• fmstrat@lemmy.nowsci.com
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    17時間前

    Everyone always says “Companies should fund FOSS instead of spending money on big corpos!”, yet then this.

    It’s FOSS. It’s auditable. Funding is a good thing.

    • HiddenLayer555@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      15分前

      Google managed to backdoor Linux and Firefox with their “FOSS” libWebp. Took literally years until some security researcher not affiliated with any of them found the bug by chance and made a public report, and by then it had already been explited by NSO for ages. If they had worked for Google (or Apple/Microsoft/Amazon/any of the other corporations that just imported Google’s libWebp code without looking at it) they would have gotten silenced and the exploit would still be there as a gift to Israel. Turns out just because it’s auditable doesn’t mean it gets audited before it’s too late.

    • geneva_convenience@lemmy.ml
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      16時間前

      That’s true, but we also know that funding can come with stipulations. Oracle is an especially sketchy company.

      But that counts for all big tech I guess.

      • Auli@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        7時間前

        So not using Linux at all then? Most of the development is paid for by big tech.

      • fmstrat@lemmy.nowsci.com
        link
        fedilink
        English
        arrow-up
        4
        ·
        14時間前

        In this situation it works well, IMO. For some more context, ZFS was created by Sun (FOSS). Oacle bought them and built Oracle ZFS out of it. OpenZFS forked at that point from Sun code, and that’s what we use in Linux/etc. The Oracle variant supplies support to the FOSS variant. So Oracle has no control over OpenZFS.