4 ms·
My first reaction is also that this could be a good thing. We need secure software infrastructure. Markets have not provided that and this could be one part of
by nonrandomstring 4y ago
My first reaction is also that this could be a good thing. We need
secure software infrastructure. Markets have not provided that and
this could be one part of the road to a solution.
Despite the headline this is about all software, not just code
that's developed with open source and software freedom as features.
Now could be the time that FOSS gets to put the many-eyes reasoning to
the test with crowdsourced standards compliance. It could make paid
jobs for open source developers as CE auditors for code. That code is
currently just taken by big companies for free, plus the ingratitude
of blaming developers who work for nothing when it goes wrong.
It's mostly a checklist exercise anyway. So long as there's no
monetary cost to compliance it may create a cadre of OS reviewers who
are skilled and prepared to do it for free for projects they support.
Surely, in a real security meritocracy the cruft that passes for
"closed proprietary" software will soon be exposed for what it is. How
long will Windows 11 last in an environment with good security
culture?
Proprietary software will not only have to compete against free, it
will have to compete against _good_, and certified good free and
commercial FOSS. The FUD, disinformation and fearmongering of Big Tech
and it's shills may end up having less impact, not more.
OTOH I doubt this will impact hobby developers and Non-Commercial FOSS
that comes with liability disclaimers from the get-go. It will
however, impact those who want to take that work and deploy it in
critical roles for commercial gain.
- nonrandomstring 4y agoIt's disappointing to see missed opportunities to discuss some challenging and progressive twists to FOSS raised here.