4 ms·
If you want professional developers pay professional rates. A doctor asks for a hundred bucks for 15 min.
by ctrw 3y ago
If you want professional developers pay professional rates. A doctor asks for a hundred bucks for 15 min.
- michelsedgh 3y agoYes and people are paying top money to Canonical and RedHat to maintain these software don’t you think? They have huge enterprise contracts and I feel like this should be on them? Im not blaming anyone it just goes to show how vulnerable they are. Also other linux distros, Fedora, arch, etc. they have the money and should make their software safe don’t you think?
- Macha 3y agoFedora is supported by Red Hat. And yes, I do think there is something to the fact that Red Hat is selling businesses commercial support for projects they have no expertise in, which probably means some of the pressure flows downwards from Red Hat's clients to the unpaid maintainers. Arch, (Gentoo, Nix, Mint, etc.) have no commercial aspect on the other hand and certainly doesn't have the money, but those distros are offered on the same "as is" basis as the downstream software.
- Brian_K_White 3y agoYes and haven't Canonical and RedHat and others already reacted and their users are fine? I see no problem.
- michelsedgh 3y agoFirst, the problem is the reputation hit and the trust going away. Right now on Hacker News 2 maybe 3 of the posts on front page have been about this since the news broke out. Also when trust goes away, its very hard to come back. Secondly, the main problem that I see is how many other backdoors/dependencies are vulnerable that we might not know? They might not have performance issues. Also if this went unnoticed, in the long term it might have found its way and actually compromised people. I’m glad this was taken care of and no one was compromised.
- Brian_K_White 3y agoIs there some implied proposal I missed?
- fsflover 3y agohttps://news.ycombinator.com/item?id=39904034 https://news.ycombinator.com/item?id=39904034
- fmajid 3y agoOpenSSH is developed by the OpenBSD project and I have a lot more confidence in them than in any random "enterprise". The issue in this case is that Linux distros took it upon themselves to alter its code base by linking in libsystemd (thus also liblzma) for the dubious benefit of better systemd integration, which comes with a generous helping of attack surface.
- WesolyKubeczek 3y ago> Yes and people are paying top money to Canonical and RedHat to maintain these software don’t you think? They have huge enterprise contracts Money alone makes poor filler material to patch such holes. Microsoft famously doesn't make their stuff for free, and yet somehow Windows systems have gained this reputation of having holes such that a train can go through. People build trust, take shortcuts, cut corners all the time. It's how we are wired. Doing otherwise is an energy sink for our bodies. We don't make ourselves overspend energy when we can.
- ctrw 3y agoI'd hardly call a $400 per year per seat contract top dollar. There is software out there that is both much worse and costs in the tens to hundreds of thousands per seat per year.
- fmajid 3y agoThere are economies of scale for widely-used software.
- ctrw 3y agoReality disagrees. Software isn't tooth brushes. The simpler and more specialized it is the cheaper it is to maintain. The more complex it is the harder it is to maintain.
- fmajid 3y agoSoftware R&D is a fixed cost. An ERP package with its at most 10,000 installations amortizes that cost on far fewer users than Linux with its millions of licensed installs.
- indymike 3y ago> Also other linux distros, Fedora, arch, etc. they have the money and should make their software safe don’t you think? Nope. With open source the user is responsible. It's been this way from day one. Come to think of it, almost every piece of software I've ever used that is commercial has a no warranties and not suited for purpose clause in the EULA... because all the components the vendor used have that clause in the license to the vendor.
- VancouverMan 3y agoThere's no connection between how much money somebody charges for their services and the quality of the services that they in turn provide. Much of the worst professional service I've ever received, despite paying them a lot of money, has been from the example you gave, doctors. Doctors aren't alone, of course. The most expensive restaurants I've ever been to have been some of the worst dining experiences I've ever had, while friends or relatives inviting me over for a backyard barbecue have been among the best, for example. I've also found this to be the case for lawyers, accountants, teachers/professors, mechanics, and other well-compensated "professionals". Software hasn't been an exception, either. I've had more success with free software than I have had with the equivalent paid offerings many times over. In general, I've found that service quality is far more tied to the provider's level of passion for the task at hand, rather than anything to do with the amount of financial compensation that may be involved.