Live data from Hacker News

“Open source” is broken

christine.website

271–280 of 357 posts

Re: “Open source” is broken

#271
post #240

> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly. That's a big if, log4j is a logging library after all. This is an understandable position to hold for other types of dependencies (think react, database, UI components etc.) but the logging library is very far down in the ordered set of projects I'd donate to. I will however…

> If you offer your software at no charge, you shouldn't be surprised if people accept that offer. So I even disagree with the "moral obligation" Sure, but don't complain then, if it doesn't work, or you get hacked using it. You get what you pay for. Nor should you be surprised if eventually, no one decides to "give you for free" something you value so little.

Of course I can't expect anything. But paid software has critical security vulnerabilities too.

Re: “Open source” is broken

#272

Earlier quoted context omitted.

Yes it's broken, But not because of open-source philosophy itself but because corporations are greedy and general consumers are largely poor.

And you’ve concluded that those things don’t have a causal relationship?

I don't get you, But I hope it's gibe at 'Late Stage Capitalism'.

Re: “Open source” is broken

#273

The market value of an open source library is the price you’d have to pay to replace it. How much would it cost Google to hash out a minimum viable rewrite of log4j2? Probably not much. Why don’t they? Because the cost of just using log4j2 is 0… until it isn’t. The externalities of the damage caused were never priced into that zero dollar price. I think about this every single time I depend on a third party library.…

> The market value of an open source library is the price you’d have to pay to replace it. Nope not at all. As long as somebody is willing to provide the code for $0 then the market value is $0. It is basic economics. The value of something is whatever you can get somebody to pay for it.

Ahem, consider a hypothetical situation where the $0 version has an RCE :)

Re: “Open source” is broken

#274
post #244
post #146

Earlier quoted context omitted.

It's not flame-bait. We, as a society that values FOSS, should fund it, but not at the personal level of "I use this software so I'll pay for its license". FOSS licenses should state nothing about paying for the software. You should not feel bad because you are not paying FOSS at the individual level. Taxes and allocation of funding at a societal level might indeed be the answer.

People that are not software engineers would not support it though, right?

They benefit from FOSS as well, so maybe if we could do some adovacy. After all, I support paying taxes and funding stuff that doesn't directly benefit me.

Re: “Open source” is broken

#275
post #263

Earlier quoted context omitted.

Right … open source doesn’t guarantee an absence of problems, only that, in the worst case, a user can repair a problem herself. As you note, that’s strictly preferable to closed source, where a problem with a dependency is not guaranteed to be fixable by the user. Isn’t that enough?

That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.

> As a user, I want to be able to support developers so they have the time to fix things that go wrong.

As an individual user, you shouldn't be required to. It's not how or why the project started, anyway. Maybe big companies whose system depend on log4j could fund it, yes.

> what amounts to slave labor

That kind of hyperbole doesn't help the discussion. The situation is nothing at all like slave labor.

Re: “Open source” is broken

#276
post #5

I seriously doubt that open-source is broken. What is broken is companies using open-source to build their products, expanding to billion dollars total revenue and not giving anything back in the long run. This will - as shown in the latest example - come back to bite them. It's the classic tragedy of the commons; everyone is willing to profit from the public good and nobody is willing to invest resources into it.

If you provide work/code for $0 then you yourself signal that your work is worth $0. So why should companies spend more than $0 on your work? If you truly think your work is worth more than $0 then put that in your licence for companies. It isn’t rocket science.

Human society has for thousands of years relied on unpaid voluntary labor. Be it taking care of the elderly, taking care of the sick and the poor, managing public spaces, organizing festivals, on and on and on. Human society is built on voluntary participation much more than on monetary incentives.

It's part of the capitalistic delusion that only what a price label has attached has worth; you are conflating "worthless" with "priceless".

Re: “Open source” is broken

#277
post #263

Earlier quoted context omitted.

Right … open source doesn’t guarantee an absence of problems, only that, in the worst case, a user can repair a problem herself. As you note, that’s strictly preferable to closed source, where a problem with a dependency is not guaranteed to be fixable by the user. Isn’t that enough?

That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.

You have zero clue about what slave labour is.

Re: “Open source” is broken

#278
post #263

Earlier quoted context omitted.

That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.

You have zero clue about what slave labour is.

I have plenty of clues of what slave labor is and big companies exploiting the hard work of people working for free without paying them is definitely pretty damn close.

Re: “Open source” is broken

#279
I understand everyone who wants $$ for his time writing code, but this article makes no sense.

Why would you release your code open source and then expect to get paid for it?

Also if you are the author of such an important open source library and you can't get a paid job as a software dev than there just must be something off-putting about you.

Re: “Open source” is broken

#280

Earlier quoted context omitted.

I think this argument massively ignores the underlying message of this blogpost: addressing that the human beings that make and use software aren't always treated as, well, human beings. > A maintainer goes to jail for vehicular manslaughter and a bugs needs fixing, no problem The author didn't seem to hint that open bugs in core-js or its usefulness to its community of users are / is problematic. They hinted that ma…

ESR doesn't get to decide how it works; the revealed preferences of the participants do. And those revealed preferences are that everyone pretty much does what they want, and nobody owes anybody anything. And it seems to have clearly created a vibrant ecosystem. If you're in it for money or the fame, you're going to end up very unhappy. If you prioritize OSS work above addressing your real life problems, you're going…

You're addressing maintainers who somehow arrive at open source with expectations which set them up for failure and disappointment. I can agree with you there.

In the past, I've made comments that open source isn't a business model. It's a licensing model which governs intellectual property.

My comment, however, isn't addressing maintainers. It's addressing their audience and their behavior: anyone who uses and leverages open source code without consideration of the labor that goes into it, which is a big difference.

ESR is absolutely right when he points out that anyone who shares creative work also shows themselves vulnerable when it comes to reputation, good name and public perception. Sure, you could use the argument that "open source doesn't make any promises regarding support". But that still doesn't excuse the entitlement and indifference.

If you can happily ignore it, that's great for you. Calling it out for what it is, however, isn't any less valid a way of responding. Even when it's just a hobby project and you don't get paid.

Every so often, there's a case where a small open source project with limited maintenance ends up being leveraged by entire industries with interests worth billions. When things fall apart, media outlets and pundits will report about the failings of that small project and how it affects big interests, but they won't point out the elephant in the room: how these projects are maintained by a skeleton crew working in their spare time.

The Ars Technica article is an example of this:

https://arstechnica.com/information-technology/2021/12/minec...

At most, the lack of due diligence of these big passive players gets called out, like in this Wired article:

https://www.wired.com/story/log4j-flaw-hacking-internet/

Sure, none of this is going to awaken people's minds to be more apprehensive or more empathic to the challenges of maintaining a popular OSS project. The value proposition of being able to leverage free labor is simply too attractive.

Meanwhile though, the log4j maintainers are now stuck being perceived as not having done enough to avoid these kinds of bugs. Whether that's trough investing "enough" time, making the "right" calls (whatever those are) or finding "appropriate sources of funding" for themselves. Thousands of engineers are scrambling to roll out fixes upstream. And millions of end users merely learn how "a software bug almost breaks the Internet and Minecraft."

Ultimately, nobody gains from these disasters as a result of a lack of assuming shared responsibility for a common good.

Post reply on HN