Working together and gaining trust
Alexandre Oliva
oliva@gnu.org
Thu Feb 19 02:48:24 GMT 2026
On Feb 18, 2026, Siddhesh Poyarekar <siddhesh@gotplt.org> wrote:
> potential threats posed by SaaSS are more dependent on the parties
> involved
No, no, the reasons to retain our software freedom are the same
regardless of what means would be used to take it away, or by whom.
It's a very common misconception that third parties that are friendly
now will remain friendly, or that hostile ones will remain hostile, but
that's not how things work. Such alignments change, and that's why
keeping freedom is important: ceding control over ourselves to a hostile
party is immediately perceivable as foolish, but ceding control over
ourselves to a friendly party doesn't seem foolish immediately, it only
reveals itself as such later, when the alignment between us and the
friendly party changes, whether that's because they changed or because
we did.
And none of this has to do with SaaSS specifically. If you install a
piece of nonfree software for use on your own computer, particularly of
the modern kind that calls home and auto-updates, it may also seem like
relying on a friendly supplier is less problem-prone than on a hostile
one, but once you've given control to the third party (through the
installed software, the information it collects and the universal
backdoor in its auto-update machinery), that control will make the
supplier a more attractive target for hostile take-overs, for corrupting
and enshittifying forces.
>> Now, let's not be dishonest, please.
>> The definition has been set in stone for far more than a decade.
> The core idea of SaaSS may well be, but the idea itself in practice
> greatly depends on a number of factors involved as you've seen
> yourself in the discussions you've had in this thread.
I suppose you mean the deal of determining whose computing a program or
service does, and whom it pertains to. Yeah, it's not as immediately
obvious as when you do your computing on your own computers.
But that's not a reason to go recklessly doing your computing on others'
computers. Quite the opposite: when it doubt, strive to do it on your
own computer. If that proves to be impossible, because it involves
other parties, that may very well be a symptom that it's not your
computing.
> The difference I observe is the varying standards applied to
> definition of user freedom commitment based on the parties involved
Then we have to do some work on that misperception.
I guess my vocal dislike for the LF, and your favor to it, contribute to
bringing noise to your observation.
I suppose a mispresumption that I'm favorable to the Sourceware
arrangements, or aligned with those who favor Sourceware, contribute as
well.
Your being on the 'for' side can make it seem like everyone who's
'against' is a single block acting in unison. That's a misassumption
that can further twist perceptions and observations.
My primary concern is to ensure we don't take steps that undermine our
freedoms. As long as we do that, and more importantly, as long as the
community knows what to avoid to keep our freedom, there's very little
reason for me (or anyone) to be concerned about who offers us services.
But while a far-from-negligible fraction of the community takes an
ignorant, dismissive and even at times hostile attitude to taking
precautions to defend our freedoms from certain common lines of attack,
and seemingly insist on taking steps before as much as understanding
what, erhm, landmines (to keep with the analogy of steps) are, let alone
seeking assurance that there aren't any at the desired destination or on
the path towards it, I can't help feeling and raising concerns about it.
> This is also why your perception of SaaSS w.r.t. involved
> services and parties may not align with others'.
I have no evidence that it doesn't align with that of others who are
familiar with the concept.
I have plenty of evidence that it doesn't align with that of others who
aren't, but what are the odds that they would?
> To repeat my request, please work out a SaaSS argument for a forge,
That's not how it works. "forge" is too abstract a concept, and one
that is not even familiar to me. We have to look into each and every
piece of computing that you (and others) mean by "forge", and work out
how to reassure our control over the computing that is ours, in case we
decide to use a forge hosted by someone else. That's a lot of labor.
Since there is likely to be some computing of ours involved in a forge,
I'd much rather we all agreed to *save* that labor by deciding to host
our forge under our own control, if we want a forge.
> (e.g. what if the FSF gets a generous donor to host a forge and as a
> result the FSF is able to provide those services to GNU software?)
You'd presumably get something like Savannah. If you expect more of a
"forge", such as its doing some of the hosted project's computing, you'd
pretty much *necessarily* get into self-hosting territory.
It really is that simple. Outsourcing your computing, so that it runs
under someone else's *control* (!= *computers*), is what SaaSS is about,
and since that takes your software freedom away, that's a no-no,
especially for the FSF and for GNU.
--
Alexandre Oliva, happy hacker https://blog.lx.oliva.nom.br/
Free Software Activist FSFLA co-founder GNU Toolchain Engineer
Learn the truth about Richard Stallman at https://stallmansupport.org/
More information about the Libc-alpha
mailing list