Bonum Certa Men Certa

The Free Software Community is Exploited by Greedy Business People, It's Not Freeloading (Yet More Name-calling, Trolling and Shaming of Volunteers)



Reprinted with permission from Ryan Farmer

IBM’s new pejorative for people who use Fedora or an Enterprise Linux clone. “Freeloader” (And they don’t want to know about security holes.)



A word that IBM and their fanboys, and remaining unpaid volunteers are bandying about lately, is “Freeloader”.



In IBM Red Hat’s book, anyone who isn’t currently coughing up a subscription fee to use RHEL is “Freeloading”. Basically, they see you as a parasite.



This word doesn’t just apply to a person who grabs Fedora and uses it on their laptop and never files bug reports or anything. It applies more broadly to organizations that deploy a free Enterprise Linux clone to their business because they think they can self-support.



It also applies specifically to Oracle, because even before IBM, Red Hat was already trying to portray Oracle Linux as some sort of “stolen product” with their “Unfakeable Linux” marketing campaign.



Let’s talk about users. Fedora has always had a very transactional relationship with users from Red Hat’s point of view. Users were valuable as bug reporters. We’d get this software on our daily systems for free, and in return, when something went wrong, we were “requested” to file bug reports.



However, IBM doesn’t value bug reports because as the new boss in town, it’s not actually interested in fixing bugs. It wants to hide them, like Microsoft, according to AlmaLinux developers who tried reporting security vulnerabilities in RHEL components.



KnownHost CTO and AlmaLinux Infrastructure Team Leader Jonathan Wright recently posted a CentOS Stream fix for CVE-2023-38403, a memory overflow problem in iperf3. Iperf3 is a popular open-source network performance test. This security hole is an important one, but not a huge problem. Still, it’s better by far to fix it than let it linger and see it eventually used to crash a server.



That’s what I and others felt anyway. But, then, a senior Red Hat software engineer replied, “Thanks for the contribution. At this time, we don’t plan to address this in RHEL, but we will keep it open for evaluation based on customer feedback.” 



[…]



The GitLab conversation proceeded: 



AlmaLinux:  “Is customer demand really necessary to fix CVEs?” 



Red Hat: “We commit to addressing Red Hat defined Critical and Important security issues. Security vulnerabilities with Low or Moderate severity will be addressed on demand when [a] customer or other business requirements exist to do so.”



AlmaLinux: “I can even understand that, but why reject the fix when the work is already done and just has to be merged?” 



At this point, Mike McGrath, Red Hat’s VP of Core Platforms, AKA RHEL, stepped in. He explained, “We should probably create a ‘what to expect when you’re submitting’ doc. Getting the code written is only the first step in what Red Hat does with it. We’d have to make sure there aren’t regressions, QA, etc. … So thank you for the contribution, it looks like the Fedora side of it is going well, so it’ll end up in RHEL at some point.”



One user wrote, “You want customer demand? Here is customer demand. FIX IT, or I will NEVER touch RHEL EVER.” While another, snarked, “Red Hat: We’re going totally commercial because Alma never pushes fixes upstream! Also, Red Hat: We don’t want your fixes, Alma!”



On Reddit, McGrath said, “I will admit that we did have a great opportunity for a good-faith gesture towards Alma here and fumbled.”



Finally, though the Red Hat Product Security team rated the CVE as “‘Important,’ the patch was merged.

-ZDNet Article “AlmaLinux discovers working with Red Hat isn’t easy”


The attitude that Microsoft and IBM share in security vulnerabilities is that they don’t want to touch the fix, even if someone else already wrote it, because it may cause a regression that they then have to spend time and money sorting out.



Microsoft’s attitude is so bad that they use old and insecure versions of gnupg to generate package signatures on their “Linux” software, but it also hardly matters because they point dnf on Fedora or RHEL to their server to get the .asc file, which means that users who have Microsoft programs on their computer can get a copy that’s been tampered with as an “update” and not have any warning, because the attacker can modify the .asc with one that they control, and put that one on the server as part of the attack.



I think it’s, frankly, frightening, that IBM admits that security patches are not one of their highest priorities in such a widely used system as RHEL.



Instead of getting caught up in the “security poser” malarkey, and buzzword bullshit bingo, like Matthew Garrett does with his nerve-grating overuse of things like “attestation”, “TPM”, and “roots of trust”.



These things are not security. If the software you’re using is garbage, your security is garbage. You need to use software from people who just fix their damn bugs, and vendors who get you those patches shipped ASAP. Everything else is basically pointless.



My roots of trust are simple. It’s on my computer, I trust it. Fuck off.



The first and last time I’ve had a computer virus, it was on Windows 98, and Chernobyl (it was set to trigger a malicious BIOS flashing until the ROM was bricked). Thankfully, I pulled it out in time.



