Live data from Hacker News

“Open source” is broken

christine.website

171–180 of 357 posts

Re: “Open source” is broken

#171

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

ESR - the person who coined "open source" in the first place! - agrees that this is a problem worth addressing. See his Loadsharers initiatve http://www.catb.org/esr/loadsharers/ (more info at https://esr.gitlab.io/loadsharers/ ) discussed http://esr.ibiblio.org/?p=8383 http://esr.ibiblio.org/?p=8387 http://esr.ibiblio.org/?p=8403

Re: “Open source” is broken

#172
post #170
post #135

Earlier quoted context omitted.

But...and bear with me as I'm no JS guy and am unfamiliar with that library...how hard is it for the community to fork it and go on from there? Literally every time I find an esoteric library on Github the first thing I do before forking it or adding it to my dependencies is immediately pull up the "network" tab to see if there's are active branch downstream I should follow. Perhaps Github can do a better job of high…

You can fork it til the cows come home, but everyone downloading core-js off of npm gets the one from upstream.

True, I suppose I should have been clearer: fork and resubmit to npm with a new label. 'core2-js' or something.

Re: “Open source” is broken

#173

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

I mostly agree with your argument. But, if we just de facto accept everything for how it has been in the past. Then we stop making things better, for everybody involved. Is Open-Source thriving? yes. Can we make fix the places where it's broken? Also, Yes.

> Can we make fix the places where it's broken? Also, Yes.

Two problems:

1. How is it broken? As I and others in this thread attest to, the thing that makes open source so powerful is, in fact, the lack of legal and moral obligation to do anything in exchange for the right to use the software. Not having obligations is a two-way street. Same for donations; donations do not give you any additional assurances.

2. If it is truly broken, then what is the solution? Nobody has really offered any solution, that I can see. If the solution is that everyone rushes to support a project the moment it hits the news, that's not sustainable. It's good that log4j and its maintainer(s) will get more attention and hopefully funding as a result of this snafu, but it's not a sustainable solution to a problem.

(As a clarification, I am not implying that the answer is "it's not broken." I certainly do agree that open source is underfunded, though I think this is more of a procedural issue than anything.)

Re: “Open source” is broken

#174
I think it's great to realize when you are not getting enough from open source and should focus on software you are paid to write. The benefits of open source are basically three fold:

1) mentorship opportunities and learning different problem domains by solving real world problems in those domains. This helps solve the bootstrap problem of skill acquisition in things like networking, graphics, etc.

2) exposure - this can be used to help land a job by publicly demonstrating your skills.

3) Pay -- there is a small minority of open source developers who are hired on a salary or contract basis to develop or support the code.

Now whether the above three benefits are worth the cost of spending your time on open source depends on each individual developer. Each will have their own trade off.

But I'd hope people can make this trade off without condemning the entire movement or declaring it broken or in need of change so that it would become a better trade off for you.

Re: “Open source” is broken

#175

Earlier quoted context omitted.

> You say that as if you even know your full dependency chain. Reality doesn't quite work that way. No one knew their codebase even relied on leftpad until it broke millions of applications the world over when it got pulled. We're professionals - we in fact simply can do that with some elbow grease. Doesn't take a genius to understand how software is built.

There is too much information out there to know all of it. Sure everyone knows how to do it, but it's often not worth the time to do so.

My point is it's your collective job as a professional software dev shop to do so. It's a relatively fixed cost too - incrementally knowing your toolchain once you've done it the first time isn't that bad.

Re: “Open source” is broken

#176
post #144
post #122

Earlier quoted context omitted.

It does because now I pull in a dependency that indirectly relies on log4j instead of my favorite fork of log4j and I end up having the same CVE in the project anyway. Yes this needs to work ecosystem wide, otherwise you have fixed nothing at all.

> It does because now I pull in a dependency How would proprietary software make this better? You wouldn't even have anything to pull in! Is your argument "having the source code and the legal rights to fix this bug even when nobody else wants to or even can fix it is not good enough because not everyone will use my fix"? Because good luck with proprietary software then!

My argument is not closed source. My argument is that "just fork it" does not magically fix all problems. Closed source makes this worse but "fork it" is no answer either.

I believe I made this very clear on my very first comment.

Re: “Open source” is broken

#177
post #37
post #3

I'm the author of the post in case you have any questions for me.

I always think about paying for the open source software that I use and I try to be more dilligent in paying for it. The problem for me is, that while calculating how much I theoretically should spend on the OS I use for example (gnome+fedora+linux kernel,etc), it would be actually cheaper to pay for a windows version+microsoft cloud/office suite or switch to the apple ecosystem. Same applies for programming framewor…

If everyone paid 15$ (+-Netflix sub price in my country) to single favorite FOSS project they use, we'd be in a much better place. In case of libraries/frameworks - they should be founded by companies.

Re: “Open source” is broken

#178
This is a good article, and 99% of this article I agree with. I'm going to quibble at something very small, not because I think the author is guilty or anything or because they're doing something wrong, but because this is a general pattern I've been seeing over and over again in multiple takes from multiple people: it feels weird to me to have a criticism of corporate behavior where corporations don't know how to ensure the continued success of the commons they build on, and to title this that "Open Source" is broken.

If a bunch of hunters go out and shoot all the ducks to extinction, you don't title an article that ducks have failed as a species, you say that duck hunting is a problem. And I've seen a few different articles now talk about how Open Source devs need to get better about setting up contracts and finding sponsors, or saying that this reveals a fundamental problem with Open Source, and I just don't get why we're laying this at their feet.

