Depends what interest, contingencies and on other information to understand if 1.2B debt is a problem or not. Otherwise, for most UHNW people, debt is just a number on a balance sheet.
It might actually be wise [1] to create a new, slightly less permissioned license for open source wherein the open is defined as anything that isn’t in a kill or surveillance chain or, more broadly, for military use…
That wouldn't be open source. OSI includes the clause "No Discrimination Against Fields of Endeavor"[0] for its definition of open source. Famously, the JSON license[1] has a clause "The Software shall be used for Good, not Evil," so the Free Software Foundation considers it nonfree.[2]
Arguably, any such clauses - similar to attempt for "non commercial" licenses would do more harm than good.
If you actually wanted to respect such a license,you would have to endlessly argue what is dual use technology for example, the same as people argue if advertisements on project website or tangentially related donations make the thing "commercial"?
While at the same time, any "bad guys" will just ignore both.
I've contemplated writing an email to RMS asking him how he feels about the use of GNU software in military and surveillance systems and if he could do it over if he would do things differently to alllow users to put a clause in their OSS licenses that forbid such things.
This line of reason is one I find appealing but somewhat untimely. If I'm grokking the deeper message it's that "limiting licensed use in these creative ways opens the door to potentially evil chicanery" -- i.e. you start limiting licenses to non-police activities and then some corporation goes "great! now that we can do that our licenses now limit usage to only endeavors that boil your firstborn and undermine our competition".
Problem is in era de la grift we've sort of realized that they never needed permission - there's no precedent to set anymore.
Call that "deeper message" A1. He's got arguments A1 and A2, and goes "if P, then A1(P) implies C; and if ¬P, then A2(¬P) implies C; therefore C". But we can just as easily go "if ¬P, then A1(¬P) implies ¬C" (as you did); "and if P, then A2(P) implies ¬C; therefore ¬C". Logical arguments don't let you do this: the arguments are pure rhetoric.
Quite a lot of Richard Stallman's arguments are pure rhetoric, actually. And, I mean, I guess it worked, in that the GPL and FSF ended up being quite influential; but the trouble with building a philosophy on rhetoric is that people start to believe that rhetoric – including you –, and it erodes and replaces the foundations of their beliefs, so it'll all come crashing down sooner or later.
I don't really think we need to engage with the rhetoric on an intellectual level, since it's obviously wrong: far better to read philosophers whose reasoning is sound, or to come up with your own ideas.
Sorry, but you must be way smarter than me or something because that made no sense. Not that I don't understand what that notation is supposed to mean, but that I'm not seeing the connective tissue here. It's also a little weird to come at me based on the 'erosion of my foundation of beliefs', considering how orthogonal that is to the topic of legal precedent and contracts.
For what it's worth, what I do believe is that our system of law was a good idea at one point but is totally ineffectual in the current context - that's my point about an era of grifters. Didn't get that one from stallman, measured that on the eyeball mark I.
This is the first time my poor communication skills have been interpreted as a sign of my superior intelligence. I think I'm ready to become a professional expert consultant!
I was abstracting Richard Stallman's argument to its (il)logical structure: P and ¬P are whether the license restriction is enforceable, etcetera. "Erosion" was talking about people who, seeing free software as a good idea, begin to adhere to Stallmanite orthodoxy (which is, largely, philosophically-unsound): that was not aimed at you, but at Richard Stallman himself (the Ur-Stallmanite, we could say). I saw this as generalising your criticism. I didn't notice you were making a broader point about the law, so this was somewhat of a supercalifragilisticexpialidocious non-sequitur; thanks for clarifying your point.
Ah! Sincere apologies for being defensive. Yeah, I share your eye when it comes to orthodoxy in most if not all areas - wary. The problem with any orthodoxy is that it's dumb - not as in 'stupid' but as in 'doesn't think or adapt to changing circumstances'.
Being the most correct 20 years ago is fairly meaningless today - not making a judgement on whether D-Stall is, was, or wasn't. But it's important I think to deal with reality. Thanks for your clarification!
