

Considering the raw amount of incompetence displayed, not having a third-party AV in the first place seems like a reasonable choice. Want something scanned? Run it through Virus Total or something. Done.

Re: Being Thankful for Free Software Developers

#90
post #82

Earlier quoted context omitted.

At the end of that article, the writer directly thanked the Symantec team for fixing these problems quickly. Every company has vulnerabilities. How they respond when told about these vulnerabilities is much more important, and, at least by this account, Symantec is pretty responsible when it comes to responding to the discovery of these vulnerabilities. And, to be clear, in the past year so, Symantec has been investi…

> Every company has vulnerabilities. How they respond when told about these vulnerabilities is much more important, and, at least by this account, Symantec is pretty responsible when it comes to responding to the discovery of these vulnerabilities How about eliminate the attack vector in the first place? No third-party AV, no problems. The more they extend their offerings , the more features they add, the more they e…

That's not exactly a scalable solution. You have to keep in mind that large companies often have thousands of requests they have to process every _second_. VT is great, but I doubt they'd be happy if they were getting DDoS'd by every major corporation that wanted to run signature checks they didn't have cached.

EDIT: I also think you're misunderstanding. Symantec Endpoint Protection isn't the one that has multiple AV engines. Their (well, Blue Coat's) CAS appliance uses them.

Post reply on HN