• 4 Posts
  • 804 Comments
Joined 11 个月前
cake
Cake day: 2024年12月13日

help-circle






  • Security vulnerabilities are different

    No, it’s still open source work, completely voluntary in the free world.

    Disclosures are often used so people are aware that they’re using libraries that the maintainer has refused to patch

    No, they merely tell reality: an unresolved security issue was found. How anyone handles that is their business. There is no inherent duty.

    People who would rather write a fix than write & maintain their own daunting library will send a fix.

    could lose actual funding they get

    If someone’s getting paid, and it’s not worth the work, then that is also their business. It’s still open source. If the solution saves more effort than doing it yourself, then the people who need it won’t just let it all go to waste.

    This is entirely a social issue of managing & rebuffing unrealistic expectations. It’s perfectly valid to set boundaries, remind folks beggars can’t be choosers, and tell them pitching in gets more done.


  • Again, ignoring/postponing is an option. At work, we’d just move that to the backlog of shit we may never touch: having it there is good for tracking the issue & gathering notes on our thoughts regarding it, which saves time approaching it like new each time it comes up. It’s no different for open source maintainers. Marking an item as won’t fix, deferred, or help wanted or closing redundant items isn’t much paperwork.

    Again, the objective reality is the defect exists, and that reality doesn’t change with our awareness of that fact: it’s better to know & track for planning even if the plan is to do nothing.


  • Human time costs resources, and human aren’t that energy efficient. Would it take more energy & resources for a person to inefficiently grind away at a task they dislike than for a machine that can perform it fairly quickly?

    There’s also opportunity cost, eg, shit we’d rather do. Time spent on an unwanted task is time we don’t get to spend on something better.

    Drawing’s been figured out by better artists, and there are better problems to solve that those artists absolutely suck at.







  • We sought legal advice, and unfortunately discovered that French law, specifically Article 6-I-7 of the Loi pour la Confiance dans l’Économie Numérique (LCEN), might actually require us to respond and apply blocking measures, at least for French users.

    That said, this whole situation shows just how inadequate this regulation is. Such decisions should be made by a court — a private company shouldn’t have to decide what counts as “illegal” content under threat of legal action.

    Good ol’ European governments exerting legitimate authority to protect civil liberties & information freedom. At least they had enough sense to stipulate penalties for manipulative reports:

    Art. 6-I-4 LCEN:

    1. Any person who presents content or activity to the persons referred to in paragraph 2 as being illegal with the aim of having it removed or its dissemination stopped, when they know this information to be inaccurate, shall be punished by one year’s imprisonment and a fine of €15,000.




  • if you come in guns blazing and condescending people will shut you down no matter what facts you have

    I love that approach, but then I’m not trying to change minds of those who lack the wisdom to prioritize the truth & objectivity over themselves and should know better. Merely trying to vindicate a neglected consideration for cooler minds. If someone’s ready for it, then great, and if not, then we can admire & ridicule their folly: reality doesn’t care. Defending truth & rationality is reward enough & those too foolish to appreciate it can find their own way there.

    It’s pretty much acknowledging

    you can lead a horse to water, but you can’t make it drink.

    It’s good enough to point out the water & even be insolent about it: the horse only prolongs its dehydration by not drinking, & there are better horses. I’m not a horse trainer.