Close Menu
Ztoog
    What's Hot
    Mobile

    Meta’s Q3 earnings prove AI and Reels will profit more than the Quest 3

    The Future

    UK probes Amazon and Microsoft over AI partnerships with Mistral, Anthropic, and Inflection

    Technology

    5 features the Pixel camera app needs to make the Pixel 8 great

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      What is Project Management? 5 Best Tools that You Can Try

      Operational excellence strategy and continuous improvement

      Hannah Fry: AI isn’t as powerful as we think

      FanDuel goes all in on responsible gaming push with new Play with a Plan campaign

      Gettyimages.com Is the Best Website on the Internet Right Now

    • Technology

      Iran war: How could it end?

      Democratic senators question CFTC staffing cuts in Chicago enforcement office

      Google’s Cloud AI lead on the three frontiers of model capability

      AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

      Productivity apps failed me when I needed them most

    • Gadgets

      macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

      Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

      POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

      The Mission: Impossible of SSDs has arrived with a fingerprint lock

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    • Mobile

      Android’s March update is all about finding people, apps, and your missing bags

      Watch Xiaomi’s global launch event live here

      Our poll shows what buyers actually care about in new smartphones (Hint: it’s not AI)

      Is Strava down for you? You’re not alone

      The Motorola Razr FIFA World Cup 2026 Edition was literally just unveiled, and Verizon is already giving them away

    • Science

      Big Tech Signs White House Data Center Pledge With Good Optics and Little Substance

      Inside the best dark matter detector ever built

      NASA’s Artemis moon exploration programme is getting a major makeover

      Scientists crack the case of “screeching” Scotch tape

      Blue-faced, puffy-lipped monkey scores a rare conservation win

    • AI

      Online harassment is entering its AI era

      Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

      New method could increase LLM training efficiency | Ztoog

      The human work behind humanoid robots is being hidden

      NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    • Crypto

      Google paid startup Form Energy $1B for its massive 100-hour battery

      Ethereum Breakout Alert: Corrective Channel Flip Sparks Impulsive Wave

      Show Your ID Or No Deal

      Jane Street sued for alleged front-running trades that accelerated Terraform Labs meltdown

      Bitcoin Trades Below ETF Cost-Basis As MVRV Signals Mounting Pressure

    Ztoog
    Home » Nginx core developer quits project in security dispute, starts “freenginx” fork
    Gadgets

    Nginx core developer quits project in security dispute, starts “freenginx” fork

    Facebook Twitter Pinterest WhatsApp
    Nginx core developer quits project in security dispute, starts “freenginx” fork
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Getty Images

    A core developer of Nginx, at the moment the world’s hottest internet server, has give up the project, stating that he now not sees it as “a free and open supply project… for the general public good.” His fork, freenginx, is “going to be run by builders, and never company entities,” writes Maxim Dounin, and can be “free from arbitrary company actions.”

    Dounin is among the earliest and nonetheless most lively coders on the open supply Nginx project and one of many first workers of Nginx, Inc., an organization created in 2011 to commercially assist the steadily rising internet server. Nginx is now used on roughly one-third of the world’s internet servers, forward of Apache.

    A tough historical past of creation and possession

    Nginx Inc. was acquired by Seattle-based networking agency F5 in 2019. Later that 12 months, two of Nginx’s leaders, Maxim Konovalov and Igor Sysoev, have been detained and interrogated in their properties by armed Russian state brokers. Sysoev’s former employer, Internet agency Rambler, claimed that it owned the rights to Nginx’s supply code, because it was developed throughout Sysoev’s tenure at Rambler (the place Dounin additionally labored). While the prison prices and rights don’t seem to have materialized, the implications of a Russian firm’s intrusion into a well-liked open supply piece of the online’s infrastructure precipitated some alarm.

    Sysoev left F5 and the Nginx project in early 2022. Later that 12 months, as a result of Russian invasion of Ukraine, F5 discontinued all operations in Russia. Some Nginx builders nonetheless in Russia shaped Angie, developed in massive half to assist Nginx customers in Russia. Dounin technically stopped working for F5 at that time, too, however maintained his position in Nginx “as a volunteer,” in line with Dounin’s mailing listing submit.

    Dounin writes in his announcement that “new non-technical administration” at F5 “just lately determined that they know higher run open supply initiatives. In explicit, they determined to intrude with security coverage nginx makes use of for years, ignoring each the coverage and builders’ place.” While it was “fairly comprehensible,” given their possession, Dounin wrote that it means he was “now not in a position to management which modifications are made in nginx,” therefore his departure and fork.

