4 ms·
But the rub is that open source owners have no actual obligation to you. So while you might want them to be "prepared with answers" they don't actually need to
by tensor 4y ago
But the rub is that open source owners have no actual obligation to you. So while you might want them to be "prepared with answers" they don't actually need to be. Some will want to be because they want their software to be used and up-to-date. But others have likely shelved their software, or just don't care to solve your security problems for you but will accept a patch if you provide one.
- karmicthreat 4y agoAnd its literally what developers that are taking open source software and using it to sell something need to understand. The sellers are adding that value and taking that risk. If I go to the store, buy some wood, build a shelf from the wood and sell the shelf. Then it burns my customers house down, its on me not Home Depot.
- est31 4y agoThat's where OSS companies like Suse or RedHat come in: they do provide support for their distributions. And, unlike Amazon, they also employ many maintainers and if they don't employ them, they sometimes submit patches to upstream so are good OSS citizens.
- oaiey 4y agoThat is all fair. The premise is the article headline that open source or Foss is dead. An open source software no one can use is a dead software. So the success of a Foss software might not only depend on functional aspects in Future but also on non functional aspects like the Cybersecurity management. And do not think that this influence will not happen. There are reason why the non functional requirement licensing has switched to MIT from previously more LGPL constructs. Having said all that... Yes, no one is obligated to answer.