6 ms·
It is really interesting that major open source initiatives are now being ran by corporations. I feel this will be open source in the sense that it is being dev
by TACIXAT 6y ago
It is really interesting that major open source initiatives are now being ran by corporations. I feel this will be open source in the sense that it is being developed in the open, but not in the sense that they will foster an environment of community contribution.
For example, the working group for vulnerability disclosure includes a lot of corporate players, and from what I can tell, not a single security researcher. Only one side of the disclosure process is represented in that working group.
Realizing how allergic major companies are to GPL code really creates some skepticism when they speak about embracing open source.
- scovetta 6y agoHi! I'm leading one of the working groups for the OpenSSF (Identifying Security Threats) and I understand your point here. I hope I speak for everyone, that we want the larger community to be directly involved, and not have this be an organization "run by corporations". (I'd go so far as to say that this initiative cannot be successful without strong community support.) If you or anyone else is interested in participating or learning more, please drop me a line at michael /dot/ scovetta {at} microsoft.com.
- nwellnhof 6y agoThen why is there no obvious way to get in touch with you on your website? Are we supposed to search for random forum posts of your members? I once applied for a grant with the Core Infrastructure Initiative, the predecessor of the OpenSSF. It took me about half a day to write and submit a proposal, only to never hear back. After a couple of weeks, I tried to contact the Linux Foundation through their contact form and ask about my grant application, without success. Then I tried to contact some responsible people directly. I never got a single reply. That's just shameful. Organizations like the Linux Foundation are antithetical to core idea of Open Source which is, well, openness. But maybe Microsoft can bring some change into these encrusted institutions. BTW, I'm the maintainer of the XML parser and XSLT engine in your latest web browser. Bet you never even heard of me. There are quite a few security-related issues that still need work.
- caniszczyk 6y agoIt's because all the work is happening in the open on GitHub in Working Groups if you want to get in touch with people, it's literally describe in the FAQ + "Community" top level button that takes you to https://github.com/ossf https://github.com/ossf Also, the LF not only helps fund the development of Linux through Linus and other fellows, it hosts a plethora of other open source organizations, like LetsEncrypt which I'm sure you use on a daily basis without knowing.
- _msw_ 6y agoDisclosure: I work at Amazon on cloud infrastructure, and I am a technical advisor on FOSS related topics from time to time. Chris, I think that the feedback on the CII grant process deserves to be acknowledged and addressed if possible. I wasn't directly part of the day-to-day efforts of CII, but I (as an individual providing one's opinion and advice) supported the original charter of directly funding security related development of critical software libraries that are often unnoticed like libxml2, OpenSSL, etc. I am disappointed that CII didn't achieve this objective for more software (there were a few grants that were awarded and completed, but over time this seemed to end, from the public updates I read at the time). I think that it is still a good one to have.
- caniszczyk 6y agoMatt, the CII grant program became problematic for a number of reasons and that OpenSSF is certainly aiming to avoid replicating those mistakes and making entirely new mistakes instead (to not only focus on grants and truly help define what critical software is). The CII was before my time at the LF so I don't have much to share outside of it was in the mind of the OpenSSF founders to do better.
- _msw_ 6y agoI imagine the folks where were directly involved in CII (so, not me) would have loved to have had an opportunity to share their experiences and perspective during the closed-door formation phase of OpenSSF.
- goalieca 6y agoBest way to rise the corporate ladder is to get your name on an industry wide working group.
- dwheeler 6y ago> It is really interesting that major open source initiatives are now being ran by corporations. That should not be surprising, as they now all depend on OSS. I think this can be a good thing. The resources they bring can help OSS, and thus all its users and contributors. > I feel this will be open source in the sense that it is being developed in the open, but not in the sense that they will foster an environment of community contribution. I think it's reasonable to worry about that. But the Linux Foundation works very hard to foster contributions and comments from all. The Linux kernel, Kubernetes, and many other important OSS projects are in the LF. I think LF has a good track record. Full disclosure: I just started to work for the Linux Foundation. But I would have said the same before.
- charliebrownau 6y agoBULLSHIT ... Its filled with left wing wankers that pander to discrination against merit, anti freedom and left wing feminists/marxists/etc ... I wouldnt be suprised if someone with the LF has dirt over Linus and thats why he cucked out recently in the last year... SJW COC + Removing words, it NEVER FUCKING Stops for the global left until all right wing and pro freedom people are CULLED
- oddity 6y agoIt's not too strange. Open source has taken off for a similar reason that news wire services took off in the early 1900s. Most software organizations create isn't the end product, so if you can leverage a community to maintain it, it (hopefully) reduces costs for all maintainers. Meanwhile, free software is really right to repair for software enforced via copyright instead of (dedicated) legislation. It threatens to reduce the power of the corporations, so they will be generally hostile to it unless their end products are the services that only they can build around it.
- bruce511 6y ago>> Realizing how allergic major companies are to GPL code really creates some skepticism when they speak about embracing open source. While orthogonal to your main point, this sentence conflates Free Software (GPL) with Open Source. It should be emphasised that the GPL is NOT open source, and that Open Source is not Free Software. https://www.gnu.org/philosophy/open-source-misses-the-point.en.html https://www.gnu.org/philosophy/open-source-misses-the-point....
- DoctorNick 6y ago...GPL is an Open Source license as defined by the OSI. Free Software and Open Source Software have overlapping (but not 1:1) definitions.
- MaxBarraclough 6y agoThis is correct. Here's the OSI's list of approved licences: https://opensource.org/licenses/alphabetical https://opensource.org/licenses/alphabetical
- darkwater 6y agoEvery line of GPL code is opensource. Not every line of opensource code is GPL.
- hannob 6y agoYou seem to be very confused about these things, though those misconceptions are common... Ultimately Free Software and Open Source mean the same thing. They come from philosophically different viewpoints that they emphasize - free software tries to emphasize on freedom, while open source is more a technical approach and often comes from more business oriented people. But in terms of what licenses actually qualify as either Open Source or Free Software - they don't differ. And the GPL absolutely is an Open Source license. The organization that made the term Open Source popular agrees: https://opensource.org/licenses/gpl-license https://opensource.org/licenses/gpl-license
- bruce511 6y ago
- Foxboron 6y ago> For example, the working group for vulnerability disclosure includes a lot of corporate players, and from what I can tell, not a single security researcher. Only one side of the disclosure process is represented in that working group More importantly, the vulnerability disclosure group does not have a single contributor from the largest consumers of vulnerability disclosures: Linux distribution security teams. And while I think they can go far improving the current situation, 'creating an API' isn't really the main pain point we are faced with when a legacy entity deals with handing out CVEs. Thus I'm unsure if a corporate-only working group is capable of getting a complete picture of problems regarding F/OSS vulnerability disclosure.
- MaxBarraclough 6y ago> Realizing how allergic major companies are to GPL code really creates some skepticism when they speak about embracing open source. I'm aware of Google being AGPL-allergic, but are there companies out there that ban everything under the ordinary GPL? They'd have to avoid the Linux kernel, if they really meant it.