> If log4j2 is responsible for your company's success, you have a moral obligation to donate to the person who creates this library thanklessly. That's a big if, log4j is a logging library after all. This is an understandable position to hold for other types of dependencies (think react, database, UI components etc.) but the logging library is very far down in the ordered set of projects I'd donate to. I will however…
> If you offer your software at no charge, you shouldn't be surprised if people accept that offer. So I even disagree with the "moral obligation" Sure, but don't complain then, if it doesn't work, or you get hacked using it. You get what you pay for. Nor should you be surprised if eventually, no one decides to "give you for free" something you value so little.
“Open source” is broken
271–280 of 357 posts
Re: “Open source” is broken
#272Earlier quoted context omitted.
Yes it's broken, But not because of open-source philosophy itself but because corporations are greedy and general consumers are largely poor.
And you’ve concluded that those things don’t have a causal relationship?
Re: “Open source” is broken
#273The market value of an open source library is the price you’d have to pay to replace it. How much would it cost Google to hash out a minimum viable rewrite of log4j2? Probably not much. Why don’t they? Because the cost of just using log4j2 is 0… until it isn’t. The externalities of the damage caused were never priced into that zero dollar price. I think about this every single time I depend on a third party library.…
> The market value of an open source library is the price you’d have to pay to replace it. Nope not at all. As long as somebody is willing to provide the code for $0 then the market value is $0. It is basic economics. The value of something is whatever you can get somebody to pay for it.
Re: “Open source” is broken
#274Earlier quoted context omitted.
It's not flame-bait. We, as a society that values FOSS, should fund it, but not at the personal level of "I use this software so I'll pay for its license". FOSS licenses should state nothing about paying for the software. You should not feel bad because you are not paying FOSS at the individual level. Taxes and allocation of funding at a societal level might indeed be the answer.
People that are not software engineers would not support it though, right?
Re: “Open source” is broken
#275Earlier quoted context omitted.
Right … open source doesn’t guarantee an absence of problems, only that, in the worst case, a user can repair a problem herself. As you note, that’s strictly preferable to closed source, where a problem with a dependency is not guaranteed to be fixable by the user. Isn’t that enough?
That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.
As an individual user, you shouldn't be required to. It's not how or why the project started, anyway. Maybe big companies whose system depend on log4j could fund it, yes.
> what amounts to slave labor
That kind of hyperbole doesn't help the discussion. The situation is nothing at all like slave labor.
Re: “Open source” is broken
#276I seriously doubt that open-source is broken. What is broken is companies using open-source to build their products, expanding to billion dollars total revenue and not giving anything back in the long run. This will - as shown in the latest example - come back to bite them. It's the classic tragedy of the commons; everyone is willing to profit from the public good and nobody is willing to invest resources into it.
If you provide work/code for $0 then you yourself signal that your work is worth $0. So why should companies spend more than $0 on your work? If you truly think your work is worth more than $0 then put that in your licence for companies. It isn’t rocket science.
It's part of the capitalistic delusion that only what a price label has attached has worth; you are conflating "worthless" with "priceless".
Re: “Open source” is broken
#277Earlier quoted context omitted.
Right … open source doesn’t guarantee an absence of problems, only that, in the worst case, a user can repair a problem herself. As you note, that’s strictly preferable to closed source, where a problem with a dependency is not guaranteed to be fixable by the user. Isn’t that enough?
That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.
Re: “Open source” is broken
#278Earlier quoted context omitted.
That is not sufficient no. As a user, I want to be able to support developers so they have the time to fix things that go wrong. That the log4j Maintainers are entirely unpaid for maintaining what amounts to the bedrock of the java ecosystem is a tragedy and that people continue to argue that this is how it should be are simply exploiting what amounts to slave labor.
You have zero clue about what slave labour is.
Re: “Open source” is broken
#279Why would you release your code open source and then expect to get paid for it?
Also if you are the author of such an important open source library and you can't get a paid job as a software dev than there just must be something off-putting about you.
Re: “Open source” is broken
#280Earlier quoted context omitted.
I think this argument massively ignores the underlying message of this blogpost: addressing that the human beings that make and use software aren't always treated as, well, human beings. > A maintainer goes to jail for vehicular manslaughter and a bugs needs fixing, no problem The author didn't seem to hint that open bugs in core-js or its usefulness to its community of users are / is problematic. They hinted that ma…
ESR doesn't get to decide how it works; the revealed preferences of the participants do. And those revealed preferences are that everyone pretty much does what they want, and nobody owes anybody anything. And it seems to have clearly created a vibrant ecosystem. If you're in it for money or the fame, you're going to end up very unhappy. If you prioritize OSS work above addressing your real life problems, you're going…
In the past, I've made comments that open source isn't a business model. It's a licensing model which governs intellectual property.
My comment, however, isn't addressing maintainers. It's addressing their audience and their behavior: anyone who uses and leverages open source code without consideration of the labor that goes into it, which is a big difference.
ESR is absolutely right when he points out that anyone who shares creative work also shows themselves vulnerable when it comes to reputation, good name and public perception. Sure, you could use the argument that "open source doesn't make any promises regarding support". But that still doesn't excuse the entitlement and indifference.
If you can happily ignore it, that's great for you. Calling it out for what it is, however, isn't any less valid a way of responding. Even when it's just a hobby project and you don't get paid.
Every so often, there's a case where a small open source project with limited maintenance ends up being leveraged by entire industries with interests worth billions. When things fall apart, media outlets and pundits will report about the failings of that small project and how it affects big interests, but they won't point out the elephant in the room: how these projects are maintained by a skeleton crew working in their spare time.
The Ars Technica article is an example of this:
https://arstechnica.com/information-technology/2021/12/minec...
At most, the lack of due diligence of these big passive players gets called out, like in this Wired article:
https://www.wired.com/story/log4j-flaw-hacking-internet/
Sure, none of this is going to awaken people's minds to be more apprehensive or more empathic to the challenges of maintaining a popular OSS project. The value proposition of being able to leverage free labor is simply too attractive.
Meanwhile though, the log4j maintainers are now stuck being perceived as not having done enough to avoid these kinds of bugs. Whether that's trough investing "enough" time, making the "right" calls (whatever those are) or finding "appropriate sources of funding" for themselves. Thousands of engineers are scrambling to roll out fixes upstream. And millions of end users merely learn how "a software bug almost breaks the Internet and Minecraft."
Ultimately, nobody gains from these disasters as a result of a lack of assuming shared responsibility for a common good.