Bonum Certa Men Certa

IBM Still in Control of Fedora-Legal and FESCo Despite Unpaid Volunteer Labor Picking Up More Fedora Grunt Work



Reprinted with permission from Ryan Farmer

IBM Still In Control Of Fedora-Legal and FESCo Despite Unpaid Volunteer Labor Picking Up More Fedora Grunt Work.



While IBM is purging LibreOffice, a bunch of GNOME, parts of the Bluetooth stack, and everything related to trying to manage an Apple device from file managers and media players, among others, and tossing the work onto unpaid volunteers, spreading FUD about the competition’s Enterprise Linux distros (they are now squarely into full blown paranoid), and promoting Microsoft “Clown Computing” as a replacement for LibreOffice….



IBM Office Space

So Red Hat is essentially killing all work on desktop packages, not just on LibreOffice? Also considering that several of those packages are libraries that cannot just be put on Flathub as LibreOffice can (which was their excuse for terminating all work on LibreOffice packaging). With the layoff and the destruction of the position of the Fedora Program Manager, the termination of public RHEL source releases, and this move, Red Hat is really turning into an unfriendly company, and I really have to wonder whether Fedora is going to be of any use to me in the long run.

-Kevin Kofler


Later on, IBM Red Hat showed up and started doing damage control and pimping Microsoft and Google “Clown Office” programs.



Also a lot use online docs like Office365 or Google docs. I personally used to use Libreoffice a lot but now I mostly use gDocs. […] This sort of comment is off topic, various companies are free to do with their data as they wish, just as you are free to do with it as you please. Frankly it’s often more secure with cloud providers [ed: link mine] than on corporate networks. Either way that comment doesn’t provide useful discourse in this discussion.

-Peter Robinson (IBM Red Hat)


The comment about Clown Computing being more secure was shot down again just several days ago. Microsoft Azure, Office 365, OneDrive, and Outlook all have terrible security records. Just awful. But this time it affected banks and other Azure Clown deployment customers.



 According to data from Google Project Zero, Microsoft products have accounted for an aggregate of 42.5% of all zero-days discovered since 2014.



Microsoft’s lack of transparency applies to breaches, irresponsible security practices and vulnerabilities, all of which expose their customers to risks they are deliberately kept in the dark about.



In March 2023, a member of Tenable’s Research team was investigating Microsoft’s Azure platform and related services. The researcher discovered an issue which would enable an unauthenticated attacker to access cross-tenant applications and sensitive data, such as authentication secrets. To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank. They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.



Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers’ networks and services? Of course not. They took more than 90 days to implement a partial fix – and only for new applications loaded in the service.



That means that as of today, the bank I referenced above is still vulnerable, more than 120 days since we reported the issue, as are all of the other organizations that had launched the service prior to the fix. And, to the best of our knowledge, they still have no idea they are at risk and therefore can’t make an informed decision about compensating controls and other risk-mitigating actions. Microsoft claims that they will fix the issue by the end of September, four months after we notified them. That’s grossly irresponsible, if not blatantly negligent. We know about the issue, Microsoft knows about the issue, and hopefully, threat actors don’t.

-Tenable CEO Amit Yoran “Microsoft: The truth Is even worse than you think”


“Clown Computing” is just dumb. Even if we take a sidebar from the security angle for a moment, where Microsoft just leaves critical bugs open while attackers take your banking information and Social Security numbers and file, downloading an ENTIRE OFFICE SUITE into a Web browser every time you need to edit a document, and trusting that you’ll have Internet access, that Microsoft can keep their server running 100% of the time (they don’t), and that they won’t have crashes and lose your files, then how are you supposed to edit your files or even access them if your subscription lapses, or they say you can’t use it anymore?



One of the people on the Fedora Hyperkitty thread mentioned how IBM Red Hat blocks people from getting RHEL or updates for RHEL from countries on the US Export Control List.



Do you know that your country won’t be added to the list at some point? Then how do you get your “Clown data”?



Also raised was the obvious issue of foreign governments, businesses, and citizens storing their data on Microsoft servers in the United States. This is not only stupid, it’s actually against the law in some cases.



Clearly IBM is only worrying about customers in the United States, and even then only barely.



It encourages them to do foolish things with their data, even something as stupid as editing documents. Then the guy says it’s “easier to share” in the Clown. Like, you can’t email a document to someone?



