Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

151–160 of 257 posts

Re: We all depend on open source. We will defend it together

#151
post #98

Earlier quoted context omitted.

Idk I swapped to a Linux-only PC last April and have been steadily shifting over to open source software for basically everything in my life. I haven’t done everything, I doubt I ever will hit 100%, but well over half the stuff I use on a daily basis I have real control over now and can audit. Keep in mind I am not a coder/engineer, I’m just kind of a tourist in that world, so if I can do it it’s clearly very achieva…

> I have real control over now and can audit. > Keep in mind I am not a coder/engineer How do you control and audit something you don’t understand? What specific steps are you taking?

I depend on the community tbh. Poor phrasing, it implies I personally audit it. But ultimately if I want to I can and I know plenty of folks scour repos/compile code themselves, so if something is wrong it’ll likely come out. It’s open source, they can’t hide it from people who are looking. Also I’m not entirely ignorant - I can sometimes see when something is up, I am comfortable using a CLI, I know my way around a computer better than most.

Wouldn’t you say that’s way better than the status quo with windows/macOS?

Re: We all depend on open source. We will defend it together

#153

I yearn for the day I see a headline like "We All Depend on Open Source. We Will Fund It Together"

Many of these bigger companies are "funding open source" by paying their employees to participate. Look at all of the corporate email addresses on the LKML for instance...

Re: We all depend on open source. We will defend it together

#154
post #144
post #95

Earlier quoted context omitted.

My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely. People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases…

Remember when google set up a whole project to find vulnerabilities but never sent any fix and unpaid developers were basically having to fix things that an entire team of people was hired to find… yeah maybe they could have just made an offer to some maintainers instead of burning them out?

They are contributing back, which is a good thing. Other companies just fork, fix, and forbid to contribute back.

Re: We all depend on open source. We will defend it together

#155

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…

> A lot of open source folks are going to be very skeptical, rightly so, of this group of players.

You say this as if these players aren't members of "the open source folks". It's not an exclusive club.

Re: We all depend on open source. We will defend it together

#156
post #81

Earlier quoted context omitted.

Imagine if the AGPL had become the default license for open source projects, as it was intended to when the service provider loophole in the GPL became apparent. The software industry would be unrecognizable. Instead, millions of developers now gift corporations their work by releasing everything under MIT or Apache, and those corporations take from that treasure trove what they want and give back what they want, whi…

I believe Open Source software sold developers the dream of "to be hired for what they have developed" and cash-in the effort they have spent as a future, stable employment. Many die on the hill of "developing something required for free with permissive licenses for recognition which will help with their future endeavors", which is the same with other creative lines of work. As a result they are milked of their knowl…

I think you can get recognition just as well with share-alike licenses. Plus you leave the opportunity open to ask for money for a different license grant.

Re: We all depend on open source. We will defend it together

#157
Nonsensical corporate posturing.

"Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities"

As a reminder, Microsoft runs NPM and GitHub. Microsoft has access to the best AI models and massive data centers. Despite that, their own products are rapidly getting worse at security and their services are central hubs through which various exploits are propagated. They are not making things better, they are actively and rapidly making things worse.

--

For a great example of how Microsoft deals with security issues within their own Open-Source projects, I recommend reading this GitHub thread:

https://github.com/dotnet/efcore/issues/38257

EF core currently distributes a version of SQLite that has a severe vulnerability. The issue was discovered over a year ago. It was fixed by SQLite within one week. EF core didn't mark their driver as vulnerable until a user recently reported it, got bounced around and argued with developers. The current stable version of .NET core will only get a fix in roughly two months.

Re: We all depend on open source. We will defend it together

#158

Earlier quoted context omitted.

I believe Open Source software sold developers the dream of "to be hired for what they have developed" and cash-in the effort they have spent as a future, stable employment. Many die on the hill of "developing something required for free with permissive licenses for recognition which will help with their future endeavors", which is the same with other creative lines of work. As a result they are milked of their knowl…

I think you can get recognition just as well with share-alike licenses. Plus you leave the opportunity open to ask for money for a different license grant.

I believe strongly so, however companies doesn't like this, hence the current state we're in. Also it's part of the "advertising" done by the companies.

Last but not the least, many people are very ill-informed about GPL and how it works. I experience this when we discuss this with peers.

This is why I only use copyleft (or non-commercial/share-alike) licenses on what I build/produce/put out.

Re: We all depend on open source. We will defend it together

#159

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…

Keep in mind that while I am employed by the Linux Foundation, I know nothing of the internals of this project; I will speak, instead, of what the projects I support do.

I have found (c) to be high noise, low signal. We're winding down our HackerOne program.

D: we do this in a couple ways. For PQCA, for instance, we use credits from AWS to get access to hardware to run proofs and CI on. PQCA also has a paid mentorship program.

For OWF, we do the same with AWS credits, as well as provide hosting for projects to run services on for testing.

For LFDT, we offer paid mentorships, have paid for Trail of Bits to do reviews, and run events. We had a maintainer summit in New York in January so our maintainers could meet for two days face-to-face. We fund large GitHub CI runners for projects as well.

I know it doesn't answer everything, but our team is only a few people and we really do work hard to help developers. What I'll call the devrel team for OWF/PQCA/LFDT is three FTE, one contractor, and our manager.

LFDT: https://www.lfdecentralizedtrust.org/

OWF: https://openwallet.foundation/

PQCA: https://pqca.org/

PQCA benchmarks, for instance: https://pq-code-package.github.io/mldsa-native/dev/bench/

Re: We all depend on open source. We will defend it together

#160
post #146

It seems to me as someone who wasn't paying attention to open source 10 or 20 years ago that its no longer a real community effort. Projects are maintained by their maintainers and get very little from the community. Commercial open source gets even less from the community. The only real value generated is corporate supported projects sharing with corporate supported projects. The average person is happy because they…

[dead]
Post reply on HN