Live data from Hacker News

“Open source” is broken

christine.website

161–170 of 357 posts

Re: “Open source” is broken

#161
The broken part is dependency management. People will install anything as a dependency, and just because the code functionally works today they often assume that they can expect maintenance, support, and security into the future.

One of the biggest myths of "open source" is that it can replace commercial software in every way, but for free. It simply doesn't. Code is code, but nobody buys just code. They buy trust, support, a warranty, expertise, and a contract to back it up in court. You get none of this when your engineers `npm install who-knows-where-this-code-comes-from`

Engineers are kicking the can down the road, and I don't think management in most places truly understand the extent of the code their companies are running for which:

* they employ nobody who is familiar with it

* they have no vendors on call who are familiar with it

* they have no idea who is committing to it

* if anything goes wrong, there is nobody to help them

Re: “Open source” is broken

#162

Earlier quoted context omitted.

Yes it's thriving, but it's also broken. From a tweet[1] cited in the article: > This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. > "I work on Log4j in my spare time" > "always dreamed of working on open source full time" > "3 sponsors are funding @rgoers's work: Michael, Glenn, Matt" [1]: https://twitter.com/FiloSottile/status/1469441487175880711

No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan. Making and maintaining a piece of software and giving it away for free isn't a great business plan, or at best it's an incomplete one.

> No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan.

This attitude totally ignores how hard it is to actually run a software tooling business and collect when you have a free/community offering.

Take the Obsidian note app, for example. It's technically free until you start using it for revenue-generating, work-related activity per their license, but how do they go about enforcing that? If they were to dig through customer data to see who is violating the agreement, they'd get roasted on Twitter in an instant and risk losing their user base. Should they hire attorneys to investigate and shake down violators for the $25/mo fee plus damages? Again, major risk of losing the customer base.

Software devs have to represent a significant, if not majority share of the user base of Obsidian, and I'd bet a year of my salary that most of them aren't paying for it when they're using it for work. Committing to a business plan is an important step, but software's value is directly correlated with it's use, and more widely used software is inherently more valuable, but achieving that kind of growth without giving it away free is a major challenge.

It kinda feels like tipping in the restaurant industry, where folks argue that it's to ensure proper service, when in reality it's often just a way for the restaurant owner to not have to pay minimum wage by offloading that portion of a workers wages onto the customer, who often just doesn't give a tip.

Re: “Open source” is broken

#163

> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly. This is absolutely not what open source is about. The author just sounds completely against open source, which is fine, but don’t lecture people for not paying for that which was intended to be free.

I'm the author in question. I'm not against open source, I'm against the culture of taking without giving back.

Re: “Open source” is broken

#164

Earlier quoted context omitted.

Yes it's thriving, but it's also broken. From a tweet[1] cited in the article: > This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. > "I work on Log4j in my spare time" > "always dreamed of working on open source full time" > "3 sponsors are funding @rgoers's work: Michael, Glenn, Matt" [1]: https://twitter.com/FiloSottile/status/1469441487175880711

No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan. Making and maintaining a piece of software and giving it away for free isn't a great business plan, or at best it's an incomplete one.

I also wonder about the futility of the statement that someone could cause millions of dollars of damages when those companies elected to depend and build upon truly free software.

Free lunches don’t exist for anyone.

Re: “Open source” is broken

#165
post #159
post #87

Earlier quoted context omitted.

A good analysis of what open source enables - Facebook et al. were able to build their companies more easily using it. But you forget to compare it to the alternative, where there is no significant open source or libre software available. You can't run Linux, you have to trust Windows not to backdoor you. There is no Signal or Matrix or other encrypted messaging - or if there is, you have no way of verifying it. If y…

Indeed Open Source also benefits Libre Software today. But do we really know what the ecosystem would be like today in a world where only Copyleft existed ? Linux itself is GPL, so are some of the distributions. Hurd hasn't seen adoption, probably because the alternative is good enough. Signal is still there, client and server. But maybe it wasn't needed because ejabberd, one of the biggest XMPP servers, was already…

Ah, sorry. I misunderstood you as talking about the problems of open source in general, but you were referring only to non-copyleft open source. In that case I think we agree.

Re: “Open source” is broken

#166

The market value of an open source library is the price you’d have to pay to replace it. How much would it cost Google to hash out a minimum viable rewrite of log4j2? Probably not much. Why don’t they? Because the cost of just using log4j2 is 0… until it isn’t. The externalities of the damage caused were never priced into that zero dollar price. I think about this every single time I depend on a third party library.…

> How much would it cost Google to hash out a minimum viable rewrite of log4j2? Probably not much.

Building software is expensive. Based on a quick glance at the repository, it would probably cost $1+ million in developer salaries to replace it. To a company the scale of Google that isn't a lot of money, but they're benefiting a lot more than they let on

Re: “Open source” is broken

#167

> I simply do not want to be in a situation where my software that I develop as a passion project on the side is holding people's companies together. People love to hate on Richard Stallman but he was really clear about the motivation for Free Software (which is not the same as Open Source but shares some tenets). What companies do with the source is their thing. They get all of the benefits and all of the responsibi…

> Which is very difficult / nigh impossible for closed source. Closed source does not mean that the customer has no access to it. In case of my Sciter, for example, customers are getting access to SVN server with sources. Some of them are sending patches with fixes and features. Sciter's [1] core customers are antivirus vendors - highly professional, dedicated and disciplined teams that know very well what they are d…

Same for the Unreal Engine

Re: “Open source” is broken

#168

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

Just out of curiosity - I wouldn't use vehicular manslaughter as a point of comparison for open source projects? Is there a reference I'm missing with that part of the comment?

Re: “Open source” is broken

#169
post #60

> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly. This is false. Free software is given away by those who produce it. When you receive a gift, no moral or ethical obligation is created. This idea that you can do things with free software that are contrary to the spirit (such as create a profitable company around it and not…

Does that also mean that it is morally OK for the author to backdoor their code or sell zero days they discover in it? A direct reading of the license says there's no warranty so they have no grounds to complain, right?

Re: “Open source” is broken

#170
post #135

Earlier quoted context omitted.

In the case of core-js the issue isn't that "nobody is contributing", the issue is that there is one guy with commit authority and he's an asshole who reportedly spends most of his days rejecting PRs from people he doesn't like. IBM, Oracle, Apple, Microsoft could submit all the PRs in the world and it won't do any good if he says "I don't like your coding style" or "this takes core-js in a direction I don't like." O…

But...and bear with me as I'm no JS guy and am unfamiliar with that library...how hard is it for the community to fork it and go on from there? Literally every time I find an esoteric library on Github the first thing I do before forking it or adding it to my dependencies is immediately pull up the "network" tab to see if there's are active branch downstream I should follow. Perhaps Github can do a better job of high…

You can fork it til the cows come home, but everyone downloading core-js off of npm gets the one from upstream.
Post reply on HN