Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Thomas Depierre

@Di4na@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

SRE. Elixir Dev. Learner in Resiliency. French.
All Opinions are my own. And i have a lot.

Yeller about clouds and Cassandra on Hobbyist Maintainers and FOSS

dom. He/him.

815 Followers
679 Following
50 Posts
Joined December 18, 2022
blog:
https://www.softwaremaxims.com
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Why I do not see a future in coding with genAI/LLM. And why I am an AI skeptic. This post has been waiting for me to polish it for a year now, but I never found the energy. So you are going to get it raw. No pass through any of the beta readers I usually do. I may do a pass later to clean it up, but I am just too tired these days to spend a lot of time on my hobby. So it may stay that way. If you want references, feel free to ask, but they should not be hard to find. https://www.softwaremaxims.com/blog/reviewing-ai-code
softwaremaxims.com
24
0
17
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2w ago
Replying to
@ChrisMayLA6@mastodon.me.uk as said i don't disagree on the taxation. And I agree with raising lower pensions. But in the current situation, yes, a percentage increase on all pension linked to the triple lock is unsustainable. Both can be true!
1
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2w ago
Replying to
@ChrisMayLA6@mastodon.me.uk that's fair, but then it is a problem with the thinking behind the argument and the way it is done. Not with the same reality of the data. Also note that i only lived in the UK for a few years. So I am not personally concerned or important about it. I am back in France for years and we have our own problems around pensions. Quite similar tbh. But it is a generic "Western" world problem. And it is more linked to the Wealth hoarding that a particular generation ended up doing, while also hoarding the electoral power. And yes, there are inequality inside this cohort too. The class lens makes sense to use. But I think the class lens as the major one here is a bit myopic and risk failing to take into account the demographics.
1
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2w ago
Replying to
@ChrisMayLA6@mastodon.me.uk I would agree for one exception. A lot of old people are not in poverty and nowhere close to it. Last I checked, most wealth is in pensioners in the UK. Yes part of them are close to poverty. And a wealth tax may be an easier way to redistribute this. But don't go thinking that being a pensioner is being poor. Iirc for the past decade, the average pensioner has better income and buying power than the average employee.
1
1
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
When people wonder why I wrote https://www.softwaremaxims.com/blog/open-source-hobbyists-turf and why I am angry... I just received the OpenSource Summit schedule from a LF newsletter. And it is fascinating how much it can be all stuff from Alpha Centauri that have nothing to do with the realities of FOSS. Like, I know for who it is. I get it. But also, why do you happily pay to be misinformed if you are in a decision making position? I mean, I know why. I get it. But still, this is such a waste of money and time that is precious for everyone.
softwaremaxims.com
11
0
7
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@andrewnez@mastodon.social oh fuck. I am in this picture..... Fucking hell that one hurt. That one hurt so fucking hard.
6
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 3mo ago
If you ever wonder what I mean when I keep going back to "if you want better FOSS infrastructure, fix the tools", consider the time spent on this build problem. Then compare it to the average budget of "2 to 4h per quarter" of a hobbyist maintainer. The problem is not that we have little ressources. The problem is that we spend it in useless build system and dependencies side quests. https://algassert.com/post/2603
algassert.com
6
0
2
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to

@dahukanna@mastodon.social @glyph@mastodon.social @grumpydad@infosec.exchange @thomasfuchs@hachyderm.io as someone that has been on both sides...

There are real deep ergonomical problems with html, xml, latex, etc. even Rst. Like. If you make people try to write with them, you will see them in pain. Yes ofc it can be leaned and yes, technically, it is more adapted.

But it seems that in practical user study, it doesn't actually work. On top of that, it demands learning. That creates problems because 99% of foss depends on drive by for any contribution. And these cannot happen with something that needs to be learned.

The things I would love to see are

  1. Studies of what resonate so well in md with people
  2. Studies on what are the parts of the other formats that are non ergonomic

So that we can try to devise something with these capabilities that is ergonomic. But this is not a widely studied domain.

Meanwhile I will just try to push Djot as a step in the right direction...

