Feedback 2023/12/11
As I am going through the course, I'll be posting in this thread things that you may want consider fixing. Each issue will be in a separate reply, so that it would be easier to link to them.
The text:
Open source isn’t going away. As noted in "The State of Enterprise Open Source: A Red Hat report", open source software is more flexible, higher quality and has better security than commercial alternatives.
Another key benefit of open source is that it prevents vendor lock-in. This is where a software vendor can either force upgrades or charge license fees that increase over time against their customers’ wishes. As we will see, this practice is incompatible with the license that open source software is provided under.
Is present on both these pages:
Likely the page was split or merged - in any case you probably want to remove the duplication.
0 -
Regarding the copyright, it is a good idea to clarify this statement:
NOTE: When working as an employee for a firm, your firm holds the copyright to anything you write, including software.
Without any explicit arrangement, the firm only owns what you produce as part of the employment engagement, or using the firm's resources (hardware, tools, services, premises). You own the copyright of anything you do on your personal time without using firm's resources.
Some employment contracts lay broader claims, as in "the firm owns everything you produce and you cannot share without explicit authorization". In such firms, an OSS contribution policy constitutes such authorization (as long as you comply to its stipulations).
0 -
It may be worth adding a sentence or two, stating what does it mean for code to be in the public domain, and how does it differ from the permissive license. Even better a table summarizing the key differences between the four types of licenses (including proprietary).
I believe that it is an open question if an author can disclaim their responsibilities (regarding licensing, high tech export regulations) by putting a work in public domain.
I would love if we can start phasing out the cutesy "copyleft" and "viral" monikers and use the descriptive "reciprocal licenses".
0 -
General comment:
So far - pages are chunked at way too small pieces. I find myself losing context, and getting distracted, looking where to click instead of focusing on the material.
Scrolling is not necessarily bad.
This page is offensively clicky - opening all the boxes to reveal one sentence feels like jumping through hoops.
0 -
On OSS Criteria:
The program must include source code, or some easy way to get hold of it.
It is worth getting a bit more specific as that is very relevant to corporate OSS - reciprocal licenses require the _final modified source code _to be available to any user; permissive licenses require the upstream code that is being built on to be acknowledged and linked; public domain does not require any of these (and technically does not classify as OSS).
Furthermore, it is important to note that licenses require that code is offered to users of the software - hence if one reuses even a strong reciprocal license such as AGPL, but keeps the usage in the firm, there will be no external obligations.
0 -
A good way to engage with OSS is to start participating in the user community, first by asking good questions (insert your favorite guide here), then by providing answers, helping new users, initiating discussions about requirements and new features.
0 -
It is worth mentioning that Eclipse now hosts the Adoptium project, coordinating the activities of the the various Java builders and their artifacts, as well as Temurin - a vanilla OpenJDK runtime: -
Which type of open source license allows the end user to redistribute the software with their own license?
Technically both PD and Permissive licenses allow for relicensing.
The quiz results bar chart render misses the last question
0 -
The linked ISO 27001 standard costs 124 CHF - I doubt anybody will be willing to spend this kind of money just to check the reference material. A summary would be very useful, as well as guidance in which cases is it worth reading the primary source.
0 -
As OSS contribution can be done both in firm's capacity and in personal capacity, do we really need to be on record when not using our firm's identity? Can we have more detailed reasoning if that is the case?
When I hack something on a Sunday afternoon and put it on Github, do I need to ask my OSPO? How about if it is a private project? How about if it is an issue comment? Support comment? Tweet?
I know it is common sense, but this pages in their current form can be misinterpreted, and it is critical to draw good boundaries.
0 -
Quiz 2:
What is the term used to describe communication related to a financial firm's products, services, investments, or other business matters?
From an open source perspective, what’s the difference between public information and classified information?
This was probably in the 124CHF document, but I cannot meaningfully make a difference between "Internal", "Restricted" and "Firm business" - this doesn't line up with my company classification.
I'd rather have a question about what I should and should not do, over "what name did we give to..."
0 -
It would be useful to show few supply chains to emphasize that it is a concept, not a fixed set of stages and processes.
Besides the provided "server application", few more illustrations would be "library", "mobile application", "pacemaker firmware", or "package in Linux distribution".
0 -
One more criteria:
- Value of reused functionality vs. maintenance/coupling/complexity cost of added dependencies
0 -
It could cause your firm serious reputational damage if it were found that a member of staff had committed code that had somehow aided terrorism.
This is vague example for what is OK and what not OK would be appreciated.
Many of the terrorists use Android phones and end-to-end encrypted messaging (Whatsapp, Telegram, etc) - does that reflect poorly on those projects?
0 -
SVB is no more, and has somewhat negative associations - perhaps we can have a different example?
0 -
The quiz of section 7 was funny, but not useful. Most of the answers were obviously false, and as such it did not add value. If we cannot come up with useful questions, perhaps it is better to remove the quiz, of fold the "escalation" section in the "regulatory landscape"
0 -
This is a weird way to ask a question:
Popularity, community support, documentation, code quality, security and vulnerability management should be considered when selecting software components in addition to:
Pretty much all answers are correct to an extent and one has to guess what is intended.
Similar with:
Requiring approval before submitting personal OSS contributions is necessary to prevent:
The following sentence is hard to parse. (What risk? In what way does it challenge? What are "traditional ways"?)
A new technology has created risks regarding data leakage and challenges the traditional ways of contributing to an open source project involving this technology. What is the suggested action to manage these new scenarios?
0 -
Surveymonkey is blocked by my corporate proxy:
0 -
Bottom line, very good as scope and content.
