OpenBSD will shut down if we do not have the funding to keep the lights on
81–90 of 415 posts
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#82A little bit off topic, but this reminds me again of how much the web needs an easy payment system (as easy as in-app purchases in mobile). EFF, wikipedia, I often see notices or news of things they're doing and think to myself that I should donate. But I'm usually in the middle of something and stopping everything to take out my wallet, get the CC, fill out a form, etc. is just too disruptive. So I try to remind mys…
Indeed, they should consider looking more at Europe, especially France and Germany. Their donation page seems to focus too much on US, Canada and seems to assume the rest of the world is happy with PayPal. Other organization provide all information for SEPA bank transfers on their donation page (e.g. http://www.osmfoundation.org/wiki/Donate/SEPA ), while the OpenBSD donation page just provides an email address that y…
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#83Useful (non-slashdot) links: Initial ask for help: http://marc.info/?l=openbsd-misc&m=138730448307723&w=2 How much it costs: http://marc.info/?l=openbsd-misc&m=138972987203440&w=2 Why old hardware platforms matter: http://marc.info/?l=openbsd-tech&m=138973312304511&w=2 Why not kickstarter: http://marc.info/?l=openbsd-tech&m=138973837906139&w=2 And most importantly, the donation link: http://www.openbsdfoundation.org/…
I really love how we keep getting advice. Anyone want to suggest we hold a bake sale? It's funny to hear this sort of thing from someone trying to accrue $20k in donations. Yes, many people will give bad advice. No, you don't really get to complain about it when you are asking them for large sums of money.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#84Earlier quoted context omitted.
Why not move the machines, and if the Amiga breaks down and they can't find a replacement, end Amiga support? I mean, that's not a wonderful outcome, but what would you prefer to see given the following options? a) Shut down OpenBSD b) Shut down Amiga support in OpenBSD I mean, is it even a hard choice? Besides, if there are many developers who like developing for Amiga, surely they would be able to find a replacemen…
Or hidden option c): ask people to donate money.
the fact is right now, OpenBSD will shut down if we do not have the funding to keep the lights on.
suggests the necessary $20k (cash) has not been forthcoming.
P.S. I understand it's not a threat in the sense of ransom etc, but the most correct word is not coming to my mind.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#85A little bit off topic, but this reminds me again of how much the web needs an easy payment system (as easy as in-app purchases in mobile). EFF, wikipedia, I often see notices or news of things they're doing and think to myself that I should donate. But I'm usually in the middle of something and stopping everything to take out my wallet, get the CC, fill out a form, etc. is just too disruptive. So I try to remind mys…
Indeed, they should consider looking more at Europe, especially France and Germany. Their donation page seems to focus too much on US, Canada and seems to assume the rest of the world is happy with PayPal. Other organization provide all information for SEPA bank transfers on their donation page (e.g. http://www.osmfoundation.org/wiki/Donate/SEPA ), while the OpenBSD donation page just provides an email address that y…
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#86Earlier quoted context omitted.
Seriously? What's not to understand? He said they had reasons that prevent them from moving and didn't want to discuss it further. Why push it? Isn't he in a better position to decide what's unacceptable than you are?
If I'm donating I would like to know exactly where the money is going, and what options have already been explored. OpenBSD should have referenced, full documentation about these things if they want to maximize donations. Apparently, there isn't very much documentation/open accounting, and they aren't willing to discuss options to reduce the bill. That doesn't inspire confidence.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#87when i make budgeting decisions (whether personal or in business), i start with the needs before going to the "nice to haves". for openbsd, i can't help but assume powering their various servers/systems is kiiind of a priority...
so what i want to know is: - the over all budget $ amount for 2014 - what was the cost of power in 2013 * how did you get to $20k for 2014? - which priorities are worth funding over power
my suspicion is that there's plenty of room for give and take here.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#88So let's deal with the elephant in the room: the OpenBSD project is run by complete and utter jerks. Not just Theo, but he has set the bar quite low when it comes to friendliness and tolerance of questions from younger/less experienced contributors. Linus' rants on the Linux kernel lists are almost cookie cutter copies of Theo's. There is "opinionated software" and then there is Theo being an intolerable, obnoxious,…
Linus is a jerk towards experienced maintainers. Theo is a jerk towards everyone. There is a big difference.
I can't be bothered to look for it right now, but there was an email on lkml where an inexperienced contributor basically asked "should i just give up?" and Linus chipped in with quite a friendly manner and mentioned how important contributions from everyone were to the project.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#89> The OpenBSD project uses a lot of electricity for running the > development and build machines. A number of logistical reasons > prevents us from moving the machines to another location which might > offer space/power for free, so let's not allow the conversation to go > that way. I don't understand this comment. If the choice came down to moving versus shutting down entirely, why is moving an unacceptable answer?
