Live data from Hacker News

Professional maintainers: a wake-up call

blog.filippo.io

301–310 of 464 posts

Re: Professional maintainers: a wake-up call

#301

Earlier quoted context omitted.

It has certainly 'worked great' for leeches, if you ignore bombs like this logging bug destroying Western civilization. Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?

> It has certainly 'worked great' for leeches, And for communities, and for sponsoring companies, and for some (although not all) authors. > if you ignore bombs like this logging bug destroying Western civilization. ...yeah, no; a library had a bug. Somehow, Western civilization is still here. > Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work…

> library had a bug

That was exploited since April

https://github.com/nice0e3/log4j_POC

... this 'bug' is RCE on the logging infrastructure.

> Can you explain why you think the majority of authors/maintainers burn out?

Please try maintaining a popular FOSS project for a few years and explaining to your wife why you neither have any money nor have any time.

Re: Professional maintainers: a wake-up call

#303
post #263
post #260

Earlier quoted context omitted.

I think the point is that while it would be awesome to just have everyone pay open source maintainers what they can afford to when they use their project, in practice relying on people's (or worse, companies') good will is a losing strategy. It seem wildly unrealistic to just expect that everyone will just naturally give back to open source in a meaningful way absent any actual incentives or requirements, and even if…

You're largely correct, but I'm not speaking about peer pressure. 'Tis the season, so we've been listening to a lot of Christmas carols. One of my favorites is Good King Wenceslas, which concludes with the verse: "Therefore, Christian men, be sure, wealth or rank possessing, Ye who now will bless the poor, shall yourselves find blessing." Charity used to be a behavioral expectation in the West. Charity is not "giving…

Such a license doesn't seem likely to fit the Open Source Definition.

Re: Professional maintainers: a wake-up call

#304
post #12

I feel like the examples of log4j and ua-parser aren't that great, because it would be relatively easy for any other similar lib to take their place, as it's mostly straightforward to implement, even though it still takes time. But there are some things like Kafka, PostgressSQL, Spring Boot, Tomcat, Apache Math, ZooKeeper, the OpenJDK, and all that which are definitely non-trivial and a huge amount of time and effort…

>I feel like the examples of log4j and ua-parser aren't that great, because it would be relatively easy for any other similar lib to take their place Log4j is a good example, anyway. It's an old library, very old. And a lot of other software depends on it. So the effort of replacing log4j is not proportional to it's feature list, but rather to the feature list times the number of projects already depending on it. (Th…

I tend to use Logback for new code an the slf4j log4j bridge when an old library (usually Hadoop) likes log4j. Log4j hasn't been the first choice in Java logging for a while.

Re: Professional maintainers: a wake-up call

#305
post #249

Earlier quoted context omitted.

> "you owe nothing and can do with it what you wish: sell it, fork it, modify it" in exchange for "the author provides no guarantees and is not liable for this software". This is demonstrably not how many people many treat open-source authors. Just look at how the Log4J folks are feeling right now: https://twitter.com/yazicivo/status/1469349956880408583 I do have some open-source code out there where people have been…

the text of the tweet: > Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. Why don't they 'resolve' the security issue by removing the feature and then set up a bug bounty for backporting fixes…

So your proposed solution is for the open source maintainers to release a hotfix build and to put up their own money to host a bug bounty program so someone else can fix it?

Re: Professional maintainers: a wake-up call

#306

Earlier quoted context omitted.

It has certainly 'worked great' for leeches, if you ignore bombs like this logging bug destroying Western civilization. Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?

Do you pay for every piece of Open source software you use? How much? What is the criteria you use to determine how much you want to give them? Yes, it would be very good if more people started to contribute to software they depend on, but to call them "leeches" is not only against the spirit of free software, it is counterproductive as it will probably lead people to the idea that proprietary/closed source is better…

> pay for every

No... projects want contribution more than money, the idea of paying the author is that they can then continue to contribute in the long term by proxy for the payers.

