- DigitalNeighbor@lemmy.worldEnglish54 minutes
I can explain a major reason why public services and administration are begrudgingly moving to FOSS or OSS at all. They need to apply security standards like ISO 27001 and when they start going through what the documentation requires they realize that most OSS let alone FOSS make it very hard to have any say in the development of the software.
How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs? I can tell you from experience that some OSS devs will tell you to make your own merge request if it’s so important to you. GDPR makes having vulnerable public facing services very unattractive. What about support for the product when you need something fixed or have an issue with running the software?
You can definitely get a license for an OSS, or get a legal agreement for support from the OSS devs for money. I can guarantee you that when managers in public services look at either patching together and managing a bunch of separate OSS or using Microsofts integrated infrastructure, they see the advantages right away.
That is the sad truth… It’s resource intensive and a regulatory problem to create and manage a whole infrastructure. It’s much easier to use integrated and centralized solutions.
- Flipper@feddit.orgEnglish12 minutes
How do you make sure that the security flaws are patched promptly? Do you open a ticket on GitHub and simply hope it gets picked up by the devs?
No you dont expect free labour and pay them.
- Aceticon@lemmy.dbzer0.comEnglish5 minutes
The problem you point out has been known in the Linux community for literally decades and is the reason why Red Hat Linux was created and any company can, right know, get an Enterprise version of it with an Enterprise support contract.
That said, over the years I worked in seriously large multinational companies which used Linux and other open source products like Apache extensively on the server side (pretty much all such machines had it) so at least on the server side things did change massively from back in the day when companies would get Sun servers with SunOS or IBM server with Minix rather than generic server PCs with Linux due to that rationale you stated.
In fact, it has also become a common thing in much smaller companies, though maybe not the small and micro-sized ones.
The reality on the ground at least on the server side and for infrastructure software is that companies did find a way to deal with the problem of not being able to get support contracts from many of the OSS apps makers, and did so either by just paying some company specialized in supporting it or by having their own developers - after all, it’s exactly the thing with OSS that any developer can change it hence you’re not limited to paying for support from a specific company that makes the software.
- FE80@lemmy.worldEnglish48 minutes
The U.S. imposed sanctions on the International Criminal Court
…fuck this place.
- 2 hours
I’ve been doing a project https://themildtake.com/articles/2026-07-04-a-declaration-of-independence/ ever since Independence Day and I have been shocked by how insane the open-source tooling out there is now. NextCloud and Collabara alone solves 90% of company’s needs. ERPNEXT covers a huge swath in mid-range needs. I combine it with a mailcow server and Authentik for SSO and I am not sure how much else most businesses need. The whole stack is zero cost.
- brsrklf@jlai.luEnglish2 hours
I’m in a local administration in France, it’s rapidly getting closer to home… Our higher-ups somehow decided a thourough Microsoft integration was a good idea like 5 years ago.
Seems like we’re just one political comment about support to the ICC to be in the same situation. And I mean, fuck it, we should be. But I am not happy about the shit we’ll have to go through to purge it all now.
- fodor@lemmy.zipEnglish6 hours
Foreign countries using Google, Microsoft, or Apple, would be suicidal not to change platforms. Right now, the U.S. has incredible leverage: it can turn off their government servers, delete their data, and is certainly spying on them right now.
The only reasonable move is some kind of self-hosted setup, at least for a large chunk of critical infrastructure, with some cloud options for backups, maybe, who knows, if the country is too small or centralized.
- Squizzy@lemmy.worldEnglish2 hours
I am in a large (couple thousand staff) company and I cant get why we dont selfhost everything. Like yeah it would have an upfront cost but the savings stack immediately. We spend like 30-50 a user for office access.
Copilot is so shit and we could build an alternative with relative ease and never pay again. It wouldnt be baked into teams but who gives a fuck.
- corey931@lemmy.wtfEnglish5 hours
US: You want to cut us off? No! We cut you off!
NL: How petty are you?
US: Yes.
- SabinStargem@lemmy.todayEnglish8 hours
Considering the Dutch have ASML, this seems an unwise move for the US. But then, the Dogey Confederates are working towards the destruction of the USA. 😒
FudgyMcTubbs@lemmy.worldEnglish
30 minutesNot OP, but I don’t understand your question.
As a US citizen, I try to say “The States” instead of America when talking about my country. I do that out of respect for all of the countries that call these two beautiful American continents home.
I admit to defaulting to “American” instead of a cumbersome “United Statesian” or the above “US Citizen.” But that’s what we grew up calling ourselves and told to call ourselves and our fellow countrymen.
“Just another American Country” seems like it would be insulting to Canada, Chile and all of our neighbors in between. I’m not sure my fellow Americans would even pick up that you were talking about the States unless you really layed on thick context.