3
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@Rairii@labyrinth.zone @andrewnez@mastodon.social that one is for you!
2
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 4mo ago
Replying to

@paulmelis@social.edu.nl @alexandrageese@bonn.social The sovereignty discussion is mostly coming on the heels of the US impact on the ICC. Which is a good thing for the EU governments to look at. But it means that the discussion become focused on two things

  1. How to replace US tech stacks that our government depends on for the "User visible" stuff. Ie Office, video conf, chat, emails, etc etc. Important but this only impact a minuscule size of the FOSS ecosystem. Most of FOSS is in packages not in finished products. This is an important thing to look at, but solving it need work that is not the realities of FOSS today.

  2. When it understand the importance of packages, it tend to go to support supply chain of them. Which once again, make sense in a sovereignty discussion. Except that means mostly supporting things like package repository, forges, etc. Important too but... once again not where the FOSS ecosystem need help the most. We can replicate that stuff in a hurry in an acceptable way to support continuity relatively easily if we needed to.

The FOSS ecosystems does have needs, that does impact the public, in particular around maintenance and support and security and risks for the wider society. But they are far more complex and mostly are more comparable to Road and Bridges infrastructure in term of investment, mindset and action needed. And these would only yield "Sovereignty" results indirectly, not directly in a "become independent" pov.

8
0
2
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to

@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social i have thoughts

  1. It probably was like that before LLMs even. Look at your dependency reports for all the projects your company have. It has not been clean in nearly a decade. Not because too many vulnerability. Because too much FOSS. These were tools (and compliance) built with the vendors world of the 90s/early 00s in mind.

  2. I think we can go far faster. Faaaar faster. Our tooling is crap, noone use it and we have not even tried. But i think we have different toolings and going faster in mind. See the github "want" list from @andrewnez@mastodon.social for one take on it. I have more.

  3. There are systemic problems there that can be looked at systemically. It will not be a quick fix but eh. We have been living with this for years, we don't need a quick fix.

  4. The whole idea of vuln feed is probably dead though. It never made a lot of sense in a language package manager enabled world anyway. Only in this 90s/00s view.

  5. Part of going faster is probably going to be a software engineering organisation of work problem. The SDLC, the Agile and the whole way we produce code in commercial software is probably the biggest problem here. It is fundamentally inefficient, probably for systemic reasons (i have some theories there, with some evidential support from research). But that links to the rest.

9
10
4
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@andrewnez@mastodon.social one fun metric we can use to show the alternative funding source you talk about at the end is that the number 1 reason project goes unmaintained are... The maintainer changed employer. We have relatively good data on this.
7
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@cliffle@hachyderm.io idk if you saw my post from yesterday but ... I know why. Because if you review it, it is so slow it makes no sense to generate it! The research is pretty solid there
2
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@eniko I recommend https://www.youtube.com/watch?v=ZuXzvjBYW8A I do not agree with is solutions, and this is UK only data, but it is thorough data, really on point, and hard to get this kind of data actually. And everything points at equivalent situation in nearly all of the Western world.

