Live data from Hacker News

Single vendor is the new proprietary

opensource.net

51–60 of 98 posts

Re: Single vendor is the new proprietary

#51

I somehow still don’t get what single vendor open source code is, even after reading the article. Is it code that is open source but the license says “no forking.” And maybe the license says they are allowed to fork it and chance the license to proprietary? Or is it code that is open source, but nobody has ever bothered to fork it. With the potential spin that sometimes code is just so specific that nobody would both…

Take Hashicorp's Terraform as an example. Until recently, the code was completely open source with a permissive license. You could do exactly as you like with it. The 'single vendor' decided that was no longer in their best interests. What's the problem? Now you have 1000's of companies that rely on this software, and if they want to continue to receive security updates, they need to comply with the new license. Of c…

[deleted]

Re: Single vendor is the new proprietary

#52

I somehow still don’t get what single vendor open source code is, even after reading the article. Is it code that is open source but the license says “no forking.” And maybe the license says they are allowed to fork it and chance the license to proprietary? Or is it code that is open source, but nobody has ever bothered to fork it. With the potential spin that sometimes code is just so specific that nobody would both…

Take Hashicorp's Terraform as an example. Until recently, the code was completely open source with a permissive license. You could do exactly as you like with it. The 'single vendor' decided that was no longer in their best interests. What's the problem? Now you have 1000's of companies that rely on this software, and if they want to continue to receive security updates, they need to comply with the new license. Of c…

And then you have the look and "you can touch if you give away all rights for what you contribute". Contributor License Agreements where basically you contribute to a "GPL" project, but you sign away the rights to your contribution to the company, so they can still close source it any time they please while including your code.

Re: Single vendor is the new proprietary

#53
post #43
post #38

Earlier quoted context omitted.

> re: things being produced as their exclusive property, what is the issue with this? They did the work to make the thing, therefore it's their property (unless they choose to release it otherwise). the issue is that they also want the benefit of not being ignored, so they claim to be less proprietary than they actually are while trying to build mindshare

> the issue is that they also want the benefit of not being ignored So in order to get any interest in your project, you have to be open source (and align with the ideology absolutely)?

I don’t think this was intended to be a normative statement. Just an observation that “open source as marketing” seems to work, so people use it despite it not actually being true of their project.

Re: Single vendor is the new proprietary

#54
Single-vendor is not proprietary because I can fork VSCode and I can't fork Microsoft Word.

Single-vendor open source is the balance some companies have found between sharing their software with the community and capturing the value of their employees' labor. It's less free than openly developed FOSS and more free than proprietary software. It's unrealistic to expect all software to be openly developed FOSS with today's economics; the hundreds of thousands of contributors to single-vendor open source projects all need rent money, and you can't build a business on providing the open-source backend for AWS managed services.

Companies will move up and down the freedom gradient depending on their needs at any given time. Sometimes they do it well, and sometimes they handle it in a kludgy and myopic way (I'm looking at you, HashiCorp). LinkedIn open-sourced Kafka, and Elastic restricted their license for ElasticSearch. Software doesn't always go from "more free" to "less free."

Re: Single vendor is the new proprietary

#55

Single-vendor is not proprietary because I can fork VSCode and I can't fork Microsoft Word. Single-vendor open source is the balance some companies have found between sharing their software with the community and capturing the value of their employees' labor. It's less free than openly developed FOSS and more free than proprietary software. It's unrealistic to expect all software to be openly developed FOSS with toda…

You can't forkvscode...

Re: Single vendor is the new proprietary

#56
post #55

Single-vendor is not proprietary because I can fork VSCode and I can't fork Microsoft Word. Single-vendor open source is the balance some companies have found between sharing their software with the community and capturing the value of their employees' labor. It's less free than openly developed FOSS and more free than proprietary software. It's unrealistic to expect all software to be openly developed FOSS with toda…

You can't forkvscode...

https://github.com/microsoft/vscode/forks

27,000 people seem to have done so.

Re: Single vendor is the new proprietary

#57
post #48
post #27

Earlier quoted context omitted.

