Live data from Hacker News

Professional maintainers: a wake-up call

blog.filippo.io

141–150 of 464 posts

Re: Professional maintainers: a wake-up call

#141
post #89

Earlier quoted context omitted.

Reviewing code is the elephant in the room. Filosotile -perhaps out of ignorance or disconnect- fails to mention that the vast majority of open source projects (log4j being a great recent example) are absolute shit. Nobody should be building anything on top, nevermind giving the maintainers more money. In-house development, software BOMs, rising of standards and multiple rounds of code review are the processes that t…

The industry is nor moving towards multiple rounds of code review. Nor towards in house development nor away from using open source.

Every engineering-driven fintech company I know of (having myself worked there or having friends who work there) is doubling down on every single one of the processes I mentioned.

Re: Professional maintainers: a wake-up call

#142
Even if you dual license your software with AGPL/Commercial license, there's still companies that just plain ignore them. I was doing some scripting on my PDF bank statements and discovered they were generated using iText (AGPL version). Imagine a multinational bank blatantly violating copyright laws let alone expecting them to pay for open source.

Re: Professional maintainers: a wake-up call

#143
I liked that analogy to paying a law firm.

Most of these companies spend more on greenhouse services to keep plants in their offices than they spend supporting the F/LOSS stuff that they built their product around. That's how it should be viewed.

The Faangs probably have on the order of 100m boxes running Linux etc. It would be totally reasonable to expect they would pay someone $1/year/box to help maintain all the F/LOSS in there.

Re: Professional maintainers: a wake-up call

#144
Maybe businesses should pay a tax that goes into paying a respectable universal basic income.

That would make it easier to develop and maintain such software, and it would make it easier for people doing other things besides software development (yes, they exist) to open up their artware without starving.

Then there wouldn't be a need for the insane "professional" formalism described in this blog post.

Re: Professional maintainers: a wake-up call

#145
This assumes that large companies are willing to pay in the first place. In my experience most companies if they can get something half-developed for free. They will jump on it and think nothing further of the ramifications in the future however near or far that is. Any business that operates on that level deserves what is to come.

Re: Professional maintainers: a wake-up call

#146
post #77
post #53

Earlier quoted context omitted.

If I could figure out for certain which big companies were using my software, I might try the invoice idea for fun. I expect it would be ignored, but I would send it anyways to prove the idea one way or the other.

Big companies don't just pay random invoices;* you need to indicate what project and account (usually IDs from their CRM). So it would merely be chucked out. * In really big companies it's possible for admins to buy routine stuff below a threshold just to save on paperwork. So there's a scam in which someone sends out a bunch of $100 invoices for "printer paper" -- account payable assumes the department code was left…

It's called a Purchase to Pay system - whoever makes an order supplies a Purchase Order number from their internal system, which the supplier will reference on their invoice so the accounts team can look it up before paying it.

In terms HN would understand, it's a stateful firewall for invoices that prevents paying orders that didn't originate from your company.

Re: Professional maintainers: a wake-up call

#147
post #94

Earlier quoted context omitted.

> You need a proper "asshole" in such organizations that will go and threaten complete lack of support if the bill isn't paid. That's the point, they don't pay, and they don't get support. But they still complain when there is a major CVE. > For comparison, $1M is the total yearly cost of ~3 average engineers at FAANGs. I wish we got that...

Note "yearly cost ". Between administrative and organizational overhead, taxes, benefits, etc, typically only 50% of that cost is actually taken home as employee-visible salary [1] (which the employee then pays income taxes on...). $175k is still a healthy salary especially when compared to other locales, but it's not the $333k that is easy to presume based on GP's comment. [1]: From what I've seen this ~50% number s…

It doesn't seem like that 50% number would just keep scaling with salary. There is a cap on payroll tax [1], administration stuff around administering health, vacation, etc. doesn't change that much, office space.. maybe so with things like the Apple spaceship ($5 billion with capabilities for 12,000 employees; amortized over 25 years would be $16,000 per employee so I wouldn't think so).

[1] https://en.wikipedia.org/wiki/Payroll_tax#/media/File:Effect...

Re: Professional maintainers: a wake-up call

#148
It seems like Stripe Atlas could be adapted to help people formalize side projects, with invoices and subscriptions, while providing guardrails to keep from having to worry too much about the minutia of business, taxes, fees and so on.

Re: Professional maintainers: a wake-up call

#150
post #74

> Now is the perfect time for Open Source maintainers to become legible to the big companies that depend on them—and that want to get more out of them—and send them five-to-six figure invoices. Well, this is exactly what I've been doing around VideoLAN (VLC, x264) and FFmpeg for the last few years. In order to do that, I've created 2 official companies Videolabs and FFlabs (besides the non-profit orgs) and I've gone…

Would following an open core model work better, like it has for Hashicorp, Sidekiq, Tailwind, etc? Also, would focusing more on the low 4 figures result in more revenue? I feel the crowd sensitive to open source has that kind of spending authority, but once you get into the enterprise amounts, it's out of our reach to effect change.

At Enterprise levels there is no excuse to be using open source software and not paying some amount to get support. Boo!!! Booo!!! To anyone in an Enterprise that exploits FOSS without diverting funds to it. https://youtu.be/74GdZs2Ilk4
Post reply on HN