Live data from Hacker News

Professional maintainers: a wake-up call

blog.filippo.io

361–370 of 464 posts

Re: Professional maintainers: a wake-up call

#361

Earlier quoted context omitted.

Just because a blob of code is free doesn’t mean the support is free, and it has been this way for a very long time. Have you ever seen how much an email-only 1-year support contract from ISC costs (clue: Five figures)? In the real world, free but pay for support is a reasonable expectation. RedHat has been doing it since 1993. Even with end user software, freemium has been a thing for quite a while. I see from your…

> I can’t be sure you’re not trolling; I will assume good faith and think you actually believe this ridiculous argument. OK and I will assume you are not trolling and that your explanations of things I already understand was done with good intentions and not being condescending. You clearly don't understand my argument and are offering a straw man interpretation. So in the spirit of explaining things, let me try agai…

Thank you for the reply, but you didn’t address the point I am making.

My argument is this: People are unreasonable when they expect free hand-holding support just because the software is free. I never argued in this thread that people should pay for my open source software. What I am saying is that people are being unreasonably entitled when they expect to also have free professional level support (e.g. private email support), using ISC and RedHat as real world examples where open source software is free, but professional support costs real money, e.g. https://www.isc.org/support/

If you try to tell the ISC that their gold level support should be free using the trollish [1] logic that, since the software is free, it has no value, so the support also has no value and should also be free, they will politely and professionally laugh in you face.

Ignoring the fact that free market fundamentalism [2] requires have a lot of holes in one’s logic to believe (roads, police, and, in most first world countries, medical care)—that’s another discussion for another day—there exists, in today’s free market, free software without free support.

Now, in terms of whether we would be in a better world today if those “no commercial use” licenses were not excluded from open source around two decades ago—I remember the KDE-vs-Gnome flame wars all too well, as well as the BitKeeper license flame wars which resulted in Git—I agree that is a legitimate point, but that ship sailed out to sea a long time ago. There’s also the ethical issue of FOSS developers who give away their code, but then turn around and complain that those with big pockets should pay them. Both of these issues have nothing to do with the issue I am bringing up: Free software != free support, as much as entitled users wish to think otherwise.

[1] Trollish, because telling open source developers that their software has no worth comes awfully close to the “no personal attacks” rules ycombinator has.

[2] There are a lot of free market fundamentalists out there that think the free market will magically solve all problems. Maybe you’re not one of them, but with all this going on about how something which costs $0 has no value, that comes off as free market fundamentalism to me.

Re: Professional maintainers: a wake-up call

#362
post #220

Earlier quoted context omitted.

That's how it is most of the time but I don't see how you can say it's "supposed to" be that way. It's pathological. Essentially it's a form of group sociopathy.

Supposed as per economical theory/ideology, legal expectations and also per "what kind of CEO will get the job". It is not like most of the time randomly. It is like that, because economic system is designed to work that way.

> It is like that, because economic system is designed to work that way.

"Designed" is probably putting it too strongly. But however you characterize the process that got it that way, people did it, and people can change it with enough effort. In fact it is constantly changing, and each of us can decide the direction we are going to push it, and how hard.

"And friends, they may thinks it's a movement." — Arlo Guthrie, Alice's Restaurant Massacree

Re: Professional maintainers: a wake-up call

#363

Earlier quoted context omitted.

This might sound weird, but I find every time someone publishes or contributes open source, they are stealing value from me, because it is one less thing that a company will need me to implement, build and maintain for them, instead they'll now expect me to simply use the existing free of charge open source one. Not only does it feel like I'm stolen value, open source work tends to be the most interesting, and as mor…

This is just the broken window fallacy. Hobbyists giving away schematics for unbreakable windows are not stealing from your window repair business. Yes, having open source competition means you'll have to either build a superior product that customers are willing to pay for, or find another niche. That's a good thing.

> This is just the broken window fallacy. Hobbyists giving away schematics for unbreakable windows are not stealing from your window repair business.

Of course, the smart glazier would figure out that giving away the schematics for a window-breaking device is in their interest.

Commoditize your complements, as the saying goes.

Re: Professional maintainers: a wake-up call

#364
post #249

Earlier quoted context omitted.

the text of the tweet: > Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. Why don't they 'resolve' the security issue by removing the feature and then set up a bug bounty for backporting fixes…

Can anyone recommend a service that allows people to back specific GitHub issues (pledge money) other than Bountysource?

You don’t really need a service, you can just post in the issue “I will pay $X for a merged PR that closes this issue.”

