Live data from Hacker News

EU study recommends OpenBSD

undeadly.org

51–60 of 153 posts

Re: EU study recommends OpenBSD

#51
post #7

Link to Part 1 of the study (wherein the recommendation lies): http://www.europarl.europa.eu/RegData/etudes/STUD/2015/52740... Part 2 of the study recommends government funding of Open Source Projects: http://www.europarl.europa.eu/RegData/etudes/STUD/2015/52741... Potential and actual conflicts of interest between governments and citizens in regard to privacy are not addressed.

They don't address conflicts of interest but it seems like they're fine with privacy: "[...] the use of open source computer operating systems and applications reduces the risk of privacy intrusion by mass surveillance. They seem to be touting that as a benefit, not a drawback.

When the same governments are funding signals intelligence gathering with one hand and open source software development with the other, there is potential conflict of interest, if not actual conflict.

The NSA's role in weakening open source encryption standards was the result of the internal logic by which all intelligence organs typically operate irrespective of sponsoring state. The differences between the politics of some EU states and the politics of the US or Russia or the UK don't change that internal logic of intelligence organs. Their job remains to maintain data collection capability.

Re: EU study recommends OpenBSD

#52
post #41
post #4

Earlier quoted context omitted.

> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.

More often than not, he wasn't referring to contributions in the FSF sense (i.e. people modifying code that they don't send back to the original authors). He simply meant that many of the institutions that run and use OpenBSD, which is available entirely for free, don't give anything in return - be it in the form of code, money, documentation or promotion. Another free license solves only a small proportion of this p…

    Another free license solves only a small proportion of this problem.
True, but with BSD I'm not sure you can view it as a problem to begin with since the license is explicitly designed to legally absolve the user of all obligation to do just that.

If you desire monetary contributions be made, some kind of commercial license is the solution. If you desire modifications be contributed back, there are other licenses that cover that expectation. And there's nothing stopping you from creating your own license.

If you don't require or expect any contributions back or monetary contributions under any scenarios, then BSD is a great license for that.

I'm sure when confronted with a lack of contribution (monetary, labor, code modifications), most companies would reply "Well, yes. That's why we chose software with a BSD license."

Re: EU study recommends OpenBSD

#53
post #16

Earlier quoted context omitted.

You could have easily taken the full quote -- it's not quite the contradiction you're trying to make: "GPL fans said the great problem we would face is that companies would take our BSD code, modify it, and not give back. Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Just like the Linux community, we h…

>Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Does he offer any examples of this happening ?

That comment came about because of a licensing spat with the atheros source code.

http://undeadly.org/cgi?action=article&sid=20070913014315

Re: EU study recommends OpenBSD

#54
post #29

"[...] the use of open source computer operating systems and applications reduces the risk of privacy intrusion by mass surveillance. Open source software is not error free, or less prone to errors than proprietary software, the experts write. But proprietary software does not allow constant inspection and scrutiny by a large community of experts." That worked great for OpenSSL didn't it? ;)

Microsoft has had 2 Heartbleed-level vulnerabilities in its Windows code so far, that were not just 2-3 years old but 10+ years old, leaving systems vulnerable to them for much longer.

The "advantage" of proprietary code here was that Microsoft got to downplay them (surprise surprise, no scary logo made by Microsoft for them!), and that's how proprietary code owners deal with security issues in general - they try to hide that they exist to keep the illusion that the software is (more) secure.

Re: EU study recommends OpenBSD

#55
post #47

Earlier quoted context omitted.

Let me rephrase the quote for you: "once the code is GPL'd, we cannot get the modifications back" That's what he meant. Look at the full context.

And you can from proprietary licensed modifications? FSF recommendation is that you use the same license as the project which you are contributing to. If you use a BSD project, contribute your patches under BSD. If its GPL, contribute under GPL. If you combine work under BSD and GPL and write modifications, contribute back the modifications based on what code you are doing modification for. The proprietary way is to…

That's not the point. Let me rephrase that:

- one of GPL's cool thing is that it prevents proprietary software from including GPL'd code without contributing back to the community

- Because BSD is not as strict as GPL regarding license derivation, GPL says "BSD is bad, you're allowing proprietary software to use BSD code without giving back"

- Some people take BSD code, modify it and distribute modifications under GPL

- Because of this, the original BSD code authors can't benefit from the modifications, only GPL projects can... doing exactly what GPL was against in the first place (preventing authors from enjoying modifications)

Theo is only pointing out the irony of it all.

Re: EU study recommends OpenBSD

#56
post #23
post #19

Earlier quoted context omitted.

Interesting! Could you elaborate some more and perhaps list a few projects, if you're allowed to?

I primarily know about the projects listed at https://www.fokus.fraunhofer.de/809f10db25eddf3e/projects A personal observation is that, nowadays, gitlab seems to be preferred to github as part of a push to rely more on software developed inside the EU (guess it's an aftermath of the whole NSA story). PolicyCompass, for example, lives at https://github.com/policycompass Carneades lives at http://github.com/carneades M…

GitLab CEO here, we indeed see more and more organizations starting to host their own GitLab server to become self reliant.

Re: EU study recommends OpenBSD

#57
post #52
post #41

Earlier quoted context omitted.

More often than not, he wasn't referring to contributions in the FSF sense (i.e. people modifying code that they don't send back to the original authors). He simply meant that many of the institutions that run and use OpenBSD, which is available entirely for free, don't give anything in return - be it in the form of code, money, documentation or promotion. Another free license solves only a small proportion of this p…

Another free license solves only a small proportion of this problem. True, but with BSD I'm not sure you can view it as a problem to begin with since the license is explicitly designed to legally absolve the user of all obligation to do just that. If you desire monetary contributions be made, some kind of commercial license is the solution. If you desire modifications be contributed back, there are other licenses tha…

There are things in this world that are not a business.

Re: EU study recommends OpenBSD

#58
For those that know more about OpenBSD than the EU (and I salute you for it), the EU parliament is a fairly powerless institution. Eurocrats show it little respect; one described it as "just one big fucking NGO".

Update after reading it: this isn't even an official parliament document or recommendation. It's something by the parliament's research service.

Re: EU study recommends OpenBSD

#60
post #4
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.

TBH a single organization adopting and customizing a GPL software for internal usage isn't forced to contribute back, as GPL affects redistribution not adoption.
Post reply on HN