Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

241–250 of 257 posts

Re: We all depend on open source. We will defend it together

#241
post #98

Earlier quoted context omitted.

> I have real control over now and can audit. > Keep in mind I am not a coder/engineer How do you control and audit something you don’t understand? What specific steps are you taking?

I depend on the community tbh. Poor phrasing, it implies I personally audit it. But ultimately if I want to I can and I know plenty of folks scour repos/compile code themselves, so if something is wrong it’ll likely come out. It’s open source, they can’t hide it from people who are looking. Also I’m not entirely ignorant - I can sometimes see when something is up, I am comfortable using a CLI, I know my way around a…

> Wouldn’t you say that’s way better than the status quo with windows/macOS?

I would say it’s irrelevant to the conversation. I wasn’t throwing shade or criticising your approach, I was making an honest question to understand your argument better. I have no interest in flame wars.

Re: We all depend on open source. We will defend it together

#242
post #241

Earlier quoted context omitted.

I depend on the community tbh. Poor phrasing, it implies I personally audit it. But ultimately if I want to I can and I know plenty of folks scour repos/compile code themselves, so if something is wrong it’ll likely come out. It’s open source, they can’t hide it from people who are looking. Also I’m not entirely ignorant - I can sometimes see when something is up, I am comfortable using a CLI, I know my way around a…

> Wouldn’t you say that’s way better than the status quo with windows/macOS? I would say it’s irrelevant to the conversation. I wasn’t throwing shade or criticising your approach, I was making an honest question to understand your argument better. I have no interest in flame wars.

I’m not engaging in a flame war, you just seem to have a very terse way of writing that kind of caught me off guard. That initial question felt a bit leading and there’s a bit of a hostile tone coming through. Seems it’s unintentional though so not a big deal.

Re: We all depend on open source. We will defend it together

#243

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler Many of the names on the list makes the initiative rather suspect. Companies who do a lot to undermine free and open-source software, who hide critical software behind their walls, preven…

Not...really? It's pretty normal. Tech companies share intelligence and knowledge all the time -- there are a lot of birds of a feather and consortium groups out there. Since a lot of places are close in proximity, companies sometimes run private fiber lines and such to let peers download updates without competing with the entire world lol. Everyone's fighting the same fight. Sharing and collaborating are normal thin…

> Tech companies share intelligence and knowledge all the time

Share it and hide from the public, you mean?

> Everyone's fighting the same fight

Companies really are not "fighting the same fight" as people, generally. And some of these ones are definitely not "fighting the same fight" as FOSS developers, or just people in general.

Re: We all depend on open source. We will defend it together

#245
post #241

Earlier quoted context omitted.

> Wouldn’t you say that’s way better than the status quo with windows/macOS? I would say it’s irrelevant to the conversation. I wasn’t throwing shade or criticising your approach, I was making an honest question to understand your argument better. I have no interest in flame wars.

I’m not engaging in a flame war, you just seem to have a very terse way of writing that kind of caught me off guard. That initial question felt a bit leading and there’s a bit of a hostile tone coming through. Seems it’s unintentional though so not a big deal.

> you just seem to have a very terse way of writing that kind of caught me off guard.

Fair.

> That initial question felt a bit leading

How would you have phrased it? I’m genuinely asking.

> and there’s a bit of a hostile tone coming through.

It’s been my experience that in online writing with strangers it’s best to assume good faith and not assume tone. Read things imagining the other person is smiling and in a good mood (exceptions for obvious trolls). Not that I can do that every time, mind you, we all have flaws, but it avoids a ton of needless misunderstandings and doesn’t escalate.

> Seems it’s unintentional though so not a big deal.

It was. Thank you for replying.

Re: We all depend on open source. We will defend it together

#246
post #222

Earlier quoted context omitted.

Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?

https://linuxiac.com/libxml2-becomes-officially-unmaintained...

[dead]

Re: We all depend on open source. We will defend it together

#247

Earlier quoted context omitted.

