Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Ending the Free Lunch
Hal Flynn, 2003-11-26

Linux vendors spend money building security bug fixes. How much longer will they give them away for free?

Comments Mode:
Ending the Free Lunch 2003-11-26
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-06
Anonymous
Ending the Free Lunch 2003-11-26
Rob McQuillen
Lots of points missed... 2003-11-26
Penguinisto (2 replies)
Lots of points missed... 2003-12-01
Anonymous (1 replies)
Lots of points missed... 2003-12-01
Penguinisto
Lots of points missed... 2003-12-02
Anonymous (1 replies)
Lots of points missed... 2003-12-03
Penguinisto
Ending the Free Lunch 2003-11-27
Anonymous Coward
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous
Apple no, Suse sure 2003-11-27
groovecat
Ending the Free Lunch 2003-11-27
Anonymous
Free lunch? Hal, have you somehow forgotten what makes up Free Software distributions? I'll answer that for you: the work of Free Software developers worldwide.

Many companies finance important Free Software projects and developers within their organization (Red Hat, Mandrake, etc). But how in the world did you forget that most of those businesses would not and could not exist without the vast majority of Free Software they package and distribute from the "outside" world? Indeed, these companies distribute "no cost" basic copies of their distributions as part of, among other things, the symbiotic relationship with Free Software developers worldwide. But that's not their only obligation, morally or legally. That the companies make a valid and hopefully thriving business out of Free Software is wonderful and more than encouraged, but that doesn't free them from responsibilities to the community that enables their bottom line in the first place. Part of that responsibility is providing "no cost" security fixes for their distributions, even if they didn't internally write the software that needs patching. Is this a legal requirement? Depends on the individual case. Is this a moral obligation? Absolutely.

One of your quotes quite specifically sums up the bizarre view you hold of Free Software companies:

"If you're a software vendor, these resources aren't free. Developer time that could be dedicated to creating new or improved products that are, ironically, often also given away for free, are instead devoted to providing maintenance on applications not originally authored by the vendor."

Who's creating the vast majority of the "new or improved" products they sell? Its not just those companies as you so wrongly imply, it?s the worldwide Free Software community. "Ironically, (their products are) often also given away for free". What is so ironic to you? That obligation is part of the licence requirement they practice business under, let alone a moral obligation. The above very firmly defines where your misguided perceptions and understanding of Free Software lie in my opinion.

So, in answer to your article's major query of when will Linux vendors charge for security fixes. Not ever if those companies know what's good for them and want to avoid the ire of the Free Software community that enables them to do business in the first place.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/200/23908#23908
Ending the Free Lunch 2003-11-27
cowbutt
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Huh? 2003-11-28
OCG (2 replies)
Huh? 2003-11-30
Anonymous (1 replies)
Huh? 2003-12-01
Anonymous
Huh? 2003-11-30
Anonymous
Ending the Free Lunch 2003-11-29
Anonymous (2 replies)
Ending the Free Lunch 2003-12-02
trips
HEEE HEEE 2003-12-02
Anonymous
Filet Mignon 2003-11-28
Tomothy Millen
Missed the point quite a bit 2003-11-28
Anonymous (1 replies)
Missed the point quite a bit 2003-12-01
Anonymous (1 replies)
Missed the point quite a bit 2003-12-02
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
UH? 2003-11-30
Tripper
So wrong..... 2003-12-01
jmorris@beau.org
GPL - simple really 2003-12-01
Anonymous (1 replies)
GPL - simple really 2003-12-03
Anonymous
wrong 2003-12-01
Anonymous
Freedom, not Freeness 2003-12-01
Frihet
Ending the Free Lunch 2003-12-01
esjatharvee
Ending the Free Lunch 2003-12-01
Joseph Smith
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-07
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
Who actually fixes bugs? 2003-12-01
Anonymous (1 replies)
Who actually fixes bugs? 2003-12-03
Anonymous
Ending the Free Lunch 2003-12-01
Z2
Ending the Free Lunch (IT reporting) 2003-12-01
Anonymous (1 replies)
Jouro-Lobbiest 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous (1 replies)
Ending the Free Lunch 2003-12-04
Anonymous
Lame article 2003-12-05
Anonymous
Ending the Free Lunch 2003-12-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus