• fireshell@lemmy.ml
    link
    fedilink
    English
    arrow-up
    46
    arrow-down
    26
    ·
    edit-2
    17 hours ago

    Linus Torvalds Confirms Decision to Remove Maintainers from Russia

    You couldn’t come up with a more powerful spit in the direction of FOSS. And from Linus, who is now kind of showing f*ck to the entire community. Here you have freedom, openness and all that. Today they just wiped their ass with it, and by one of the founders.

    This is the moment when the split politics, dirty ones from all sides, have penetrated into the very heart of OpenSource - into the Linux kernel. https://www.youtube.com/watch?v=v_YozYt8l-g

        • vga@sopuli.xyz
          link
          fedilink
          arrow-up
          4
          arrow-down
          4
          ·
          edit-2
          11 hours ago

          I’m not sure if you’re kidding, so I’ll just note that Finland and Iceland are NATO member states, and Finland is notoriously against Russian aggressions due to history.

          • BCsven@lemmy.ca
            link
            fedilink
            arrow-up
            5
            ·
            11 hours ago

            I think the commentor meant in regard to US restrictions that may get imposed on a project, since they have odd ITAR/EAR controls. Moving sonewhere with less export restrictions could alter choices of development.

      • Allero@lemmy.today
        link
        fedilink
        arrow-up
        5
        arrow-down
        3
        ·
        16 hours ago

        Kernel cannot follow or not follow any legal rules. Linux Foundation can.

        And if regulations become a serious issue and go against the spirit of open-source, it is time to move the Foundation somewhere else.

        • BCsven@lemmy.ca
          link
          fedilink
          arrow-up
          2
          ·
          11 hours ago

          i don’t know what exactly was in question in the kernel, that the lawyers had to worry about, but From EAR rules… “note that open source software can still be subject to export control measures if it includes technologies or functionalities that are regulated. In such cases, specific controls may be applied to prevent the unauthorized export of these technologies or functionalities.”

          IF something was deemed controlled, it makes sense to pull it so kernel can ship anywhere, and whomever received it can do their own tweaks

          • nanook@friendica.eskimo.com
            link
            fedilink
            arrow-up
            3
            ·
            2 hours ago

            @BCsven @Allero Given the modular nature of the kernel, the module can always be made available separately those today’s Internet really makes such restrictions, as they apply to software, moot.

            • BCsven@lemmy.ca
              link
              fedilink
              arrow-up
              2
              ·
              38 minutes ago

              Exactly. Not much different than a distro that can’t legally ship non-free drivers for initial instal due to licensing, but you load them in yourself on first boot

              • nanook@friendica.eskimo.com
                link
                fedilink
                arrow-up
                1
                ·
                30 minutes ago

                @BCsven As I stated though moot, the laws have really outlived their usefulness. There are simply too many unsecured systems on the Internet to make it impossible for a bad foreign actor to gain access to any software that is not intended for export. When I worked for the local telco, many of their switches had dial-in modems that connected to the recent change channels, the channels that allow you to alter how lines were assigned, telephone calls were routed, etc, without so much as a login or password. If you knew the commands you could do pretty much anything you wanted to. I caused a major meltdown that got me an unwanted interview with directors merely for suggesting that they put a password on the root account of a pbx interface Unix system used to serve a 40,000 line customer. So yea security is mostly a joke and as a result these laws serve no useful purpose.

                • BCsven@lemmy.ca
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  edit-2
                  7 minutes ago

                  Oh I get the futility of it. But if you are in the USA you are bound by it. Same reason encryption devs had to cross to Canada to do development because USA would not allow encryption code shared across boundaries. Or how I once sent a software bug report in for an Engineering product; because company is USA based they assigned it an ITAR /EAR status. It was a 4" cube I modelled, and now some dev has to treat it as sensitive EAR data. LOL

        • merthyr1831@lemmy.ml
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          3
          ·
          15 hours ago

          the foundation should have moved long ago but I think Linus’ personal adoration of the US is going to get in the way of that.

    • ChiefSinner@lemm.ee
      link
      fedilink
      arrow-up
      9
      arrow-down
      8
      ·
      15 hours ago

      Uhh sir Linus, this is a Wendy’s Linux kernel.

      .

      Why force your political beliefs on something that has nothing to do with?

      • Allero@lemmy.today
        link
        fedilink
        arrow-up
        29
        arrow-down
        4
        ·
        edit-2
        16 hours ago

        If we follow through with it, I would absolutely never ever trust anyone from the US, for example. US is very much known for cyber espionage and shady operations, and could absolutely backdoor Linux.

        This is all power play, and it comes from a very certain direction amidst this political struggle.

        You want your open source code not to have backdoors? Review it meticulously. This is really the only way, and the one an entire open-source community relies on - pretty successfully, by the way.

      • fireshell@lemmy.ml
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        1
        ·
        16 hours ago

        by this logic it turns out that the code quality control system is built in such a way that if someone has malicious intent and wants to add malicious code, but is not affiliated with dubious structures, then he will easily succeed? Hey, what about enough eyeballs and shallow bugs?

        • MrAlternateTape@lemm.ee
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          7 hours ago

          I do agree that quality control should catch things, but we are all human and we don’t catch a 100%. So if quality control is flooded with too much things to catch, the chance of one slipping by increases.

          Also, a lot of FOSS is based on volenteers, do we just ask those people to put in more hours? Who is responsible anyways if something makes it through and actually causes damage to something or someone?

          I find the decision quite reasonable. You at least filter out the party most likely to pull something shady. We should still be very careful, but it takes away some the work.

      • gnuhaut@lemmy.ml
        link
        fedilink
        arrow-up
        18
        arrow-down
        7
        ·
        15 hours ago

        Yeah better discriminate based on nationality /s. But why stop at that? Poor people are too easily bribed can’t have them. I hear the CIA recruits from top US universities, can’t trust those college grads either. Anyone belonging to some homophobic church or religious group? Better not what if they’re closeted gay and get blackmailed? Anyone in a monogamous relationship should be excluded for the same reason, if you think about it. *tips forehead*

      • Ledivin@lemmy.world
        link
        fedilink
        arrow-up
        10
        arrow-down
        2
        ·
        16 hours ago

        If only there was some sort of review process for code to get into the kernel…