The big companies who's stuff broke because of Log4j have both a giant legal department with infinitely more resources than any single developer available to them to figure out how to kick money to these projects. And this is something that article touches on, which it describes completely accurately: there are developers who build this stuff that do not want it to be a professional thing, and they should still be compensated. There are developers who don't want compensation in the form of money, they want additional development resources or dedicated people helping them triage bugs, and that's a legitimate need that companies could start learning to provide. Volunteer developers should not need to learn how to set up an LLC or a nonprofit to get some compensation for their work if their work is important; the idea that compensation is dependent on a very specific model of professionalism and that it's incompatible with people doing something as a hobby is just wrong. The author does a good job of pointing this out that Open Source funding often looks different from commercial funding. A quote even admits:

> Okay, part of this may also be an ADHD thing and not really being able to stick to projects longer term.

But the thing is, that's OK. Like, you should be able to be in that position and to jump around between projects and if a company really cares about it it's still their job to give you money or to invest resources and maintainers into the project to make your life easier. This should not be conditional on you turning your work into a full-time job with years of commitment. But even as I praise the article for that phrasing, and even though I suspect this is something a lot of people agree with, I'm still frustrated that we don't get a bunch of articles that say "corporate financing is broken and unsustainable" or "our culture about funding and who/what deserves money is broken." We get articles that say that "Open Source" is broken.

I know that I'm kind of just quibbling over something small, and I know this is if anything the wrong article to even post this rant under. I don't want to make needless conflict over something where the author is mostly just right and in many cases saying the same things I'm saying. But I do kind of think this phrasing is important. My objection is I think the phrasing here implies to people (unintentionally) a kind of unconscious bias that this is Open Source's problem to solve. But the commercial companies broke and went into panic mode because they weren't willing to invest into the infrastructure that they rely on. That is their problem to solve, they are the ones on fire. They have the resources and they are capable of learning how to give money directly to developers. Maybe it's a cultural problem that they need to work on that's just ingrained in business heads; I somehow doubt we're going to get a bunch of corporate think-posts on LinkedIn about that framing though. Companies should be expected to occasionally evolve themselves instead of having everybody constantly hold their hands and console them that we understand that large direct donations and regular investments are just ever so scary and difficult to do and that this is a systemic problem with the community, not a direct problem with their individual behavior as an individual company.

Funding for Open Source is a serious problem, but I'm kind of tired of seeing article titles and phrasing implicitly suggesting (again, I think completely unintentionally in this case) that it's the Open Source community's problem to solve. You all use our stuff! This is your problem, your stuff broke because projects were underfunded. Why is it our job to make our funding methods more comfortable to you? The company's stuff breaking because their lawyers are irrationally scared of straight no-strings-attached donations is their problem. Let commons be commons, get over the short-sighted thinking that says companies can't possibly invest into making their products not fall over and catch on fire randomly unless they get something exclusive out of that investment. Or if they're incapable of doing that, stop giving them sympathy and treating their irresponsibility like it's everybody else's job to solve. They'll learn to fund Open Source, or their stuff will break in embarrassing public ways that make them look bad, and maybe after a while they'll start learning some heckin lessons from that.

This is something that (outside of the title) the article does a good job of reinforcing: build the software you want to build, and don't let leaches pretend that gives you an extra obligation to them. Particularly don't let leaches argue that your inability to keep leaches away is your fault. Honestly, the Log4j maintainers would have been completely justified in saying, "hey, yeah, we see this critical vulnerability, but it's the weekend, we'll get to it on Monday."

Re: “Open source” is broken

#179

No, it's not broken -- it's thriving. Everyone involved has their own incentives, and gets to make their own decisions about when and where to invest their time and money. Some devs are in it for the passion, some for the experience, some for the challenge, some for the learning, some so their work will live on when they change employers. Startups get to use well-tested community supported libraries and don't have to…

ESR - the person who coined "open source" in the first place! - agrees that this is a problem worth addressing. See his Loadsharers initiatve http://www.catb.org/esr/loadsharers/ (more info at https://esr.gitlab.io/loadsharers/ ) discussed http://esr.ibiblio.org/?p=8383 http://esr.ibiblio.org/?p=8387 http://esr.ibiblio.org/?p=8403

I think most people, at least certainly myself, do not disagree that open source infrastructure projects are often underappreciated and underfunded. However, there's a dramatic difference between the way that ESR's LBIP initiative frames the problem vs this article (not to single anyone out - this article expresses a commonly held belief among plenty of influential and intelligent people, and no doubt the person who wrote the article is one.)

To me, the money quote is here:

> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly.

I don't agree. I think that it is tragic if nobody does, but I draw the line at "moral obligation." Furthermore, the article doesn't really provide any sustainable solution, it just expresses that it's broken and says people should pay for it. Initiatives like ESR's LBIP proves that there are some attempts to get more funding in, but the problem is manyfold, and simply put: I don't think trying to create a new norm that there is a moral obligation to pay your dependencies is really a good idea, nor do I think it solves the problems that lead to this situation. I think that discovery and awareness of load-bearing dependencies is an even greater problem, and that plenty of entities that relied heavily on log4j had honestly not even realized it until now.

I'll repeat myself: It's good that log4j will now see additional attention and funding, if only temporarily, but it's still not fixing the sustainability problem if we only ever fund things when they become newsworthy snafus.

Re: “Open source” is broken

#180
It would be nice to see public grants like those in the EU for software here in the US. If you want to replicate SV, get rid of non-competes first, then try doing something like this along with tax breaks.
Post reply on HN