The author is not so much against proprietary software, as bait-and-switch tactics that present software as open source. > Anyone who truly thinks that software developed by a diverse set of actors working in an open collaboration is not better should just adopt the proprietary model. But they should be honest about it.

I don’t see how it’s bait and switch. You can still used and develop against the last open version. In fact, we’ve seen recent examples of that in Terraform and Redis. Open source does not mean you are entitled to all future improvements unless the license says you are, like the AGPL. Personally, I’m grateful these project made their source open for so long. The alternative would not be AGPL terraform, it would be co…

It probably feels like bait and switch for the folks that created or used lots of open source in the time period where there was less opportunity/temptation to move the license from GPL/BSD/MIT to something proprietary. In our minds, we attached some altruistic intent to those licenses. Things have changed now, of course.

Re: Single vendor is the new proprietary

#58
post #48
post #27

Earlier quoted context omitted.

The author is not so much against proprietary software, as bait-and-switch tactics that present software as open source. > Anyone who truly thinks that software developed by a diverse set of actors working in an open collaboration is not better should just adopt the proprietary model. But they should be honest about it.

I don’t see how it’s bait and switch. You can still used and develop against the last open version. In fact, we’ve seen recent examples of that in Terraform and Redis. Open source does not mean you are entitled to all future improvements unless the license says you are, like the AGPL. Personally, I’m grateful these project made their source open for so long. The alternative would not be AGPL terraform, it would be co…

I’d also go as far as saying most of the value added to these open core projects is contributed by employees of the companies themselves. The fact that they do it out in the open with the possibility of someone else forking it is a plus, we shouldn’t want this to be solely proprietary. Hashicorp paid for a lot Terraform’s development for instance. Microsoft is paying top computer scientists to develop an editor

Re: Single vendor is the new proprietary

#59
post #23

> You should be on board if you want Open Source to win against proprietary software. But those companies are still doing what is, essentially, proprietary software: like the proprietary software companies of the 80s, they very much consider the software being produced as their exclusive property. They still intend to capture all the value that derives from it. And thanks to copyright aggregation or permissive licens…

> why does open source need to "win"

Open source does not need to win.

But your ability to be in control of your computer needs to be preserved (restored?). A proprietary fridge cannot control your diet, while a proprietary App Store can control what software you install on YOUR phone (unless you live in EU, hello DMA!). The tail wagging the dog, so to speak. Proprietary software has also been shown to break user workflows or remove functions in an update while leaving users with no choice whatsoever.

One alternative to having open source win is to ensure software comes with a robust warranty and other assurances you expect from the things you buy (like the ability to resell it etc.). EU's CRA will make software vulnerabilities in WiFi routers covered by warranty, for example. But that's just a first step.

You can also ensure robust and interoperable data storage options. For example, https://obsidian.md/ stores all notes in Markdown, not holding the data hostage in case users will not like how future versions will work. GDPR actually has a provision for data portability (Art. 20), but it does not seem to have a requisite effect on the industry yet.

And until the above issues are solved, open source remains the best way to ensure that a software tail cannot be wagging your computer dog.

Re: Single vendor is the new proprietary

#60
post #32
post #23

> You should be on board if you want Open Source to win against proprietary software. But those companies are still doing what is, essentially, proprietary software: like the proprietary software companies of the 80s, they very much consider the software being produced as their exclusive property. They still intend to capture all the value that derives from it. And thanks to copyright aggregation or permissive licens…

Wrt winning: Open is the least worst way of doing things. With the xz kerfuffle people say "aha! So much for your security now!" when the alternative is someone tampering with code on an unsecured ftp serve i.e. it's the devil you can see

For sure, I think that last part is underestimated but powerful. When the SolarWinds or similar attacks occured, we had to rely on investigation reports put out via PR teams and such about how such an attack occured, what processes missed it, etc. With the xz attack, every step of the attack was out in the open for everyone to analyze. Or at least the vast majority, if there were private emails exchanged between "Jia Tan" and the original maintainer, those we can't recover. But we can see pretty much every other aspect of the attack.
Post reply on HN