6 ms·
> If I disclose a security issue to you, it doesn't matter if you're a multinational trillion dollar corporation or a hobbyist in Nebraska, the onus is on you t
by noselasd 2y ago
> If I disclose a security issue to you, it doesn't matter if you're a multinational trillion dollar corporation or a hobbyist in Nebraska, the onus is on you to fix it. Not the security researcher. Their job is done once it's disclosed.
On the other hand, if I'm a hobbyist, I have 0 obligations to do or fix anything I've made open source. Patches are welcome ofcourse.
- deleted 2y ago[deleted]
- ziddoap 2y ago>I have 0 obligations to do or fix anything I've made open source. While technically true, this seems pretty scummy when you're advertising security software for real people and companies to use as their identity management. Nowhere on the Keycloak home page does it say "just a hobby project" or anything that would remotely indicate that it is not a serious project and that you shouldn't use the software. Instead, it seems like they are trying very hard to be taken seriously as an identity management product.
- flanked-evergl 2y ago> Nowhere on the Keycloak home page does it say "just a hobby project" or anything that would remotely indicate that it is not a serious project and that you shouldn't use the software. https://github.com/keycloak/keycloak/blob/main/LICENSE.txt#L144-L175 https://github.com/keycloak/keycloak/blob/main/LICENSE.txt#L... Indeed 7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.
- ziddoap 2y agoPoint 7 buried in the license document of the github repository is very much not https://www.keycloak.org/ https://www.keycloak.org/
- willcipriano 2y agoCustomers have been refunded in full.
- mardifoufs 2y agoRed hat consumers have been refunded? Where?
- willcipriano 2y agoAs per the terms here: https://www.keycloak.org/pricing https://www.keycloak.org/pricing
- mardifoufs 2y agoThe point is that red hat also sells keycloak and develops it. I agree that most users don't pay, but your point is a bit weird considering that some people do actually pay/paid for its development and still do not get a refund
- lucianbr 2y agoYou really feel that anything that is not directly on the home page does not matter? A link to a separate document explicitly named as containing the conditions of license, warranty and such should not count? Seems like an absurd view to me. For all that I think RedHat is not a poor hobbyist and morally at fault. It's just a different matter altogether. The terms under which the software is provided are clearly spelled and in public view. You're just inventing a reason to disregard them.
- 2y ago
- marcosdumay 2y agoAs long as you disclose that right-front on your value statement, yeah, you don't have any other obligation.
- Macha 2y agoIs there an open source license that doesn't?
- vetinari 2y agoIt is right in the license.
- KajMagnus 2y agoThat's not what these licenses have come to mean. They're a way to reduce the risk that you'll get sued, but not any "I don't give a fuck" statement. You could add "I don't care about fixing security vulnerabilities" somewhere in the beginning of the readme, if you're developing security related OSS software? That'd be more clear. Maybe the WTFPL actually a little bit indicates that the developers maybe don't give a fuck, though: https://en.wikipedia.org/wiki/WTFPL https://en.wikipedia.org/wiki/WTFPL ?
- kube-system 2y agoThat sounds a little like having your cake and eating it too. 'Giving a fuck' is not really a boolean value but more of a broad spectrum. Of course, anyone who writes any software cared a little bit about it at one point, or they wouldn't have written it. But warranty is about whether they care enough to cater specifically to you when you have a problem in the future. Maybe many of these projects do care enough to give general updates to the community as a whole on a best effort basis, but that's a lower level of assurance and more voluntary than what you'd get in a legal warranty.
- hifromwork 2y ago>You could add "I don't care about fixing security vulnerabilities" somewhere in the beginning of the readme I care about fixing security vulnerabilities in my OS projects, but I care more about my sanity, my family, getting enough money to survive, and a few other things. Unless you pay me I don't care about your problems with my free (as in a beer) software. And that's a good thing btw - I tried to ask for donations once, got the equivalent of a few cups of coffee per month, and... burned out almost immediately. I started to feel responsible for that project, staying up late to fix reported minor bugs, and it turns out watching Github issues 365 days a year for a few dollars monthly is not a great business strategy.
- hinkley 2y agoThen you should never work on software with security implications, or if you do you should keep it to yourself. I’m a terrible party host, so I don’t host parties. I help other people do so when I can.
- thunky 2y agoAnd you also shouldn't expect anyone to use your software. Which of course is up to you.