Since this regulation is happening, necessary and welcome, it's good
to see some of the most respected FOSS groups taking the
lead. Hopefully many others representing smaller development
communities will join the Eclipse initiative. I would characterise
"Apache Software Foundation, Blender Foundation, OpenSSL Software
Foundation, PHP Foundation, Python Software Foundation, Rust
Foundation, and Eclipse Foundation" as BigFOSS. :) Joe Hacker
also needs a seat at this table.
> establishment of common specifications for secure software
> development based on existing open source best practices.
The problem with "best practices" is that there are always better
practices. Hopefully this group don't ossify around "best practices"
that are already out of date but become research focused. To be blunt,
a problem is not that "best practices" are never followed, but that we
have about 30 years of technical security debt to catch up with.
This foundation is also going to be a money pit, because it needs to
help other developers. It cannot rule, dictate or enforce anything.
Since most European devs are going to want to join in, it's going to
be paying out for conferences, education, development grants and
T-shirts. It'll need a pipeline of money from EU and commerce - and
there's the danger of corruption.
Whether they'd have something to contribute with their resources is a completely different question.
A bit of a tangent: FSF has a separate legal entity within the EU (https://fsfe.org/) which is (IMHO) way better at advocating than its American counterpart. There's also FSFI (India) and FSFLA (Latin America), but I'm unfamiliar with their work.
> I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as BigFOSS
While names cited are associated to long-standing well-recognized projects, it strikes me at odd to include Rust Foundation here. Not only the language itself is still relatively new and used in few real life projects, but the foundation is very new (2021).
Moreover, looking at its last annual report, it spent half of it's budget (1.5M$) on "membership & admin". It seems like the true action of this foundation is to beg money from big corps and give it to a few selected members.
Here's[0] a breakdown from the foundation on that budget category. They also commit to breaking it down better in the future:
Salaries, benefits, payroll taxes, payroll service provider fees: $1.17m
Travel, event sponsorship, & support: $192k
Legal and Professional Fees: $66k
Fund transfer to the Grants Program from membership fees: $40k
Fund transfer to the Specification work from membership fees: $20k
Marketing: $36k
General Admin: (software, bank fees, meeting rooms, etc.) $20k
It's mostly salaries. They employ four engineers (software, security, infrastructure) that work on Rust, who they pay "at or above the average in their local market."
> establishment of common specifications for secure software > development based on existing open source best practices.
The problem with "best practices" is that there are always better practices. Hopefully this group don't ossify around "best practices" that are already out of date but become research focused. To be blunt, a problem is not that "best practices" are never followed, but that we have about 30 years of technical security debt to catch up with.
This foundation is also going to be a money pit, because it needs to help other developers. It cannot rule, dictate or enforce anything. Since most European devs are going to want to join in, it's going to be paying out for conferences, education, development grants and T-shirts. It'll need a pipeline of money from EU and commerce - and there's the danger of corruption.