Most of the rest is just chatter about unpaid volunteers doing work in IBM’s GULAG, that will benefit IBM, and they won’t even be paid for it. Then in return, IBM won’t even necessarily show you the code when it ends up in RHEL.



IBM is making decisions for RHEL customers and the remainder of the Fedora “community” that are not in the best interests of those customers or the community.



About the only contribution IBM makes anymore to Fedora is hosting and build bots, and that’s about it.



In exchange for that, IBM lawyers and IBM employees on FESCo decide what will happen in Fedora.



To an extent, that’s always been true, but it was also true that Red Hat (before and after IBM) was doing more of the grunt work.



I’m amazed that Kevin Kofler even managed to post on Hyperkitty. He was banned by decree of IBM from Fedora-KDE, which they don’t even care about and which is now rotting away.



At one point, Kofler was on FESCo, and he generally got outvoted 8-1 on things, because Red Hat (now IBM) has basically all of the seats. They set it up so they always get what they want. It’s like the Illinois legislature, but the only people who get to decide anything are Chicago politicians.



There is certainly nothing wrong with making money selling Free Software, but IBM’s actions lately have made it an “unreliable” partner to their customers and to Fedora’s users (which have value as testers and package integrators, not that IBM cares).



Their decisions have been chaotic and announced as they were being implemented.



If you are a RHEL customer, you presumably want predictability.

Why settle for this?



Recent Techrights' Posts

BASIC Predates Microsoft by Over a Decade, Microsoft-Controlled Sites Like The Register MS Don't Want You to Know This
The state of the media is really bad when it relies a lot on oligarchs' money and is appointing editors who are working for oligarchs
Brian Kernighan, "Only Third to Dennis Richie and Ken Thompson" (UNIX), Agreed With Someone Who Said Rust Was Just Hype, Should Not Replace C
17 hours ago
Reminder: Microsoft's "Secure Boot" Certificate for "Linux" Will be Expired in One Week
Many PCs won't manage to 'rotate' to another certificate
 