If I could change one thing, it would be to reduce the number of "slides" - as a guideline, 150-200 words per screen is a good amount. If I have to click "Next" for every sentence, I'm losing context.
Another minor pick is that it would be nice to make sure to minimize the number of questions requiring to memorize nomenclatures, especially when speaking of taxonomies that may vary between companies.
- All Categories
- 232 LFX Mentorship
- 232 LFX Mentorship: Linux Kernel
- 812 Linux Foundation IT Professional Programs
- 365 Cloud Engineer IT Professional Program
- 183 Advanced Cloud Engineer IT Professional Program
- 82 DevOps Engineer IT Professional Program
- 151 Cloud Native Developer IT Professional Program
- 140 Express Training Courses & Microlearning
- 140 Express Courses - Discussion Forum
- Microlearning - Discussion Forum
- 6.4K Training Courses
- 48 LFC110 Class Forum - Discontinued
- 71 LFC131 Class Forum
- 47 LFD102 Class Forum
- 229 LFD103 Class Forum
- 20 LFD110 Class Forum
- 44 LFD121 Class Forum
- LFD125 Class Forum
- 18 LFD133 Class Forum
- 8 LFD134 Class Forum
- 18 LFD137 Class Forum
- 71 LFD201 Class Forum
- 5 LFD210 Class Forum
- 5 LFD210-CN Class Forum
- 2 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum - Discontinued
- 2 LFD233 Class Forum
- 4 LFD237 Class Forum
- 24 LFD254 Class Forum
- 712 LFD259 Class Forum
- 111 LFD272 Class Forum - Discontinued
- 4 LFD272-JP クラス フォーラム
- 13 LFD273 Class Forum
- 200 LFS101 Class Forum
- 1 LFS111 Class Forum
- 3 LFS112 Class Forum
- 3 LFS116 Class Forum
- 7 LFS118 Class Forum
- LFS120 Class Forum
- 9 LFS142 Class Forum
- 8 LFS144 Class Forum
- 4 LFS145 Class Forum
- 3 LFS146 Class Forum
- 15 LFS148 Class Forum
- 15 LFS151 Class Forum
- 5 LFS157 Class Forum
- 49 LFS158 Class Forum
- LFS158-JP クラス フォーラム
- 10 LFS162 Class Forum
- 2 LFS166 Class Forum
- 5 LFS167 Class Forum
- 3 LFS170 Class Forum
- 2 LFS171 Class Forum
- 3 LFS178 Class Forum
- 3 LFS180 Class Forum
- 2 LFS182 Class Forum
- 5 LFS183 Class Forum
- 33 LFS200 Class Forum
- 737 LFS201 Class Forum - Discontinued
- 3 LFS201-JP クラス フォーラム - Discontinued
- 19 LFS203 Class Forum
- 135 LFS207 Class Forum
- 2 LFS207-DE-Klassenforum
- 2 LFS207-JP クラス フォーラム
- 302 LFS211 Class Forum
- 56 LFS216 Class Forum
- 52 LFS241 Class Forum
- 50 LFS242 Class Forum
- 38 LFS243 Class Forum
- 16 LFS244 Class Forum
- 5 LFS245 Class Forum
- LFS246 Class Forum
- LFS248 Class Forum
- 54 LFS250 Class Forum
- 2 LFS250-JP クラス フォーラム
- 1 LFS251 Class Forum
- 156 LFS253 Class Forum
- 1 LFS254 Class Forum
- 1 LFS255 Class Forum
- 10 LFS256 Class Forum
- 1 LFS257 Class Forum
- 1.3K LFS258 Class Forum
- 11 LFS258-JP クラス フォーラム
- 134 LFS260 Class Forum
- 160 LFS261 Class Forum
- 43 LFS262 Class Forum
- 82 LFS263 Class Forum - Discontinued
- 15 LFS264 Class Forum - Discontinued
- 11 LFS266 Class Forum - Discontinued
- 24 LFS267 Class Forum
- 25 LFS268 Class Forum
- 32 LFS269 Class Forum
- 6 LFS270 Class Forum
- 202 LFS272 Class Forum - Discontinued
- 2 LFS272-JP クラス フォーラム
- 4 LFS147 Class Forum
- 1 LFS274 Class Forum
- 4 LFS281 Class Forum
- 15 LFW111 Class Forum
- 262 LFW211 Class Forum
- 184 LFW212 Class Forum
- 15 SKF100 Class Forum
- 1 SKF200 Class Forum
- 2 SKF201 Class Forum
- 797 Hardware
- 199 Drivers
- 68 I/O Devices
- 37 Monitors
- 104 Multimedia
- 174 Networking
- 91 Printers & Scanners
- 85 Storage
- 759 Linux Distributions
- 82 Debian
- 67 Fedora
- 17 Linux Mint
- 13 Mageia
- 23 openSUSE
- 148 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 354 Ubuntu
- 470 Linux System Administration
- 39 Cloud Computing
- 71 Command Line/Scripting
- Github systems admin projects
- 95 Linux Security
- 78 Network Management
- 102 System Management
- 47 Web Management
- 69 Mobile Computing
- 18 Android
- 38 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 377 Off Topic
- 115 Introductions
- 175 Small Talk
- 26 Study Material
- 807 Programming and Development
- 304 Kernel Development
- 485 Software Development
- 1.8K Software
- 263 Applications
- 183 Command Line
- 3 Compiling/Installing
- 988 Games
- 317 Installation
- 103 All In Program
- 103 All In Forum
Upcoming Training
August 20, 2018
Kubernetes Administration (LFS458)
August 20, 2018
Linux System Administration (LFS301)
August 27, 2018
Open Source Virtualization (LFS462)
August 27, 2018
Linux Kernel Debugging and Security (LFD440)