|
|
|
|
|
by glangdale
2684 days ago
|
|
You seem to know a surprising amount about (a) the significance of a regex library to security companies and (b) the business reasons for open sourcing it. Perhaps you were there at Intel, or one of our customers, and I just don't recognize your Hacker News id? To fill in: many security products put almost every packet on the wire past our library, sometimes multiple times. This wasn't a product used to, I dunno, validate user fields or something. Companies used to build hardware to do this, many of which are now pushing up the daisies (I like to think in part due to our work), and we got quite a nice acquisition out of it (while still open source). I actually expected $0 from open sourcing it and was not surprised - the business reasons had absolutely nothing to do with direct revenue (which honestly would have been an enormous hassle to collect). I was still wowed at how standoffish a lot of our customers were (to the point of having 'secret' customers we found with detective work). My real complaint wasn't about money, it was about companies giving pretty much zero recognition to OSS groups at other companies upon use of their s/w - they shouldn't be surprised when, as a result, the infrastructure they depend on rots away. But hey, they can "figure stuff out themselves". Maybe... |
|
That’s not a statement of moral or ethical anything, just a impartial statement of a basic generalized truth.