What's you point? That if you had run your own DC in that region (because that was your business requirement) then you'd have better missile defense than AWS?
Or maybe AWS or DIY, you are always responsible for geographic diversity?
Anyone losing data over this lost it because they'd literally told AWS to only store it in one place.
You don't need better missile defense than AWS. You don't need missile defense at all because you won't be a target. 99.999999% of the land has no missile threat on it. You are actively increasing the threat to your business by running it on the same servers that military contractors run their software on.
> You don't need missile defense at all because you won't be a target.
No, you don't need it because you have offsite backups. And this is completely disconnected from whether you use AWS or DIY.
> you won't be a target.
Of missiles, maybe in this particular conflict, sure. But running a DC is not your core business, so which DC is more likely to be subject to burglary, power outages, diesel shortages (Amazon will have better negotiators than you), fire suppression, hell, private fire departments if needed, etc…
Was missiles or copper thieves the biggest threat, even there, in 2020? Would AWS or every small company be better at protecting against the latter?
I feel like this is hindsight bias, and in a different scenario you'd be saying "not hosting your infrastructure in a DC without AWS level diesel backup contracts is even better".
Which I already said, and you ignored.
Anyway, it's all moot, because the military will now also spread out.
You can go with "Joe's pizza and cloud services", hoping there aren't enough military workloads there, but where are you more likely to have an outage?
> In a war where schools and bridges and aid convoys and bread lines are targeted
Yes but that's clearly not this war. This is a missile war where high-value strategic military targets are the priority. The US and Israel hit some prisons, damaged some hospitals, and ofc killed 168 schoolchildren. They also targeted residential areas to assassinate important leaders. But Iran has not returned that. They've stuck pretty strictly to military targets with very few exceptions
If this was a war where bridges were a target, Iran would not be so successful. There's simply a too limited amount of missiles. Also only 20% of Saudi Arabia has citizenship while almost the whole rest is basically indentured servants. It's not like they could provoke a popular uprising or anything. There's no strategic value in hitting "bread lines"
What CARVER score would you give an AWS data center? I would probably put it around the 40 to 50s. Where would you put your own individual company by itself on the CARVER matrix as it relates to enemy forces? Pretty damn low.
Which is why your job as a responsible company you should have verified your offsite backups on 28th Feb.
Just like you would if wildfires started breaking new records in Oregon, if that's where your (for some reason sole) cloud region is.
It should already be set up, of course, but from a data point of view this is when you're thankful that at least this raised risk came with a heads up.
An American-run data center is much more likely to be targeted than some locally-owned and run company that isn't obviously connected to a foriegn power or the state that hosts it.
The point is that AWS has the same problem as Wildberries.
There is no difference at all between Wildberries and AWS data centers.
If you don't know what Wildberries is then go watch their facilities systematically destroyed on YouTube - centralisation is a target.
If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones. Is that on your risk management plan?
> If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones.
If your organization runs on servers in your basement you should have a contingency plan for flooding, fire, copper thieves, diesel shortages, etc… etc… etc…
Or are you basically saying that the only safe place is outsourcing your ops to a mid sized operator? Too small and nobody will pay for the every day risks. Too big and it's a war target? Ok, let's continue that plan. Now military users move their workloads to the mid sized operators for the exact same reason you did. Oh no, we're back at square 1.
A plan of putting all your eggs in one basket is never good. And it's completely orthogonal to AWS vs the non-AWS options.
Pretty basic stuff.
> If you don't know what Wildberries is
Not exactly esoteric knowledge. But it's also not the same thing. Wildberries could not "back up" their inventory to an offsite location with the footprint of a suitcase.
> If your organization runs on AWS then you should have a contingency plan for the data center being destroyed by drones. Is that on your risk management plan?
Sure, if you discard ALL other risks, that happen every day, leaving only war as the remaining risk to manage, then your risk management plan makes sense.
But the other risks are still there. Your DC operator going bankrupt and having their power cut is a risk that didn't go away.
