Bonum Certa Men Certa

Free Software Licence Compliance is About Security Too

posted by Roy Schestowitz on Nov 03, 2024,
updated Nov 03, 2024

Electric Pylon at Georgia, USA.

Is security a real goal? The chief used to be Microsoft staff despite Microsoft working on back doors. Now:

Kris Borchers is a Technical Project Manager at the OpenSSF with 20 years of experience in open source and software development. He previously led GM Financial’s Open Source Program Office, focusing on risk management and community engagement. Prior to that, Kris managed technical programs at Microsoft and served as Executive Director of the JS Foundation, where he played a key role in driving innovation and growth in the open source community. He specializes in project management, stakeholder engagement, and open source strategy.

SOMEONE has pointed out to us that, in the context of the Linux Foundation (LF), "strip-mining" of Free software is also a problem for security. Under the LF they're relicensing code (now it's the Academy, according to The Register*), outsourcing it to Microsoft, and sharing it less or under more restrictive terms.

But then there's the aspect of security.

"The strip-mining of FOSS," someone has said, "leads to an alternative branch of Linux which is effectively closed source, proprietary abandonware. Once in production, proprietary abandonware remains as it was when it was shipped and thus unpatched even in the face of ongoing CVEs. Eventually some of the CVEs lead to remote exploits, the result will be falsely blamed on 'Linux' rather than the illegal, proprietary fork which was subsequently modded and then abandoned. There are *HUGE* repercussions here for embedded systems, especially routers. The inevitable result of unmaintained, closed source, proprietary on routers and switches will lead to a new form of bot net."

The Register recently ran this piece about Torvalds. "Unlike some tech bros," it said, "the world’s most famous software developer [Torvalds] sees his car as an appliance not an appendage. He reckons it runs Linux, “but I don’t touch it”."

So it's Linux as de facto proprietary off-the-shelf platform. How many of these products will be properly updated?

_____

* It also reveals that IBM has managed to scare away many users. To quote: "With the latest two versions of Rocky Linux taking 80 percent of the studio workstation market, but AlmaLinux just under 12 percent, it also rather confirms our suspicions about those projects' relative success – but that's not important right now."

Other Recent Techrights' Posts

Professor Eben Moglen on How Social Control Media Metabolises Humans and Constrains Freedom of Thought
Nothing of value would be lost if all these data-harvesting giants (profiling people) vanished overnight
Debian Left Twitter (MElon "X"), We Think the Free Software Foundation (FSF) Should Do the Same
What would the FSF really lose if it stopped posting there?
 
Links 07/02/2025: Amazon’s Stock Collapses and US Government Being Dismantled (Still)
Links for the day
Gemini Links 07/02/2025: Mid-level Details and Simple Code
Links for the day
Links 07/02/2025: US 'Demolition Crew', e-ID Loopholes, and Sanctions
Links for the day
Social Control Media is Narcissism
Nowadays there's a lot more literature and even press coverage explaining the harms of Social Control Media
statCounter Sees GNU/Linux Share Doubling in China Over the Past Year
It'll be interesting to see what data in the coming months shows
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 06, 2025
IRC logs for Thursday, February 06, 2025
Richard Stallman (RMS) Confirms Next Week's Talk in Europe
He gave at least 2 talks in Europe last month
Nationalism As A Service (NaaS) by Microsoft Azure, Gutting the US Government for Profit
Will Microsoft be receiving bailouts as a reward for all this?
Rumours of IBM Layoffs Apparently Confirmed Yesterday, IBM Canada Consulting Impacted (as Rumoured)
when IBM has layoffs we must also read it as Red Hat layoffs
Tons of Anti-Linux 'Articles' Published by Bots (LLMs), Maybe Microsoft's
Upon closer inspection, all this FUD turned out to be LLM garbage
Gemini Links 06/02/2025: Voicemail Sucks and Night of Lights
Links for the day
Ubuntu Desktop Director of Engineering Has Only One Blog Post. It Promotes Microsoft Windows.
Remember that even 15 years ago (more or less, maybe 16 years ago) Canonical appointed a a 'former' Microsoft manager (Spencer) to lead Ubuntu on the desktop
Links 06/02/2025: YouTube Takedowns Out of Control, 'DOGE' Breaking Laws
Links for the day
IBM Red Hat on "era of cloud computing", pushing "hey hi" (AI) hype in Microsoft Azure
LLM slop might actually be more benign than Microsoft promotion
Corruption and Rule-Breaking Prevail at the European Patent Office (EPO), Europe's Second-Largest Institution
The law does not really exist at the EPO; it can be perceived as merely a "recommendation"
statCounter: More Countries Where Windows is Around 1% "Market Share" (People Have Moved to Android/Linux)
in some nations Windows is already 1% or less
404 Media Says "Workers at NASA Told to Drop Everything to Scrub Mentions of Indigenous People, Women from Its Websites" But There's Also Accessibility in the Firing Line
In the case of abandoning accessibility, everyone stands to be hurt and proprietary software can be brought in to replace standards
When BetaNews Writes Real Articles About "Linux" They Promote Windows
The Web is in a bad state. We need to at least try to correct this.
Gemini Links 06/02/2025: Cynicism and "Real Magic on the C64"
Links for the day
Links 06/02/2025: New Sanctions, Layoffs, and Executive Orders
Links for the day
Distros and Desktop Environments, Devices
GNU/Linux focused
New Rumours of IBM Layoffs in 2025, IBM Consulting Still Struggles, Based on Management
"Hey hi" (AI) has been a common excuse for business failure
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 05, 2025
IRC logs for Wednesday, February 05, 2025
Links 05/02/2025: Kessler Syndrome and News Online
Links for the day
statCounter: Monaco Now 7% GNU/Linux ("Proper")
GNU/Linux, not counting Chromebooks, is on the rise
Many Parts of Google Lose Money
It's quite apparent that many parts of Google - even some that rely on ad revenue or push ads - aren't profiting
European Internet Forum (EIF) is Dominated by American Corporations and Microsoft Lobbyists, Staff Take the Lead
Should the officials over here or the European Parliament pay attention to these people?
Links 05/02/2025: Connection without Connectivity and Unionised Grocery Workers
Links for the day
Just Because People on Top of the Microsoft Pyramid Made a Lot of Money Doesn't Mean Microsoft is Wealthy
The bigger they are the harder they fall
Gemini Links 05/02/2025: Learning, Madman Ruling a Mad Country, Back in Geminispace
Links for the day
statCounter Shows "WIntel" Chasing a Dying Market
Microsoft acts as if it's running out of money
Free Software Foundation, Inc. (FSF) Still Raising Money, Richard Stallman Contributes
total exceeding $430k
A Lot of Stuff About "Linux" in Google News is LLM Slop, Fake 'Articles'
It seems to be getting worse
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, February 04, 2025
IRC logs for Tuesday, February 04, 2025