Bonum Certa Men Certa

IBM Still in Control of Fedora-Legal and FESCo Despite Unpaid Volunteer Labor Picking Up More Fedora Grunt Work



Reprinted with permission from Ryan Farmer

IBM Still In Control Of Fedora-Legal and FESCo Despite Unpaid Volunteer Labor Picking Up More Fedora Grunt Work.



While IBM is purging LibreOffice, a bunch of GNOME, parts of the Bluetooth stack, and everything related to trying to manage an Apple device from file managers and media players, among others, and tossing the work onto unpaid volunteers, spreading FUD about the competition’s Enterprise Linux distros (they are now squarely into full blown paranoid), and promoting Microsoft “Clown Computing” as a replacement for LibreOffice….



IBM Office Space

So Red Hat is essentially killing all work on desktop packages, not just on LibreOffice? Also considering that several of those packages are libraries that cannot just be put on Flathub as LibreOffice can (which was their excuse for terminating all work on LibreOffice packaging). With the layoff and the destruction of the position of the Fedora Program Manager, the termination of public RHEL source releases, and this move, Red Hat is really turning into an unfriendly company, and I really have to wonder whether Fedora is going to be of any use to me in the long run.

-Kevin Kofler


Later on, IBM Red Hat showed up and started doing damage control and pimping Microsoft and Google “Clown Office” programs.



Also a lot use online docs like Office365 or Google docs. I personally used to use Libreoffice a lot but now I mostly use gDocs. […] This sort of comment is off topic, various companies are free to do with their data as they wish, just as you are free to do with it as you please. Frankly it’s often more secure with cloud providers [ed: link mine] than on corporate networks. Either way that comment doesn’t provide useful discourse in this discussion.

-Peter Robinson (IBM Red Hat)


The comment about Clown Computing being more secure was shot down again just several days ago. Microsoft Azure, Office 365, OneDrive, and Outlook all have terrible security records. Just awful. But this time it affected banks and other Azure Clown deployment customers.



 According to data from Google Project Zero, Microsoft products have accounted for an aggregate of 42.5% of all zero-days discovered since 2014.



Microsoft’s lack of transparency applies to breaches, irresponsible security practices and vulnerabilities, all of which expose their customers to risks they are deliberately kept in the dark about.



In March 2023, a member of Tenable’s Research team was investigating Microsoft’s Azure platform and related services. The researcher discovered an issue which would enable an unauthenticated attacker to access cross-tenant applications and sensitive data, such as authentication secrets. To give you an idea of how bad this is, our team very quickly discovered authentication secrets to a bank. They were so concerned about the seriousness and the ethics of the issue that we immediately notified Microsoft.



Did Microsoft quickly fix the issue that could effectively lead to the breach of multiple customers’ networks and services? Of course not. They took more than 90 days to implement a partial fix – and only for new applications loaded in the service.



That means that as of today, the bank I referenced above is still vulnerable, more than 120 days since we reported the issue, as are all of the other organizations that had launched the service prior to the fix. And, to the best of our knowledge, they still have no idea they are at risk and therefore can’t make an informed decision about compensating controls and other risk-mitigating actions. Microsoft claims that they will fix the issue by the end of September, four months after we notified them. That’s grossly irresponsible, if not blatantly negligent. We know about the issue, Microsoft knows about the issue, and hopefully, threat actors don’t.

-Tenable CEO Amit Yoran “Microsoft: The truth Is even worse than you think”


“Clown Computing” is just dumb. Even if we take a sidebar from the security angle for a moment, where Microsoft just leaves critical bugs open while attackers take your banking information and Social Security numbers and file, downloading an ENTIRE OFFICE SUITE into a Web browser every time you need to edit a document, and trusting that you’ll have Internet access, that Microsoft can keep their server running 100% of the time (they don’t), and that they won’t have crashes and lose your files, then how are you supposed to edit your files or even access them if your subscription lapses, or they say you can’t use it anymore?



One of the people on the Fedora Hyperkitty thread mentioned how IBM Red Hat blocks people from getting RHEL or updates for RHEL from countries on the US Export Control List.



Do you know that your country won’t be added to the list at some point? Then how do you get your “Clown data”?



Also raised was the obvious issue of foreign governments, businesses, and citizens storing their data on Microsoft servers in the United States. This is not only stupid, it’s actually against the law in some cases.



Clearly IBM is only worrying about customers in the United States, and even then only barely.



It encourages them to do foolish things with their data, even something as stupid as editing documents. Then the guy says it’s “easier to share” in the Clown. Like, you can’t email a document to someone?



Most of the rest is just chatter about unpaid volunteers doing work in IBM’s GULAG, that will benefit IBM, and they won’t even be paid for it. Then in return, IBM won’t even necessarily show you the code when it ends up in RHEL.



IBM is making decisions for RHEL customers and the remainder of the Fedora “community” that are not in the best interests of those customers or the community.



About the only contribution IBM makes anymore to Fedora is hosting and build bots, and that’s about it.



In exchange for that, IBM lawyers and IBM employees on FESCo decide what will happen in Fedora.



To an extent, that’s always been true, but it was also true that Red Hat (before and after IBM) was doing more of the grunt work.



I’m amazed that Kevin Kofler even managed to post on Hyperkitty. He was banned by decree of IBM from Fedora-KDE, which they don’t even care about and which is now rotting away.



