Live data from Hacker News

Announcing Caddy Commercial Licenses

caddyserver.com

221–230 of 295 posts

Re: Announcing Caddy Commercial Licenses

#221
post #78

Earlier quoted context omitted.

> Secondly, it makes it more difficult to take steps to make it less obvious which web server is being used. I'd do this to make it slightly more difficult for script kiddies looking to exploit recent vulnerabiltiies - not because I think security through obscurity is a good idea. I thought about this as well, but I'm not convinced that hiding the Server header or anything like unto it is really that beneficial. Most…

> I thought about this as well, but I'm not convinced that hiding the Server header or anything like unto it is really that beneficial. Most exploits are automated anyway. It probably doesn't help much but it can't hurt. Some servers send back a "Server" header that tells you the OS being used with the Apache and PHP version up to the minor version number for example. There's no benefit to leaking this information an…

> It probably doesn't help much but it can't hurt ... There's no benefit to leaking this information and it's potentially useful to an attacker even if only marginally so why risk it?

Actually, it can hurt. One really good reason to note it is that for the same reason an attacker might want to know the version, a defender (such as an employee) might want to as well. I've noted exploitable versions of software found to other divisions of the company I was working at before. For the attacker, it's really not much of an issue anyway, they'll just throw every exploit at it anyway (my webserver logs were always filled with random exploit attempts such as for wordpress and IIS).

Re: Announcing Caddy Commercial Licenses

#222
post #213

@mholt is being exceedingly generous to the whingers on this thread, on top of the generosity he's shown in writing Caddy to start with. It's not 2005 any more, Sun Microsystems is long gone. You won't raise any money from a business model that gives away your best work or selling support contracts alone. Caddy is a real innovation, and brings web server defaults bang up to date - it makes loads of complex configurat…

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

I disagree.

Big companies are where they're going to buy the licenses because in those companies time is often more kmportnant than budget so you just buy stuff.

Another reason is that as soon as other teams become involved you get comments like "this bug is yours because you self compiled this thing", or "we have to buy the vendors version", etc etc. It's not logical and is basically arse covering. Buying the vendor version is an easy way to shoot down a whole category of stupid internal politics.

Re: Announcing Caddy Commercial Licenses

#223
post #213

@mholt is being exceedingly generous to the whingers on this thread, on top of the generosity he's shown in writing Caddy to start with. It's not 2005 any more, Sun Microsystems is long gone. You won't raise any money from a business model that gives away your best work or selling support contracts alone. Caddy is a real innovation, and brings web server defaults bang up to date - it makes loads of complex configurat…

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

The company that goes and builds this themselves instead of paying a small fee for it, would be a pretty stupid company haha...

Re: Announcing Caddy Commercial Licenses

#224
post #213

Earlier quoted context omitted.

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

I disagree. Big companies are where they're going to buy the licenses because in those companies time is often more kmportnant than budget so you just buy stuff. Another reason is that as soon as other teams become involved you get comments like "this bug is yours because you self compiled this thing", or "we have to buy the vendors version", etc etc. It's not logical and is basically arse covering. Buying the vendor…

[deleted]

Re: Announcing Caddy Commercial Licenses

#225
post #213

@mholt is being exceedingly generous to the whingers on this thread, on top of the generosity he's shown in writing Caddy to start with. It's not 2005 any more, Sun Microsystems is long gone. You won't raise any money from a business model that gives away your best work or selling support contracts alone. Caddy is a real innovation, and brings web server defaults bang up to date - it makes loads of complex configurat…

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

[deleted]

Re: Announcing Caddy Commercial Licenses

#226
post #213

@mholt is being exceedingly generous to the whingers on this thread, on top of the generosity he's shown in writing Caddy to start with. It's not 2005 any more, Sun Microsystems is long gone. You won't raise any money from a business model that gives away your best work or selling support contracts alone. Caddy is a real innovation, and brings web server defaults bang up to date - it makes loads of complex configurat…

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

> The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it.

That's not true at all. Big companies pay for software, not small shops. If J Developer says to their boss, "Well, I'd really like to use this thing, but it costs $X" and $X is sufficiently small, companies will frequently just go for it. No technical manager worth their salt is going to argue for their engineers who cost $X0,000 per month to be spending time managing a bespoke build pipeline to get out of paying somebody.

> Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that the only market for Caddy is a fairly small niche of people who are unwilling/unable to run NGINX or set up their own build process.

The auto-TLS aspect (among many other niceties such as simple configuration) is really quite nice for a large swath of users.

Re: Announcing Caddy Commercial Licenses

#227
post #213

Earlier quoted context omitted.

What I think is interesting, is the licensing model is basically reverse whaling The bigger the company is, the more likely they are to go with just building Caddy themselves instead of paying for it. So, the only people who need to run the commercial binaries are the situations where the licensing costs actually matter. Maybe I'm underestimating the size of the demographic they're targeting, but it seems to me that…

I disagree. Big companies are where they're going to buy the licenses because in those companies time is often more kmportnant than budget so you just buy stuff. Another reason is that as soon as other teams become involved you get comments like "this bug is yours because you self compiled this thing", or "we have to buy the vendors version", etc etc. It's not logical and is basically arse covering. Buying the vendor…

> Big companies are where they're going to buy the licenses because in those companies time is often more kmportnant than budget so you just buy stuff.

It doesn't work quite like that. Unless you're friend with the guy who decides who the checks are signed to, or you are already an established brand or your product provides a value so big it's a no-brainer, nobody in a big company will invest in your solution. If the company can get your product for free it will.

Caddy is trying to cash in on a product that is young, that has everything to prove, while at the same time pissing off the people it relies on to acquire an "audience", the users of the open source version, it never ends well.

The right way to do it is, to leave the open source version as it is, without any license change, while creating a new product,closed source, suited for enterprise.

> "this bug is yours because you self compiled this thing",

never heard anything like that in my life.

> Buying the vendor version is an easy way to shoot down a whole category of stupid internal politics.

If you have the power to do so at your business by all means. Buying into a commercial product also require a crazy amount of politics as well, especially if it's a recurring payment PER month PER instance at a minimum of $50, so more than the price of a basic VM on Amazon.

Re: Announcing Caddy Commercial Licenses

#228

Earlier quoted context omitted.

you are 'not willing to pay' money or time? why not?

Because it feels like a bad investment. In terms of cash, $1200 a year is a lot to me personally, I'm a student, I have no income, and I'm trying to bootstrap a startup. $1200 could feed me for a year. Even when I had my PhD stipend, $1200 was a months stipend. I originally chose to use Caddy over NGINX because it made https easy: just download, configure, run. If I have to remove the sponsor code and build it myself…

What on earth bootstrapped startup needs ~24 Caddy licenses? If you're operating at that scale and not generating revenue, your business won't last long anyway...

Re: Announcing Caddy Commercial Licenses

#229
post #169

caddyserver.com emits those headers if you want to see them in action: https://urlscan.io/result/8093833b-8ac7-4d18-8f20-a02373f577... Go to the first transaction, click the show button and click "Show headers". Right now it says: caddy-sponsors - This free web server is made possible by its sponsors: Minio, Uptime Robot, and Sourcegraph Personal opinion: I've never understood the appeal of Caddy except for the built…

It has a few bells and whistle and there is some work behind it, no question. HOWEVER, the fact that it relies entirely on go std lib net/http|http2 package implementations personally doesn't make it very useful if your developing your application in Go directly. Caddy team didn't code all that network layer, like Nginx or Apache teams did. You don't need Caddy to add let's encrypt to your Go application.
Post reply on HN