    Advertisement

    The CVEs on the middle of the break up

    Comments on Hacker News, together with one by a purported worker of F5, recommend Dounin opposed the assigning of revealed CVEs (Common Vulnerabilities and Exposures) to bugs in elements of QUIC. While QUIC shouldn’t be enabled in essentially the most default Nginx setup, it’s included in the appliance’s “mainline” model, which, in line with the Nginx documentation, comprises “the newest options and bug fixes and is all the time updated.”

    The commenter from F5, MZMegaZone, seemingly the principal security engineer at F5, notes that “numerous clients/customers have the code in manufacturing, experimental or not” and provides that F5 is a CVE Numbering Authority (CNA).

    Dounin expanded on F5’s actions in a later mail response.

    The most up-to-date “security advisory” was launched even though the actual bug in the experimental HTTP/3 code is predicted to be mounted as a traditional bug as per the prevailing security coverage, and all of the builders, together with me, agree on this.

    And, whereas the actual motion is not precisely very dangerous, the method in common is kind of problematic.

    Asked concerning the potential for identify confusion and trademark points, Dounin wrote in one other response about trademark issues: “I imagine [they] don’t apply right here, however IANAL [I am not a lawyer],” and “the identify aligns effectively with project objectives.”

    MZMegaZone confirmed the connection between security disclosures and Dounin’s departure. “All I do know is he objected to our determination to assign CVEs, was not comfortable that we did, and the timing doesn’t seem coincidental,” MZMegaZone wrote on Hacker News. He later added, “I do not assume having the CVEs ought to replicate poorly on NGINX or Maxim. I’m sorry he feels the way in which he does, however I maintain no sick will towards him and want him success, severely.”

    Ars reached out to F5 for remark and can replace this submit with any new info.

    Dounin, reached by e-mail, pointed to his mailing listing responses for clarification. He added, “Essentially, F5 ignored each the project coverage and joint builders’ place, with none dialogue.”

    MegaZone wrote to Ars (noting that he solely spoke for himself and never F5), stating, “It’s an unlucky state of affairs, however I believe we did the precise factor for the customers in assigning CVEs and following public disclosure practices. Rational individuals can disagree and I respect Maxim has his personal view on the matter, and maintain no sick will towards him or the fork. I want it hadn’t come to this, however I respect the selection was his to make.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

    Gadgets

    Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

    Gadgets

    POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

    Gadgets

    The Mission: Impossible of SSDs has arrived with a fingerprint lock

    Gadgets

    6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    Gadgets

    5 changes to know about in Apple’s latest iOS, macOS, and iPadOS betas

    Gadgets

    Lenovo Unveils AI-Enhanced Legion Y700 (2026): A New Benchmark For Compact Gaming Tablets

    Gadgets

    ASUS Vivobook S16 OLED Review: The Most Practical 16-inch Laptop Right Now

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    AI

    Neural architecture search in polynomial complexity – Ztoog

    Posted by Yicheng Fan and Dana Alon, Software Engineers, Google Research

    AI

    Meet Time-LLM: A Reprogramming Machine Learning Framework to Repurpose LLMs for General Time Series Forecasting with the Backbone Language Models Kept Intact

    In the quickly evolving knowledge evaluation panorama, the quest for strong time sequence forecasting fashions…

    Gadgets

    Max confirms 2024 password crackdown, explores adding transactional ads

    Enlarge / Max viewers will quickly want their very own account to look at Ellie…

    The Future

    How to Buy Workout Headphones, According to Fitness and Audio Experts

    Something else to take note? “With most headphones, once you get over a certain decibel…

    AI

    My colleagues turned me into an AI-powered NPC. I hate him.

    In Studio, builders can even customise security settings, controlling how a lot the character curses…

    Our Picks
    AI

    Transforming Catalyst Research: Meet CatBERTa, A Transformer-Based AI Model Designed For Energy Prediction Using Textual Inputs

    Technology

    Best Drone for Adults 2023

    AI

    UCSD Researchers Evaluate GPT-4’s Performance in a Turing Test: Unveiling the Dynamics of Human-like Deception and Communication Strategies

    Categories
    • AI (1,560)
    • Crypto (1,826)
    • Gadgets (1,870)
    • Mobile (1,910)
    • Science (1,939)
    • Technology (1,862)
    • The Future (1,716)
    Most Popular
    Crypto

    Ethereum Leaves Bitcoin Behind, But Is This Rally Sustainable?

    The Future

    Blade Runner TV Show Delayed as Writers Strike Continues

    Mobile

    Samsung’s working on a cheap Galaxy Z Flip and a surprise for the Watch 8

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2026 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.