Live data from Hacker News

Expanding Fuchsia's open source model

opensource.googleblog.com

281–290 of 334 posts

Re: Expanding Fuchsia's open source model

#281

Earlier quoted context omitted.

These kind of projects are just “open washing” at that point. The source is available, but outsiders can’t meaningfully contribute stuff outside of the preordained roadmap nor is the project beholden to community consensus. As an open source contributor, it’s very unfulfilling and disappointing to find out you’re essentially an unpaid contributor to a company project.

I think unpaid internship is unquestionably a good thing. It's consensual, and unpaid interns are usually happy to do unpaid internship. It makes sense you are not happy to do unpaid internship, but the only thing it shows is that you are not the target audience.

>I think unpaid internship is unquestionably a good thing.

Unpaid internships are definitely questioned. You're very much incorrect here.

Re: Expanding Fuchsia's open source model

#282

Earlier quoted context omitted.

These kind of projects are just “open washing” at that point. The source is available, but outsiders can’t meaningfully contribute stuff outside of the preordained roadmap nor is the project beholden to community consensus. As an open source contributor, it’s very unfulfilling and disappointing to find out you’re essentially an unpaid contributor to a company project.

I'm playing Devil's Advocate here because I sympathize with your point, but isn't there a way you can squint and look at this weird that it's true of pretty much everything else? IBM makes tons of money off of Linux, for example. iXsystems profits off of FreeBSD. Facebook profits off of their wildly popular C++ libraries. I think we really need to divorce "profit" from "open source". OSS is great because we can contr…

> IBM makes tons of money off of Linux, for example.

Personally I would rather contribute to a GPL licensed project, because if big companies try to profit of it, they will also have to release their changes. Those could improve the project, and now the community does no longer have to do themselves -> Community devs get payed back in development time that they would have to spend themselves.

With permissively licensed projects (or commercially dual-licensed), where big companies are allowed to just take and improve it internally without giving anything back to the community, a community dev would pretty much be an unpaid developer for those companies.

Re: Expanding Fuchsia's open source model

#283

Earlier quoted context omitted.

Chromium, as built in many open-source distributions, uses a per-distribution Google API key for service access. [1] [2] [3] If built without API keys, Chromium warns 'Google API keys are missing. Some functionality of Google Chrome will be disabled.' [4] [5] The APIs used include [6]: * Calendar API * Contacts API * Drive API (Optional) * Chrome Remote Desktop API * Chrome Spelling API * Chrome Suggest API * Chrome…

To elaborate, the following distributions of Chromium are violating the Google API terms of service [1] [2] by publishing the API secret key publicly in the build source code responsible for building Chromium: * Alpine Linux (community port) - https://git.alpinelinux.org/aports/tree/community/chromium/A... * Arch Linux (svntogit, AUR) - https://github.com/archlinux/svntogit-packages/blob/1e8f3fe7... - https://aur.arc…

The Arch Linux one sort of doesn't count. The AUR is a user-created package repository. Anyone can make a build and add it to the AUR.

Re: Expanding Fuchsia's open source model

#284

Earlier quoted context omitted.

I believe they should have closed source the OS, Android being open-source is the number one reason for its fragmentation. What i dont understand is the "security" logic given by fuchsia. How is Linux less secure ? I dont think anyone starting a new kernel now can guarantee its security to be superior to Linux, because Linux had 25 yrs of evolution to where it is now. That logic is pure garbage, the real reason proba…

I do believe building a new OS from scratch - taking the learnings of the past 25+ years into consideration - will lead to a better and safer OS. I mean for Linux they had to invent a lot of new concepts, replace a ton of things for security reasons, etc. It's secure NOW, and it was secure enough since its inception (I presume?), but it's the cumulative effect of years of polishing. I mean search the kernel for refer…

Sure but thats a lot of work and things arent as simple as they seem there is always a risk of introducing newer bugs. So why switch?

