5 ms·
Thanks a lot for such a thorough comment! You are right, asking people to run the binary on their servers is not a good idea. I guess I have no other choice b
by medvednikov 11y ago
Thanks a lot for such a thorough comment!
You are right, asking people to run the binary on their servers is not a good idea.
I guess I have no other choice but to provide the source code to the clients, just like Atlassian does.
I just did some research, and it looks like GitHub are protecting their source code:
http://stackoverflow.com/questions/13185814/how-github-enterprise-protects-the-code-they-deliver-on-virtual-machines http://stackoverflow.com/questions/13185814/how-github-enter...
How do they get away with this?
- dmix 11y agoAn about page about who you are would be a good start. Additionally, what country your from would be of interest. Most importantly would be your incentives for doing this project. If it's money, how to you plan to monetize? Do you plan to sell your users data? etc. Trust is critical. Almost all of us Linux users run at least a few prepackaged binaries on our systems. But they come from trustworthy sources such as big companies like Github. These proprietary binaries are usually vetted by security researchers as well to detect any malicious behaviour. Additionally, I'd recommend posting SHA checksums and offering a more traditional "Download" button as an alternative to the one-liner. TLDR: You're asking people to take a risk on a new project, without any indiciation of who's behind it or why they should trust you.
- cyphar 11y ago> Trust is critical. Almost all of us [GNU/]Linux users run at least a few prepackaged binaries on our systems. But they come from trustworthy sources such as big companies like Github. These proprietary binaries are usually vetted by security researchers as well to detect any malicious behaviour. Speak for yourself. I explicitly have removed all proprietary software from my machine. The whole "vetted by security researchers" is such a vague metric with mixed results. One researcher will find 30 bugs while another will find 5 in the same time. > Additionally, I'd recommend posting SHA checksums and offering a more traditional "Download" button as an alternative to the one-liner. > TLDR: You're asking people to take a risk on a new project, without any indiciation of who's behind it or why they should trust you. Which is why he should just release the source. Then trust isn't a factor. I don't trust random people on the internet. And no, I don't trust GitHub or whoever you want to pick.
- kbutler 11y ago> I explicitly have removed all proprietary software from my machine Video drivers? BIOS? These are possible, but every individual's weighting of the difficult trade-offs may be different.
- cyphar 11y agoI use Intel's free software drivers. I've got libreboot on one or two of my machines (the others are work machines, so I'm fairly sure my employer wouldn't let me flash libreboot onto the BIOS). I wish RISC-V and free hardware design FPGAs would be a thing soon so I can get rid of the proprietary Intel microcode. Not sure what I'll do about video then though.
- dmix 11y ago> I explicitly have removed all proprietary software from my machine. So you don't use a desktop operating system? Or smartphone?
- akerro 11y agoThere are several distributions that come with no binary blobs, it's not only trisquel, but also Arch (-libre- from AUR), he could compile Gentoo himself or any BSD with flags to remove the blobs... It's easier than you think.
- cyphar 11y agoI use Arch Linux, with the proprietary blobs shipped with Linux removed. As for a smartphone, yes I have a smartphone, and yes it does bother me that I cannot run one in freedom. This is a compromise that's necessary, and I am doing my best to find alternatives that are viable. Replicant is great, but it only supports 2G (which is known to be insecure at a protocol level). Ultimately, if someone was pitching a smartphone with free hardware designs and was running completely free (or free enough that it could be made completely free) software, I would totally pitch in >$1000 for such a project, even if the phone was only objectively worth $300. That's how important the future of software freedom is to me, personally. But you might have different views, and that's fine. I just wanted to make clear that trusting a proprietary software vendor is something that I find to be extremely foolish (they will always screw you over eventually).
- imron 11y agoIf it's money, how to you plan to monetize? Do you plan to sell your users data? etc. From the webpage: Skadi is free for projects with less than 3 users, public projects hosted on our servers, and non-profit organizations. For everyone else it's only $1/month per user.
- mwcampbell 11y agoWhy does it matter at all what country the developer is from?
- Falkon1313 11y agoI can't speak for dmix, but some things that pop to my mind: Some companies have information security policies that certain types of data cannot be stored on (or sent through) servers in other countries. It's not about nationalism. It's about having it all under one legal jurisdiction (or limited set of jurisdictions). Having something like this self-hosted would be a great way to solve that problem vs using cloud services, (if it was verified not to phone home, leak data, update itself without permission, or allow remote access - hence why people want to see the source).
- cyphar 11y ago> I guess I have no other choice but to provide the source code to the clients, just like Atlassian does. Is there a reason you don't want to do that? It clearly works. Release your code under the BSD or GPL licenses and provide it to your customers. If you did that, I'd be happy to pay for software like that. But for me, free (as in freedom) software is a requirement for anything I'm going to run on my machine.
- sdesol 11y ago> How do they get away with this? They have a unique offering and they are a trusted brand. If you have neither, you are relying on blind faith. For the vast majority of business to consumer products, this isn't a problem. However, in your case, you have a product that requires the installer to be somewhat knowledgeable, hence the scrutiny. The easiest way to gain credibility is to have an incumbent vouch for you. For example, if Trello were to say, if you want to host your own Trello like solution, there is no better option than X, then most people wouldn't really care about installing a binary. Since your solution isn't novel enough for people to take that leap of faith, you really have no other choice but to make the source available or try to align yourself with an established incumbent. For example, create your product so it has tight integration with an Atlassian product and sell your solution through Atlasisan's marketplace. Or create a tight integration with GitHub and try to get it listed as an integration partner. And so forth.
- masukomi 11y agoSpot on. Couldn't agree more. I didn't download it because I didn't know anything about the creator, couldn't see the source, and had not evidence that it wasn't just some malware with a useful looking screenshot.