- ms.lane@lemmy.worldEnglish3 hours
Considering the Dutch have ASML,
That’s a card which only hurts ASML if played.
- Jiral@lemmy.worldEnglish5 hours
Tell us, how does “stuff work”? What up and running alternatives do the US have to ASML machines for latest generation high performance silicon? No matter where.
- bigmamoth@lemmy.worldEnglish2 hours
Look at asml client. Either us or Taiwan. They can’t skip that market. U dont have alternative to asml yet but asml has no alternative for client either. Also fab are long term devlopement thoses contract are already lock. And asml play by american rule regarding ban export and so more. Asml is never gonna ban the us. The us can but it serve them no purpose. Asml is a public traded company. If u think they gonna loose their biggest client… Idk what to say but that s unreal
- im_fine_sandy@nord.pubEnglish10 hours
This might just be the best thing that happens in tech (for me) all year.
I daily drive debian just because boring and reliable. However, fancy package managers like flatpak and appimages and nix have made debian much more vibrant - it’s easy to install new versions of things now.
That said, nix package manager on debian is just freakin amazing. Being able to just
nix-shell -p <obscure cli tool>andexitwhen I’m done with it is magnificent.That’s the gateway drug anyway. The nix based home-manager is pretty cool.
While I’ve been tempted to jump in with NixOS my experience with nix packages and home-manager has felt kind of bleeding edge or experimental. Loads of things that don’t work as intended on debian.
A sophisticated well funded user base like a federal government has really good implications for the stability of the project in the future. I’m really stoked about this.
- 4 hours
Personally id say try it in a VM*. Home-manager and nix packages (and even flakes at this point) havent felt like experimental features for a good 5 years for me on NixOS
Edit: while on Mac yes. Havent played with it that much on other distros
- AHemlocksLie@lemmy.zipEnglish6 hours
NixOS is great, but it definitely breaks things. It’s the way it works, though, not whether the software is bleeding edge. Nix lets a package specify its own dependencies, even if those dependencies conflict with those of another package. It does this by breaking the traditional POSIX file system structure that many programs assume they can depend on. It puts all sorts of things where they “don’t belong”, and then uses a small army of environment variables, scripts, and symlinks to stitch it back together so that no individual package realizes what happened. If you only use software from the package manager, this is often (but not always) seemless, but if you download stuff from the web, none of the system libraries it traditionally expects are there. Likewise, if you’re using Nix alongside something like Debian’s apt, I wouldn’t be at all surprised if the two package managers doing things in two different ways causes some issues that are hard to interpret to the uninformed.
- ouch@lemmy.worldEnglish13 hours
US has been building soft power like this for decades, and Trump is pissing it all away.
If this process to get rid of dependency on US gets well underway, there’s no turning that ship. US won’t recover the position it had in fifty years or more.
- LilB0kChoy@reddthat.comEnglish8 hours
US won’t recover the position it had in fifty years or more.
This is not a bad thing. Over dependency on any one nation or even a bloc of nations is a bad thing.
I can’t help but think the dependency on the US that has been created played some role in what’s happening now.
- SabinStargem@lemmy.todayEnglish8 hours
Honestly, I can see that. America has been top dog for so long, it doesn’t value what it has.
- LilB0kChoy@reddthat.comEnglish8 hours
Not even that. I’m thinking too much money, power and influence all consolidated in one place.
The US has the most billionaires at 989 and I’m guessing of the remaining ~2400 billionaires in the world, a not insignificant amount have substantial interests in the US.
It’s good the rest of the world is watching it happen. I hope they’re taking notes because it’s not stopping in America.
- fodor@lemmy.zipEnglish6 hours
Well of course. The whole point of US trade policy was to maintain global dominance. You don’t think that politicians were sending money to other countries purely out of the goodness of their own heart, do you? … Of course some of them have good intentions some of the time, but let’s not pretend no other reasons came into consideration.
- Typotyper@sh.itjust.worksEnglish12 hours
Nope. The US isn’t teaching people to fish, its forcing them to learn How to to feed themselves. In the past they handed them the fish so they could control them. That power is lost now.
- schipelblorp@sh.itjust.worksEnglish18 hours
US: Let’s sanction everyone everywhere all at once!
Also US: Why don’t people want to be dependent on US systems? 😭
- Ech@lemmy.caEnglish15 hours
Couldn’t undermine the country more if they tried, which makes one wonder.
Jaysyn@lemmy.worldEnglish
14 hoursYep. Trump’s actions are no different than what any bad actor would do if they wanted to destroy the USA without invading it.
- Destroy our soft power… check!
