GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 09-Dec-2025 02:07:35 JST Filippo Valsorda Filippo Valsorda

    When I talk about professionalizing open source maintenance, and about the Geomys Standard of Care, this is what it is about.

    The solution is neither gatekeeping nor blanket legal liability nor making demands of volunteers. The solution is relying on, and funding, professionals.

    https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661/165

    In conversation about 3 months ago from abyssdomain.expert permalink

    Attachments


    1. https://cdn.masto.host/abyssdomainexpert/media_attachments/files/115/684/878/371/657/298/original/915f8383cb7f2677.jpeg
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 02:07:33 JST Rich Felker Rich Felker
      in reply to

      @filippo Holy shit, WTF? Maintainer just handing over control/keys to a rando who volunteers to maintain it, putting everyone who trusted them in danger?? If you don't want to maintain it, delete your keys, tell users that, and let them make a choice to switch to a new maintainer's fork.

      In conversation about 3 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 02:08:43 JST Rich Felker Rich Felker
      in reply to

      @filippo I disagree strongly with "professionals" being the solution tho. It's completely reasonable to use a program someone makes as a hobby or labor of love.

      The crime here is Google making an automated-update system users are pressured or forced into where ownership of the project can be transfered and updates pushed to users by the new owner.

      In conversation about 3 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 02:17:16 JST Rich Felker Rich Felker
      in reply to

      @filippo A responsible walled garden app store policy would include in its developer ToS a clause that you cannot transfer ownership without long-term advance notice to users which has to be submitted to the app store, displayed to the user as a prominent warning, and disable further updates unless the user opts in to continuing with the new owner.

      Attempt to transfer secretly without following this procedure should result in termination of developer account, and removal (along with marking as malware) of any versions published after the transfer.

      In conversation about 3 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 02:29:35 JST Rich Felker Rich Felker
      in reply to

      @filippo They won't do this, and the reason they won't is that the "freedom" to transfer ownership of anything without the permission of anyone affected by it is a CORE TENET OF CAPITALISM and part of what makes their whole platform valuable.

      The vast majority of parties publishing junk in the walled garden app stores are doing it with the intent to build a big userbase then cash out selling it to someone who's going to use it to do harm to said userbase.

      In conversation about 3 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 03:04:48 JST Rich Felker Rich Felker
      in reply to
      • Pozorvlak

      @pozorvlak @filippo There is really no such urgency for the vast, vast majority of things. It can still go through the same type of procedure marking that ownership is transferring in the app store and switching updates to manual.

      In conversation about 3 months ago permalink
    • Embed this notice
      Pozorvlak (pozorvlak@mathstodon.xyz)'s status on Tuesday, 09-Dec-2025 03:04:49 JST Pozorvlak Pozorvlak
      in reply to
      • Rich Felker

      @dalias @filippo you need a procedure for transferring ownership in the event of the sudden death or incapacitation of the original maintainer.

      In conversation about 3 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 09-Dec-2025 04:15:09 JST Rich Felker Rich Felker
      in reply to
      • Pozorvlak

      @pozorvlak @filippo No, the vast majority actually cannot. Any app that's only dealing with local data has no attack surface. An app that's just a frontend to a particular cloud service and that isn't e2ee has no attack surface except from the cloud service provider (usually the same as the app provider). Only things like browsers, email clients, e2ee chat, etc. have *any urgency whatsoever* to get updates.

      In conversation about 3 months ago permalink
    • Embed this notice
      Pozorvlak (pozorvlak@mathstodon.xyz)'s status on Tuesday, 09-Dec-2025 04:15:11 JST Pozorvlak Pozorvlak
      in reply to
      • Rich Felker

      @dalias @filippo on the contrary, nearly any app can need security updates applied in a hurry.

      In conversation about 3 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.