i’m lizard

  • 0 Posts
  • 2 Comments
Joined 8 months ago
cake
Cake day: June 21st, 2024

help-circle
  • Borg or the like with ‘hardcoded’ plaintext/regularly full-disk-encrypted key is acceptable. Someone that has your unencrypted private key sitting on your server has almost certainly already obtained access to the entire set of data you’re backing up, with the backup key itself only meaningfully guarding access to older backups.

    The more important thing is to securely keep extra copies in case the server fails. I keep mine in a group in my password manager, one per repo.


  • There’s no 100% indicator, but presence/non-presence of a contributor license agreement that gives them the rights to distribute under any license is the best one I’ve found. Corporate backed FOSS where they want the option to turn into non-FOSS “just in case” means that will inevitably happen after people are locked in. Best place to look for one is the project’s documentation on how to contribute/how to send pull requests.

    Stuff licensed under BSD/MIT style permissive licenses don’t need a CLA to go proprietary, but the ones that do tend to have a CLA anyway.

    “CLAs” that are just an sign-off (developer certificate of origin like used by the kernel) are fine and are also treated as a CLA every so often, but the moment you see anything about giving one specific company a “perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license” or the like, run for the hills.