Live data from Hacker News

Elasticsearch is open source, again

elastic.co

411–420 of 473 posts

Re: Elasticsearch is open source, again

#411

Earlier quoted context omitted.

Including the recent trend of access to SOC2 reports requiring an "Enterprise" tier subscription.

Or worse, "SSO" as an Enterprise feature. You're a 2-3 person startup, you set up GSuite, you want to set things up right, oh, "$Call us" for a tier with SSO. Nope, I guess disparate users for now. Not the worst in the world to be clear, but an entirely arbitrary gate, in my experience.

Yeah, the SSO gates are common and borderline criminal. "The only way you can use our software is insecurely"

Re: Elasticsearch is open source, again

#412
post #265

Earlier quoted context omitted.

Unfortunately many companies charge extra for security where security should be the default. Truth to be told there some some situations where extra security costs could be justified but there are not many if charge is necessary it should be considered as a temporary measure. My $0.02.

Including the recent trend of access to SOC2 reports requiring an "Enterprise" tier subscription.

[deleted]

Re: Elasticsearch is open source, again

#413

Too late, the community all moved over to OpenSearch. I'll never forgive Elastic for locking basic security features behind their paid licence. Over the years probably millions of people had their data compromised due to that (due to people inadvertently leaving instances on the public internet - having auth enabled by default would have helped a lot)

That's hugely overblown. Maybe 20% of the companies I work with have switched.

> Maybe 20% of the companies I work with have switched.

Smells like opportunity!

Re: Elasticsearch is open source, again

#415

Here’s the initial AWS response to the license change that they made in 2018, which I helped write. At the time we didn’t think a new license made sense, as AGPL is sufficient to block AWS from using the code, but the core of the issue was that AWS wanted to contribute security features to the open source project and Elastic wanted to keep security as an enterprise feature, so rejected all the approaches AWS made at…

But why couldn't you or AWS donate/pay to Elastic for what they created to get those features in? I understand the security features you mentioned is very necessary, but Elastic will lose revenue because of this, and they are not a trillion dollars cap tech giant like AWS to support the project for free.

Re: Elasticsearch is open source, again

#416
post #387

Earlier quoted context omitted.

Those links are all generic pages related to their licenses. I'm not seeing how they support the idea of a "shakedown", which is criminal extortion.

They all say if you sell the database as a service you can't use AGPL; you have to pay for a commercial license.

no they don't unless, you are using the features like SSO that are behind the license or you are refusing to publish any patches you apply

Re: Elasticsearch is open source, again

#417

Earlier quoted context omitted.

Including the recent trend of access to SOC2 reports requiring an "Enterprise" tier subscription.

I have the same problem at the moment with Supabase. We're a startup trying to get ISO 27001 certified and need to upload Supabase's SOC2 report to Vanta, but we can't because we're on the Pro tier and they don't give access to that, even after emailing them. It's ridiculous.

It is even more ridiculous because it costs them nothing to issue an extra copy of this pdf report. They need to certify anyway because their enterprise customers will demand it.

Re: Elasticsearch is open source, again

#418
post #187
post #106

Earlier quoted context omitted.

Sounds to me like they're trying to cover up a bad case of regret. At our company we've fully shifted to OpenSearch, so there's no going back to ElasticSearch even if we wanted (not that we would want to). Also there is a lot of engineering contribution from Amazon that's seemingly gone now from Elasticsearch, right?

This is exactly it. They made the gigantic miscalculation that Amazon wouldn't win this battle. I can't believe they didn't predict that this exact outcome would happen: Amazon forks under a more permissive license and becomes the new standard instead of Elastic because the entire package (managed service from AWS + more permissive license) is a lower risk package to the average business.

I mean, if you actually can't believe they didn't predict this exact outcome, that means you believe that they DID predict it and this is what they intended/hoped to happen!

Re: Elasticsearch is open source, again

#419

Earlier quoted context omitted.

And what of small companies that need things like SOC2 reports from vendors? If you want to work with large companies, being SOC certified makes it easier. Part of that is ensuring your vendors are also compliant with good standards and that's best done with SOC reports.

Getting SOC 2 compliance alone takes ~10k USD apart from vendor reports. Yes they may be small with employee count, but when I said small I just meant someone running something for small set of users for free or close to free. Not someone working with other enterprises.

My point is that even small companies may need SOC reports from their vendors but still not be able to financially support enterprise level plans with every one of them. By being supportive of hiding those reports behind enterprise level contracts you are effectively supporting pricing those companies out and potentially making them unable to work with larger clients.

Re: Elasticsearch is open source, again

#420
post #136

Earlier quoted context omitted.

lowagie/itextpdf being an obvious/prominent one. it happens - why would you think commercial operators who’ve chosen a dual-license model wouldn’t protect their IP? That’s literally their breadwinner.

"shakedown" is a rather stronger claim than "adopted a licence".

I fairly well knew that your question wasn't good-faith, that's why I hesitated to respond rather than just flagging it.
Post reply on HN