Bonum Certa Men Certa

The Free Software Community is Exploited by Greedy Business People, It's Not Freeloading (Yet More Name-calling, Trolling and Shaming of Volunteers)



Reprinted with permission from Ryan Farmer

IBM’s new pejorative for people who use Fedora or an Enterprise Linux clone. “Freeloader” (And they don’t want to know about security holes.)



A word that IBM and their fanboys, and remaining unpaid volunteers are bandying about lately, is “Freeloader”.



In IBM Red Hat’s book, anyone who isn’t currently coughing up a subscription fee to use RHEL is “Freeloading”. Basically, they see you as a parasite.



This word doesn’t just apply to a person who grabs Fedora and uses it on their laptop and never files bug reports or anything. It applies more broadly to organizations that deploy a free Enterprise Linux clone to their business because they think they can self-support.



It also applies specifically to Oracle, because even before IBM, Red Hat was already trying to portray Oracle Linux as some sort of “stolen product” with their “Unfakeable Linux” marketing campaign.



Let’s talk about users. Fedora has always had a very transactional relationship with users from Red Hat’s point of view. Users were valuable as bug reporters. We’d get this software on our daily systems for free, and in return, when something went wrong, we were “requested” to file bug reports.



However, IBM doesn’t value bug reports because as the new boss in town, it’s not actually interested in fixing bugs. It wants to hide them, like Microsoft, according to AlmaLinux developers who tried reporting security vulnerabilities in RHEL components.



KnownHost CTO and AlmaLinux Infrastructure Team Leader Jonathan Wright recently posted a CentOS Stream fix for CVE-2023-38403, a memory overflow problem in iperf3. Iperf3 is a popular open-source network performance test. This security hole is an important one, but not a huge problem. Still, it’s better by far to fix it than let it linger and see it eventually used to crash a server.



That’s what I and others felt anyway. But, then, a senior Red Hat software engineer replied, “Thanks for the contribution. At this time, we don’t plan to address this in RHEL, but we will keep it open for evaluation based on customer feedback.” 



[…]



The GitLab conversation proceeded: 



AlmaLinux:  “Is customer demand really necessary to fix CVEs?” 



Red Hat: “We commit to addressing Red Hat defined Critical and Important security issues. Security vulnerabilities with Low or Moderate severity will be addressed on demand when [a] customer or other business requirements exist to do so.”



AlmaLinux: “I can even understand that, but why reject the fix when the work is already done and just has to be merged?” 



At this point, Mike McGrath, Red Hat’s VP of Core Platforms, AKA RHEL, stepped in. He explained, “We should probably create a ‘what to expect when you’re submitting’ doc. Getting the code written is only the first step in what Red Hat does with it. We’d have to make sure there aren’t regressions, QA, etc. … So thank you for the contribution, it looks like the Fedora side of it is going well, so it’ll end up in RHEL at some point.”



One user wrote, “You want customer demand? Here is customer demand. FIX IT, or I will NEVER touch RHEL EVER.” While another, snarked, “Red Hat: We’re going totally commercial because Alma never pushes fixes upstream! Also, Red Hat: We don’t want your fixes, Alma!”



On Reddit, McGrath said, “I will admit that we did have a great opportunity for a good-faith gesture towards Alma here and fumbled.”



Finally, though the Red Hat Product Security team rated the CVE as “‘Important,’ the patch was merged.

-ZDNet Article “AlmaLinux discovers working with Red Hat isn’t easy”


The attitude that Microsoft and IBM share in security vulnerabilities is that they don’t want to touch the fix, even if someone else already wrote it, because it may cause a regression that they then have to spend time and money sorting out.



Microsoft’s attitude is so bad that they use old and insecure versions of gnupg to generate package signatures on their “Linux” software, but it also hardly matters because they point dnf on Fedora or RHEL to their server to get the .asc file, which means that users who have Microsoft programs on their computer can get a copy that’s been tampered with as an “update” and not have any warning, because the attacker can modify the .asc with one that they control, and put that one on the server as part of the attack.



I think it’s, frankly, frightening, that IBM admits that security patches are not one of their highest priorities in such a widely used system as RHEL.