Sure. But given that the affected customers would by definition not have offsite backup, the comparison is against a smaller operator that has way more risk of fires, theft, bankruptcy, incompetence, earthquakes, power delivery, and all the other risks.
Sure, fewer customers per location, but the critique here is of customers who chose AWS, the fair comparison is NOT against those who chose to be in 6 different non-AWS DCs, but against those who chose to be in ONE non-AWS DC. Decentralized aggregated across customers or not, the customers who chose unluckily still lose data.
How about not bombing other countries and then acting surprised when retaliation happens? I mean clearly the problem isn't AWS as such - it is the problem that someone leading a country is totally clueless about the world. Only personal profit is in the interest of the orange clown.
I get your main point, but just wanna point out that AWS is one of the largest military contractors in the world. They hold multi-billion dollar contracts from the DoD, USAF, CIA, and more. An estimated $4B a year in military spending goes to AWS
As someone who did train one of the traditional martial arts for a few years, I appreciate the comparison.
I don't know how much weight your "just" is meant to carry, but I remember a culture of cope and excuses about why "my" flavor wasn't the winner of any MMA event.
But at least I got some exercise, strength, and flexibility out of it.
I think it's an interesting analogy, not to be dismissed so easily.
I don't see him saying the point is volume of code. I see AI generating code, and if I question it, it can justify design choices pretty well. I can give it bug symptoms, and it can find and fix the bug. Usually.
But yes, the analogy breaks down in the fact that I understand what it's saying and understand when it's wrong, because I learned it in the first place.
Or maybe it doesn't break down completely. If an MMA (AI) tells me to move in a way where I know I'll lose my balance, or over extend, I will say no, because of my previously acquired experience.
In a rug pull, the thing you own (usually some kind of digital asset) goes down in value, leaving you with less money than you started with, whereas theft leaves you no longer possessing the asset itself.
A few extra steps. Usually, the rug pull doesn't involve directly taking something that belongs to other people, but instead, selling your own thing in a dishonest way.
Do we really need the latest kernel on them, though? As in, is it worth it?
In 100 years, if we need to run kernel 6.12 to use a 3c509, is that all that bad? It's not like being "stuck" on an old IRIX without the proprietary dev CD where you have a catch 22 problem.
An old system version that's completely open is whatever the sysadmin version of "turning complete".
Sure, port the open system to the hardware that does not have an open system. But I question the value of keeping it up to date.
All else being equal, sure it'd be cool. But all else is not equal. So yes, ripping out old code is the right move for Linux, in my opinion.
The other open question is, will there still be operational 3c509s 100 years from now?
Another way I put it, with a heavy sigh, is: "There will come a day—and odds are, it's not far off now—when the last working real Amiga will stop working for the last time."
Did you read my comment or you just reply for the sake of it?
I release the code so that people and companies that feel like contributing to the community can use it. Companies that want to take without giving back however are mildly inconvenienced by copyleft.
> I chose to do it for free to help other people. And picking a MIT license does the opposite.
I have no idea what this is supposed to mean. I want to help other people, then giving them the means to do what they want with no real restrictions is "the opposite" of that?
> Companies that want to take without giving back
So this is not about helping anyone else, but about mandating a behavior, even if that behavior is "pay it forward".
Distributing (however defined by a given license) unmodified software that is presumably widely available to customers may be a requirement but is also a profoundly uninteresting legal requirement.
I don't think we're disagreeing about anything. I wasn't giving a legal opinion but lawyers, especially at large firms, are a lot more conservative about some matters than I might be for a personal project. If you have deep pockets and provide any path to those pockets, someone could sue you.
I used to work for a very open source-friendly company and, while AGPL wasn't broadly verbotten and I can't quote any publicly available documents, its use was not encouraged in general. (And outside of Linux which was what it was, permissive licenses became much more common for new projects.)
Which could make the business untenable. I'm not GP commenter, but I do want to be useful to these too.
And as others have said the deceptive term of "plugging the SaaS loophole" ignores that it means most software cannot be combined with it. Most. By far most.
Sure, some people will say "well fuck that software". And that's a stance. But it ain't freedom.
