4 ms·
The real problem is that Ubuntu is emitting knowingly vulnerable software for free, and then flaunting "if you were part of our pay-group, you'd get the securit
by tarotuser 4y ago
The real problem is that Ubuntu is emitting knowingly vulnerable software for free, and then flaunting "if you were part of our pay-group, you'd get the security patches".
The ethical thing is to upstream the fixes, or quit transmitting knowingly faulty and vulnerable software.
- scott_w 4y agoAs explained, this isn’t what they’re doing at all. They’re putting their own patches in, not withholding upstream patches. If all they did was patch upstream, you’d have to wait longer for the fix. I don’t see how that solution is unambiguously better.
- tarotuser 4y agoIm well aware what they're doing, as I submitted this nearly 2 days ago https://news.ycombinator.com/item?id=34605980 https://news.ycombinator.com/item?id=34605980 Charging money isn't explicitly against the GPL, BSD, or similar FLOSS licenses. However, are they doing what's required of them with the licenses they're making changes to? Better yet, are they submitting these fixes to the package maintainers to fix? What would happen if *I* get this Ubuntu Pro Plus Super crap, and download source, diff it, and submit the diff? Better yet, now that Ubuntu has a fiduciary reason to slow down updates/fixes to Universe, are they going to impede package security fixes and updates, as it now hinders their revenue stream? > As explained, this isn’t what they’re doing at all. They’re putting their own patches in, not withholding upstream patches. As explained, Ubuntu is providing knowingly security-vulnerable software, and then as an upcharge offering their own custom fix. There's plenty of ways to handle this, some better and some worse. They chose worse. > If all they did was patch upstream, you’d have to wait longer for the fix. I don’t see how that solution is unambiguously better. Again, they flagged vulnerable software. They could have emitted a message via APT to warn of a security incident with said software. Or they could remove it from the repo until fixed, or hide it behind a flag with apt. They instead chose to keep disseminating it, and then gatekeep their fixes.
- scott_w 4y ago> What would happen if I get this Ubuntu Pro Plus Super crap, and download source, diff it, and submit the diff? If it’s GPL or BSD then you’re certainly welcome to submit the patches if Ubuntu haven’t. I don’t know why you’re casting aspersions without actually checking what they’re doing.
- netsharc 4y agoIs it still open source? Can I take the source of the "Ubuntu fix" and upstream it?
- mrdatawolf 4y agoSo, if Gnome DE has a zero-day exploit Ubuntu should immediately pull the Gnome Desktop until the upstream patches it? Otherwise, it's not about ethics just time.
- tarotuser 4y agoThis isn't a binary answer, no matter how much you try to cast it as one. Software exploits are found regularly. But this is different, with the fact that Ubuntu is peddling knowingly vulnerable software, and then with the implicit threat of "Sure'd be ashame if you were hacked by our software we know is vulnerable... cause you didn't pay us for the fix". I don't know the "best" course of action that applies everywhere. In some applications, you take the chance until the fix is out. Others, you take it down. And in others, you throw on extra detections and remediations to impede the attack. But you know this - you just wanted to get your one-liner quip in. Ubuntu put crap in the MOTD. They could have just as easily made a RSS feed, and attach it to the security patches, and alert users of impending "bad stuff down the pipeline". But instead, they just SNAPify and shove more garbageware and terrible decisions down the pipeline. Basically, Ubuntu is the next case of Cory Doctorow's "enshittification" of software and goods.
- prmoustache 4y agoSoftware vendors have done that for decades with nobody giving a fuck.