Live data from Hacker News

“Open source” is broken

christine.website

141–150 of 357 posts

Re: “Open source” is broken

#141
post #25

Open source isn't broken. The software will continue to get built regardless of funding levels, clearly. But when vulnerabilities like this are found, no one -- especially corporate users -- gets to complain. Any complainers should be immediately told to fund the software they use, or shut their entitled mouths. Open source is fine. The culture of companies -- nearly all of them, including the one I work for -- that…

> The culture of companies -- nearly all of them, including the one I work for -- that freeload off this work is what's broken.

Capitalism will always try to extract work at the lowest possible cost. If it’s possible to use your work without paying for it, companies will do it. They’ll fund work when funding the work can gain them influence or political dividends.

My two open-source projects, a font and pip-chill, are, respectively, a work of love and something that solves a problem for me. I enjoy working on them. In the past I have worked on other projects, but always to solve issues I had.

Re: “Open source” is broken

#142
What are the licenses that force the licensee to:

- share money earned (support or sales)

- share theyr time to support the project (writing docs)

i do know it's illusionary that everybody does theyr part, but not asking for something back might be just wrong.

what are other ideas that do not require the developer to create a support ecosystem around his library to earn money or the possibility to work on the project full time?

Is it an idea for a startup to support developers earn money with theyr products?

Re: “Open source” is broken

#143
post #29
post #15

Earlier quoted context omitted.

thank you. it's a well written article and you got me agreeing with what you are saying. it's surprising to read comments here that start with "open source is not broken" but proceed to repeat everything you wrote in the article...

The title of the article is "Open Source is broken" and its subtitle is "Why I Don't Write Useful Software Unless You Pay Me" And I disagree with both of these statements. Open source is not broken and I'll continue to write useful software, even if you don't pay me, because it's fun. The actual problem is concisely present in the article: > There is this culture of taking from open source without giving anything bac…

You hit the nail on the head.

Re: “Open source” is broken

#144
post #122

Earlier quoted context omitted.

Does it matter that other products don’t patch something that yours does? Like, sure, it’s unsatisfying from an ecosystem perspective, and one would hope for fixes to be incorporated upstream. But if they aren’t, who cares if other products are broken after you’ve patched the ones you’re responsible for?

It does because now I pull in a dependency that indirectly relies on log4j instead of my favorite fork of log4j and I end up having the same CVE in the project anyway. Yes this needs to work ecosystem wide, otherwise you have fixed nothing at all.

> It does because now I pull in a dependency

How would proprietary software make this better? You wouldn't even have anything to pull in!

Is your argument "having the source code and the legal rights to fix this bug even when nobody else wants to or even can fix it is not good enough because not everyone will use my fix"? Because good luck with proprietary software then!

Re: “Open source” is broken

#145

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

> But that's all part of the deal going in, and everyone is fully aware of all the trade-offs straight from the onset.

I think part of the problem here, in all honesty, is that some people just _are not_ aware of the trade-offs upfront. They learn these after getting started, and it bites them in the butt one way or another.

Re: “Open source” is broken

#146
post #30

I get a little nervous when the responsibility of incentivizing FOSS is framed as a personal responsibility. Isn't there a deeper conversation to be had about how we allocate resources as a society to help build fundamental infrastructure instead of placing the blame on individual people or corporations on their lack of sponsorship or donation? My apologies if this is flame-bait. I really don't know what the solution…

It's not flame-bait. We, as a society that values FOSS, should fund it, but not at the personal level of "I use this software so I'll pay for its license". FOSS licenses should state nothing about paying for the software. You should not feel bad because you are not paying FOSS at the individual level.

Taxes and allocation of funding at a societal level might indeed be the answer.

Re: “Open source” is broken

#147
post #119

I'd also imagine someone who lost their shirt in the stock market (or crypto) might get whiny and complain "Math is broken." Open source is just a process. It never promised you anything. Either way, this is why, even if annoying, the concept of "Free Software" is a better one. Its goal may not be perfect -- but at least it has one.

Fully agreed. I'm not entirely sure if authors like the one from TFA fully embrace or understand the distinction between Open Source and Free Software (I suspect they are conflating the two, but happy to be proven wrong), but if they do, they are actually doing good work and showing why Free Software is philosophically sounder.

