Live data from Hacker News

“Open source” is broken

christine.website

231–240 of 357 posts

Re: “Open source” is broken

#231

Earlier quoted context omitted.

Yes it's thriving, but it's also broken. From a tweet[1] cited in the article: > This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. > "I work on Log4j in my spare time" > "always dreamed of working on open source full time" > "3 sponsors are funding @rgoers's work: Michael, Glenn, Matt" [1]: https://twitter.com/FiloSottile/status/1469441487175880711

No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan. Making and maintaining a piece of software and giving it away for free isn't a great business plan, or at best it's an incomplete one.

But what is broken is the disconnect between providing value and being able to earn a living from that value. More often than not, any "business plan" involves providing a worse product, because the product must be compromised to enable the business plan.

SaaS for things that could be run locally is a perfect example. Or algorithmic feeds optimized for engagement in social media. Or the advertising panopticon. Or coffee filter DRM. Or smart TV spying. Or ads in the Windows start menu. Or..

Re: “Open source” is broken

#232
post #2

It's not "Open Source" (making code public and free to use and modify) that's broken. It's how people rely on it without any consideration about the sourcing of it. It's not that it's free to pick and to use. It's that some/most people too often associate "it's free" to be equivalent to "I don't need to care about it, like, at all". It's that some/most people don't understand that, whatever they take, they become dep…

It absolutely is $0 free to pick and use. So that’s what people/companies will obviously do. Why should they pay more than $0 for something that is worth $0 in the market place?

It's common enough to see the phrases "'free' as in 'free beer'" puts it in contrast to "'free' as in 'free speech'" (which emphasises you can do what you want with the software).

Following in popularity from these is "'free' as in 'free puppy'"; which emphasises that you'd be taking on a burden of responsibility by using it. -- At the very least, if you're using it, it may have bugs.

Re: “Open source” is broken

#233
What if software engineers started asking companies during the hiring phase, "Do you offer an open source purse as a benefit, so I can contribute to projects I believe in or that may be benefiting the company?"

I think software engineers have some leverage here, because what company doesn't want to prove they are values-aligned with their engineers?

Re: “Open source” is broken

#234

Earlier quoted context omitted.

> The culture of companies -- nearly all of them, including the one I work for -- that freeload off this work is what's broken. Absolutely. Originally, we had free as in freedom software. Then businesses did their best to redefine it as free as in free labor software. That's the entirety of the anti-GPL movement. The thing about the GPL is that you can dual-license your software for companies that don't like the GPL.…

The companies are paying exactly what the price tag says it is worth: $0. What is so surprising about that? If you want companies to not “freeload” then change the price tag for companies.

For the record, that's exactly what I'm saying. Don't use a license that allows freeloading, because if you do, that's what you'll attract.

I disagree with "exactly what the price tag says it is worth: $0". That's not what the price tag says it's worth. They wouldn't be using it unless it was worth a lot more than $0.

Re: “Open source” is broken

#235
post #170
post #135

Earlier quoted context omitted.

But...and bear with me as I'm no JS guy and am unfamiliar with that library...how hard is it for the community to fork it and go on from there? Literally every time I find an esoteric library on Github the first thing I do before forking it or adding it to my dependencies is immediately pull up the "network" tab to see if there's are active branch downstream I should follow. Perhaps Github can do a better job of high…

You can fork it til the cows come home, but everyone downloading core-js off of npm gets the one from upstream.

can't the governance structure of NPM remove and reassign the NPMish "ownership" and authoritative repo to a new fork in circumstances like the maintainer abandoning it, going to jail, being a dumbass or whatever? If NPM is the authority, it's their own rules that would allow/disallow it, right?

(note: I'm unfamiliar with this project, so seriously I'm asking if/why this is an issue)

Re: “Open source” is broken

#236

Earlier quoted context omitted.

> The culture of companies -- nearly all of them, including the one I work for -- that freeload off this work is what's broken. Absolutely. Originally, we had free as in freedom software. Then businesses did their best to redefine it as free as in free labor software. That's the entirety of the anti-GPL movement. The thing about the GPL is that you can dual-license your software for companies that don't like the GPL.…

The companies are paying exactly what the price tag says it is worth: $0. What is so surprising about that? If you want companies to not “freeload” then change the price tag for companies.

I really dislike the way you phrased that. Are you saying that things don't have value unless you have to pay money for them?

Re: “Open source” is broken

#237

Earlier quoted context omitted.

No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan. Making and maintaining a piece of software and giving it away for free isn't a great business plan, or at best it's an incomplete one.

I also wonder about the futility of the statement that someone could cause millions of dollars of damages when those companies elected to depend and build upon truly free software. Free lunches don’t exist for anyone.

Right, if this is a huge problem for these big companies they only have themselves to blame, they decided to use software from a guy who writes it in his spare time.

Re: “Open source” is broken

#238
post #173

Earlier quoted context omitted.

> Can we make fix the places where it's broken? Also, Yes. Two problems: 1. How is it broken? As I and others in this thread attest to, the thing that makes open source so powerful is, in fact, the lack of legal and moral obligation to do anything in exchange for the right to use the software. Not having obligations is a two-way street. Same for donations; donations do not give you any additional assurances. 2. If it…

I feel like a lot of this isn't that individuals are the ones who should be forking over money, but rather corporations who are making tens of millions or billions who rely on this stuff as a core to their stack, but do nothing to support the ecosystem monetarily.

Any large tech company probably uses thousands or tens of thousands of open source components (because the licenses are well understood). Sone even support the projects officially, or unofficially by paying salaries to developers who contribute in their free time.

I like licenses that bind all users equally: whether you're a lone developer, a charity, or developing nukes. If you do not like a certain class of use using your software, then choose a license that matches your philosophy. One shouldn't piggyback on common licenses for popularity and then complain about users keeping to the terms if the license.

Re: “Open source” is broken

#239
post #225

Earlier quoted context omitted.

If you give your work away for $0 then the world will expect to pay $0 for it. That’s it. It isn’t rocket science. If you value your work make companies pay for it.

Doesn't the reverse hold true too? If you rely on software you paid $0 for and it fails you, you got what you paid for.

Exactly, the companies should be blamed for using the software not the maintainer for not catching the bug on his free time.

Re: “Open source” is broken

#240

> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly. That's a big if, log4j is a logging library after all. This is an understandable position to hold for other types of dependencies (think react, database, UI components etc.) but the logging library is very far down in the ordered set of projects I'd donate to. I will however…

> If you offer your software at no charge, you shouldn't be surprised if people accept that offer. So I even disagree with the "moral obligation"

Sure, but don't complain then, if it doesn't work, or you get hacked using it. You get what you pay for. Nor should you be surprised if eventually, no one decides to "give you for free" something you value so little.

Post reply on HN