←back to thread

1124 points CrankyBear | 3 comments | | HN request time: 0.53s | source
1. honktown ◴[] No.45894806[source]
It'd be a silly license or condition, but, a license that says employees of companies in the S&P500 cant file bugs without an $X contribution, and cant expect a response in under Y days without a larger one, would be a funny way to combat it. Companies have no problem making software non-free or AGPL when it becomes inconvenient so maybe they can put up or shut up.
replies(2): >>45895519 #>>45896064 #
2. tpmoney ◴[] No.45895519[source]
Where in this bug report was there any expectation for a response? They filed a private bug report and have a policy of making private reports public in 90 days whether or not they get a response. How did the OSS world go from "with enough eyes all bugs are shallow" to "filing a bug report is demanding I respond to you"?
3. Aurornis ◴[] No.45896064[source]
> cant file bugs without an $X contribution, and cant expect a response in under Y days

A license to define that nobody can expect a response? Or file bugs?

None of this has anything to do with the issue. They can just turn off Google’s access to the bug tracker. No license needed.

However Google is free to publish security research they find.

It would be most concerning if projects started including “Nobody is allowed to do security research on this project” licenses. Who would benefit from that?