News: 0000824265

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

FOSS Contributor Survey

([Briefs] Jun 23, 2020 15:23 UTC (Tue) (ris))


The Linux Foundation's [1]Core Infrastructure Initiative (CII) and the [2]Laboratory for Innovation Science at Harvard (LISH) have developed a [3]survey for contributors to free and open-source software (FOSS) projects. The aim is " to identify how to improve security, including the sustainability of the FOSS ecosystem, especially the FOSS systems heavily relied upon by organizations worldwide. "



[1] https://www.coreinfrastructure.org/

[2] https://lish.harvard.edu/

[3] https://www.linuxfoundation.org/blog/2020/06/linux-foundation-harvard-announce-free-libre-and-open-source-software-foss-contributor-survey/

FOSS Contributor Survey

The survey is embedded in a nonfree javascript program and can't be taken without running it. It's a survey of contributors willing to run a nonfree program in their browser. It won't be an accurate survey of FOSS contributors, because many of us won't do that.

LWN usually seems to care about licenses and mention when they are nonfree, I think its time that gets extended to javascript programs that are required for a website to work at all.

FOSS Contributor Survey

The survey is embedded in a nonfree javascript program and can't be taken without running it. It's a survey of contributors willing to run a nonfree program in their browser. It won't be an accurate survey of FOSS contributors, because many of us won't do that.

LWN usually seems to care about licenses and mention when they are nonfree, I think its time that gets extended to javascript programs that are required for a website to work at all.

FOSS Contributor Survey

It's also really broken, often telling you you didn't answer a question when you did, or giving you suddenly two pages of questions in one go... I stopped half-way.

FOSS Contributor Survey

It's also really broken, often telling you you didn't answer a question when you did, or giving you suddenly two pages of questions in one go... I stopped half-way.

FOSS Contributor Survey

As always, it will represent those who participate. But if you chose to not participate, don't blame anyone but yourself if the outcome doesn't represent your views.

Personally, I think the survey is flawed in that it implies that "security" is purely the responsibility of project upstreams -- as opposed to downstreams that don't keep their products updated and/or actively prevent end-users from supporting themselves.

It also seems to imply that the main reason upstreams don't have "security" is due to ignorance, instead of the simple fact that most upstreams are badly resource-starved.

"You can't teach people to be lazy - either they have it, or they don't."
-- Dagwood Bumstead