Have the Boomers Pinched Their Children’s Futures? - with Lord David Willetts

6
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@deshipu @eniko Yeah well, there is a reason funeral insurance and funeral plans paid in advance are a rising product to sell... Also, there is a reason the whole economy is panicking. The moment the stock market goes down, there is no more pensions from investments. And the housing market is what support most of these people wealth (and by that I do not mean billionaires, I am the old lady down your street). And they are not spending money to maintain it, because hell, they will be dead soon. So we will get a lot of fucked up housing on the market from inheritance...
6
0
3
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @corsac@mastodon.social @Viss@mastodon.social Here is a small thing to think about. The whole point of cve is to allow you to not update. That may sound strange but think about it. The whole point is that as long as we do not reveive a massive panic alert from this limited source, then we do not have to update. This is why it has become so central. Orgs are fundamentally wired against updates.
6
5
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 3mo ago
Replying to
@Lana@beige.party so the good news is... Probably not? H202 quickly decompose into h20 and 02, the 02 is what kills stuff, but also it disappears quickly. This is probably not going to impact anything at all, especially slowly poured out during daylight
3
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@AmenZwa@mathstodon.xyz I may or may have seen someone do that too for an EU RFP....
1
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@joshbressers@infosec.exchange @gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social Here is my take. Just publishing it and letting people catch up, without the "disclosure" is ok. What is not ok is spreading misinformation and trying to make yourself look bigger than it is, yelling "patch now" when no patch exists, etc Yeah we need to patch. We know. That is a job for our tooling to tell us. Not the people getting social and possibly marketing clout out of it.
5
5
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@lina because noone gives you money for it and it is not actually that useful. The reason the LLM like ChatGPT "works" is not because they are useful. It is because they feel like Her to the humans. This is partially due to their training but also how they are presented and what they do. Generic chatting. If you make them specific, then you lose the AGI look and feel. And that destroy the main value... Which is the look and feel of massive growth. We will probably do it, but in a few years. Once the mania calm down.
5
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@joshbressers@infosec.exchange good post. I like the metaphor. I have thought like that for a long time. Here is my personal take. Accept it as an immutable fact. You cannot beat it. The complexity and recursive aspect of it is what fundamentally make it works. The more we accept the constraints, the more we can find a solution. Because once you eliminated the impossible, what is left is the only thing that make sense. And that, to me, means that we are going to start realising that our boundary is _every single machine used by a FOSS maintainer_. You cannot secure just your own engineers machines. You cannot secure your perimeter. That ships sailed away somewhere in the 00s. So now, what we need, is that we need to make every machine that could end up being used by a FOSS Maintainer far more secure.... Time to invest in some thinking for the CLI and all these packages you mentioned.
1
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@dahukanna@mastodon.social @glyph@mastodon.social @grumpydad@infosec.exchange @thomasfuchs@hachyderm.io I agree! But panacea is not what we have to pick right now, because we do not have it and I don't think we are even close to it.
1
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@dahukanna@mastodon.social yeah the "interesting" part is the "attributes" which allows it to be relatively easy to extend
1
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@andrewnez@mastodon.social I mean Google meet reality is rarely done as Satire because it is so rarely happening. Usually it is reality meet Google and reality has to deal with the shitshow that Google did. Rarely the other way around
1
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@icing@chaos.social @joshbressers@infosec.exchange @andrewnez@mastodon.social ikr. I keep pointing out that some projects cannot support more than a tenth of a maintainer, not in term of money. In term of work to do.
3
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@joshbressers@infosec.exchange @gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social I am ok with waiting. That's the job. I am not ok with having to deal with all my management chain coming to me with no context one after the other asking me if we need to panic because they saw it in linkedin. Or asking me which AI tool we need to buy to find and patch these automatically before they get found, because it is what the marketing in these tell us.
3
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@dtauvdiodr @norootcause I will add that there is another way. Observation from the inside. We are all practitioners in teams doing this work, alongside others. We can find out some of the things done that go right. Yes, it is not the perfect way, but it is better than doing nothing because we are out of ideas. And yes, it means chopping wood, carrying water and reflecting on it. What is it that we do. How are we adapting to (maladapted) tools and practices. Where are the gaps between WaD and WaI that we fill. We can find people that already do the work. And train them so they can do the observation. They are already in. And sometimes they are already us ;)
3
0
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@quinn it speaks to the old way the government do things around children. Just wall them out to their own little society.
3
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@SeanCasten@mastodon.social I mean, even without these, how can it not be political to rules on the interpretation of the constitution, which is literally the source of political systems....
2
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@corsac@mastodon.social @gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social I think it is not true, but it is because we do not burn people for not updating
2
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@corsac@mastodon.social @gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social I mean, yes, this is kinda my point above :) But also, they are also burned (and not less) by not updating. It is just not considered the same way in the stats and not seen as the same thing. Because not updating is always in the past *after* the incident :)
2
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @corsac@mastodon.social @Viss@mastodon.social sooo many things. But they are not inherent to the kernel. Most software producing org are organised to slow down deployment and delivery. People are scared of changes. And the tooling to make changes less scary is ... Not well invested into.
2
6
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@wdormann@infosec.exchange @joshbressers@infosec.exchange @gregkh@social.kernel.org @deftpunk@fosstodon.org @Viss@mastodon.social mostly yes, which is also why I refuse to call it hallucinations or other anthropomorphizing statements... because it just aggregates words together that sounds like they work together.
2
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@joshbressers tbf, the FT have been pretty good so far
2
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 3mo ago
Replying to
@bagder@mastodon.social ... I am going to get the maintainer strike I keep saying we may end up getting, am I not? Damn, I don't know if I like being right or not.
1
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 4mo ago
Replying to

@andrewnez@mastodon.social I don't disagree but also I don't think this is the wrong decision. I think pushing it down to users is actually the right decision, as long as you accept that FOSS is all about enabling consumers.

