NGICommons,
@NGICommons@eupolicy.social avatar

🔊 Can a digital commons approach reinforce OSS security?

✉️ Please read the opinion blog post from members of the @NGICommons consortium

ℹ️ For more information, please reach out to us

https://commons.ngi.eu/2024/04/24/responding-to-xz-utils-can-a-digital-commons-approach-reinforce-oss-security/

@martelinnovate @OpenForumEurope @openfuture @cnrs @linuxfoundation @EC_NGI @EC_DIGIT @EC_OSPO

#digital #digitalcommons #opensource #NGICommons

Di4na,
@Di4na@hachyderm.io avatar

@NGICommons @martelinnovate @OpenForumEurope @openfuture @cnrs @linuxfoundation @EC_NGI @EC_DIGIT @EC_OSPO I mean, I cannot disagree; it is not even wrong. It is just... I mean, I get how you get to that point, but it is so far from the reality of maintainers.

This would be great, and I am pretty sure I would support it. But also, what would it have done for xz? Can you point out the link between xz and what you offer here?

jankrewer,

@Di4na hey Thomas, I think this has to be understood as a first step of a process to think about how to design public support for critical open source software in the future - which is the objective of the NGI Commons project..

jankrewer,

@Di4na The thinking is that as many others argue, cybersecurity risks in OSS (such as the one made visible by the xz backdoor) show light on current maintenance issues in OSS, which require more public support - including funding.

jankrewer,

@Di4na But we also need to preserve/strengthen the specific mode of governance that makes OSS potentially secure in the first place: distributed participation and rules of checks and balances etc. Bringing in the concept of the digital commons helps to imagine public funding without replacing what OSS currently is (not a State-led bureaucratic system).

jankrewer,

@Di4na we are organizing a workshop in June to delve deeper into all of this, maybe you can join us there? https://commons.ngi.eu/event/ngi-commons-workshop-2024/

Di4na,
@Di4na@hachyderm.io avatar

@jankrewer I mean sure. Who will pay my employer that day, the day before, the day after, my travel and my hotel?

Also nothing you said links to what happened to xz.

Di4na,
@Di4na@hachyderm.io avatar

@jankrewer I will respectfully say, that if you actually want a discussion about a Digital Commons where said ressource constrained maintainers are heard, an in person workshop in a different country during their workweek may be a bit problematic?

But it seems that is not on the nose enough for you?

jankrewer,

@Di4na I'm not assuming anything about what you do or where you live, as I have no idea who you are :) but if you're knowledgeable about the subject, there will of course be plenty of other opportunities to contribute online, and I hope you'll find the time to share your thoughts.

Di4na,
@Di4na@hachyderm.io avatar

@jankrewer I have done it in the past and I am doing it here.

The result is that you had nothing of substance to offer. We are used to it. More energy spent for nothing. Consider retrospecting :)

https://www.softwaremaxims.com/blog/open-source-hobbyists-turf

  • All
  • Subscribed
  • Moderated
  • Favorites
  • AdobePhotoshop
  • DreamBathrooms
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • InstantRegret
  • tacticalgear
  • anitta
  • ethstaker
  • provamag3
  • cisconetworking
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • modclub
  • megavids
  • normalnudes
  • Leos
  • JUstTest
  • lostlight
  • All magazines