|
|
Message-ID: <20260802152226.GA2949@openwall.com> Date: Sun, 2 Aug 2026 17:22:26 +0200 From: Solar Designer <solar@...nwall.com> To: Russ Allbery <eagle@...ie.org> Cc: Peter Gutmann <pgut001@...auckland.ac.nz>, oss-security@...ts.openwall.com Subject: Re: Some Changes to GNOME Security Tracking Hi, On Sun, Aug 02, 2026 at 07:39:04AM -0700, Russ Allbery wrote: > Peter Gutmann <pgut001@...auckland.ac.nz> writes: > > Russ Allbery <eagle@...ie.org> writes: > > >> One solution that anyone in open source software communities has heard > >> about for decades now is to turn open source software maintenance into > >> a job with a paycheck. Then it doesn't necessarily have to be fun > > > It can still be fun, and in some cases more fun than pure open-source. > > Consider the difference between "we have a practical real-world problem > > that we need solved, there's real-world demand for it, we can describe > > it in detail, and we'll pay you to solve it" (commercial user) vs "i > > have some me-only feature that I want you to add to your code just for > > me and I'll whine endlessly on Github/Discord/whatever if you don't" > > (open-source). > > Speaking as someone who has structured his entire career to be in the > first position that you describe, you're preaching to the choir on this. I > completely agree; part of the reason why I do less open source software > work in my free time these days is because I get paid to do it as part of > my day job and that comes with a much more satisfying and meaningful > problem stream to solve. [...] This thread and the "33 Vulnerabilities in cJSON" one are becoming increasingly difficult to moderate. While I understand that incentives for open source development matter a lot and are related to fixing security issues, the most recent postings by Peter and Russ do not mention security at all, so this is becoming off-topic. I think this is fine so far, but let's please refocus it back on topic or stop it here. As a result of these two threads wandering borderline off-topic, another long-time subscriber tried to bring up and wanted to discuss in here a Net Neutrality and free speech angle, which is even further off topic, so I'm not letting it through. I mention this to give you all an idea of where else and how far this may be heading if left unmoderated. I would much rather see constructive contributions on topic of the list. For example, "here's a new maintained fork of cJSON with the 33 issues fixed, and functional and regression tests added" (in the other thread, not here), or something else like that. This isn't rocket science. Thanks, Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.