Instead of getting caught up in the “security poser” malarkey, and buzzword bullshit bingo, like Matthew Garrett does with his nerve-grating overuse of things like “attestation”, “TPM”, and “roots of trust”.



These things are not security. If the software you’re using is garbage, your security is garbage. You need to use software from people who just fix their damn bugs, and vendors who get you those patches shipped ASAP. Everything else is basically pointless.



My roots of trust are simple. It’s on my computer, I trust it. Fuck off.



The first and last time I’ve had a computer virus, it was on Windows 98, and Chernobyl (it was set to trigger a malicious BIOS flashing until the ROM was bricked). Thankfully, I pulled it out in time.



I have never had any “Linux malware”, and that record is unbroken since 1998.



Seriously, patch your software, get it from a legitimate source, and don’t worry too much.



If a company is like Microsoft and IBM, and doesn’t want to know about security holes, they don’t deserve their customers on that issue alone.



Where were we? Ah, yes. Freeloading. IBM’s open contempt for Fedora is even worse.



They are throwing out many unpaid volunteers that were doing free work for IBM Red Hat, and calling those people “Freeloaders”, with absolutely no sense of irony, apparently. IBM gets a lot of software for free.



They stopped paying the FSF around the time Molly de Blanc and other unproductives, like Garrett (his last useful code was in the 2000s, I think, when he worked on ACPI), organized people around a defamatory petition against Richard M. Stallman, which Roy Schestowitz points out is a 70 year old man.



But IBM still pulls GNU software without paying for it. And many other people’s software! FREELOADERS!



Users of free clones can be future customers.



The “free” developer license for RHEL, does not allow you to deploy it across your whole organization, get settled in, and then realize you need support after all.



The free clones were an ongoing source of new customers, who would often bring lots of machines with them by the time they approached Red Hat and wanted to do an in-place conversion. This was a serious amount of money.



IBM says they’re just Freeloaders and harasses the distributions that onboard customers into the “Red Hat” way of doing things and land them clients.



Even when they don’t make sales, their product gets more marketshare, which was why they were a de facto “standard”.



Oracle “Freeloading”.



Perhaps most of all, Red Hat (pre-, and post-IBM) had disdain for Oracle Linux, but Oracle didn’t have compelling reasons to lure people away from RHEL wanting an identical product. Oracle is not the authoritative source of RHEL, IBM is. Whatever Oracle consumes is what IBM decided to put in there.



A customer education campaign on this subject would have been better than labeling Oracle as some sort of “stolen product”.



Oracle is not going for exactly the same customers. They have their own “Unbreakable Enterprise Kernel” that is really quite different already, and which boots by default.



UEK is modified to run Oracle-type workloads better than the RHEL Compatible Kernel, but despite this, the compatibility issues with it are rare.



The Linux kernel version does not directly interact with very many programs in userspace so as long as you have a stable kernel that’s getting serviced by someone who knows what they’re doing, you’re probably going to be fine running the RHEL userspace on top of it, which makes IBM’s decision to obscure their kernel all the more bizarre.



The future of RHEL clones is not entirely under IBM’s control anyway.



Already, an alliance (Open Enterprise Alliance Association) of SUSE, Oracle, and CIQ (sponsor of Rocky Linux) have come together to make a “commons” out of the Enterprise Linux source code.



Ironically, the alliance’s Web site pokes fun at IBM.



“The Community Repository for Enterprise Linux Sources No subscriptions. No passwords. No barriers. Freeloaders welcome.



Essentially, IBM has succeeded only in angering a great many people with their antics including washing their hands of Fedora this week, and spurred their competitors into an alliance to reduce the work of maintaining competing RHEL clones.



This has all been so very stupid and avoidable.



The media (bribed) has been focusing on this “AI” nonsense between Microsoft and IBM, but all it will ever do is cost IBM money.



IBM decided to throw away an actual product, and company, that it spent a considerable amount of money acquiring, in the garbage, and pivot to running like some idiotic San Francisco cash furnish with an account at the Bank of Silicon Valley.



It will not end well for them if they proceed.



Recent Techrights' Posts

Mobbing at the European Patent Office (EPO) - Part V - Strongest Strike Under António Campinos
SUEPO Munich is also reminding people of the threat of PIPs
GNU/Linux May Have Grown to 7% in Equatorial Guinea
Has there been some kind of mass migration there or is this just noise in the data?
 