I'm pretty sure that a lot of the older hardware at least require some degree of hands on administration. Rebuilding an testing a new kernel on a VAX with no remote administration features would slow things down. Having stuff easily available makes a lot of sense to me.
Re: OpenBSD will shut down if we do not have the funding to keep the lights on
#90> The OpenBSD project uses a lot of electricity for running the > development and build machines. A number of logistical reasons > prevents us from moving the machines to another location which might > offer space/power for free, so let's not allow the conversation to go > that way. I don't understand this comment. If the choice came down to moving versus shutting down entirely, why is moving an unacceptable answer?
> why is moving an unacceptable answer It seems likely that they don't trust anyone else to have physical access to the machines for security reasons. Their threat model probably includes national governments.
My first "real" job was in the mid-90's; I was the first technical hire at a small Chicago ISP (EnterAct) that grew into a relatively large ISP (when I left, we were default-free peered to several tier-1 providers and had more POPs than I can name). It was great, and the team that started it --- two Big-5 accounting firm programmers --- was inspiring, particularly when it came to business strategy.
Anyways, very early on, EnterAct managed to maneuver into a reputation for premium customer support. We got that reputation by doing some concrete things differently than our competitors: we staffed an appropriate number of CSRs, trained them to be nice to customers, did a lot of gratuitous tech support for basic computer problems, and were flexible about resolving billing disputes. Sadly, a lot of those things were differentiators at the time. A couple years in and we were essentially able to hang "best customer support" on our list of features, and eventually we became the most popular ISP in Chicago largely based on that.
But something I came to notice pretty quickly: the things we were doing to earn that support reputation stopped being empirical differentiators pretty quickly. Our largest competitor, run by Karl Denninger, did us a continuing series of favors by pissing off their customers. But other large regional ISPs pretty quickly learned not to set fire to their customer base, and, by the end, I think our customer service was pretty much at par for the whole area; we were no longer truly different based on support. The reputation, however, never left.
That observation has stuck with me for my entire career. I think about it all the time. It's banal, I know: "early impressions count a lot", but there's a little more to it than that: you can weaponize an early impression by turning it into your market positioning and having some message discipline.
I left EnterAct for a job in Calgary with a company called Secure Networks (SNI), doing development and security research. For the year prior to leaving EnterAct, I had also been working with the OpenBSD project, mostly by writing all their security advisories, but also doing a bit of part-time security research. SNI operated the world's first commercial vulnerability research team, and had a very close relationship with Theo; we had a full time employee who had essentially led the first OpenBSD security audit. I went drinking with Theo many times, and vividly remember hanging out in his basement with Tim Newsham eating bad pizza and trying to find vulnerabilities in Daniel Bernstein's qmail (we found one that would work if integers were 128 bits, but ironically missed the LP64 bugs that Georgi Guninski found; it was 1997, though).
This is all a long prelude to a simple point, which is that I think OpenBSD's reputation for security works in a very similar way to how EnterAct's reputation worked. OpenBSD started doing something very different than FreeBSD, Linux, and (particularly) NetBSD: they did an OS-wide audit for vulnerabilities, and aggressively fixed apparent bugs whether or not we could demonstrate that they were exploitable. That was a great move. But it was so obviously great that pretty much everyone (with the possible exception of NetBSD) quickly adopted the practice.
Among security research insiders, OpenBSD's reputation became a little bit farcical. Not that OpenBSD was comically insecure --- it wasn't --- but that its reputation so far outstripped its actually differentiation. People found a bunch of vulnerabilities in OpenBSD and laughed as the claim at the top of the OpenBSD changed from "no vulnerabilities" to "no remotely exploitable vulnerabilities in the default install".
And at some point in the last 10 years, didn't OpenBSD's distro servers get owned up?
I'm sure the OpenBSD project would like its threat model to include NSA. But OpenBSD is not a meaningful ally in a contest between you and NSA. NSA wins that fight. OpenBSD's userland was much stronger than FreeBSD's in 1999, but I'm not sure I think their kernel is stronger in 2013, and that's probably what matters more.
Let me wind this bloviation up with a caveat: one thing a reputation for security gets you is a feed of talent that is interested in working on security problems. OpenBSD certainly got that. So for instance, OpenBSD's developers designed and built privilege-separated OpenSSH. There is a lot of good security work that has started inside the OpenBSD project, and I don't mean to talk any of that stuff down. I'd just be careful about taking the project's overall reputation to the bank, especially if you have serious adversaries.
Sorry for hanging this sprawling comment off your (simpler) point; I just don't want the root comment on the thread to be me talking down OpenBSD.