At one point, Kofler was on FESCo, and he generally got outvoted 8-1 on things, because Red Hat (now IBM) has basically all of the seats. They set it up so they always get what they want. It’s like the Illinois legislature, but the only people who get to decide anything are Chicago politicians.



There is certainly nothing wrong with making money selling Free Software, but IBM’s actions lately have made it an “unreliable” partner to their customers and to Fedora’s users (which have value as testers and package integrators, not that IBM cares).



Their decisions have been chaotic and announced as they were being implemented.



If you are a RHEL customer, you presumably want predictability.

Why settle for this?



Recent Techrights' Posts

SLAPP Censorship - Part 64 Out of 200: Not Amused by Repeated Threats (to "Shut Down" My "Existence" While Mentioning My Wife Too)
it's about censorship
The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)
They are kidding themselves if they seriously believe Web-facing source code repositories are the real threat to patients
cPanel is Not Linux, cPanel is Proprietary Software
It's fair to say I've used cPanel for 23 years
Storage and Memory Prices Are Rising Not Because of High Demand (Production Can Match Demand), It's Partly Because of Price-Fixing (Same as Food Price Increases)
Sophisticated robberies are still robberies
Thousands of Layoffs at IBM, So IBM Pays Mainstream Media to Claim That IBM is Hiring (Paid Lies)
This is a story about the media failing us, not just IBM failing as a company
A Look at DataStax Bluewashing (IBM and Layoffs)
IBM is a place that many people leave or get pushed out of
 
A Month Since Mass Layoffs at Red Hat (400+ Engineers Laid Off), The Media Didn't Cover It
We are very concerned about the state of the media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 02, 2026
IRC logs for Saturday, May 02, 2026
Gemini Links 02/05/2026: Strange Psychosis and TUIs
Links for the day
Links 02/05/2026: Microsoft Has Begun Rebranding Vista 11 as 'XBox' (Because the Console is Dying), Slop Rejected by Oscars
Links for the day
IBM's CEO 10 Years Ago in IBM-Sponsored Forbes: "For those willing to embrace [blockchains], the future will indeed be bright."
How well did this prediction materialise?
RightsCon Cancellation as a Data Point in a World Gone Astray
RightsCon should not even be controversial
Links 02/05/2026: Gen Z is Turning Against Slop and OpenAI/Microsoft Rift Explained
Links for the day
Gemini Links 02/05/2026: Leaving Session, Alhena 5.5.7, and Slop Failing Customers
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 01, 2026
IRC logs for Friday, May 01, 2026
Links 01/05/2026: Microsoft 'Headcount' Decreasing, Apple Quietly Killing Vision Pro
Links for the day
Oracle's Debt Grew by Over 50 Billion Dollars in 6 Months
Larry Ellison spent a lot of money buying a lot of the corporate media
In Praise of Debian
30 hours ago we began an upgrade
What Linus (Torvalds, the Linux Dude) Meant by "Show Me the Code"
"Show Me the Code" is a common cultural reference
Yes, GNU/Linux Can Run on Playstation 5, But Don't Buy It, Learn From Sony's Past of Rootkit and PS3 Betrayal
Millions of Playstation 3 owners will never forget what Sony did to them
XBox Will Not Last Much Longer, XBox Chief Admits Problems
Microsoft's latest "results"
Dealing With Demagogue in Free Software
Don't spread their ideology and never participate in any of their projects
What May 1 Means to Us (and to Many Others)
To me, May 1 means something
Microsoft Lunduke is 'Pulling a Garrett' by Turning Technical and Legal Debate Over Rust Into a 'Trans Debate'
Don't fall for the demagogue
Links 01/05/2026: Regulatory Trouble for Apple, Now Even Mozilla Pushes Back Against Google
Links for the day
Microsoft "Buyout" Offer is Less Than One Year's Salary
So our assumption about this was correct
The Corrupt Lecture the Non-Corrupt - Part X - European Patent Office Managers Have Crossed Red Lines, According to Themselves
The girlfriend of the President of the European Patent Office (EPO) is trying to muzzle EPO critics
Techrights is Still Growing, Attacking Techrights Does Not Weaken the Community
Bullying us for 2+ years does not result in fear, it results in us feeling more emboldened and motivated
SLAPP Censorship - Part 63 Out of 200: Graveley as a Stripped-Down Version of Garrett in the Particulars of Claim (5RB Barrister Could Do This in One Minute)
Lazily and sloppily, it looks like the barrister took Garrett's claims and tweaked them a little (shortened) for Graveley
Lots of People Leave IBM, Today IBM Has About 1,000 Workers Fewer Than Yesterday
Confluent "last day" for 800+ people
Been a Very Busy Week
Next week, as we have no upgrades to prepare for, we should be able to publish at the usual pace of 20+ pages per day
In New Letter Sent to Chair and Heads of Delegation of the Administrative Council of the European Patent Organisation the Staff Union Explains How to End European Patent Office Strikes
If Campinos continues to behave as he does right now, the Council can show him the door
Links 01/05/2026: Poems and Continuous Privacy Policy
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 30, 2026
IRC logs for Thursday, April 30, 2026
Microsoft Debt Rose Almost $50 Billion Since We Moved to Debian
GAFAM has a new name for debt