LWN: Comments on "Lessons from open source in the Mexican government" https://lwn.net/Articles/1013776/ This is a special feed containing comments posted to the individual LWN article titled "Lessons from open source in the Mexican government". en-us Mon, 20 Oct 2025 21:48:05 +0000 Mon, 20 Oct 2025 21:48:05 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net Claudia Sheinbaum Not Claudia Scheinbaum https://lwn.net/Articles/1017301/ https://lwn.net/Articles/1017301/ liw My rule 1 is "Always copy and paste a URL or a name." for a reason. (Jokes, but seriously: <a href="https://liw.fi/rules/">rules</a>) Sat, 12 Apr 2025 16:00:30 +0000 Claudia Sheinbaum Not Claudia Scheinbaum https://lwn.net/Articles/1017300/ https://lwn.net/Articles/1017300/ jake <div class="FormattedComment"> <span class="QuotedText">&gt; The politician's name is Claudia Sheinbaum not Claudia Scheinbaum.</span><br> <p> Ouch ... I hate getting names wrong ... fixed now ...<br> <p> jake<br> </div> Sat, 12 Apr 2025 15:55:39 +0000 Claudia Sheinbaum Not Claudia Scheinbaum https://lwn.net/Articles/1017299/ https://lwn.net/Articles/1017299/ daveok <div class="FormattedComment"> A minor correction. The politician's name is Claudia Sheinbaum not Claudia Scheinbaum.<br> </div> Sat, 12 Apr 2025 15:50:53 +0000 2FA KRB5 open source solutions for larger organization (20k+ students and staff) https://lwn.net/Articles/1016413/ https://lwn.net/Articles/1016413/ nirik <div class="FormattedComment"> Yes, fedora uses IPA on the backend... <br> </div> Thu, 03 Apr 2025 18:25:37 +0000 2FA KRB5 open source solutions for larger organization (20k+ students and staff) https://lwn.net/Articles/1016298/ https://lwn.net/Articles/1016298/ cortana <div class="FormattedComment"> This is probably using FreeIPA on the directory side; a smart card, TOTP or U2F token can be associated with a user account, and the directory can be configured to require its use to hand out a TGT. Unfortunately if you rely on AD Domain Services for your identity store, you also rely on it for Kerberos and you're very limited by what it's able to do regarding MFA. If your organization moves away from AD Domain Services towards pure-cloud MS Entra then you're screwed...<br> </div> Thu, 03 Apr 2025 11:08:09 +0000 2FA KRB5 open source solutions for larger organization (20k+ students and staff) https://lwn.net/Articles/1015875/ https://lwn.net/Articles/1015875/ mathstuf <div class="FormattedComment"> Fedora uses 2FA with Kerberos (at least I need my TOTP key when getting a new ticket). I can't imagine it is backed by MS ADS, but it doesn't seem like a *Kerberos* deficiency.<br> </div> Sun, 30 Mar 2025 15:16:17 +0000 2FA KRB5 open source solutions for larger organization (20k+ students and staff) https://lwn.net/Articles/1015792/ https://lwn.net/Articles/1015792/ ppisa <div class="FormattedComment"> Due to legal requirement (Czech National Office for Cyber and Information Security - NUKIB) to switch to 2FA, we have been recently informed that our university authentication system would be switched from Kerberos provided by the MS ADS on our local systems to Microsoft Entra ID (formerly Azure Active Directory).<br> <p> I have fear that access to our servers, data, projects would be lost in case of some lost/blocking of the foreign connectivity and I disagree with that change which would result in even stronger vendor lock-in.<br> <p> So I am interested if the authentication and roles assignment could be solved some more neutral and locally controlled way at Mexican government or if there are some other examples at large GNU/Linux distributions vendors and and users.<br> <p> Thanks for some suggestions, pointers etc in advance. I more embedded and processor expert with relatively mild security insight but I do not like this turn at university where students has been able to bring internet to their colleagues by own construction of the microwave technology in start of nineties and then build busyness on own RF technique for national telecommunication operators etc... We have developed all our laboratory and medical instruments on GNU/Linux systems from about 1995 year (at the start with help of FreeDOS and Dosemu). But after switch from Intel 8051 to M68K, MSP430, H8S, ARM and RISC-V now, we have been able to build all tools even ourselves (BDM, JTAG) to be on open-source side. So I take this as the deeper and deeper failure into the trap and I want to collect information to at least document that it could be prevented if decision makers do not hear me.<br> <p> I offer my e-mail ppisa@pikron.com as contact the domain owned by me to offer channel independent of the university where e-mails for new students are already forcibly switched to Microsoft accounts and technology only.<br> </div> Sat, 29 Mar 2025 00:55:19 +0000 Threats !? https://lwn.net/Articles/1015652/ https://lwn.net/Articles/1015652/ koomi <div class="FormattedComment"> If you think threatening lawyers are terrifying, then better don't look into what else US actors have been up to in Latin America...<br> <p> As you say, kudos to Federico and anyone else involved in this work. It is quite the achievement in a multitude of dimensions. <br> </div> Thu, 27 Mar 2025 22:03:18 +0000 Great article - thanks https://lwn.net/Articles/1015341/ https://lwn.net/Articles/1015341/ CChittleborough <div class="FormattedComment"> Thank you, Jake (and LWN in general) for a terrific and though-provoking report.<br> </div> Tue, 25 Mar 2025 09:38:50 +0000 Heroic st[au]ff https://lwn.net/Articles/1015324/ https://lwn.net/Articles/1015324/ vasvir <div class="FormattedComment"> Legendary material...<br> </div> Mon, 24 Mar 2025 23:40:41 +0000 The part on education is amazing https://lwn.net/Articles/1015314/ https://lwn.net/Articles/1015314/ kleptog <div class="FormattedComment"> Education is what makes us different from those that came before us. For developing countries, education is the way to get ahead. The effort to educate people on open-source technologies is something that will pay off big in the future in ways that are hard to predict.<br> <p> Nice work!<br> </div> Mon, 24 Mar 2025 15:33:06 +0000 Threats !? https://lwn.net/Articles/1015302/ https://lwn.net/Articles/1015302/ Poliorcetics <div class="FormattedComment"> Kudos to the people involved for not bowing to the threats, but I find it terrifying they were threatened at all. <br> </div> Mon, 24 Mar 2025 13:44:02 +0000