Re: Expanding Fuchsia's open source model

#285

Earlier quoted context omitted.

I believe they should have closed source the OS, Android being open-source is the number one reason for its fragmentation. What i dont understand is the "security" logic given by fuchsia. How is Linux less secure ? I dont think anyone starting a new kernel now can guarantee its security to be superior to Linux, because Linux had 25 yrs of evolution to where it is now. That logic is pure garbage, the real reason proba…

I think this assumes that all OS designs have equivalent levels of security, but if this is true then why are there security-focused operating systems like seL4? Also I think that without the backwards compatibility requirements of Linux, one could probably have features that improve security (eg sandboxing of some kind)

Linux container is a sandboxing feature.

Re: Expanding Fuchsia's open source model

#286

I am a Linux kernel contributor and former golang and chromium contributor and to be honest the latter experiences makes me leary about contributing to another Google project. There generally tends to be an insular 'cathedral' rather than 'bazaar' approach to Google projects where those working for the company get considerably more say and control than outside contributors. The whole issue I have with it is that they…

Google has a forking mindset and they prefer having more say than letting other rule the roost. Look at Webkit, Google forked it and derived chrome so they can have more say. Android Kernel Team didnt back port their changes to Linux kernel for yrs. This has more to do with politics and less to do with development. My guess is Fuchsia may have reached a point of internal abandonment like most google projects which is when they thought of the last effort to salvage it before ditching it completely.

Re: Expanding Fuchsia's open source model

#287

Earlier quoted context omitted.

To elaborate, the following distributions of Chromium are violating the Google API terms of service [1] [2] by publishing the API secret key publicly in the build source code responsible for building Chromium: * Alpine Linux (community port) - https://git.alpinelinux.org/aports/tree/community/chromium/A... * Arch Linux (svntogit, AUR) - https://github.com/archlinux/svntogit-packages/blob/1e8f3fe7... - https://aur.arc…

The Arch Linux one sort of doesn't count. The AUR is a user-created package repository. Anyone can make a build and add it to the AUR.

Can you elaborate on what you mean by "doesn't count"?

Re: Expanding Fuchsia's open source model

#288

Earlier quoted context omitted.

Hopefully not. They are not a monopoly and doing so would be a severe overreach. Edit: Looks like many don't understand that you have alternatives to Google and you can use them.

There's a fuzziness to the concept of monopoly. It doesn't have to mean the absolute version where no alternatives exist at all. It can (and legally does) mean that a business is so dominant that it can effectively dictate the terms of the market. Google has a search monopoly effective enough that they can solely make or break anyone who relies on search. They have enough dominance in the market that if they were to…

As a simple example of this, let us imagine for a minute that Amazon and Google go to war. Google drops all search results that point to Amazon products or products in the Amazon marketplace and direct those searches to competitors and competing marketplaces. Google also changes Chrome so that entries into the url bar that are not explicitly for amazon domains do not match or return any amazon domain or product.

Since "Google is not a monopoly" I am sure no one would have a problem with this behavior... :)

Re: Expanding Fuchsia's open source model

#289
post #202

Earlier quoted context omitted.

If only there were some way to let the phone's owner decide what apps were allowed to run in the background, we could all be happy.

It takes about 15 seconds of googling to find out that yes, the user can decide what apps are allowed to run in the background. It's just that now, it's not "every app by default" and instead "what apps a user selects".

It depends on the phone. Lots of problems with eg the COVID-19 exposure notification apps where firmware updates from Android OEMs were needed to whitelist the apps, the user accessible background settings weren't enough to keep them working.

Re: Expanding Fuchsia's open source model

#290

Earlier quoted context omitted.

The Arch Linux one sort of doesn't count. The AUR is a user-created package repository. Anyone can make a build and add it to the AUR.

Can you elaborate on what you mean by "doesn't count"?

It's not an official package. The Arch Linux project cannot be held responsible for what non-official packages do.
Post reply on HN