The idea that a defense manufacturer would be stopped by this is too funny. The code won't be auditable by you so how will you know? Secondly even if you did find out the most you'd get is a payout. Thirdly if you believe that missile aren't running GNU/Linux I have a bridge to sell you.
Why do you want the people risking their lives to protect your freedom to have worse artillery? I don't understand this thinking at all. If my country is going to shoot something, I want them to be able to control what actually gets hit. I swear, people take borderline religious stances on things to the point that they no longer make sense.
Have you served? Because I have. Still have friends in the service and they are pretty cheesed that they've been roped into this mess. Go ask a lifer what they really think about Smegsbreath some time - I think it will be enlightening.
I come from a military family - supporting soldiers and the policies of an administration are two different things. The commenter is correct in that our war in Iran has nothing to do with our freedom and everything about pushing the political agenda of a foreign country.
Many wars are simply what you’d expect from violent leaders who realize they can order other people into combat for them. But some wars really are for the greater good. There are definitely militaries that I want to see win, and militaries that I want to see lose.
I realize I don’t have any code that would be of any use to any military. If I did, I don’t see how I could write a license to allow the use of my code by only people I agree with.
You can write whatever you want in a license, including something as vague as “you can only use this code if I agree with your moral stances”. (For expediency, it might be worth enumerating the cases.)
The OSI might disapprove, but you don’t have to listen to them.
> Why do you want the people risking their lives to protect your freedom to have worse artillery?
Hi. Veteran here. I protected his freedoms to do just that. You asking this question in that way insults veterans, whether you intended it or not. People using this line of thinking usually only care about veterans when it can win them arguments, and do not care any other time.
> I don't understand this thinking at all
Then, instead of asking questions with inflammatory language, you should humble yourself and ask respectfully so you can understand.
> Why do you want the people risking their lives to protect your freedom to have worse artillery
If better artillery is being built on open source tech then everyone has better artillery. Not just the people "protecting you" but also the people trying to kill those people
The only thing that protects my freedom is active peace-making at levels greater than active war-making.
We are all under a great deal of threat precisely because borderline religious warrior narcissism has taken precedence over emphatic, unstoppable peace-making.
The USA has been bombing people into oblivion "protecting peace", for decades now. Is the world safer now?
No, it very definitely is not.
>Why do you want the people risking their lives ..
I want people risking their lives to make great peace. That is not happening at the scale that it should be.
Instead, the lazy, less noble warrior narcissist, has the world by the nose. The only difference between an utter criminal and a war fighter is a very, very thin line of paper which makes murder in one case illegal and in another case, legal. This paper is tattered and torn and covered in the muck of the victims, held high by the victors to justify their crime.
However, we see today the fallacy of this condition.
If your country is going to shoot something, I want to be damn sure it has done everything ethically, technologically, and administratively possible to have first made peace, at all costs.
That is simply not evident in any of the current world conflicts.
Instead of engaging in foreign cultures, we in the West march in lock-step behind those who have deemed foreign cultures inferior and worthy of nothing but destruction and despair.
I want to see the warrior narcissist who profit from this condition, disarmed and made irrelevant. The only way that happens is if human life takes precedence over human identity.
No humans identity is worth more than another humans life.
Risk your life for true peace this way: Before you murder, abandon yourself!
I'm going to assume that you're an American, speaking from an Americentric point of view and I'd like to take this as an opportunity to discuss the fact that Hacker News is a website that is available to people around the world. Many of those people are not American citizens and do not have the same relationship with the US military and government that you do.
Only Americans want to defend their country? I'm Swedish, did my military service, and generally agree that I would want our defence forces to have the best weapons available.
This isn't a gotcha or 'try' it's a critique about how US defaultism overwhelms conversations on this site and how it is detrimental to the conversation at hand.
I'm not disputing that one of the links from the comment that gmerc made came from a US military domain, but that's moot. A licence against military use covers every army, not the one you happen to identify with.
As an aside, I'm curious what nationality user gmerc is. If they're the person in the video that they linked to it sounds like they're German?
