3 ms·
"Here's Daniel a guy who struggle to keep his open source project used by millions working in very important big tech projects. Despite the fact that big compan
by oscargrouch 5y ago
"Here's Daniel a guy who struggle to keep his open source project used by millions working in very important big tech projects. Despite the fact that big companies use its project, he mostly get funded by ordinary people who can pay a few bucks"
"But Daniels destiny is about to change, a ORG that funnels capital from big tech companies to make software more secure is about to give him a grant"
"Here Daniel, we have a grant so you can fix your security bugs"
"Oh great, now i can invest in more unit test and have people to fix them.. and.. "
"But you will only receive the money if you or someone we pay for write those parts in Rust"
While Daniel is being payed, this is not actually/only focusing on security as an end goal, but is using security as a pitch to rewrite popular software in Rust which in the end will probably have more bugs giving the older software were much more battle tested..
So we have people with foot on big tech collect money through an org to rewrite software in Rust and not to ACTUALLY help the people doing software with very low resources to fix their software.
Daniel is saying he will still keep doing it in C. So why do this org tried this approach giving i bet whatever you want that this money invested for them to focus on security even in C would make it have less bugs, because the real problem here is economics and less the language.
Its a pity that an ORG is being used as a facade to create implants of Rust in popular projects, instead of helping out open source developers with money that would probably reach them if they did not act as the middle man to those important projects.
See their goals here, is not even about security as a whole, but memory safety, and while they cite other languages, this is clearly biased towards Rust.
https://www.memorysafety.org/docs/memory-safety/ https://www.memorysafety.org/docs/memory-safety/
Please dear ORG take the money from big tech, invest part of it for new projects in Rust if you wish, but really help the open source maintainers to fix their security bugs in the technology they use. Note that you are receiving this money using their projects to receive the grants. Really help them make their software more secure.
If you are really into the Rust hype, so create a fork in Rust, show that you were right.. or at least be open when collect the money to invest what your real goals.
But its a pitty, a project like OpenSSL for instance wont see a dime of this money. So sorry if i dont feel happy about this..
- mwcampbell 5y agoAgain, Stenberg himself seems to feel differently about what's going on than you do. From his blog post "What goes into curl?" [1]: > I’m the lead developer of the curl project but I also offer commercial support and curl services to allow me to work on curl full-time. This means that paying customers can get a “priority lane” into landing new features or bug-fixes in future releases of curl. They still need to suit the project though, we don’t abandon our principles even for money. [1]: https://daniel.haxx.se/blog/2021/06/16/what-goes-into-curl/ https://daniel.haxx.se/blog/2021/06/16/what-goes-into-curl/
- oscargrouch 5y ago> Will I ever rewrite curl in rust? > I don't believe in rewrites, no matter which language. I believe in replacing code and fixing components gradually over time. That could mean that we have a curl written mostly in rust in 10 years. Or in 20 years. Or not. https://twitter.com/bagder/status/1360131939794042884 https://twitter.com/bagder/status/1360131939794042884
- geofft 5y agoThat exactly matches the philosophy of this organization: https://www.memorysafety.org/about/ https://www.memorysafety.org/about/ > We recognize the amount of work it will take to move significant portions of the Internet’s C and C++ software infrastructure to memory safe code, but the Internet will be around for a long time. There is time for ambitious efforts to pay off. By being smart about our initial investments, focusing on the most critical components, we can start seeing significant returns within 1-2 years. > We encourage projects to replace libraries or modular functionality with memory safe libraries, rather than embark upon ground-up rewrites. This allows us to break up the work into manageable pieces and deliver value incrementally. > Since many projects will end up using the same memory safe libraries, this approach also allows us to invest and build confidence in a particular set of libraries. Investments in a library for one project will add value across multiple projects. For example - the curl project will use the Hyper and Rustls libraries. The work we do to build excellent C API wrappers and improve the integration experience will help with many projects that will use the libraries in the future.