- Turn allies against us… check!
- Destroy our economy… check!
- Drastically weaken our military… check!
- 5 hours
And I’m accepting that he does it because he’s likely a Russian asset, but why the fuck are the rest of them playing along? You can’t tell me they’re all being bought.
- peathah@fedinsfw.appEnglish5 hours
They want corporate slaves, if the us is governed by the rich and corporations, corporate cities/islands they are trying to build are not needed anymore.
- CIA_chatbot@lemmy.worldEnglish18 hours
Yea we got a bit of the “inmates are running the asylum” situation over here.
In the immortal words of the joke (paraphrased) this country needs an enema
- benjirenji@slrpnk.netEnglish16 hours
I wish. Organizations and countries/municipalities are far too lazy to make the change.
- shalafi@lemmy.worldEnglish15 hours
The time and money involved are both staggering. This isn’t about you switching operating systems on your personal laptop.
Where are you going to get support staff anytime soon? All those Windows admins magically switching to Linux overnight?
Hell, Linux offers nothing remotely comparable to the power of Active Directory. That alone will keep Windows in the lead.
And more. This isn’t about lazy.
- The_v@lemmy.worldEnglish9 hours
Time + motivation + money can overcome a lot of obstacles. It also helps that template of what is needed already exists in Active Directory. This changes the project from “innovating something new” to “a slightly better copy” and is usually a lot faster and easier.
All copyright/patents are also void because of the sanctions at least in practice.
Valmond@lemmy.dbzer0.comEnglish
13 hoursI have worked in big company where linux and windows coexisted, but we were developers so maybe that’s why (IT was very strict though).
- forkDestroyer@infosec.pubEnglish14 hours
What is the alternative to AD, and are there currently companies running that, big or small?
- brimlar@lemmy.worldEnglish6 hours
I replied elsewhere, but our org has just been so happy with Jumpcloud.
- 10 hours
Red hat IDM, aka freeipa.
Depending on what youre doing you absolutely don’t need active directory.
Hell, a lot of orgs are just going entra anyway. If you’re using SSO like that or okta or keycloak you likely don’t need AD.
- SparroHawc@piefed.worldEnglish12 hours
At this point, a lot of entities don’t need AD because their entire workflow runs in a web browser, and practically any SSO provider will work.
That said, accessing actual computer resources can be managed with groups and ACLs. Perhaps not as elegantly or as well-integrated as AD is, but that’s the price you pay.
- rynn@piefed.socialEnglish16 hours
Windows is basically a zombie OS at this point, shambling along and eating brains.
- NaibofTabr@infosec.pubEnglish15 hours
Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.
I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.
- rumba@lemmy.zipEnglish14 hours
I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.
Kissaki@feddit.orgEnglish
14 hoursEntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.
Of course, legacy AD systems, if they exist, are also lock-in.
- InFerNo@lemmy.mlEnglish2 hours
Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.
- NaibofTabr@infosec.pubEnglish7 hours
EntraID is just a rebranding of Azure AD
Azure AD, the cloud version, still isn’t as feature-complete (or possibly feature-bloated) as the original on-prem AD, which is a big reason large organizations won’t switch away from it.
- NaibofTabr@infosec.pubEnglish7 hours
Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.
Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.
I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).
When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).
All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.
- ms.lane@lemmy.worldEnglish3 hours
Not to even mention the biggest of elephants in any MS room - Exchange.
- brimlar@lemmy.worldEnglish6 hours
You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.
- NaibofTabr@infosec.pubEnglish6 hours
living in a cloud-first, Microsoft-free future
Oh really, whose cloud? Oracle?
We don’t even maintain on-premises servers
Ah, you’re dependent on someone else’s computers, someone else’s network architecture.
That sounds awful.
Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.
Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.
NO. CLOUD.
- brimlar@lemmy.worldEnglish6 hours
It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).
Appoxo@lemmy.dbzer0.comEnglish
5 hoursFor business you should be able to fully control the VM, back it up and restore it somewhere else.
If you can’t do that ypu are chained.
- NaibofTabr@infosec.pubEnglish6 hours
OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine
IaaS? No. Nope. Not for anything we actually need.
No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.
It’s not about “feelings”, it’s about proper risk assessment and mitigation.
You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.
- LogicOverFeelings@piefed.caEnglish15 hours
Neet, if NixOS get used more and more then the skills I acquired making my config will become marketable.
CapuccinoCoretto@lemmy.worldEnglish
17 hoursAll middle powers need to align and collaborate on this. There is limited programming talent and gaps and especially security (ai) gaps need to be filled. EU, UK, Canada, Aus, NZ, SK, Japan should actively pool resources.