And this isn't being nitpicky -- it's really important in the context of this discussion. People from certain countries more than others seem to lack this concept of civic hygiene and clam up when the discussion comes up.
We should push past that awkwardness and keep having these discussions about concepts like civic hygiene. It's important.
I doubt this is enforceable. Are you going to sue a government secret program because they used some open source code in a way that violates some weird clause?
Yes, citizens should sue the government when the government takes actions which are grounds for suit. The government sure will come after your money if you do things they say you shouldn't, and what's good for the goose is good for the gander.
You won't know, they'll say it's for national security so licenses don't matter, and then if you keep going they'll make sure your life is a living hell and your bank accounts closed.
I'm begging tech bros to understand that abusive governments _do not care about abusing you_
You seem to be suggesting that it's impossible to successfully sue the federal government, which is provably untrue. Yes the government abuses the rights of its citizens and will vehemently defend itself if challenged, but suit is the one of the more potent peaceful means we have to redress grievances with them.
As this is a civil discussion, being rude is uncalled for. Maybe go for a walk in nature and get your head back on straight.
No one is saying you can't sue the government. You can in fact. What we're saying is you won't get the outcome you desire. The fact that you think they will simply stop production because you sued them is frankly laughably naive. That's not being rude. It's just reality.
On the other hand, it may be worth publicly and unambiguously stating a position even if unenforceable. This seems to be what most modern protest movements are based on. For instance, how many software repos "stand with Ukraine", even though they won't make an impact on frontline military reality?
Ah yes, they're carpet bombing people and indiscriminately killing fighters, adults and children, but they're going to be stopped because... the software they use is two clause GPL.
RFCs are used by developers as strict guidelines for implementation.
The mere publishing of an RFC has customarily been treated by developers as a stamp of approval from the IETF.
The NSA, contractors and their fans argue that simply adding a "RECOMMENDED=N" in an obscure section of this draft will somehow prevent said implementations in deployments.
However, as an example, Canada's NSA equivalent specifically requested the draft to be published so that they can use it to support their poor choice in deployment of solo ML-KEM nation-wide.
While ML-KEM may be sound, significant bugs in implementations in the wild continue to be published.
To be clear, CRQCs do not exist today.
ECC is battle tested, proven, and is used today.
It makes no sense to delete working cryptography and replace it with potentially buggy, non-battle tested implementations of new cryptography for a threat that does not yet exist today.
Instead, you fight HNDL [1] with hybrid which preserves the safety of today, and hopefully also, tomorrow.
No serious security person should be recommending otherwise which is, perhaps, why some may question the motives of those that are pushing for solo ML-KEM.
> A majority (but not a large majority) of cryptography engineers would use hybrids at this point
Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.
> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.
The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.
Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.
Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.
I certainly find it fascinating that the majority of those in favor come from signal intelligence agencies, while the majority of those against are PhD cryptographers.
I was happy to see the lead of Europe’s PQC team also voted with the cryptographers.
Software would be equated to nukes if companies and people put more time and energy into the security aspects. They cut costs for a long time by not spending on certain aspects. The does not make AI a nuclear bomb equivalent in my mind. Banning the best models makes that harder to rectify. State level hackers will have access to this technology regardless.
Unlike nukes, AI is being used in the cyber warfare realm daily, as both an offensive and defensive tool.
I seem to remember - but cannot find, even with an AI boost - someone's "law of computing" or somesuch describing the amount of time that has to pass before code you wrote is indistinguishable to you from code written by someone else. At any rate the interval is not so long.
In your own codebase you can at least run a "you simulator" to arrive at the answer fairly reliably. "Where would I have put this bit? Oh yes, of course ..."
> The site’s content happens to include an HTTP/2
endpoint that, when presented with an anonymous authorization token, behaves as a VPN server’s outer layer
Is this not the fingerprintable aspect? Wouldn't you need to randomise the HTTP endpoint to avoid eventually being banned based on URI?
I agree hw attestation is net negative when forced upon end users. OTOH, when service providers use it, it results in transparency to end users [1] so it's really about how it is used.
reply