TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Core Infrastructure Initiative

251 pointsby chiachunabout 11 years ago

9 comments

matt__roseabout 11 years ago
Basically, through a combination of clever marketing and actual impact, Heartbleed hit the Open Source community HARD, and left most people in the Open Source Community asking two questions: 1. How did this happen? 2. How can we stop this from happening again?<p>LibreSSL and openSSLRampage is the OpenBSD response, and, it&#x27;s absolutely in keeping with their character. I admire the &quot;Fuck it, let&#x27;s just fix this shit&quot; attitude that goes along with it.<p>The Core Infrastructure Initiative is the Linux Foundation&#x27;s response.<p>They&#x27;re two valid ways of dealing with the problem. the LibreSSL way is more direct, targetted, and, in a way, satisfying, especially if you run OpenBSD, and can gain from these efforts relatively quickly.<p>The &quot;Core Infrastructure Initiative&quot; is looking at it from a more holistic perspective and saying: OK, OpenSSL was in trouble and nobody noticed, what other projects are in the same situation, and how can we prevent what happened to OpenSSL from happening to other projects.<p>Neither way is necessarily &quot;The only right way&quot;, or even better than the other way. In fact, both approaches complement each other. OpenBSD fixes the actual current problem child, Linux Foundation is on the hunt for the next problem child
评论 #7640544 未加载
评论 #7641535 未加载
评论 #7645448 未加载
评论 #7640375 未加载
tedksabout 11 years ago
Holy crap, Microsoft donating to the Linux Foundation. Cats and dogs, living together. It&#x27;s the end of days for real this time.<p>My one real question: How well has the Linux Foundation managed its money in the past? Are they going to be an effective steward of this fund?
评论 #7640630 未加载
评论 #7640865 未加载
评论 #7641133 未加载
general_failureabout 11 years ago
As expected no Apple. I have always been fascinated how Apple gets a lot of developer love and yet is completely absent in most (all?) conference&#x2F;event sponsorship, initiatives etc.
评论 #7642318 未加载
评论 #7642331 未加载
评论 #7641641 未加载
评论 #7641673 未加载
sanxiynabout 11 years ago
I hope that OpenSSH developers get some funding too. OpenSSH is clearly a core infrastructure, and they had financial difficulty in the past.<p>Mozilla Foundation once donated 10K USD to OpenSSH after OpenSSH&#x27;s call for donation. Not many others did.
评论 #7642235 未加载
ausjkeabout 11 years ago
OpenBSD is great but it has its own agenda. Linux Foundation does have a Linux in it, maybe that tells something. Plus, Libressl can pull in whatever changes future openssl will have. I think it&#x27;s a win-win for both sides. I used OpenBSD in the past, but nowadays it&#x27;s all Linux for everything, from server to desktop to my cellphone.
评论 #7640329 未加载
评论 #7640383 未加载
rubyfanabout 11 years ago
So to get this straight, the Linux Foundation has responded to OpenSSL problems by creating a web page, a committee and are soliciting dollars from sponsors and grass roots?<p>OpenBSD responds by rolling up sleeves and fixing the problem.
zatkinabout 11 years ago
I get the feeling that these companies are throwing money at trying to fix the problems (in other projects besides OpenSSL that are fundamental), and not talent&#x2F;manpower.
gnu8about 11 years ago
Their web page says OpenSSL group is their first candidate for funding. It&#x27;s puzzling that they would choose to fund such a corrupt and incompetent organization over LibreSSL, which is actually fixing the code and ultimately is what will actually be used.<p>Or maybe it&#x27;s not so mysterious, the principle companies involved have a long record of benefiting from OpenSSH and never contributing to that either.
评论 #7640064 未加载
评论 #7640151 未加载
评论 #7640115 未加载
评论 #7640103 未加载
评论 #7640199 未加载
评论 #7641223 未加载
评论 #7640344 未加载
a2079648about 11 years ago
Looks like somebody is trying hard to prevent LibreSSL from becoming widely adapted.<p>&gt; By raising funds at a neutral organization like The Linux Foundation, the industry can effectively give projects the support they need while ensuring that open source projects retain their independence and community-based dynamism.<p>I somehow can&#x27;t imagine an organization named &quot;Linux Foundation&quot; to give money to OpenBSD and other non-Linux related open source projects.
评论 #7640289 未加载
评论 #7640350 未加载
评论 #7640116 未加载