Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID:
 <SYBPR01MB6336A068E514052B108247BBEED62@SYBPR01MB6336.ausprd01.prod.outlook.com>
Date: Sun, 2 Aug 2026 07:32:14 +0000
From: Peter Gutmann <pgut001@...auckland.ac.nz>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Some Changes to GNOME Security Tracking

Russ Allbery <eagle@...ie.org> writes:

>One solution that anyone in open source software communities has heard about
>for decades now is to turn open source software maintenance into a job with a
>paycheck. Then it doesn't necessarily have to be fun

It can still be fun, and in some cases more fun than pure open-source.
Consider the difference between "we have a practical real-world problem that
we need solved, there's real-world demand for it, we can describe it in
detail, and we'll pay you to solve it" (commercial user) vs "i have some me-
only feature that I want you to add to your code just for me and I'll whine
endlessly on Github/Discord/whatever if you don't" (open-source).  That's an
extreme for illustrative purposes, but with commercial users you've got
direction and focus while with open-source you've got a kind of free-for-all
where people want this and hack in that unless you have a strong benevolent-
dictator model or small group of maintainers who screen everything to keep the
codebase stable and bells and whistles to a minimum.

Peter.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.