OwnCloud Statement concerning the formation of Nextcloud
owncloud.com
owncloud.com
I have seen such forks degenerate hugely into "they said / we promised / they suck / we're awesome", so I understand the need to delicately balance press releases between the need to inform and need to keep it civil/diplomatic, but I wish I understood more why the act of forking has caused their credit to disappear.
Unfortunately, the announcement has consequences for ownCloud, Inc. based in Lexington, MA.
Our main lenders in the US have cancelled our credit.
Following American law, we are forced to close the doors of ownCloud, Inc.
with immediate effect and terminate the contracts of 8 employees."- Lukas (Nextcloud'er - see also http://www.zdnet.com/article/owncloud-founder-forks-popular-...)
That said, we'll likely have Webcal support (https://github.com/owncloud/calendar/pull/443), that way you can at least in ownCloud view your Google calendars. (it's not synced though)
Radicale will also automatically commit every change into a Git repo, so you can always go back to any point in time. Just amazing.
https://www.stavros.io/posts/private-contacts-and-calendars-...
I know nothing of PHP other than its reputation. But apparently ownCloud is written in PHP and JavaScript. And PHP has its own "Security" section in its Wikipedia entry. And it has a reputation for security problems.
So, how "secure" (whatever that means) is ownCloud / Nextcloud? Has security been a problem for this software in real life?
There is often the perceiption that ownCloud would be insecure because we have so many advisories. But these are just there because we proactively look for security vulnerabilities and patch them. (see also https://statuscode.ch/2015/09/ownCloud-security-development-...)
Oh! And we also run a bug bounty program for ownCloud and Nextcloud will have one with probably even higher rewards soon! - HackerOne did even do a case study with us so it can't be too bad ;) (https://hackerone.com/resources)
Quite the contrary, most probably yes. Mistakes happen, but different languages make different kinds of mistakes impossible or very easy. You can't get segfault when manipulating strings in Perl or Python, while in C it takes plenty of effort to avoid.
But many of these problems can also be caught using the right tools and framework. With Ruby, using Rails will eliminate entire groups of risks you would have without it.
This is the same with PHP and frameworks like Symfony - which, incidentally, we use large parts off. And Lukas has been working a LOT on doing this kind of work, making sure we eliminate types of problems and mistakes developers could make. Combined with training (giving talks and workshops on writing secure code to our developers at events), code reviews by him and others, static code checking and so on, you get something that is really quite secure.
I am confident enough to say that our code base is the most secure way of sharing and syncing files using open source. Of course, before you or somebody else brings it up, SSH and rsync makes for a more secure experience but that's not exactly what Nextcloud competes with so perhaps add 'that gives a dropbox-like experience' to the above qualification :D
But this looks to be more complicated... ownCloud GmbH is unaffected? What was the purpose of having both companies then? There are many EU firms that seem to compete just fine without the Inc/LLC/Co at the end of their name
- nextCloud forking / poaching
- ownCloud having an event where they showed off new planned features
- the bank pulling the plug on financing
Since they're all talked about in the article, it seems as though they're related, but the links between them are really unclear.
Disclaimer: I quit ownCloud to work now at Nextcloud.
That could be close or far from the truth, but one thing is clear: the 8 devs who left couldn't see a path to solvency (technical and financial) that was reachable. The most likely reasons for this are either economic realities, or inadequate political capital.
I hope they do better in their new positions.
There's much more to this than we know yet.
For more info I recommend the Q&A from Frank and Jos today: https://youtube.com/watch?v=iMfokaX2r8g – we try to be as honest as we can.
Disclaimer/source: I'm one of the »poached developers«, or rather the designer. ;)