Microslop is Slop, Slop is Considered "Quality"
no wonder Microsoft's stuff breaks down so often
thelayoff.com Deletes On-Topic Discussions (Layoffs) While Leaving in Tact Pro-Corporate Trolling Made by LLMs (Slop)
Who at thelayoff.com deems spam made by LLMs (slop) to be on-topic and unworthy of zapping, whereas actually on-topic and authentic threads get routinely deleted?
The Solicitors Regulation Authority (SRA) Delusion - Part IV - Machos in Charge of the House (and System), Even If the Faces Are Female (Optics)
basically a Windows/Microsoft (US) shop
Gemini Links 09/02/2026: Great Salt Lake Ecological Observatory and Offpunk 3.0 "A Community is Born" Release
Links for the day
Links 09/02/2026: Mass Plagiarism and Pollution/FakeCoin Company Nvidia Contacted Anna’s Archives, Narges Mohammadi Gets Second Prison Sentence
Links for the day
Links 09/02/2026: Russia Intentionally Killing Civilians, Jimmy Lai Effectively Sentenced for Life for Publishing News
Links for the day
Microsoft Competitions, Addictions, and Popularity Contests Are Not Going to Help Perl, They'll Waste Everybody's Time and Give Microsoft More Control Over Its Competition
Microsoft does not like Perl
A Can of WORMS - Part IV - They Would Even Attack RMS for Criticising Autocrats (Saying This is "Politics")
Conforming to society's perceived expectations isn't how effective activism can ever be done or was ever done in the recent past
Gemini Links 09/02/2026: The Exploration Myth and Making JavaScript Fun
Links for the day
EPO Outrage and Maintaining the Pressure
A vending machine does not fall over after a first push
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, February 08, 2026
IRC logs for Sunday, February 08, 2026
"Low Performer" and "Underperformer" as Harmful Misnomers That Damage a Company's Reputation
Misnomers need to be avoided or called out
Expensive errors: Forbes Gold price, $44 billion Bitcoin given away by Bithumb, South Korea
Reprinted with permission from Daniel Pocock
Links 08/02/2026: Microsoft OSI (Openwashing Lobby) in Europe, Raised Against Social Control Media Provocateurs in EU
Links for the day
The Open Source Initiative (OSI) Lobbies for Microsoft in the EU, Promoting Proprietary Lock-in
OSI pushing and selling Microsoft and GitHub. OSI is Microsoft front group.
Getting the European Court of Justice to Annul the Illegal and Unconstitutional Unified Patent Kangaroo Court (UPC)
We're still working on it
Finland's Dependence on GAFAM (US) Needs to be Lessened, EU Must Follow This Path
It's unwise to make one's entire national infrastructure (computer systems) dependent on a regime which compares its black citizens to monkeys and assassinates nonviolent dissenters
Links 08/02/2026: Microsoft GitHub as Burden on Developers and "The Chomsky Epstein Files"
Links for the day
Gemini Links 08/02/2026: "Doing Not Much Tweaking" and "Reclaiming Digital Agency"
Links for the day
Forbes: BitCoin, Cryptocurrency pages removed from investment database, links stop working
Reprinted with permission from Daniel Pocock
Bitcoin warning followed immediately by network outage
Reprinted with permission from Daniel Pocock
Money Funneled to Protection of Software Freedom, But Nothing Really Lost
Crossposted from personal site
They Tell Us Slop Replaces Workers, But the Reality Is, US Debt Has Surged 2,300 Billion Dollars in Six Months (the Economy is Collapsing)
Oligarchy already entertains the option of running away to (or colonising) some other planet without pitchforks and "unwashed masses"
Mozilla Firefox Sinks to Just 1.5% in the United States
According to analytics.usa.gov
We're Still Fast
The site is even faster than the BBC's despite being on shoestring budget with only a small technical team
Gemini Protocol is Not a Waste of Time of Effort
We see more and more GNU/Linux- or BSD-focused bloggers turning to Gemini
Our Gemini Protocol Support Turns 5 Today
today is a rare anniversary for us
In Today's World, One Must be Tough and Principled to Get Ahead Morally