If you share your code with me under a copy left license, I will share my contributions under the same copy left license... you will not then be free to ask for money for things built on top of or with my contributions. You may be okay with that, but it is a decision you have to make.

A common misunderstanding with the GPL and other copy left licences is that they care about money and monetary transactions. They mostly do not. They only demand that you offer the source code to anyone that asks for it if you also distribute any kind of executable (you may even charge to cover the costs of the distribution). The AGPL expands this to SaaS's too to close that loophole.

Sorry, I am aware of this, I worded my comment incorrectly. What I meant to say is that one will be unable to ask for money for a ~different license~ to my contributions, becuase my contributions will be under the copyleft license, and I will not sign any agreements that give the project maintainers rights to license my contributions under a proprietary (Non open source) license. Yes, anyone is still free to ask for money for copy left code. But it is still copy left, and as such, the license goes with it.

Apologies for my poorly worded comment!

Re: We all depend on open source. We will defend it together

#248
post #245

Earlier quoted context omitted.

I’m not engaging in a flame war, you just seem to have a very terse way of writing that kind of caught me off guard. That initial question felt a bit leading and there’s a bit of a hostile tone coming through. Seems it’s unintentional though so not a big deal.

> you just seem to have a very terse way of writing that kind of caught me off guard. Fair. > That initial question felt a bit leading How would you have phrased it? I’m genuinely asking. > and there’s a bit of a hostile tone coming through. It’s been my experience that in online writing with strangers it’s best to assume good faith and not assume tone. Read things imagining the other person is smiling and in a good…

I understand we need to give people the benefit of the doubt, but take this previous comment for example. It comes off as pretty patronizing, I have to really squint to remove that feeling. I understand I have a responsibility to try and focus on the best possible interpretation of somebody’s comment, but it also behooves you to maybe take a second look at the way you’re writing and maybe consider ways to encourage a more generous interpretation. I can only work with what is given to me at the end of the day. Discussions are a two way street, and sometimes people are just rude/combative, especially online.

Anyway it’s all good. I hope you have a nice weekend.

Re: We all depend on open source. We will defend it together

#249

Earlier quoted context omitted.

This looked great until I saw that list. It feels, to me, as if all of these companies are scared of the risk. The risk that decades of tech debt and shitty products sold at a premium built on other people's work will now come back to reverse brand fuck them. I've worked for one of these companies and it was built on OSS and they contribute absolutely nothing back. They just take. And they've literally built a produc…

Which one

Z.

Total dumpster fire of a company. They acquired a company called Edgewise and it was so bad that after a number of P0 outages in customer networks they pulled it from the market. I was there less than 6 months after constantly arguing with leadership about how the product was not production worthy. They pulled it about 3 months after I left.

But while I was there I saw just horrid things within ZPA and ZIA (their core products at the time). And with that so many GPL violations, which seems to be the norm within the security market, anyway.

Re: We all depend on open source. We will defend it together

#250
post #245

Earlier quoted context omitted.

> you just seem to have a very terse way of writing that kind of caught me off guard. Fair. > That initial question felt a bit leading How would you have phrased it? I’m genuinely asking. > and there’s a bit of a hostile tone coming through. It’s been my experience that in online writing with strangers it’s best to assume good faith and not assume tone. Read things imagining the other person is smiling and in a good…

I understand we need to give people the benefit of the doubt, but take this previous comment for example. It comes off as pretty patronizing, I have to really squint to remove that feeling. I understand I have a responsibility to try and focus on the best possible interpretation of somebody’s comment, but it also behooves you to maybe take a second look at the way you’re writing and maybe consider ways to encourage a…

Oh, sure sure, I am in agreement with you. In no way do I believe this to be the exclusive responsibility of the receiving side. I’m usually competent at detecting this and don’t see why you’d interpret the previous comment as being patronising, but I concede I may be having an off day.

Thank you again for replying. A nice weekend to you too!

Post reply on HN