• DigitalNeighbor@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    12 hours ago

    I can explain a major reason why public services and administration are begrudgingly moving to FOSS or OSS at all. They need to apply security standards like ISO 27001 and when they start going through what the documentation requires they realize that most OSS let alone FOSS make it very hard to have any say in the development of the software.

    How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs? I can tell you from experience that some OSS devs will tell you to make your own merge request if it’s so important to you. GDPR makes having vulnerable public facing services very unattractive. What about support for the product when you need something fixed or have an issue with running the software?

    You can definitely get a license for an OSS, or get a legal agreement for support from the OSS devs for money. I can guarantee you that when managers in public services look at either patching together and managing a bunch of separate OSS or using Microsofts integrated infrastructure, they see the advantages right away.

    That is the sad truth… It’s resource intensive and a regulatory problem to create and manage a whole infrastructure. It’s much easier to use integrated and centralized solutions.

    • fruitycoder@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 hour ago

      Commercial support or if it’s critical enough infrastructure have a full time department/team to do it. Commercial support is the obvious choice for most countries starting out tbh.

      Honestly SuSE, Ubuntu, and Hetzner all have good for enterprise support and its crazy that they don’t have more major gov business in the EU now.

      But honestly yeah, pay for labour to maintain things. It’s not a breaking new idea. You can do that AND own the things instead of renting from private companies too. Also not a new idea.

      The only thing new is that we are talking about computers and we have museums for them already so maybe get with the times, right?

    • NewNewAugustEast@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 hours ago

      Don’t get me started about ISO. They can go fuck themselves.

      But that particular standard doesn’t apply to software. It applies to a company. Its a best practices, audited authoritative report. None of that means the software doesnt have backdoors, flaws, issues, its how they handle them.

      Microsoft is a known ISO cheater, and will pay off companies or at least influence them, so I wouldn’t trust ISO or the auditors.

      So now, any company that is willing to take on the challenge of being certified can use open source software (which actually is audit-able as opposed to Microsoft’s).

      Seems like there is a path forward. Yes they may have to fund a project that helps audit, develop, or maintain critical software. If its open source, you have an entire world could also participate in securely developing software, in the open.

    • CyberSeeker@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 hours ago

      There is absolutely nothing preventing them from hiring a firm to develop a feature in FOSS. Hell, they can even keep it proprietary if they wanted to.

      • Hasnep@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 hours ago

        they can even keep it proprietary if they wanted to.

        Yes, with the caveat that it would have to be an internal piece of software, or if it’s a public facing tool then it would have to be under a non-copyleft licence. But yeah, for 99% of use cases they could have a proprietary fork.

    • Aceticon@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 hours ago

      The problem you point out has been known in the Linux community for literally decades and is the reason why Red Hat Linux was created and any company can, right know, get an Enterprise version of it with an Enterprise support contract.

      That said, over the years I worked in seriously large multinational companies which used Linux and other open source products like Apache extensively on the server side (pretty much all such machines had it) so at least on the server side things did change massively from back in the day when companies would get Sun servers with SunOS or IBM server with Minix rather than generic server PCs with Linux due to that rationale you stated.

      In fact, it has also become a common thing in much smaller companies, though maybe not the small and micro-sized ones.

      The reality on the ground at least on the server side and for infrastructure software is that companies did find a way to deal with the problem of not being able to get support contracts from many of the OSS apps makers, and did so either by just paying some company specialized in supporting it or by having their own developers - after all, it’s exactly the thing with OSS that any developer can change it hence you’re not limited to paying for support from a specific company that makes the software.

    • Flipper@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      12 hours ago

      How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs?

      No you dont expect free labour and pay them.