One problem is that people (mostly--we'll ignore the various edge cases) know what traditional *nix-style distribution looks like. No one knows what network interactions resolve to if someone with deep pockets and/or a grudge wants to file a lawsuit. So better to just run away.
Use an AGPL license if you like but--and I'm not even a lawyer--but I'll probably just walk away. Your software is probably not that interesting to compensate for any risk.
Yup. As I said in another comment "I treat AGPL as a rabies infected animal. I may have uses for it, but I'll keep it EXTREMELY segregated from everything else".
Indeed, keeping track of every shader/asset/texture under CC BY-SA 4.0 was a nonstarter.
For media, 3D files, game FX, and icons it is only CC0 Public Domain projects we recommend to folks having fun. Keeping track of every Copyright and Copyleft trolls content demands is just too much work for small hobbies. =3
We also financially support people clearing barriers for future artists and creatives (clean Blender resources.)
One of the problems we found was people reselling other peoples pirated works, or plug-ins for features already in Blender for free. Cons will always con regardless of community intentions. Make something fun and beautiful instead =3
There can be issues with public domain in Europe (moral rights you can't disclaim yada-yada in some non-common law countries). And, as I distantly recall, there were some issues with CC0 related to patents. MIT-0 would probably be my choice absent deep legal research into the topic (though I have discussed public domain as related to software with IP lawyers as related to a book I wrote).
Trademarks are still a possible liability, which is why film sets use gaffers tape or stickers to cover equipment logos and branding. The photo can be CC0, but the coca-cola logo is still owned by a company.
Patent claim sections are the only legal part at the end of the document, and may only cover functional or process facets of an innovation. Software patents are also only valid in certain jurisdictions.
Generally speaking, if something has been time-stamped in the public domain you can challenge a patent for $2k. Since a global patent is around $240k to $600k each, most people would not want to take that bet with archive.org active.
The Patent first-to-file changes under the US system may have altered the 17 organizations disclosure limit rules, but as far back as I can recall any patented technology older than 19 years is almost certainly public domain. =3
Yes, especially in an actual commercial context (e.g. an ad on a billboard) companies are or should be very careful. I've had panicked last minute emails from organizations where some CC photo of mine was being slated to be used. I've said yes of course as they were usually some form of worthwhile charitable organization.
I did even get a check once from a magazine but it was Canadian so that was very cute. (Sorry to any Canadians in the audience.)
But there are a lot of, often unclear, rules related to publicity and model rights that are by no means clear across geographies. Even leaving aside Eiffel Tower light displays, I'm sure a lot of the photos I've taken in Europe and put up on Flickr or Facebook could be an issue if someone really wanted to pursue it. Organizations do often have disclaimers as part of event registrations as well but they're pretty pro-forma and a lawyer could probably argue that there was no meeting of the minds in any contract.
Do you have data on that last bit, or just a guess? As a hobbyist and OSS developer I treat AGPL as a rabies infected animal. I may have uses for it, but I'll keep it EXTREMELY segregated from everything else.
This means you have only solved the problem for large companies, and specifically those who have money and who have a functioning procurement system that's developer-driven. Which is a very narrow use case.
Again, that only works for large companies, and for companies that can exists even if their service is downloadable.
Which fine, you can choose to take that political stance. But that's a stance of "I want to change the world to my liking", not "I want to help the world/people".
Up to you, of course, but I prefer to help not only large companies.
Sure, but for anything except large companies it has a bootstrapping problem. I'm absolutely not going to use AGPL software in a test one-person trying to sell a service kind of deal. So if it takes off, I'm already on a non-AGPL stack, so why reach out at that point to get a commercial license for software I don't even use?
And hell, even without money involved, I'm not going to make a hobby project with AGPL software either. Not only may I have small parts of the project I've not opensourced, but AGPL is untested in how far the virality goes. Are my backup cronjobs in scope? I certainly don't want to be the test case for this. Even if I win against an AGPL troll, I'll still lose.
Or maybe AWS or DIY, you are always responsible for geographic diversity?
Anyone losing data over this lost it because they'd literally told AWS to only store it in one place.
reply