Re: “Open source” is broken

#148

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

I think this argument massively ignores the underlying message of this blogpost: addressing that the human beings that make and use software aren't always treated as, well, human beings.

> A maintainer goes to jail for vehicular manslaughter and a bugs needs fixing, no problem

The author didn't seem to hint that open bugs in core-js or its usefulness to its community of users are / is problematic. They hinted that maintainers are people with real life problems, whether that's struggling to make a livelihood, or facing imprisonment and ignoring that social/economic context is problematic.

Stating "well, let's just fork their code and off we go" basically ignores the person behind the code entirely. It reduces the value of a person to their ability to spend time and effort on maintaining code. And that's just a morally very questionable way of approaching other people. That kind of behavior just doesn't foster any mutual trust or respect which are the basic requirements for open source to thrive to begin with.

> But that's all part of the deal going in, and everyone is fully aware of all the trade-offs straight from the onset.

No, absolutely not. That's not how the original instigators of the Open Source movement envisioned this.

Yes, open source licensing allows forking, but that's not something you'd do, for instance, because a maintainer fails to respond to your issues on GitHub.

Eric S. Raymond can be quoted from his seminal essay "Homesteading the noosphere":

> The three taboos we observed above make perfect sense under this analysis. One's reputation can suffer unfairly if someone else misappropriates or mangles one's work; these taboos (and related customs) attempt to prevent this from happening. (Or, to put it more pragmatically, hackers generally refrain from forking or rogue-patching others' projects in order to be able to deny legitimacy to the same behavior practiced against themselves.)

> Forking projects is bad because it exposes pre-fork contributors to a reputation risk they can only control by being active in both child projects simultaneously after the fork. (This would generally be too confusing or difficult to be practical.)

> Distributing rogue patches (or, much worse, rogue binaries) exposes the owners to an unfair reputation risk. Even if the official code is perfect, the owners will catch flak from bugs in the patches (but see [RP]).

> Surreptitiously filing someone's name off a project is, in cultural context, one of the ultimate crimes. Doing this steals the victim's gift to be presented as the thief's own.

http://catb.org/~esr/writings/homesteading/homesteading/ar01...

Especially the last taboo is incriminating.

In the past, I kept a handful of tiny open source libraries in PHP on Packagist. Someone forked one of those without notifying me and started directly competing with mine. I can't express how off putting that experience was at the time. It has made me quite apprehensive of pro-actively sharing code I write in my spare time under an open source license.

Because someone falls on hard times or isn't available for a while, that doesn't justify taking their work and presenting it as your own under the guise of "having a thriving, organic, creative, productive ecosystem."

Re: “Open source” is broken

#149

> I simply do not want to be in a situation where my software that I develop as a passion project on the side is holding people's companies together. People love to hate on Richard Stallman but he was really clear about the motivation for Free Software (which is not the same as Open Source but shares some tenets). What companies do with the source is their thing. They get all of the benefits and all of the responsibi…

> What companies do with the source is their thing. They get all of the benefits and all of the responsibilities. I know this very well and for some irrational reason it still makes me anxious to think about the many people relying on one of my free-time project that is used in classroom and medical settings. When there is a nasty bug found it's hard to shake the feeling of responsibility. I have disabled the countin…

>> When there is a nasty bug found it's hard to shake the feeling of responsibility.

I know right? Someone just opened a github issue for a CVE in one of our dependencies. It's only relevant if you're opening a .DXF file from an untrusted source, so it doesn't seem terribly relevant but yet... And updating to a newer version would take effort, and we want to replace it with something else anyway which would take effort. None of that effort is where I want to spend my free time. But I do work on the software because I like it and really want it to continue being around and useful, and that isn't going to happen unless I (and others) make it happen.

Re: “Open source” is broken

#150

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

Yes it's thriving, but it's also broken. From a tweet[1] cited in the article:

> This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage.

> "I work on Log4j in my spare time"

> "always dreamed of working on open source full time"

> "3 sponsors are funding @rgoers's work: Michael, Glenn, Matt"

[1]: https://twitter.com/FiloSottile/status/1469441487175880711

Post reply on HN