Re: Professional maintainers: a wake-up call

#365
post #74

> Now is the perfect time for Open Source maintainers to become legible to the big companies that depend on them—and that want to get more out of them—and send them five-to-six figure invoices. Well, this is exactly what I've been doing around VideoLAN (VLC, x264) and FFmpeg for the last few years. In order to do that, I've created 2 official companies Videolabs and FFlabs (besides the non-profit orgs) and I've gone…

Thanks for sharing, Couldn't have asked for someone with better authority for an open-source project vital for both business and end-users; Payments from the latter can be excused as they're largely poor but we need better ways to make the greedy corporations pay.

Many open-source project maintainers wouldn't go to the length of setting up companies like you've done, The paper work and compliance don't cut slack for building an open-source product.

Perhaps there's a need-gap for services which maintain those for open-source projects and acts as a middle-men between the maintainers and the Account Payable of companies?

Re: Professional maintainers: a wake-up call

#366
post #364

Earlier quoted context omitted.

Can anyone recommend a service that allows people to back specific GitHub issues (pledge money) other than Bountysource?

You don’t really need a service, you can just post in the issue “I will pay $X for a merged PR that closes this issue.”

Commenting may work if the issue has one or two large backers that can independently be vetted to be trustworthy. But if there are several dozen small backers, having to track them all down after closing the issue seems less than ideal.

Re: Professional maintainers: a wake-up call

#367
post #354

Earlier quoted context omitted.

Your view of the "nativity of open source developers" is itself naïve. To my understanding, most people who want to get paid a reasonable amount to develop FOSS go one of two routes. 1) Service-oriented, à la the Cygnus Solutions (now Red Hat) approach. FOSS developers get paid to fix bugs, add features, answer questions, and provide training. This has been my approach. 2) Employer cost savings. Work as an employee f…

I think you are slightly misunderstanding my point. I love OSS. I am a big fan. What I am not a fan of is maintainers giving their work away for $0 and then complaining that nobody pays them $ for their work. That is what I call naive. It shows a complete lack of understanding of how humans and markets work. If you want to be paid $ for your OSS work then make it part of the license and sue companies that doesn't pay…

And what I am complaining about is that NOTHING in my comment had anything do with "giving their work away for $0 and then complaining that nobody pays them $ for their work."

Moreover, the linked-to essay even called out services which companies COULD pay for.

Re: Professional maintainers: a wake-up call

#368
post #51

Can someone help me find whos idea was it? Basically kill free open source. Make every "new open source" (NOS) program dual licensed, free for non commercial use and paid for conmercial use. He proposed companies paying 1% of revenue to license this software. But it would all go through a proxy company that would gather payment and send it to participating companies, I dont remember how it would be split. I think thi…

Doesn’t answer your question but something I’ve wondered about as well. I don’t maintain any open source software (yet?) but if I were to start a project I’d likely use a permissive license. I don’t want to start a philosophical flame war about licenses, but this idea makes sense to me. The details will likely take work to iron out, but why not have open source licenses with a clause for companies with over a certain…

What you're describing is not an open source license. You seem to be looking for something akin to the Unreal Engine license, which Wikipedia describes as "source-available commercial software."

Re: Professional maintainers: a wake-up call

#369
post #74

> Now is the perfect time for Open Source maintainers to become legible to the big companies that depend on them—and that want to get more out of them—and send them five-to-six figure invoices. Well, this is exactly what I've been doing around VideoLAN (VLC, x264) and FFmpeg for the last few years. In order to do that, I've created 2 official companies Videolabs and FFlabs (besides the non-profit orgs) and I've gone…

> and I've gone through all the hoops to get paid (PO, billing, invoices, registering to large companies is a lot of paperwork, tbh, but well..) and we try and bill small to large companies that depends on those projects.

I see an opportunity to create a "create-a-company"-as-a-service, to help tons of other maintainers to do this with ease.

Re: Professional maintainers: a wake-up call

#370
I can make an argument that money will make it even worse, as people will full-time make even more useless features that just increase the attack surface.

This particular class of problems (same as the sqlite fts tokenizer exploit and most of openssl exploits, even lots of the sendmail exploits) are just obscure unused features. It happens even in CPUs themselves. (e.g. https://www.youtube.com/watch?v=lR0nh-TdpVg)

Removing code is twice harder than adding code, why do you think paid maintainers would improve anything? Just look at the code written in FAANG or any enterprise, and those maintainers are very well paid, imagine this code being public, we will have 1 new exploit per day per company... and that is assuming non malicious developers that can be shipping trojan code https://lwn.net/Articles/874951/ (it is also hard to assume all millions of developers are non malicious, even if we assume 1 in 100000, things look really bad)

Less code is the one solution. Regardless if open source or enterprise code.

We are stuck, and change is needed, but money is not a solution, and might even be the cause of the problem. (incentive to write more code)

Post reply on HN