• sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    You don’t need a public repo to be FOSS. You don’t need to accept changes. All you need is to provide a copy of the source code upon request. You can even automate that with a link to a tarball or something in the app.

    My concern is less about privacy and more about security and longevity (i.e. what happens if they turn evil?). If it’s FOSS, I can audit the source and fork it if they go in a direction I don’t like. If it’s proprietary, I’m SOL if they turn evil or stop development. Projects like these tend to die.

    I don’t really see any negatives here. The chance that someone makes a more popular fork is incredibly low, and the chance that someone audits it and points out a bug is a lot higher. They can retain control of the name, sell the software, etc. I really don’t see how providing source code is a downside.

    • prof@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      I guess we just have to agree to disagree then. Which is fine.

      Your points are valid and thank you for detailing them for me. If I was in their shoes making others able to steal my IP, even if they’re not allowed due to licensing and having to deal with constant scrutiny of the source code are k.o.-criteria, which hinder the project and lead to potential revenue loss.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        And it’s totally fair to run your project however you choose. My point is just that FOSS doesn’t automatically mean you can’t make money, tons of businesses are built on a FOSS-first basis. Pick the model that works for your business, and I sincerely hope you find a way to make FOSS part of it.

        • prof@infosec.pub
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          As I’ve said. Nextcloud is a great example of FOSS working out for a business, haha.