But FOSS-systemwide, I give much more than I take. It just needs leechers, who systemwide, give nothing back, to do the same.

Re: Professional maintainers: a wake-up call

#307
post #84

Earlier quoted context omitted.

> So, large SV companies and startup should also start agreeing to pay for open source, when it's the core of the tech. Companies usually have a reason to keep their expenses low. Sometimes they are a public company with fiscal responsibilities. A startup will only have so much runway and is likely trying to reduce expenses. Given this situation, why will they pay for what they can get for free?

It seems like you haven't quite got the concept of open source. If everybody consumes and nobody contributes, how long will that last? A while back I bought a cheap robot vacuum. Their scheduling feature didn't meet my needs, so I reverse-engineered the protocol and open-sourced a cron-friendly CLI tool and a library so people could do other things with it: https://github.com/wpietri/sucks Honestly, this was a mistak…

[deleted]

Re: Professional maintainers: a wake-up call

#308
post #263
post #260

Earlier quoted context omitted.

I think the point is that while it would be awesome to just have everyone pay open source maintainers what they can afford to when they use their project, in practice relying on people's (or worse, companies') good will is a losing strategy. It seem wildly unrealistic to just expect that everyone will just naturally give back to open source in a meaningful way absent any actual incentives or requirements, and even if…

You're largely correct, but I'm not speaking about peer pressure. 'Tis the season, so we've been listening to a lot of Christmas carols. One of my favorites is Good King Wenceslas, which concludes with the verse: "Therefore, Christian men, be sure, wealth or rank possessing, Ye who now will bless the poor, shall yourselves find blessing." Charity used to be a behavioral expectation in the West. Charity is not "giving…

>Charity is not "giving money to somebody else so they can do charity on your behalf" nor is it "paying taxes to fund social programs". Charity is you, directly, investing your resources in your community, with no expectation of return.

Can you give some concrete examples? Because I can't tell what distinction you are trying to define, at all.

In which bucket would you put:

   1) Giving money to a local hospital
   2) Volunteering with a non-profit organization
   3) Giving cash to a wandering schizophrenic
   4) Buying lunch for someone who's been holding up a cardboard sign at an off-ramp
   5) Giving money to the United Way through paycheck deductions.
   6) Giving money to an organization that funds research into a disease
   7) Giving money to a local organization that gives grants and loans to disadvantaged people to start small businesses.
   8) *Lending* money to a local non-profit that gives loans to disadvantaged people to start small businesses.
   9) Giving money to a local food bank.
   10) Donating blood to the Red Cross
   11) Giving money to the Red Cross

Re: Professional maintainers: a wake-up call

#309
post #208

Earlier quoted context omitted.

Open source developers can still release things to everyone for free. Seems fair to say that companies derive value from open source in proportion to their scale. How about a $1m value generated threshold before it's considered impolite for a company to not at least give a little something back?

Ultimately these tools have already been released for free so asking for a rent seeking style payment after the fact is a little bit like sour grapes. What stops me from just forking the project? Really nothing. If anything open source maintainers that want to get paid should look into a model that mirrors the bug bounty programs. Have bounties for features. Generally these projects only really need security updates.

What stops a company from forking and paying 200,000 a year for someone to maintain vs paying 20,000 back? Money.. cheaper to support than fork.

Re: Professional maintainers: a wake-up call

#310

Earlier quoted context omitted.

It has certainly 'worked great' for leeches, if you ignore bombs like this logging bug destroying Western civilization. Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?

I have no sympathy for maintainers who give away their work for $0 and the act all surprised when the world pays $0 for it and value it at $0. Wake up! Look around and notice how the world actually works and act accordingly. If you want people to pay real $ for your work then make that the price tag.

If you want endless unmaintained security apocalyse -ware at all levels of your organization, just keep using FOSS dependencies while explaining to yourself you don't have to contribute anything back.

"Look around and notice how the world actually works"...

Post reply on HN