Gentoo Archives: gentoo-nfp

From: "Michał Górny" <mgorny@g.o>
To: gentoo-nfp@l.g.o
Subject: Re: [gentoo-nfp] Developer Crypto Hardware (AGM)
Date: Sun, 19 Aug 2018 19:36:50
Message-Id: 1534707402.2937.6.camel@gentoo.org
In Reply to: [gentoo-nfp] Developer Crypto Hardware (AGM) by Aaron Bauman
1 On Sun, 2018-08-19 at 14:42 -0400, Aaron Bauman wrote:
2 > Gentoo-bug: https://bugs.gentoo.org/659620
3 >
4 > All, this email will serve as a comparison between the two vendors which
5 > have provided quotes to the Foundation. This does not include Alice's
6 > proposal as U2FZero is currently out of stock in the United States and
7 > does not seem to offer any availability in Asia. Alice did suggest that
8 > we split vendors across geographical markets, but I find this will make
9 > the situation become very difficult to handle. It would also put the
10 > burden on individuals to receive and disperse the tokens and increase
11 > shipping costs, burden the treasurer for reimbursements to be processed,
12 > and possibly cause delays.
13 >
14 > Yubikey:
15 >
16 > Quote received for (150) Yubikey FIPS tokens.
17 >
18 > Unit Price: $44.16 USD
19 > Total: $6,624 USD
20 > Discount: 4% (already available to anyone ordering in bulk)
21 >
22 > Shipping costs can be found at [1] and the lowest cost projections
23 > given. They do not offer any standard costs for shipping and cannot
24 > discount it.
25 >
26 > Open source: Several products are no longer open sourced and tracking
27 > which is/is not can be difficult [4].
28 >
29 > Nitrokey:
30 >
31 > Quote received based on (150) Nitrokey Pro tokens.
32 >
33 > Unit Price: 27,59 € ($31.58 USD at the time of this email)
34 > Total: 4,138.50 € ($4737.06 USD at the time of this email)
35 > Discount: 33% (With sponsorship agreement on gentoo.org)
36 >
37 > All prices are already inclusive of VAT.
38 >
39 > Shipping times can be found here [2]. Shipping costs can be found here
40 > [3]. The most expensive shipping is worldwide starting at 7,40 €
41 > ($8.47 USD at the the time of this email).
42 >
43 > Nitrokey has also offered several unique options for Gentoo. They will
44 > provide a custom portal which allows each developer to request their
45 > security token. This is done via a Foundation (infra really) provided
46 > list of valid gentoo.org email addresses. Additionally, they will
47 > provide monthly billing of all purchased devices and the Foundation is
48 > not obligated to purchase all (150) tokens. This can be a standing
49 > agreement until the Foundation decides to remove financial support.
50 >
51 > Considering both vendors, we can estimate shipping at the highest cost
52 > in order to best prepare for potential expenses.
53 >
54 > Open source: All products are considered open [4].
55 >
56 > -----
57 >
58 > Motion: I move that the board vote to accept the offer from Yubico or
59 > Nitrokey and begin our agreement with the accepted vendor beginning 1
60 > September 2018. This motion will provide security tokens to all current
61 > developers listed in Gentoo's LDAP infrastructure as of 31 August 2018.
62 >
63 > Motion: I move that the board vote to maintain the aforementioned
64 > agreement in order to support future Gentoo developers with security
65 > tokens. This motion includes the right to terminate future purchases
66 > based on the Foundation's financials.
67 >
68 > [1]: https://www.yubico.com/support/shipping-and-buying-information/
69 > [2]: https://www.nitrokey.com/documentation/frequently-asked-questions#how-long-does-the-shipping-take
70 > [3]: https://shop.nitrokey.com/shop/product/nitrokey-pro-2-3
71 > [4]: https://old.lwn.net/Articles/736231/
72
73 1. Should we include all developers or only developers with gentoo.git
74 commit access?
75
76 2. Shouldn't we set some minimal time-as-a-dev for this?
77
78 What I'm concerned about are people joining Gentoo only to get the free
79 token and then stopping to contribute. We historically had both cases
80 of people joining and then disappearing shortly afterwards, and people
81 trying to join just to gain the developer status and not to contribute.
82
83 Alternatively, require developers to return the token upon termination
84 of developer status, with allowance that after X years as a dev
85 the token is considered scrapped and does not need to be returned.
86
87 --
88 Best regards,
89 Michał Górny

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) "Robin H. Johnson" <robbat2@g.o>