I have never had any “Linux malware”, and that record is unbroken since 1998.



Seriously, patch your software, get it from a legitimate source, and don’t worry too much.



If a company is like Microsoft and IBM, and doesn’t want to know about security holes, they don’t deserve their customers on that issue alone.



Where were we? Ah, yes. Freeloading. IBM’s open contempt for Fedora is even worse.



They are throwing out many unpaid volunteers that were doing free work for IBM Red Hat, and calling those people “Freeloaders”, with absolutely no sense of irony, apparently. IBM gets a lot of software for free.



They stopped paying the FSF around the time Molly de Blanc and other unproductives, like Garrett (his last useful code was in the 2000s, I think, when he worked on ACPI), organized people around a defamatory petition against Richard M. Stallman, which Roy Schestowitz points out is a 70 year old man.



But IBM still pulls GNU software without paying for it. And many other people’s software! FREELOADERS!



Users of free clones can be future customers.



The “free” developer license for RHEL, does not allow you to deploy it across your whole organization, get settled in, and then realize you need support after all.



The free clones were an ongoing source of new customers, who would often bring lots of machines with them by the time they approached Red Hat and wanted to do an in-place conversion. This was a serious amount of money.



IBM says they’re just Freeloaders and harasses the distributions that onboard customers into the “Red Hat” way of doing things and land them clients.



Even when they don’t make sales, their product gets more marketshare, which was why they were a de facto “standard”.



Oracle “Freeloading”.



Perhaps most of all, Red Hat (pre-, and post-IBM) had disdain for Oracle Linux, but Oracle didn’t have compelling reasons to lure people away from RHEL wanting an identical product. Oracle is not the authoritative source of RHEL, IBM is. Whatever Oracle consumes is what IBM decided to put in there.



A customer education campaign on this subject would have been better than labeling Oracle as some sort of “stolen product”.



Oracle is not going for exactly the same customers. They have their own “Unbreakable Enterprise Kernel” that is really quite different already, and which boots by default.



UEK is modified to run Oracle-type workloads better than the RHEL Compatible Kernel, but despite this, the compatibility issues with it are rare.



The Linux kernel version does not directly interact with very many programs in userspace so as long as you have a stable kernel that’s getting serviced by someone who knows what they’re doing, you’re probably going to be fine running the RHEL userspace on top of it, which makes IBM’s decision to obscure their kernel all the more bizarre.



The future of RHEL clones is not entirely under IBM’s control anyway.



Already, an alliance (Open Enterprise Alliance Association) of SUSE, Oracle, and CIQ (sponsor of Rocky Linux) have come together to make a “commons” out of the Enterprise Linux source code.



Ironically, the alliance’s Web site pokes fun at IBM.



“The Community Repository for Enterprise Linux Sources No subscriptions. No passwords. No barriers. Freeloaders welcome.



Essentially, IBM has succeeded only in angering a great many people with their antics including washing their hands of Fedora this week, and spurred their competitors into an alliance to reduce the work of maintaining competing RHEL clones.



This has all been so very stupid and avoidable.



The media (bribed) has been focusing on this “AI” nonsense between Microsoft and IBM, but all it will ever do is cost IBM money.



IBM decided to throw away an actual product, and company, that it spent a considerable amount of money acquiring, in the garbage, and pivot to running like some idiotic San Francisco cash furnish with an account at the Bank of Silicon Valley.



It will not end well for them if they proceed.



Recent Techrights' Posts

"AI" Hype or LLM Slop is Not About Efficiency, It's About Lowering Standards
It does not seem like IBM is genuinely committed to the same goals (or commitments) as the original Red Hat
If Free/Libre Software is Adding Trillions in Value to the European Economy, Then the European Commission Must Crush Software Patents
Further to what we wrote yesterday
Over at Tux Machines...
GNU/Linux news for the past day
 
