Earlier quoted context omitted.
> security compliance is really more of a box checking activity than anything else. Yup. Same at my job, new FIPS requirements. Current functional hardware is now e-waste because not compliant. And, of course, the few vendors who do support FIPS are the usual incumbents like MS and Cisco. So buy new Dell hardware with TPMs, Cisco switches, Windows 11 and server 2025. Forced obsolescence and waste stream for check box…
I’d be very curious as to what you’re doing with your old hardware. My homelab is always eager to grow
Sovereign Lumber
21–26 of 26 posts
Re: Sovereign Lumber
#22Lumber is organically grown without tending or supervision, fits a generally homogeneous form factor, processed with a small number of tools to produce near-identical mass produced products.
But the essence of the argument is there. Government should be funding open source as necessary infrastructure like roads and bridges.
But not just that. Funding open source is necessary for national defense.
There are hundreds of billions of dollars in budgets out there that should be sent to funding open source developers.
Re: Sovereign Lumber
#23agree with Svilen_Dobrev, that this could be solved by making certain types of software public infrastructure. The article says that the main conflict is part one of the OSS license, "The license shall not restrict any party from selling or giving away the software as a component… [and] shall not require a royalty or other fee for such sale." Which makes it very hard to sell OSS software (read the article for nuance)…
OSS provides value (let's say, large) uncorrelated to a large extent with those externalized costs (often almost zero). The multiple is enormous.
Commercial software companies capture that value, because they can; they're not stupid.
But, Commercial software companies also create an undeniable value above the captured value - they provide support, security, documentation, even familiarity, a "throat to choke", etc. The captured value, often at zero initial cost, is the margin.
There is no change that can be made to any OSS license that will change that dynamic. Unless it's not OSS anymore.
Governments can do very little; most OSS developers, as cost, will not work, for free, for a government. Maybe the patriots will, but not many others - so that idea will go nowhere unless the developers are government employees. That has its own issues, not all of which are necessarily bad.
Government sponsored software infrastructure will probably not be as good as the OSS projects, or the Commercial products we use today. That's certainly not a given, but overlay it all with leadership, administration and bureaucracy, and you're probably on a hiding to nothing. Governments have little vision beyond the next election cycle.
Software isn't the same as roads. A citizen knows what a road is; they see it, they use it directly, and also see its obvious value for many other purposes - they intuitively understand why they're paying, and for what they're paying. A citizen doesn't easily see the value of some OSS project embedded in the operations of their government - they see the chair and couldn't care less about the lumber. (I'll grant that taxes paid to a general fund might work.)
That's also often the view of people and organizations that buy commercial products based on OSS software. They care about the chair, not the tree, or the process that turned the tree into the chair.
OSS should, and probably will, always exist. People like doing things. It gives them pleasure. But, we can't really mix the open with the closed by screwing around with licenses. It's open or it's closed.
Re: Sovereign Lumber
#24I think that, at least for b2b software, there's a lack of appreciation here for the role compliance plays. The author cites both googles and Microsofts office tools, but they really suck. My fiancee has to use Microsoft, and now I do too; no one likes them! Their janky online office actually deletes text as I type! However, I know that the only reason my company is using it is because it makes compliance really easy…
I think there was a one-two punch that sort of destroyed common sense.
First the rise of cloud computing where some data went remote.
Then the pandemic where people were remote too.
And I think most corporations sort of GAVE UP. Now everything including employee lists, business strategy, code, internal documents, chat sessions, email, meetings... it's all just out there.
Re: Sovereign Lumber
#25Just take a bunch of open-source code and then "re-sell" it with a US HQ. Solves a lot of government compliance problems and I can use my 100% profit margin to actually do security testing on the packages.
Re: Sovereign Lumber
#26Earlier quoted context omitted.
I’d be very curious as to what you’re doing with your old hardware. My homelab is always eager to grow
A lot of companies worried about things at this level grind their machines into small bits after finding out potential leaks of information were occurring on things like NVRAM on devices.