4 ms·
Imagine blaming a FOSS dev/mantainer because you didn't do your job properly and trust a third party on a production code!
by adabaed 5y ago
Imagine blaming a FOSS dev/mantainer because you didn't do your job properly and trust a third party on a production code!
- watwut 5y agoI find thins point of view equally absurd as all the abuse on maintenners of Foss. It is standard for production code to rely on third party libraries. Not just standard, but the opposite is considered bad thing - you are not supposed to implement everything from scratch. If you do, you will end up with more bugs and issues. There is nothing, absolutely nothing in development last 30 years that would say "it is bad to use open source libraries".
- piaste 5y agoYep. Log4Shell and Heartbleed were nasty security bugs, but imagine living in a world where every single software shop wrote their own logging libraries or SSL libraries. 99% of them would have far worse vulnerabilities. It would be like '90s php cowboy coding.
- izacus 5y agoSee also: The state of proprietary closed hardware drivers and IoT firmwares. There's more security bugs in those than in Windows Me.
- tonyedgecombe 5y agoAbsent open source we would all be buying those libraries from small software shops just as happened in the ninieties before OS become so prevelant.
- mbrodersen 5y agoExactly. And the people maintaining it would be paid to do it. Instead of complaining about nobody paying them.
- watwut 5y agoI worked with small shop library. It was complete crap. We used, because management decided so. But no, it was not all that kuch prevalent. Instead, people wrote their own almost everything.
- mbrodersen 5y agoFunnily enough that would make the world more secure since a security problem found in one logging library might not be a security problem in another logging library. So you have thousands of firewalls instead of a single point of failure (the shared library). Making it very expensive for the attacker.
- GoblinSlayer 5y agoThe legacy code is definitely bad, because it uses bad programming practices. A rewrite can easily be better by not doing known bad things.
- adabaed 5y agoWhere did I say you should develop everything from scratch? I'm talking about auditing, updating, sharing revenue with the main FOSS software you use.. Being responsible with your software to minimize attack vectors.
- wheresmycraisin 5y agoUsing third party libraries in production libraries, regardless of its license, means you audit, vet, and test as much as possible the consequences of bringing in the library. And going through the same process every time you update the library. "Who does that?" Good software engineers do that.
- watwut 5y agoThat is just not a thing that would be expected or normal. Not for run of the mill commercial software It would also be irrational. The rare security issue like this is kot a good enough reason for such massive undertaking. You manage risks, you are not supposed to act purely out of fear. > Good software engineers do that. The amount of effort required would necessitate management sign up for this. And they won't, because it is not rational thing to do for majority of software.
- lnxg33k1 5y ago
- GoblinSlayer 5y agoIronically the maintainers can always say "fuck you, pay me", but they don't, because they know blaming is a good thing.
- thawkins 5y agoThat should possibly be something that is added directly to the licenses, you can take my product free of charge, but if you want changes you have to pay me at this rate. Put contact details and an expiry date on the deal so people can't get jacked up with very old prices on very old versions. That would also encourage people to keep thier 3rd party inclusions up to date. I don't think that would pass muster as an OSS license but maybe a built in support contract should be a feature of the licenses, one that earns people proper money that makes OSS a model that supports maintainers.
- GoblinSlayer 5y agoThe support offer can sit side by side with the license in, say, support.txt