Gemini Links 13/08/2025: Movie Memories and Mystery Machine Bus
Links for the day
Links 13/08/2025: GitHub Trouble and Openwashing by Microsoft OSI With the Typical Buzzwords
Links for the day
Microsoft Swallows GitHub Losses
Only Microsoft knows how much money it has already lost on GitHub
Gemini Links 13/08/2025: Climate, Coffee, and Deploying Troops in Washington DC After Pardoning 1,000+ Insurrectionists in Washington DC
Links for the day
The Register MS Lowered MS Focus This Week
We hope The Register recognises its errors and tries to make up for them
Learning Ethics From Jeffrey Epstein's Enabler/Client/Ally, Coca-Cola, and Microsoft Accenture
Whatever merits vocabulary changes initially had are being tainted or obscured by later iterations, which tell us to avoid word like "normal", which apparently offend some people (so they argue)
Personal Attacks From Rust People Serve to Confirm They Have Lost the Argument
"The discussion I find around the net so far has no technical merit and centers around ad hominem"
Physical Meters and Purely Mechanical Meters Aren't Dumb; It's Dumb to Mock or Dismiss Them as Antiquated
I've learned a lot this week, both online and over the telephone
IRC Proceedings: Tuesday, August 12, 2025
IRC logs for Tuesday, August 12, 2025
GitHub Will End Up like XBox and Skype
It is not likely that the XBox franchise will survive the next 5 years
Stones Thrown in Glass Houses
Projecting? You bet!
As Europe Gets Increasingly Serious About Software Freedom and Digital Sovereignty It Needs to Enforce a Ban on Software Patents ASAP
many councils in Europe move to Free software and US policy/companies cannot be trusted
Windows 12 in Bahrain (Microsoft "Market Share" Down to 12%, an All-Time Low)
They really ought to get away from Windows even faster
The Web Needs 'Pest Control' When It Comes to LLM Slopfarms
The goal is to discourage more sites becoming slopfarms
Microsoft Can Now Stop Reporting the GitHub Layoffs (Even When They Happen)
GitHub's original staff will see the true cost of becoming "b0rged" - something that Microsoft earned a bad reputation for
How to Get Very Bad or Even Malicious Code Into Linux? Write it in a Language That Linus Torvalds and Most Other Linux Developers Don't Understand.
One point nobody brings up is, what if code gets committed while evading audits and scrutiny?
Links 12/08/2025: Wikipedia Fails at UK High Court, Perlmutter Still Fights to Squash the Slop Lobby
Links for the day
Gemini Links 12/08/2025: Field Recording and Digital Legacy
Links for the day
Links 12/08/2025: WinRAR Zero-Day, SonicWall Does More Harm Than Good
Links for the day
Links 12/08/2025: More Sabotage of Underwater Cable Ahead of Russian Alaska Summit
Links for the day
Richard Stallman Will Not Miss Microsoft GitHub, It Was Only Good at Harvesting a Lot of Code for Plagiarism-as-a-Service
investors are apparently willing to lose money for buzzwords
Slopfarms Slopping Away at "Linux" and Spreading Microsoft Misinformation
Slopfarms don't comprehend this as they lack actual comprehension, they're just parrots
Links 12/08/2025: Science, Hardware, and Ukraine Excluded From Negotiations About Its Future
Links for the day
GitHub the Company Has, in Effect, Just Died (Time to Look for Alternatives)
To Microsoft, what's left of GitHub after dismantling/folding it is some "training set" (people's code, without permission to "train" i.e. misuse under the guise of "GenAI" plagiarism)
Linux Foundation Says "Housekeeping", "Hung", "Normal", "Native Feature/Support" and "Girl/Girls" Are Offensive Words
Bombing people is OK, just use the right "terms"
It Looks More Like Microsoft GitHub Layoffs
GitHub is just losing loads of money
Gemini Links 12/08/2025: Meditation, OpenStreetMap, Smolweb, and More
Links for the day
Google News is Dying: Most of Its Top Stories Now Are LLM Slop With Slop Images (i.e. 100% Fake 'Content')
Google News has been drowning in this sort of stuff for quite some time
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 11, 2025
IRC logs for Monday, August 11, 2025
Our Predictions Were Right: GitHub Dying as Losses Pile Up (as a Company It Cannot Continue to Exist, It's Not 'Free Hosting')
GitHub always lost money
Links 11/08/2025: Meritless Twitter Suspensions and Disney Scraps Deepfake Dwayne Johnson
Links for the day
Gemini Links 11/08/2025: Upgrading Debian Bookworm and Better Quality PDFs From Gemini Pages
Links for the day
Currys PCWorld Lied a Decade Ago, 10 Years Later It Still Effectively Voids Your Warranty for Installing GNU/Linux Despite It Being Increasingly Mainstream
Microsoft gatekeepers
Team GNOME Has Libeled Me for Nearly 20 Years
we are not dealing with sane people
Experience With Airlines in 'Web Sites' and in 'Apps'
In a lot of ways, Stallman Was Right about what JavaScript would turn out to be
Open Does Not Mean Free
wiser to ask if some program is freedom-respecting
The Register MS Takes Money From Companies Banned by the Biden and Trump Administrations (National Security Risk)
today's sponsor
Sabotaging GNU/Linux PCs (and Users) is Not a 'Joke'
maybe cruelty is the very objective
How We Process Screenshots of Slop to Suitably Tag Them as Slop
everything is a single command
Links 11/08/2025: Data Breaches, Politics, and Climate
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 10, 2025
IRC logs for Sunday, August 10, 2025
Gemini Links 11/08/2025: Tea Caffeine Hot and Super ZZ Zero
Links for the day