• 2 Posts
  • 836 Comments
Joined 2 years ago
cake
Cake day: June 30th, 2023

help-circle

  • The issue is big companies.
    Google/Amazon/Microsoft can now fork sudo-rs and not have to upstream their changes.
    So then Google fixes an exploit for their sudo-rs implementation (or whatever software) and patch it under a different licence. Now the upstream, Amazon and Microsoft forks don’t know if that exploit is also in their implementation, is related to their implementation, or how to potentially fix it.

    The only way it works is if sudo-rs is implementing new features in a way that it benefits Google/Amazon/Microsoft to contribute back to upstream so they don’t have to keep merging/fixing their exploit code.

    For something as stable as sudo, it actually benefits Google/Microsoft/Amazon NOT to share their changes.
    If they are rolling and recommending their own distros (which I’m sure they already are) that include their forked changes, then they can say that their software is more secure than other brands. It benefits them for their competition to suffer security breaches, especially if they trace back to these kinda changes.

    Which makes everything worse for everyone.







  • XKCD alt text is always worth!
    And it’s not always available (like, the well known ones being circulated around social media).

    Props to the OP for linking to the image from XKCD (as opposed to rehosting it) and further props for linking the source!

    Just missing the delicious alt text (at least for me using jerboa, Firefox and a pixel phone)


  • Years ago, I played with AWS then contacted their support to make sure any AWS billing to my account was disabled.
    I thought I’d try it again recently, and couldn’t log in.
    I still don’t think I’m missing anything.

    I’d rather have VPS or server providers where I know exactly what I’m getting per month no matter what, tho I’ve ran near data transfer surcharges.


  • Oh, it’s expected costs.
    Like, figure out the compute requirements of your code, multiply by the cost per compute unit (or whatever): boom, your cost.
    Totally predictable.
    Compared to suddenly having to replace a $20k server that dies in your data center.
    So much easier.

    Except when your code (let’s be honest, the most likely thing to have an error in it… At least compared to some 4+ year old production hardware that everyone runs) has a bug in it that requires 20x compute.
    But maybe that is a popularity spike (the hug-of-death)! That’s why you migrated to the #cloud anyway, right? To handle these spikes! And you’ve always paid your bills so… Yeh, here’s a 20x bill.


  • The amount of software that is limited free self-hosted but the next tier of “self hosted” is enterprise and thousands per year is ridiculous.
    Absolutely ridiculous.

    Like, you have self hosted. I like your software, I use it personally and that’s why I’m using it for (and recommending it to) small businesses. They could afford your 10-100 per month for whatever extra features, but they don’t want to rely on 3rd party hosting. They want to host it themselves.
    But the only way to get those features is to go for some “cloud” bullshit they don’t control, or to pay “enterprise” prices.

    It’s why I make part of what I make/charge a contribution to the products and projects I use and recommend.
    I’ll set all that up and tailor it to your company, but anything and everything I recommend/implement is standing on the shoulders of giants. So pay those giants.
    Although I think I’m lucky with the people I work for, in that that are interested in the tech, but not the detail.


  • Such a framework for a government to properly adopt FOS software would require provisions against a “bad government” controlling said software.
    Just because the US is plummeting into a political nightmare doesn’t mean the EU couldn’t do the same I. 20-40 years.

    Such a framework of governments moving from Microsoft/Google/Amazon/Cloudflare/Whoever to a FOSS equivalent should require the target Foss platform to be run by an independent non-profit that cannot be politically influenced.

    But I have no idea how to actually future proof that from corruption. Because money talks, and billions can buy so much influence in so many unexpected places






  • No, they apply to everyone except white republicans. Their abortions are obviously justified and ordained by God (or something).
    See, white right-wingers are the “in group” to to the white right wingers (the predominant people & people in power of the American republicans).
    Everyone else is sent by the devil, or taking jobs, or freeloading on benefits. So anything they do is wrong


  • Yeh, I’m a real person. And I live in Scotland. And I’m not Russian.
    So fuck off with that pish.

    I would also rather keep the Tories and reform out of power.
    But I also suffered many years of not voting Tory - and having a Scottish government that isn’t Tory - and still had to put up with a Tory government.
    I voted against independence because I didn’t want to leave the EU - something I felt the UK government had a guarantee on, but was very undefined with independence.

    And now that we have labour in the UK government, they are just Tory-lite.
    I get that they moved right in order to scoop up more votes, but they aren’t going to return left.
    They are passing austerity laws. They are not standing up for trans and immigrant rights.
    I’m certain they are better than the Tories, and maybe they’re just having a rocky start.
    Maybe I’m paying too much (or maybe not enough?) attention to the news, so I’m only catching the negatives.

    Reform aren’t gonna get power in Scotland, Tories aren’t gonna get power in Scotland.
    But it feels like Scotland is trying to do better and keeps on getting dragged down by the UK.