Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

161–170 of 257 posts

Re: We all depend on open source. We will defend it together

#161
post #132
post #129

Defending open source should begin with real, tangible support for both the projects and its developers. Not just words. With my OpenBSD developer hat on, getting new hardware in the hands of developers is really important, many of us are hacking on 5-10 year old thinkpads that need replacing. https://www.openbsd.org/want.html The OpenBSD foundation is ~50% away from its fundraising goal for 2026! https://www.openbsd…

Also in addition to funding the open source projects you use, if you can, please consider directly supporting individual contributors/developers personally who work on those projects, many are volunteers and even a small monthly contribution could mean the difference. https://brynet.ca/wallofpizza.html

[flagged]

Re: We all depend on open source. We will defend it together

#163
post #144

Earlier quoted context omitted.

Remember when google set up a whole project to find vulnerabilities but never sent any fix and unpaid developers were basically having to fix things that an entire team of people was hired to find… yeah maybe they could have just made an offer to some maintainers instead of burning them out?

They are contributing back, which is a good thing. Other companies just fork, fix, and forbid to contribute back.

Burning out maintainers isn't "contributing back".

Re: We all depend on open source. We will defend it together

#164
post #95

Earlier quoted context omitted.

My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely. People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases…

> This is the Linux Foundation, so it must put OSS and community first, surely. Linux Foundation is run by the said called corporates from the list. So is Rust Foundation. Linux in itself is safe cos Linus controls it. Not the rest of the projects LF controls.

So far, the Linux Foundation, from what I have seen, has pretty darn good track record of keeping the projects under its umbrella open source, even going against corporate sponsors to do so. For a recent example, see the recent NATS tuffle. (And I should.recognize that Synadia, finally, did the right thing and backed down).

Re: We all depend on open source. We will defend it together

#165
post #163

Earlier quoted context omitted.

They are contributing back, which is a good thing. Other companies just fork, fix, and forbid to contribute back.

Burning out maintainers isn't "contributing back".

Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?

Re: We all depend on open source. We will defend it together

#166

Earlier quoted context omitted.

Idk I swapped to a Linux-only PC last April and have been steadily shifting over to open source software for basically everything in my life. I haven’t done everything, I doubt I ever will hit 100%, but well over half the stuff I use on a daily basis I have real control over now and can audit. Keep in mind I am not a coder/engineer, I’m just kind of a tourist in that world, so if I can do it it’s clearly very achieva…

One of the reasons why a source-based system like Gentoo is particularly nice is that you can compile your binaries with debug flags, so if you hit bad behavior you can inspect, write a patch, compile into your running system, and then push the same patch upstream. I barely have to do it, but imho, this is how software should work and what running a computer should feel like.

I use OpenBSD and it’s actually the same thing with the additional niceties of binary packages. A bug or an issue with any program (including the kernel and drivers)? Patch and rebuild.

Re: We all depend on open source. We will defend it together

#167
post #146

It seems to me as someone who wasn't paying attention to open source 10 or 20 years ago that its no longer a real community effort. Projects are maintained by their maintainers and get very little from the community. Commercial open source gets even less from the community. The only real value generated is corporate supported projects sharing with corporate supported projects. The average person is happy because they…

> It seems to me as someone who wasn't paying attention to open source 10 or 20 years ago that its no longer a real community effort. I would disagree with this, it's the same amount of community effort as it's always been. Big projects have big governance, and receive lots of patches. Smaller projects receive fewer patches. The community generally happens in Discord or IRC or on mailing lists, but it definitely exis…

I fully understand that I may be completely wrong but I just dont see that a lot of effort comes from outside a projects core maintainers. Its always a core maintainer group usually paid by some company doing 95% of the work and the patches contributed are localizations, small bug fixes and weird edge cases.

I'm not an open source maintainer so I could be completely off base here.

Re: We all depend on open source. We will defend it together

#169
post #144
post #95

Earlier quoted context omitted.

My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely. People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases…

Remember when google set up a whole project to find vulnerabilities but never sent any fix and unpaid developers were basically having to fix things that an entire team of people was hired to find… yeah maybe they could have just made an offer to some maintainers instead of burning them out?

Is this an oblique reference to OSS Fuzz, or something else?

It seems weird to blame Google here, given that they didn’t manufacture the bugs: the bugs were already there, and they just found them. This is arguably the best thing for all parties: open source maintainers are still under no obligation to fix things, but downstreams can properly inform themselves about the risks they inherit by using any given project.

The alternative is a “don’t ask, don’t tell” system, which people generally agree doesn’t work well in other aspects of life.

Re: We all depend on open source. We will defend it together

#170
post #95

Earlier quoted context omitted.

My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely. People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases…

Um, the Linux Foundation is an industry body, not a user or community group. You seem confused?

I am pretty sure that these industries use the open source projects the Linux Foundation maintains. So it is pretty clear the Linux Foundation is indeed a user community group, too.
Post reply on HN