Hacker News new | ask | show | jobs
by Macha 34 days ago
> Did you have other plans for the weekend? Or a long term project you’re prioritizing? That’s nice, you have a new plan — fix every vulnerability that comes in NOW.

Or you know, provide the security companies and businesses using your software for free with all the fix timelines and out of hours support they’ve paid for (none).

2 comments

Yeah ... this gets into the question of what exactly an OSS creator's responsibility is towards users that don't pay them.

In theory, nothing.

In practice, it's in our long term interest that bad things don't happen to them.

How sustainable all of this is, I have my doubts?

It's not for the benefit of the security company though. In fact they get zero benefit from it. It's for the benefit of the users of the software which makes the calculus more complicated.