Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

251–257 of 257 posts

Re: We all depend on open source. We will defend it together

#251

Earlier quoted context omitted.

You are absolutely welcome to start a project and exclude anyone who you think is unworthy of contributing. Software is not and never was a public good.

No, what I would rather do (read as am actively doing) is help elect people into congress that want to rightfully destroy Silicon Valley and bring the benefit of public software to the masses.

So you want congress to force people to write software that you want? I'm not sure I understand you. People write free software because either they want to, or they're being paid by someone who wants them to. Is there some third way to compel people to give you their work for free?

Re: We all depend on open source. We will defend it together

#252
post #226

Earlier quoted context omitted.

It doesn't help that "Akrides" sound like a Bond villain EvilCorp run by Dr Ambergris whose face is horribly disfigured from a series botched face lifts that's plotting to populate Mars with big boobed clones running around dressed only in brassieres, just like his lead concubine, Dorothy "Dirty" Sanchez (Don't blame me for Kam Fleming's knack for double entendres...) who leads his team of equally big boobed secret h…

The name is of Greek origin https://en.wikipedia.org/wiki/Akritai from frontier soldiers guarding the Byzantine empire's borders.

A group that is working on developing streamline rules for fixing security.

> Byzantine

Not the connotations I would aim for, but after looking at the organisations involved it's probably apt.

Re: We all depend on open source. We will defend it together

#253
post #222

Earlier quoted context omitted.

Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?

https://linuxiac.com/libxml2-becomes-officially-unmaintained...

Maybe you posted the wrong link- I don't see anything at all about Google making a report or being asked to do anything and declining?

Re: We all depend on open source. We will defend it together

#254

Earlier quoted context omitted.

Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?

Wasn’t that a story with ffmpeg a few months ago? And people were getting roasted for even the suggestion that google should contribute patches?

From the horses mouth: "Michael Niedermayer, a leading FFmpeg developer, tweeted, “I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 Google OSS fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments FFmpeg (Kieran) has made about Google. From all companies, Google has been the most helpful & nice.” https://thenewstack.io/ffmpeg-to-google-fund-us-or-stop-send...

Sounds like Google has been very helpful and nice.

Re: We all depend on open source. We will defend it together

#255

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…

You realize that the companies listed employ many of the core open source maintainers for large projects? It is project-specific, but 80% of Linux kernel development is from paid corporate employees. Similar for kubernetes. All the load bearing infrastructure is already handled by these companies... literally no one else is going to have the resources or experience to redirect large efforts on securing F/OSS. What wo…

I guess you'd rather downvote than answer the question.

Re: We all depend on open source. We will defend it together

#256

Nonsensical corporate posturing. "Microsoft will contribute expertise, resources, and AI technologies to help responsibly identify and fix vulnerabilities" As a reminder, Microsoft runs NPM and GitHub. Microsoft has access to the best AI models and massive data centers. Despite that, their own products are rapidly getting worse at security and their services are central hubs through which various exploits are propaga…

> a version of SQLite that has a severe vulnerability Calling CVE-2025-70873 a severe vulnerability is a bit overplaying it imo. The vulnerability requires that you allow an attacker to import an arbitrary ZIP file I looked at the vulnerability in question by the way, CVE-2025-70873, and it really is not that severe unless you're allowing users to import arbitrary ZIP files

That's not the only CVE in question. The issue also involves CVE-2025-6965.

Re: We all depend on open source. We will defend it together

#257
This is a great mission. Open source accelerates software innovation, establishing foundation software that can be freely leveraged. That has been true for decades and therefore a great deal of critical software infra is open source. Because nefarious actors can now use AI to rapidly identify vulnerabilities, this allows a coordinated response across an extremely large number of major software providers. Those using or building on critical open source should be part of Project Akrites.
Post reply on HN