Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

51–60 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#51
post #5

awkward, but heard very recently that open source is not "vc backable, go away". maybe it will change now, after the infrastructure pillars of the modern world ruins in front of those many saas/ai/web3/cloud/whatever investors

Why should VCs back oss infrastructure directly? It doesn't help the VCs and only creates perverse incentives for the oss projects. The SaaS/cloud/etc. companies themselves should fund the projects they depend on. They actually know what those are and don't have to force their own monetization/growth models onto the projects.

> The SaaS/cloud/etc. companies themselves should fund the projects they depend on.

If anything, the same "valuable" "community" members, a lot of which includes such SaaS businesses and other freeloaders, seems to shout at projects trying to ensure their survival through formal ownership structures and license changes.

Re: Xz: A microcosm of the interactions in open source projects

#52

I'm starting to feel that one of the lessons here is that individuals invited into trusted positions should be identifiable. Jia Tan is not a real person. We don't know who they are, so there is no way to hold them accountable.

No. https://geekfeminism.fandom.com/wiki/Who_is_harmed_by_a_%22R...>

Re: Xz: A microcosm of the interactions in open source projects

#53
>>> Software developers are not fungible cogs that you can swap in and out at will.

I am thinking a lot about this. One of the issues is scale and proof. I suspect that I am interested in introducing gated ability to comment / participate in a community

Say for example github introduces “gates”. The first might be add a test to the test suite that generates a haha of the version number and test output. Then adding that number to your profile means github trusts you have at least downloaded and run make test. It shows some level of commitment. (I suppose the zero level is logging in to github and commenting on some maintainers mental health)

Re: Xz: A microcosm of the interactions in open source projects

#54
I'm under no illusions that this is a totally new thought, but for me first with cryptocurrencies, then "AI", and now this, the fundamental issue that the biggest problems come back to is one of trust. Cryptocurrencies try to code around it, LLM boosters try to dazzle you into it, and the attacker here half-succeeded in laundering it. The most consequential (rightly or wrongly) technologists of our time are failing to properly think about trust. In this case, the failure was 100% understandable – I have all the sympathy for burnt-out and (almost always) unpaid open source developers. In each case, capital either lures people away from thinking about trust, or neglects and exploits people to the point that they're broken down.

Re: Xz: A microcosm of the interactions in open source projects

#55
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

> Even writing it down here I'm worried I sound like I'm trying to curate a closed community of ego-boosting yes men.

There's this weird trend that's been happening for some time now that tries to make non-fully-open groups look wrong, but honestly, has anything ever actually been done by such open groups? As far as I can tell, "closed community" is a necessary (but not sufficient) condition for any kind of quality creative output (this includes individual projects as single-person closed group). Having a core of creators surrounded by distinct group of fans and secondary contributors is a natural organization that forms spontaneously.

Re: Xz: A microcosm of the interactions in open source projects

#56
post #46

I'm starting to feel that one of the lessons here is that individuals invited into trusted positions should be identifiable. Jia Tan is not a real person. We don't know who they are, so there is no way to hold them accountable.

Reputation works with pseudonymous identities too, and those have security upsides (eg can't be as easily pressed into service of others by extortion or rubber hose). And of course privacy is a value in itself.

You can build multiple pseudonymous identities in parallel. If one is burned, it doesn't matter, you still have 9 other.

Re: Xz: A microcosm of the interactions in open source projects

#57
post #9
post #5

Earlier quoted context omitted.

Why should VCs back oss infrastructure directly? It doesn't help the VCs and only creates perverse incentives for the oss projects. The SaaS/cloud/etc. companies themselves should fund the projects they depend on. They actually know what those are and don't have to force their own monetization/growth models onto the projects.

> The SaaS/cloud/etc. companies themselves should fund the projects they depend on. There is a bit of a free rider problem it seems.

Noooooooo you can’t ask them to pay! You’re supposed to do this for the good of the community only! They ought to be able to take whatever you do and resell at their leisure, after all you made it open source!

Re: Xz: A microcosm of the interactions in open source projects

#58
post #39

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

This ignores the very fact that peer pressure works and puts the entire blame on the victim. No, people react differently when pressured vs when not pressured. That's the entire reason why peer pressure works.

Re: Xz: A microcosm of the interactions in open source projects

#59
Some random thoughts:

- every Fortune 500 company tracks exactly which FOSS code it includes in its ecosystem (usually code scanning and fingerprinting - can’t remember the usual Provider of such)

- this is essentially the software BOM that Biden signed a while back.

- this (made public) would give a real time map of the dependancies of all organisations - and linking that to things like the above thread (“cry for help”) would be an interesting place for “intervention” - anything from plain old cash to “here are three interns doing two years in gov.uk. They will help for the next 2 years

(It’s not a great idea that last one but we need to start somewhere- no way can government “pick winners” but also no way can society just sit back and hope. And commercial incentives break this horribly.

Essentially we are going to find at some point we treat some developers like lawyers - this stuff is our societies laws, rules, processes

Re: Xz: A microcosm of the interactions in open source projects

#60
post #39

So the first step of this huge mess was: a social engineering attack. Attacking a tired, burnt-out open source project developer and peer pressuring him into giving more control of the repo to the attacker.

In the end you're only pressured as much as you allow yourself to be pressured. "I don't feel like it, if it's important to you then feel free to fork". That's really all that's needed. "I don't feel like it" is all the justification you need. Some guy just made a compression tool, because some people like doing that kind of thing, or because it was useful for him. He didn't ask to be made "critical infrastructure" o…

"I don't feel like it, if it's important to you then feel free to fork".

That's really all that's needed.

that's much harder than it sounds.

having someone fork your project can give you the feeling of loosing control over the project as potentially all your users might go with the fork. that fear is often strong enough to push yourself to do things that will avoid a fork.

it's a desire for harmony and a fear of conflict

Post reply on HN