3 ms·
Not sure why you choose an interpretation that goes against your interest, instead of the more advantageous one, namely that your one-man software business woul
by Rygian 1y ago
Not sure why you choose an interpretation that goes against your interest, instead of the more advantageous one, namely that your one-man software business would be able to charge a sizeable premium if the buyer is planning to use your software in a security-sensitive operation.
- jonathanstrange 1y agoYou're talking about a forced price increase and in the B2C market consumers do not pay sizeable premiums. Apropos "security-sensitive operation": Any software that connects to a network is a security-sensitive operation. There is no alternative reality were your proposal wouldn't just drastically raise the price of software and make it essentially impossible for small companies to use open source software because of the increased legal risk and auditing costs. There are already plenty of certifications that are required for software in certain business areas such as HIPA and FIPS certifications. However, these are voluntary for companies who want to sell in sectors that require them. Assuring compliance is very costly in development, auditing, and bureaucratic overhead, and for this reason this kind of software is very expensive. If Cloudflare was forced to get expensive certifications for the Circl library, they wouldn't publish it as open source. They'd perhaps sell it at a high price point. That wouldn't be an advantage for anyone. Without such libraries communication would be very insecure by default. The whole internet is running on open source security libraries that individual developers cannot implement on their own (and it would be a bad idea if they tried). Not just the internet by the way, the same holds for nearly every cryptographic and otherwise security relevant library of programming languages.