Onno (VK6FLAB)

Anything and everything Amateur Radio and beyond. Heavily into Open Source and SDR, working on a multi band monitor and transmitter.

#geek #nerd #hamradio VK6FLAB #podcaster #australia #ITProfessional #voiceover #opentowork

  • 138 Posts
  • 276 Comments
Joined 2 years ago
cake
Cake day: March 4th, 2024

help-circle



  • I’m a software developer with over 40 years experience. Much of it with FOSS.

    Your argument in relation to GitHub does not take in the reality of the effort involved with migrating to a different platform, effort that is likely unpaid, has no logistical upside and stalls the development efforts of a project, not to mention breaking every single source code repository link across the wider internet, links that represent publicity and community engagement.

    It’s one thing migrating after a service vanishes, it’s an entirely different thing to migrate due to the philosophical differences perceived by the ownership change to Microsoft. In my opinion, chanting FOSS is insufficient as an argument.

    I have several projects and clients that use GitHub and while I detest copilot and the enshitification that the new ownership represents, I’m also aware that it’s likely that the sale provides financial security to the continued existence of GitHub.

    I think it’s admirable that a project is asking its community if it should stay or move and I wish the developer(s) wrestling with this all the strength and patience in the world to work through it.

    I know I’ve struggled with the same considerations and I’m still using GitHub … for now.







  • It’s like “sugar free” and “green”, meaningless unless it’s regulated, policed and prosecuted.

    As others have said, the best labelling system we currently have is the licence that’s attached to the software.

    Mind you, that in and of itself is not sufficient, since the source code needs to come with it, and arguably the ability to actually compile it, neither of which are guaranteed, again more requirements for policing and prosecution.

    Also, when I say policing, I’m not talking about the law enforcement community, I’m talking about developers and end users paying attention and calling out breaches.

    Whilst contemplating all that, this costs money, something that is in very short supply within the wider open source software community and what little there is, goes to pay for food and lodging for a very very very small group of developers.

    Fix funding and you can have all the stickers in the world, in the meantime, nope.

    So, somewhat disappointedly … no.





  • First of all, congratulations.

    Second, I have a question.

    Based on the link you supplied, SPI is a USA based organisation. How do you expect to protect yourself against the legal lunacy that is currently overrunning the USA?

    For example, what if as a member project you are suddenly compelled by a USA court to install a backdoor into your codebase?

    It’s easy to ignore such concerns, but governments around the planet are reevaluating their relationship with companies like Microsoft for precisely such reasons, and they have much more money to spend on legal advice than you do.













  • Yeah … that thought occurred to me as well.

    I wonder if there’s a way that you can legally monetize the process, so the organisation who left a gaping hole … or several bazillion in this case … gets an education in corporate security and the researcher gets paid for their efforts. A corporate symbiosis if you like.

    If course the non legal way is extortion … but that tends to go towards warfare and mutually assured destruction, rather than collaboration.

    Perhaps this opens the door to a white hat penetration testing department at the corporate regulator who issues fines (which pay for the work) … but I’m not seeing any evidence of an appetite for anything even remotely resembling such a set-up anywhere on Earth.

    Espionage on the other hand …