Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

221–230 of 257 posts

Re: We all depend on open source. We will defend it together

#221
post #190

Earlier quoted context omitted.

I don't see how that was implied? Just because someone is part of the "club" doesn't mean many other "members" can't be skeptical of their role. In fact, it doesn't even seem difficult to simultaneously acknowledge and commend the valuable role they play, while also expressing concern over the influence they wield and how it might contrast with desires and goals of the wider community.

They are the wider community. Programmers working on behalf of corporate actors write open source code in the commons because their organizations have discovered competing on some parts of the stack isn't as viable as collaborating on parts of the stack. I won't pretend to speak to specific numbers, but a huge amount of work and maintenance is from these programmers, or funded via the corporate actors which employ th…

I am not sure you'd be right if you see what people use vs what other companies use.

Re: We all depend on open source. We will defend it together

#222
post #163

Earlier quoted context omitted.

Burning out maintainers isn't "contributing back".

Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?

https://linuxiac.com/libxml2-becomes-officially-unmaintained...

Re: We all depend on open source. We will defend it together

#223
post #129

Defending open source should begin with real, tangible support for both the projects and its developers. Not just words. With my OpenBSD developer hat on, getting new hardware in the hands of developers is really important, many of us are hacking on 5-10 year old thinkpads that need replacing. https://www.openbsd.org/want.html The OpenBSD foundation is ~50% away from its fundraising goal for 2026! https://www.openbsd…

I wanted to buy a couple of ubikeys to secure my gpg key (which can be used to upload to debian) and seems if I want them it's on me, yay!

Re: We all depend on open source. We will defend it together

#224
post #93

This reads as centralization and control effort. It will only provide the power to control opensource to whoever Akrites is (with the major bigtech including Google). Thank you very much, but I remember what Google is doing with Android this September (closing third party installs using .apk).

This is my concern as well. If critical open source packages become dependent on these corporations for "secure" releases, does that enable them to force ID verification into packages, for example? Related, but most of the smart folk I know think Open Source AI means Anthropic and OpenAI are financially impossible. A lot of the companies signed onto this are heavily, heavily leveraged by those two, and have significa…

USA is making deals with EU companies forcing them to guarantee no open source software included in their products comes from china or russia. Which makes me think that despite what the folks from pypi keep saying, identifying everyone on github and only allowing projects from github to upload to npm/pypi is one of the goals here.

Re: We all depend on open source. We will defend it together

#225

Nonsensical corporate posturing. "Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities" As a reminder, Microsoft runs NPM and GitHub. Microsoft has access to the best AI models and massive data centers. Despite that, their own products are rapidly getting worse at security and their services are central hubs through which various exploits are propaga…

> a version of SQLite that has a severe vulnerability

Calling CVE-2025-70873 a severe vulnerability is a bit overplaying it imo. The vulnerability requires that you allow an attacker to import an arbitrary ZIP file

I looked at the vulnerability in question by the way, CVE-2025-70873, and it really is not that severe unless you're allowing users to import arbitrary ZIP files

Re: We all depend on open source. We will defend it together

#226

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…

It doesn't help that "Akrides" sound like a Bond villain EvilCorp run by Dr Ambergris whose face is horribly disfigured from a series botched face lifts that's plotting to populate Mars with big boobed clones running around dressed only in brassieres, just like his lead concubine, Dorothy "Dirty" Sanchez (Don't blame me for Kam Fleming's knack for double entendres...) who leads his team of equally big boobed secret h…

The name is of Greek origin https://en.wikipedia.org/wiki/Akritai from frontier soldiers guarding the Byzantine empire's borders.

Re: We all depend on open source. We will defend it together

#227

Earlier quoted context omitted.

How about they actually fund open source in the sense of letting the public dictate the direction of software for the country, not a cabal of unelected people that only care for pushing changes that benefit corporations. Open source would look drastically different, for the better I might add, if devs had a real choice in what to invest in. Corporate control of open sources has not benefited devs or society as it sta…

You are absolutely welcome to start a project and exclude anyone who you think is unworthy of contributing. Software is not and never was a public good.

No, what I would rather do (read as am actively doing) is help elect people into congress that want to rightfully destroy Silicon Valley and bring the benefit of public software to the masses.

Re: We all depend on open source. We will defend it together

#228

Earlier quoted context omitted.

Which is a large part of why what cryo32 said will come to pass.

Acknowledging the result of defeatism should push us toward a different mindset, not more defeatism. Over the long run, humanity has a pretty good record, carried by the people who refuse to give up.

> Acknowledging the result of defeatism should push us toward a different mindset, not more defeatism.

Defeatism says otherwise!

> Over the long run, humanity has a pretty good record, carried by the people who refuse to give up.

Unfortunately when the struggle is against other people, especially the incumbent powers-that-be (in this case the capitalist overlords), those that refuse to give up have to fight long and hard to get enough other properly in the fight, and victory requires something drastic like at very least mass protests perhaps up to civil war level.

Re: We all depend on open source. We will defend it together

#229

Earlier quoted context omitted.

Which is a large part of why what cryo32 said will come to pass.

Only if people succumb to defeatism. There have been documented instances of that not happening.

Those cases are rarely nice fluffy conflict free times of change, unfortunately.

Re: We all depend on open source. We will defend it together

#230
post #92

Earlier quoted context omitted.

> Defeatism is easy I prefer easy. If you prefer difficult, more power to you.

> I prefer easy. Clearly you don’t feel that strongly about it. You know what would’ve been easier than making an account just to post that comment? Not doing that. Have you also stopped working, paying your bills, showering, eating, interacting with other people? Not doing any of that is easier than doing it.

> Clearly you don’t feel that strongly about it. You know what would’ve been easier than making an account just to post that comment? Not doing that.

I’m here to remind the thousands of readers that they are not alone.

The vast majority (99%?) of us, absolutely do not give a shit about open source.

Post reply on HN