>[...] Incidentally, one of the Log4j maintainers’ GitHub sponsors profile is here, if you would like to contribute some money to his cause. [...] these companies should ponder which is more expensive: $100k/year salary for a maintainer of a project they are heavily dependent upon, I don't understand the logic of cause & effect the author laid out. Commercial software with well-paid programmer employees also have lon…
To secure the supply chain, you must properly fund it
31–40 of 59 posts
Re: To secure the supply chain, you must properly fund it
#32It's kind of crazy that Apple has had the greatest visionary CEO of all time (Steve Jobs) while also having the greatest supply chain manager of all time (Tim Cook). It's no surprise that Apple is the most valuable company in the world and also the most beloved brand.
Re: To secure the supply chain, you must properly fund it
#33>[...] Incidentally, one of the Log4j maintainers’ GitHub sponsors profile is here, if you would like to contribute some money to his cause. [...] these companies should ponder which is more expensive: $100k/year salary for a maintainer of a project they are heavily dependent upon, I don't understand the logic of cause & effect the author laid out. Commercial software with well-paid programmer employees also have lon…
> Commercial software with well-paid programmer employees also have long lists of CVE/RCE including MS Windows, Azure, AWS, Adobe PDF reader, Oracle database, etc. Exactly that. What paying some dev for open source work does is give you more ways to influence the direction of the projects. It can help you to put priority on fixing bugs which affect you. But it can't magically make disclosure work better. Also I would…
Re: To secure the supply chain, you must properly fund it
#34There is no reason to believe that money would actually solve the issue, and maybe even exacerbate it. The log4j issue is product debt, similar to the sqlite fts tokenizer exploit, and a lot of the openssl exploits, features that are rarely used, and are in the codebase for "no good reason" (from the majority of user's standpoint) I think the way to make for those things to happen less, is in fact, to code less, and…
The correct answer here isn't "pay people to make log4j even worse", it's "don't use log4j".
Re: To secure the supply chain, you must properly fund it
#35It's kind of crazy that Apple has had the greatest visionary CEO of all time (Steve Jobs) while also having the greatest supply chain manager of all time (Tim Cook). It's no surprise that Apple is the most valuable company in the world and also the most beloved brand.
I hope this post was sarcasm
I’m all for pet projects on HN, but it’s getting annoying with what seems to be more and more of these garbage comments made by bots and scripts.
Re: To secure the supply chain, you must properly fund it
#36Earlier quoted context omitted.
While contracts matter,relationships are also a thing - if you are donating and they are developing, you are funding development.
As a volunteer maintainer, if you want to donate money to one of my projects it’s because you find enough value in my work then you are free to do so to help continue development. If you want to donate money in order to exert some kind of control over how I spend my time, please keep your money.
Re: To secure the supply chain, you must properly fund it
#37Recently, they were used to raise millions for Ross Ulbricht's campaign for a sentence reduction.
Re: To secure the supply chain, you must properly fund it
#38>[...] Incidentally, one of the Log4j maintainers’ GitHub sponsors profile is here, if you would like to contribute some money to his cause. [...] these companies should ponder which is more expensive: $100k/year salary for a maintainer of a project they are heavily dependent upon, I don't understand the logic of cause & effect the author laid out. Commercial software with well-paid programmer employees also have lon…
> Commercial software with well-paid programmer employees also have long lists of CVE/RCE including MS Windows, Azure, AWS, Adobe PDF reader, Oracle database, etc. Exactly that. What paying some dev for open source work does is give you more ways to influence the direction of the projects. It can help you to put priority on fixing bugs which affect you. But it can't magically make disclosure work better. Also I would…
It also gives you assurance that the project maintainer is able to maintain that project full-time, and will not be otherwise occupied at $dayjob when a CVE arises. If a maintainer can only spend spare time on a project, its state can degrade pretty quickly.
Re: To secure the supply chain, you must properly fund it
#39NFTs are an ideal way for corporations to fund open source projects. When used as a fundraising tool by non-profit projects, they are a portable proof of contribution that confers status to the contributor, and thus incentivizes contributions. Recently, they were used to raise millions for Ross Ulbricht's campaign for a sentence reduction.
Re: To secure the supply chain, you must properly fund it
#40Pardon the tone but software people seem to be uniquely incapable of understanding real world complexity.
I’m genuinely curious what I might be missing.