Genini Links 05/09/2025: Community, ROOPHLOCH, and PITkit
Links for the day
Links 05/09/2025: Vaccine Sceptics Poison the Well, Two Exploited Vulnerabilities Patched in Android
Links for the day
Gemini Links 05/09/2025: Logitech Lift and DIY Gemini Servers
Links for the day
Links 05/09/2025: Sainsbury's Caught Spying on In-Store Shoppers and Microsoft "OpenAI is Using Legal Threats to Harass its Critics"
Links for the day
Analogies for "Memory Safety" in Rust
Don't worry, it's Rust! It can do anything!
"Many of the Red Hat Employees Are Still Looking for Work"
Shame on IBM's CEO
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 04, 2025
IRC logs for Thursday, September 04, 2025
Microsoft Started With Code Literally From The Trash, Nothing Has Improved Since
The reality is, there are systems and code that are reliable. But they're not Microsoft's.
Hypothesis That New McKinsey/Microsoft Executive Inside Red Hat Will Outsource Research and Development Operations to India (Like They Do in IBM)
IBM is floundering
Slopwatch: Scams, Fake Articles About "Linux", Plagiarism, and Worse
Perhaps some time soon the LLMs or the "Big LLMs" will run out of money (to borrow) and go offline, leaving those slopfarms in a tough place
Gemini Links 04/09/2025: Means of Production and Rusting Out
Links for the day
Links 04/09/2025: Science, Hardware, and Eyes on China
Links for the day
Gemini Links 04/09/2025: Digital Minimalism and Social Control Media
Links for the day
IBM's GNU/Linux Divestment, Based on Hard But Anecdotal Evidence (IBM Fails to Recognise How Much Money It Made and Can Still Make From "Linux")
Love us or hate us, a lot of what we've been saying about Red Hat under IBM turns out to be rather accurate
Links 04/09/2025: Massive Microsoft Staff Cuts (Barely Reported), "Strange Conspiracy Theory Is Reportedly Spreading Inside OpenAI"
Links for the day
Activists Can Win, But Keep an Eye on the Ball and on the Trophy
GitHub is dying, it was a loss-making trap, not free hosting
Gemini Links 04/09/2025: Katrina Remembered, Distracted Driving, and Virtual Economics
Links for the day
At This Point It's No Longer Matthew Garrett But People Who Fund Matthew Garrett (or Companies That Fund His SLAPPs Against My Wife and I)
The only thing worse than misogynists are misogynists who fail to respect other people's right to go on holiday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 03, 2025
IRC logs for Wednesday, September 03, 2025
The UEFI 9/11 - Part VI - This Serious Harm Was Planned for Over a Decade, Not an Accident or Merely Some Misfortune
The term "Serious Harm" is legally meaningful here
GNOME Unfit for Diversity and Inclusion
GNOME's leadership is using "bad words"
Brodie Robertson Addressing the Recently-Discovered Comments
Most people probably knew nothing about this until he wrote a response
Red Hat QA Team "Had Shrunk by Half Over the Past Year." (After IBM Divestment)
If Red Hat's workforce is being moved to the East, then RHEL can become a national security problem
Slopwatch: "Open Source" and "Linux" News Faked, Made by Bots and Entered Into Google News
Spam combined with slop about "Linux" has entered Google News
Links 03/09/2025: Microsoft Causes Mass Layoffs Outside Microsoft Also, "Google Can Keep Paying for Firefox Search Deal"
Links for the day
Gemini Links 03/09/2025: calendar.txt, Alhena 5.3.1, and ROOPHLOCH
Links for the day
The Theory That the Man From McKinsey, Whom Red Hat Took From Microsoft a Month Ago as Executive, Wants 'Efficiency' (Lower Salaries)
So far... no "official" word
When Your Site's Articles Are Being 'Cheapened' by Slop as Feature Images
Dr. Farnell should become an advisor to The Register MS
Certificate Authority Let's Encrypt Drops to Only Half a Dozen Capsules and 0.2% of the Whole in Geminispace, Self-Signed is the Way to Go
It used to have hundreds, according to Lupa
Doing to Red Hat What They Already Did (and Still Do) to IBM
there seems to be a drive to hire cheaper staff, and it may be led by somebody Red Hat hired from Microsoft
Links 03/09/2025: Salesforce's Latest Mass Layoffs, 93% in Large Poll at The Register MS Say UK Government Should Dump Microsoft
Links for the day
Preparations for Our 19th Anniversary Have Already Begun
When we get back we'll probably sort out some balloons and venue for the next party
Pleased After 2 Years With team.blue
Moving from a Content Management System (CMS, dynamic) to a Static Site Generator (SSG) was a wise decision that made life so much easier
The Free Software Foundation (FSF) is Being Attacked by Organisations Jealous of Its Principled Stance and Longevity
Nobody is perfect, but imperfection does not instantaneously imply sinister intent
If You Reject the Google Verdict in the US, Then You Should Also Reject the "Modern" Web (Do Something About It)
Gemini Protocol is still open; it cannot be hijacked or subverted because it's frozen by design and by intention
Open Source Initiative IRS Filing: Almost All the Money is Corporate, Stefano Maffuli (Executive Director) Takes About a Quarter of That Money for Openwashing of "AI" Ponzi Scheme
OSI is currently little but a PR/marketing agency of Microsoft
Many People Are "Leaving" Red Hat, Even High-Level Managers
Something is definitely going on at Red Hat
Techrights Has Been Subjected to Calls of Violence (and Death Threats), It Never Condoned Violence
I have no sympathy for people who call violence "free speech" and then get in trouble
Condoning Violent Behaviour and "Free Speech"
perhaps Microsoft Lunduke lost touch with what constitutes violence
Takeaway From the Google Verdict: GAFAM Has Too Much Control (Even Over the US Government and Courts With Government Appointees)
Many people feel disappointed but hardly surprised by the verdict
The Free Software Foundation (FSF) Turns 40 in One Month
As noted a few days ago, several times in fact, many people now recognise the importance of the FSF's mission, even if most people don't know what the FSF is
Many Microsoft "Assets" Are Fabricated Baloney (to Game the Numbers)
At times it seems like what we deal with are many weak patents (on algorithms), valuations or speculations based on hype ("hey hi"), and stocks held by Microsoft and its own staff
"Voluntary" Layoffs at Microsoft (to Game the Numbers, Sugar-Coating a Crisis)
"Employees interested have until the end of October to volunteer."
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 02, 2025
IRC logs for Tuesday, September 02, 2025