Email or username:

Password:

Forgot your password?
Top-level
Matthew Lyon

congrats everyone, you’ve convinced me that github is as harmful to free software efforts as discord, surprising even me

Github has created and captured an enormous amount of value for themselves on the backs of other people’s labor, and once you see this it’s hard to look at the “software supply chain” thing and not see it as an attempt to protect their assets

8 comments
Jenniferplusplus

@mattly yeah 😞

But it's hard to do anything about that due to network effects. Assuming you want other people to contribute to a project

Matthew Lyon

the site basically enlisted everyone who used it into helping it become critical societal infrastructure, in the same way that Amber Alerts now include t.co links to x dot com accounts that require you to be signed in in order to read

and it was us who helped it get there, simply by participating

Matthew Lyon

look, I get why y’all like the “supply chain” rhetoric, it helps you continue pretending that software security can be solved through capitalistic means

here’s the thing: I’ve run a manufacturing business before. I’m getting a second one going. Supply Chains are defined by an exchange of money for goods, with value-add steps in between. That’s it

Where’s the money, Lebowski?

Software packaging security is a social trust problem, which can’t actually be “solved” in a capitalist framework

Urja

@mattly I agree with what you said, but after boosting it, decided that I want to do a little "Yes, and...".

As in, yes, and as long as we live in a capitalistic society, for people to be able to be trustworthy, they need to be able to eat. Thus I see why some people are trying to solve the money issue - but github forcing 2FA is not really helping with the money, so ehh.

Matthew Lyon

@urja I mean, I’ve long since given up on trying to encapsulate a nuanced opinion in 500 characters

Irenes (many)

@mattly yeah. glad to hear you got there! we do see a lot of reason to be hopeful that people are moving towards consensus that this corporate enclosure stuff really is a problem.

yes, it's me, liza 🇵🇷 🦛 🦦

@mattly they got bought by Microsoft which basically bought OpenAI (although that's not what their PR want us to believe).

MS also bought LinkedIn and gave and is now the default search engine for DuckDuckGo.

you see where they are going given their "investment" in OpenAI.

Go Up