But not financially (sellouts)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, February 07, 2026
IRC logs for Saturday, February 07, 2026
The Right Wing in the United States Does Not Support Free Speech, It Supports Its Own Speech
Free speech is often opposed by those who also oppose Free software
IRC is a Lot Better Than Social Control Media (They're Not the Same at All)
A good social analogy for IRC is, there are many buildings with a party in each building
Microsoft 'Open' 'AI' is 'Dead Meat'
Or 0xDEADBEEF as some geeks might call it
When Identifying "Low Performers" and "PIPs" Aren't About Improving Performance But Reinforcing a Clique in Your Company/Organisation
It's very troubling to see once-respectable brands like IBM and institutions like the EPO resorting to this
Slop and Flop (IBM), Slopfarms and Hybrids (Linuxiac)
Did Bobby Borisov assume he would never get caught?
Crowdfunding vs Bitcoins: donations are better investment than digital tulip mania
Reprinted with permission from Daniel Pocock
Links 07/02/2026: Misinformation by Slop, Overrated Slop Causes Stock Market Panic
Links for the day
Gemini Links 07/02/2026: Diode Function Generators and Panic Over Buzzwords and Slop
Links for the day
A Can of WORMS - Part III - Envying the Influence and Accomplishments of RMS, Socially Deleterious Attacks on Popular Movements
the actions are deliberate and coordinated, not some 'organic' or grassroots behaviour
Crisis teams assembled as financial regulators anticipate Bitcoin implosion
Reprinted with permission from Daniel Pocock
Reddit as a Hive of Trolls, Social Control Media Curated (Many Voices Censored and Banned) by Marketing Firm of GAFAM
Typical Reddit
The Solicitors Regulation Authority (SRA) Delusion - Part III - Women Failing Women to Help Violent Americans From Microsoft
Summed up, SRA will gladly prioritise the "legal industry" over women strangled, raped etc
The World Gets Smaller, as Does Its Real Economy ('Human Resources') and So-called 'Natural Resources' (What Humans Call the Planet)
Don't talk about "AI"
Converting FOSDEM Talk on Software Patents in Europe Into Formats That Work for "FOS" and Don't Have Software Patent Traps
transcoded version of the video
Links 07/02/2026: More White House Racism, "Europe Accuses TikTok of Addictive Design"
Links for the day
Silent Mass Layoffs: It's Not the Revolution, It's the Loophole and the Hack ("Low Performers" or "Underperformers")
Layoffs by another approach
Mark Shuttleworth (MS) Pays Salaries to Microsoft (MS) Employees
Canonical selling Microsoft
Links 07/02/2026: Windows TCO Rising, Lousy Patents Invalided
Links for the day
Microsoft Leadership: Stop Taxing Us, Tax Only Poor People
Does Microsoft create jobs?
Biggest "AI Companies" (Meta, Alphabet, Microsoft) Borrowed (Additional Debt) About $100,000,000,000 in a Year
Who will be held accountable for all this?
In Case You've Missed It (ICYMI), Google's Debt More Than Doubled in a Year
Wait till it "monetises" billions of GMail users with slop
In 2009 Microsoft Was Valued at ~150 Billion Dollars, Now They Tell Us Microsoft Lost ~1,000 Billion Dollars in Value. Does That Make Sense?
Or Microsoft lost 700 billion dollars in "value" in less than two weeks
PIPs and Silent Layoffs at IBM (and Red Hat) Still Going on, It's "Forever Layoffs" (to Skirt the WARN Act)
American workers out
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, February 06, 2026
IRC logs for Friday, February 06, 2026
Stressful Times for Team Campinos ("Alicante Mafia") at Europe's Second-Largest Institution
Keep pushing
Growing Discrimination in the European Patent Office (EPO)
it's a race to the bottom, basically
Google News Drowning in (or Actively Promoting) Slopfarms Again
LLM slop is a nuisance
Microsoft Stock Crashed When Alleged Vista 11 Numbers Disclosed
And last summer Microsoft indicated that it had lost 400 million Windows users
Gemini Links 07/02/2026: "Choosing a License for Literary Work" and "Social Media Is Not Social Networking (Anymore)"
Links for the day