Live data from Hacker News

Microsoft acquires Github

blogs.microsoft.com

731–740 of 840 posts

Re: Microsoft acquires Github

#731
post #696

Earlier quoted context omitted.

> once called open source a cancer There are some really good arguments as to why we should be worried about Microsoft so can we please stop ruining them by using this complete misquote as a component. This comment covers it well: > This is disingenuous. He was referring to the licensing model of certain open-source projects, where the introduction of a single line of code coming from an open source project would req…

To be more precise, this is what Steve Ballmer said back in 2001: > [...] Linux is a cancer that attaches itself in an intellectual property sense to everything it touches. That's the way that the license works. https://web.archive.org/web/20011108013601/http://www.suntim...

I think this is a case of "it doesn't look good, but the more you think about it the less bad it looks." There's a kernel of truth in the unfortunate wording. GPL (certain versions) is problematic if you want to keep your related code closed source. When I interned at Microsoft, you had to get approval from legal to use open sourced code specifically for copyright liability reasons.

I'm sure Ballmer also disliked Linux for other reasons, but this line makes for an ambiguous example of it.

Given that Microsoft has been pretty enthusiastic about tools like VSCode and Linux support on Azure, I'm personally cautiously optimistic with Nadella at the helm.

Re: Microsoft acquires Github

#732

When Microsoft acquired Skype, there were a subset of accounts that essentially became un-useable for close to 2yrs. There was a sub-sub case where if you had a Skype ID that was an email (not a username) which was also a pre-existing Microsoft email, your profile became unreachable and passwords could not be reset either. This is from personal experience and validated with a half dozen other people in the same sub-s…

Thank you for saying the Skype ID thing here. I thought I had gone crazy....

Re: Microsoft acquires Github

#733
In all these years, GitHub didn't make a single penny as profit

Like most "successful" startup companies over the past decade, only way (for investors) to make money was to make the company a "product" that would be sold to the highest bidder

Why is anyone surprised that GitHub would be sold ?

Re: Microsoft acquires Github

#734

Earlier quoted context omitted.

Corporations aren't people. If you change the leadership and change employee incentives, it might as well be a different company. Sure there's cultural inertia... but incentives trump culture every time.

The thought that Satya Nadella, who joined Microsoft in 1992 and then steadily climbed his way (in extremely fierce competition) to the top would be a better, more moral person than the "old guard" is kind of funny. He's just younger and less out of touch than Gates (and particularly Balmer). Many people seem to mistake ascribe this aspect of him (more in touch with modern tech) with some higher moral standards etc t…

No CEO of a company of that size is not fierce and brutal.

I agree with your assessment. For me MS motives are pretty transparent and in my opinion will have a positive net result for GitHub.

Re: Microsoft acquires Github

#735
post #685
post #599

Earlier quoted context omitted.

Whenever I read these kinds of posts on this website I think of Sterling Hayden in Dr. Strangelove. (The crazy SAC commander who thinks the Russians are plotting to steal Americans' precious bodily fluids). I understand that people don't trust the NSA/US government. And they shouldn't: the US government will always put its interests above yours and mine, and above those of allied countries. At the same time, this stu…

I didn't mean that this is going to happen. I wanted to give an example of a potential threat. My idea was to show one of many problems with centralization and relying so much in GitHub and GitHub SSL certs. Maybe we can start signing our commits to increase security giving the potential threat. The same way that after the Snowden revelations we started using more and more HTTPS. We can also think of better ways of s…

> I wanted to give an example of a potential threat.

I really don't like this line of thinking. It's the same one used by news organizations to plump up their stories, or by politicians to make an improbable threat seem more real. In both of those cases, I think the long-term effect is to cause the public to think that very rare events are a lot more common. The result is not a culture of wariness but a culture of fear.

I'd much rather people present "worst-case potential threats" instead as "likely potential threats."

Re: Microsoft acquires Github

#736
post #679

Earlier quoted context omitted.

* Drop Windows and contribute to WINE * Drop OOXML and make ODF the default format * Drop the patents * Drop the telemetry * Drop Xbox * Drop DirectX * Drop the cloud garbage * Drop or open MSVC * Drop or open Edge * Actually open .NET

so microsoft should just shut down the company?

In the end his statement is not against Microsoft but capitalism.

Re: Microsoft acquires Github

#737

Earlier quoted context omitted.

> once called open source a cancer There are some really good arguments as to why we should be worried about Microsoft so can we please stop ruining them by using this complete misquote as a component. This comment covers it well: > This is disingenuous. He was referring to the licensing model of certain open-source projects, where the introduction of a single line of code coming from an open source project would req…

It's not a misquote and it's not disingenuous. That was their attitude at the time.

It is a misquote. See above. He was talking about Linux not open source, and specifically about the licence that Linux has chosen to use.

It would be entirely reasonable to find it an objectionable comment nonetheless, but please find objectionable what he actually said, not some alternative version.

Re: Microsoft acquires Github

#738
post #422

This is a wake up call. Too many things are relying on Github right now. Microsoft was part of the PRISM program. If Microsoft shares SSL certs with NSA they could do MITM attacks. What if in some very specific cases you download dependencies from GitHub and they give you a different version with malicious code? It's the NSA. They could be smart enough to only deploy those attacks on production servers were nobody is…

They could also do it regardless of whether or not Microsoft owns them or whatever favorite acronym authorizes them, or whatever. I've never understood why people love freaking out about this stuff. If the NSA felt like spying on you, pro tip, they're gonna be able to do it. If you care about keeping your shit secure, it shouldn't be on the internet at all.

> If the NSA felt like spying on you, pro tip, they're gonna be able to do it.

True, but I suppose it matters how easy/difficult it is for them to do that.

Re: Microsoft acquires Github

#739

When Microsoft acquired Skype, there were a subset of accounts that essentially became un-useable for close to 2yrs. There was a sub-sub case where if you had a Skype ID that was an email (not a username) which was also a pre-existing Microsoft email, your profile became unreachable and passwords could not be reset either. This is from personal experience and validated with a half dozen other people in the same sub-s…

When they kill the Octocats I will get a life crisis. And I am a Microsoft fan.

Re: Microsoft acquires Github

#740

Earlier quoted context omitted.

Your intention is correct, but your details are not (as are the OPs). Microsoft share's it's SSL certs with the entire planet. Microsoft protects it's private keys and does not share them with the NSA. The NSA forges Microsoft's SSL keys, they do not need to ask for them. https://en.wikipedia.org/wiki/Flame_(malware) Even with the mitigations provided by moving away from MD5, simple integration with a CA would be muc…

Thanks. I skimmed GGP's comment and assumed it said something slightly more correct than what it actually said and then copy-pasted his error. > Even with the mitigations provided by moving away from MD5, simple integration with a CA would be much more strategically beneficial. Returning to the point, this attack would be unaffected by Microsoft purchasing anything.

> Returning to the point, this attack would be unaffected by Microsoft purchasing anything.

I was agreeing with you :)

Post reply on HN