You could just ask them to use an email address hosted outside of Russia for their kernel development work if visible compliance was the only issue. To not offer them a remedy and to exclude people on the basis of their first or last name is a bizarre overreaction to me. It stands no chance of damaging the Russian government and can only harm the project and open source in general, I'm not sure why a non-profit would…
[flagged]
On Linux MAINTAINERS file removal of Russian developers
11–20 of 84 posts
Re: On Linux MAINTAINERS file removal of Russian developers
#12You could just ask them to use an email address hosted outside of Russia for their kernel development work if visible compliance was the only issue. To not offer them a remedy and to exclude people on the basis of their first or last name is a bizarre overreaction to me. It stands no chance of damaging the Russian government and can only harm the project and open source in general, I'm not sure why a non-profit would…
[flagged]
Re: On Linux MAINTAINERS file removal of Russian developers
#13We should realize this has nothing to do with Russia or the Russian government. This could happen with any country and any group of people. The USG is constantly expanding their sanctions regime. Thus, we need to ask ourselves the obvious question; Who will be next?
What I find perplexing and surprising are the people I see online cheering this on. The people who are happy that the USG is forcing Linux kernel devs to stop working with people. Why are some people so happy for Linus and crew to take orders from the USG's sanctions regime?
Where did the free as in freedom go?
Re: On Linux MAINTAINERS file removal of Russian developers
#14[flagged]
Re: On Linux MAINTAINERS file removal of Russian developers
#15Aside from numerous ethical issues with this story, it doesn’t make a lot of practical sense. They are not major threat to avoid, even taking into account xz precedent - I don’t think it’s easy or even feasible to plant any backdoors to Linux kernel this way. This will not make any impact on Russian government or military operations or impair their OS development effort (Astra Linux will be just fine). It sounds pret…
Imagine a backdoor planted by a Russian asset. Linux could get removed from some list of approved OS that can be used in a government context.
Re: On Linux MAINTAINERS file removal of Russian developers
#16If it's genuinely naive, this is a great time to wake up to the fact that russia is conducting a war of conquest against a european country, and this is why they, and a bunch of companies associated with that, are being sanctioned. Why would any reasonable project try to circumvent such sanctions?
Re: On Linux MAINTAINERS file removal of Russian developers
#17They were removed NOT because of being Russian but because of their link to Russian state owned company (also, either legitimately or by mistake...)
Re: On Linux MAINTAINERS file removal of Russian developers
#18[flagged]
> "xenophobia"
ok.
Re: On Linux MAINTAINERS file removal of Russian developers
#19Aside from numerous ethical issues with this story, it doesn’t make a lot of practical sense. They are not major threat to avoid, even taking into account xz precedent - I don’t think it’s easy or even feasible to plant any backdoors to Linux kernel this way. This will not make any impact on Russian government or military operations or impair their OS development effort (Astra Linux will be just fine). It sounds pret…
Yes, this can be circumvented. But the optics are important. Imagine a backdoor planted by a Russian asset. Linux could get removed from some list of approved OS that can be used in a government context.
Email-based filtering of maintainers is not even close to what could be considered adequate security measures. In fact, when CISO or OSS starts caring about the optics, it’s a red flag.
Re: On Linux MAINTAINERS file removal of Russian developers
#20If certain people cannot contribute to the Linux kernel because of a list maintained by the USG then perhaps it's time for Linux kernel development to no longer be dependent on US law. We should realize this has nothing to do with Russia or the Russian government. This could happen with any country and any group of people. The USG is constantly expanding their sanctions regime. Thus, we need to ask ourselves the obvi…
It is not only US-based organizations, but also people living in the US (and US citizens even if they don't live in the US) that have to follow the US law. Even if you set up the coordinating foundation in e.g. Switzerland, many Linux kernel maintainers would still live in US, probably not wanting to move to Switzerland.
Also, Switzerland is becoming less neutral and more EU-aligned. They are following most of the EU sanctions against Russia: https://www.admin.ch/gov/en/start/documentation/media-releas...
So you might have to find a different country than Switzerland. Brazil, Venezuela, Cuba? Of course, the most sure way to avoid needing to abide by sanctions against Russia, would be to set your headquarters in Russia.