I do think that our deployment tooling also kinda lost a lot of these channels ideas and it is also hurting.

But like. At some point, we have to accept that the user have to do most of the work in FOSS. That is the basic thing we push on them.

Hell, I am at the point where I do not want to run my production machine on stable channels of distros, because they tend to be so conservative they become a performance and security problem.

1
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@shafik@hachyderm.io I get you but I feel you miss what I am pointing. When writing the code as a human, I make choices, mostly conscious, that reduce the review load. These rules and decisions are not easily encodable. But they reduced the cost of review. By generating that code, we are not only generating more code. We are generating harder to review code.
1
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@shafik@hachyderm.io tbf I have even doubts that reviews can efficiently do that. We take active steps when writing the code around how we structure, name the code. How we choose which tools and construct we use. How we organise things. Pushing it back to review is changing the meaning of reviews. It means that reviews become not only "reviewing" but mostly making. We are adding more work to the review. It is not only bottlenecking there
1
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@adrianco @dtauvdiodr @norootcause I would love to see support for that in the evidence. Because I see the negative aspects of focusing on near misses. And I understand the theory of how it would help. But I have rarely seen it produce that positive outcome in practice. If ever.
1
3
1
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@adrianco @dtauvdiodr @norootcause note that this is not only about near misses. I usually warn against overusing near misses. This is more about the every day work weaves anti incident work into everything. Basic things. Like how ingrained in your muscle memory are venv commands. How ones organise their windows. How we setup our folders. How we don't use the recommended ways. How unit test became ingrained in our tooling in modern stuff. What people look at to decide a dependency ("yes, i know what security says. Ignore them and use this" kind of stuff). All these things that are not even near misses and that we also cannot report because there is no mechanism over the years that managed to share them. And noone is paid to bake them into tools.
1
5
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@leymoo @cloudthethings "you are not the customers nor the product, and the product is not for you either. The customers are the investor class which is chasing desperate schemes because boomers are numerous and they need their pensions. And the investor class knows they cannot get enough out of 'fundamentals'. There is not enough money for the amount of pensions needed for the Boomers. So they chase pink fluffy elephants hoping they will find one."
1
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@david_chisnall@infosec.exchange @whitequark@social.treehouse.systems they are bounded actually?
0
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 3mo ago
Replying to
@Gina@fosstodon.org @apell@eupolicy.social Ok I will bite. What makes it great to tell a massive lie, that is *at best* heavily dismissive of the work of a lot of people, and at worst is also totally blind to the realities of where FOSS people come from and live from? Like, the more I look into this one, the less it seems "great" to me...
0
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@ludicity@mastodon.sprawl.club honestly the comments on my latest blog have not been too bad. That said, they are also revealing of how bad our education on what science and engineering methods are. It is fascinating.
0
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 3mo ago
Replying to
@icing@chaos.social here is my offer. We stop caring about these things and we actually spend money into making build systems and dependencies update works better, so that maintainers have the time to work on security one day. I would love to see research on how much time of hobbyists maintainers is spent updating dependencies, dealing with these breakages.... and the same thing with build systems...
0
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 4mo ago
Replying to
@andrewnez@mastodon.social yeah. I think we need to start to be a lot more explicit about the "no warranty" part of the licenses again....
0
1
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 4mo ago
Replying to
@alexandrageese@bonn.social As a domain expert... Probably a good thing. I don't think sovereignty is the right framework for that. And so far, the things that came out of this direction were not particularly adapted to the realities of the domain. The question is more if they will actually regroup and rethink or just drop it all. Happy to exchange on this.
0
2
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 2mo ago
Replying to
@icing@chaos.social as I keep pointing out, security report are mostly useless noise to 99% of maintainers. Too low in the list of priorities to be important. Curl is in a particular spot, that you have enough ressources to be able to get to them. I think the urgency of them only depends on what you assign to them
0
0
0
0
Open post
Thomas Depierre @Di4na@hachyderm.io
· 5mo ago
Replying to
@wiert@mastodon.social @ra6bit@infosec.exchange @ariadne@social.treehouse.systems @joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social i would love explanations of Patreons or Twitch subscription then. Maaaaaaybe this is a useful lie-for-children and there are other mechanisms at play. Maaaaaaaaaaayyyyyyyybe
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:56:04 UTC