Live data from Hacker News

A response to the git.centos.org changes

redhat.com

111–120 of 184 posts

Re: A response to the git.centos.org changes

#111
post #63

Earlier quoted context omitted.

Why? What compliance reasons make Ubuntu LTS work and RHEL not work?

Stupid auditors/pentesters really. Explained a bit in another comment, but essentially we had to explain the concept of backporting cve fixes to the same 'version' of random libs to the auditors and to get certified we would have to demonstrate, with actual source, that each of ~200 or so cve's were fixed in various system parts (individually). In the end, we just went with ubuntu for those nodes, and they all passed…

The issue here is with your auditors. I mean if RH tells you a CVE has been fixed with a backport, sure you can challenge that fact but at the same time and with the same standards, it'd mean your auditor would also have to check the actual source of your patched Ubuntu packages to make sure the new versions fixed the security bugs.

The bottom line really is plenty of auditors I've seen don't know how to check for vulnerabilities other than by checking a version... That's it.. Their tools or reporting only know package must have a version greater than x.y.z.

Re: A response to the git.centos.org changes

#112

Earlier quoted context omitted.

Funny; our RHEL systems were a nightmare for compliance actually. Most of the tools the auditor/pentester type people use only search for, (completely fake example) libfoo 1.x.2 having a security hole, and redhat's libfoo 1.x.2-wibble13 even though it has a backported fix, is flagged as vulnerable. For each one of these packages, it's a crazy process to prove that the CVE they reported isn't actually there, and it de…

t.b.h. all this tells me is that your pentesters are bad.

Pretty much but that's my experience as well, I made the same comment above...

Re: A response to the git.centos.org changes

#113

We don’t simply take upstream packages and rebuild them Are they seriously claiming they contribute to every one of the tens of thousands of packages they include in their repo? I'd like to see some proof of that. If they're taking any open source app, and just including it in their repo without at least 1 RH patch.. then they are "simply tak[ing] upstream packages and rebuild[ing] them". RedHat absolutely makes mone…

RHEL is only a couple of thousand packages, and yes Red Hat absolutely does contribute to many, many packages that we use. Probably not every single one, but most of them and most definitely every one that needs fixes. The principle is called "upstream first".

Re: A response to the git.centos.org changes

#114
There is an opportunity here for Amazon to take some of this goodwill IBM/Red Hat is losing. Make Amazon Linux run nicely outside of AWS with (free) LTS. Charge for support for those who need it.

When Oracle messed with Java LTS AWS did Corretto LTS. When Elastic did Elasticsearch license change, Amazon/AWS did Opensearch.

They don't need to support esoteric hardware (at least other than their own).

Re: A response to the git.centos.org changes

#115
post #29

Whats said in this blogpost may be 100% true, and of course red hat does do a lot for the community, but unfortunately the damage is done. Its always going to feel like: * Red Hat was a bastion of open source * Red Hat sold out to IBM * Red Hat stopped being Red Hat, and started being IBM by focusing on $$ over open source * Red Hat reputation degrades as $$ are put first, killing off centos, now this, just downhill…

I really don’t see it that way. If I want a free-of-charge RHEL, I’ll get CentOS.

I don’t understand the “killing off CentOS” thing. I’m still using and it updates continuously.

Re: A response to the git.centos.org changes

#116
post #113

We don’t simply take upstream packages and rebuild them Are they seriously claiming they contribute to every one of the tens of thousands of packages they include in their repo? I'd like to see some proof of that. If they're taking any open source app, and just including it in their repo without at least 1 RH patch.. then they are "simply tak[ing] upstream packages and rebuild[ing] them". RedHat absolutely makes mone…

RHEL is only a couple of thousand packages, and yes Red Hat absolutely does contribute to many, many packages that we use. Probably not every single one, but most of them and most definitely every one that needs fixes. The principle is called "upstream first".

> The principle is called "upstream first".

This really is the Only Sane Way To Go, as you don’t want to support your patches forever. And reapply them on every release.

Re: A response to the git.centos.org changes

#117
post #52

Earlier quoted context omitted.

I am pointing out what I see as a trend. Linux hardware seems to be on the way to a lockdown by companies. How many proprietary bolbs are now needed to run Linux on many Laptops. This is a failure of the Linux Foundation to push back on proprietary hardware vendors, one blaring example is Nvidia. Even Linus has commened on Nvidia. The Foundation should stop allowing proprietary hardware in Linux, instead these vendor…

> Another example is Secure Boot, some laptop manufactures are no longer allowing Legacy Boot. Were is the Foundation on this issue. Instead Microsoft donates large amounts and nothing is said about who signs the keys. It is just about impossible for many people to install Linux (or a BSD) on some new hardware without jumping through Secure Boot Loops. I think you're wrong on this one. You seem to be mixing up UEFI v…

I have a laptop from 2k15 with Arch and secure boot. Since Arch doesn't have anything signed you can't even load the LiveISO without disabling secure boot, but what I was able to do was to sign everything myself + have the MS secure boot keys (or whatever they are called). This would allow me to dual boot with Win + Linux both using secure boot, which is nice to know for a certain game that insist on an overly restrictive anti-cheat.

Re: A response to the git.centos.org changes

#118
Rebuild code without changing also means learning. It doesn't end there, i also valid it's reproducible, which is good for the sake of software freedom and also security.

"Simply rebuilding code, without adding value or changing it in any way, represents a real threat to open source companies everywhere. This is a real threat to open source, and one that has the potential to revert open source back into a hobbyist- and hackers-only activity."

Re: A response to the git.centos.org changes

#119
post #29

Whats said in this blogpost may be 100% true, and of course red hat does do a lot for the community, but unfortunately the damage is done. Its always going to feel like: * Red Hat was a bastion of open source * Red Hat sold out to IBM * Red Hat stopped being Red Hat, and started being IBM by focusing on $$ over open source * Red Hat reputation degrades as $$ are put first, killing off centos, now this, just downhill…

I really don’t see it that way. If I want a free-of-charge RHEL, I’ll get CentOS. I don’t understand the “killing off CentOS” thing. I’m still using and it updates continuously.

From how I understand it:

Before the "killing of CentOS": CentOS is based off of RHEL (basically being identical with packages, just not "officially professionally supported", I think)

After the "killing of CentOS": RHEL is based off of CentOS (with CentOS-Stream being "the staging" for RHEL packages)

But I actually have no actual clue what haseen going on there and have just been somewhat following this entire "drama" with bbit of interest, so I might be completely wrong in how it actually work

Re: A response to the git.centos.org changes

#120
post #14

>Red Hat uses and will always use an open source development model Yes, I do not mean to sound harsh but I do not know how say this in a nice way. To me, this means we will still happily take work from our volunteers, but we will restrict other people from using this work so we can get more $. But thank you volunteers for keeping our payroll low and helping out our stockholders. I really think this is another small s…

[flagged]

[dead]
Post reply on HN