Live data from Hacker News

Open Source is one person

opensourcesecurity.io

131–140 of 184 posts

Re: Open Source is one person

#131

Earlier quoted context omitted.

Huh? The DoD would not have used the package if they hadn't read every line, locked it down for updates, and were ready to patch it themselves if needed. Can you really imagine in a war they'd be like "damn, if only there were a second person we also don't trust at all to do this work for us cause otherwise we'd just be SOL"

> DoD would not have used the package if ... That's a lot of faith in military intelligence.

> military intelligence.

...is an oxymoron

Re: Open Source is one person

#132
post #130

Earlier quoted context omitted.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

Nicely said, but the reality is that no software is "perfected", just abandoned. Hell, even sysvinit had some big updates recently.

qmail, djbdns, grep, awk, sed, TeX, SQLite, zlib, curl

Re: Open Source is one person

#133
post #130

Earlier quoted context omitted.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

Nicely said, but the reality is that no software is "perfected", just abandoned. Hell, even sysvinit had some big updates recently.

qmail

Also many common lisp packages, 15-20 years old and work perfectly fine.

Re: Open Source is one person

#134

Earlier quoted context omitted.

software once "perfected" (working well enough long enough) needs NO maintenance. No cleaning. No calibrating/tunning. updating is a systemic issue, not a per-project matter

That is a hysterically wrong statement. It is true of Solitaire, Minesweeper, Calculator, and Notepad, and probably about the same number of programs on other OSes. (Notepad has recently had an important expansion of functionality, but it didn't NEED that change.) It's also true of some dinosaurs I have on my system, that copy DVDs and so forth. It's not true of most other applications, nor can it be true, unless the…

You don't think Notepad needed AI, a subscription model, and interstitial ads?

Re: Open Source is one person

#135
post #120

Has anyone seen any stats on what happens to a single maintainer project when said person is hit by a bus (or meets some other demise)? With that many data points, there should be enough of them by now to study it. Is the project taken over by another, single developer? Is it replaced by a similar project? Does it just go away?

It depends. More common than getting hit by a bus is that the maintainer loses interest, or doesn't have the time to put into it anymore. When that happens I've seen all of the following happen: * Someone forks the project, and eventually the fork replaces the original * Another, possibly new, project that fills the same niche becomes more popular, and eventually replaces most usages of the first project. * The origi…

This is theory

Re: Open Source is one person

#136

Earlier quoted context omitted.

Huh? The DoD would not have used the package if they hadn't read every line, locked it down for updates, and were ready to patch it themselves if needed. Can you really imagine in a war they'd be like "damn, if only there were a second person we also don't trust at all to do this work for us cause otherwise we'd just be SOL"

Damn, what country is this in? Maybe the US could learn a thing or two from this level of attention to detail.

I'm only really describing the due diligence I do to keep people safe who might rely on my OSS work. I didn't realize I was so far ahead of the defense industry...

Re: Open Source is one person

#137

Earlier quoted context omitted.

Curious how we're defining "democracy" and "free market" with this one. I wonder how countries with a pure democracy and an actually free market compare to the republic and regulated market we have in the US.

The US is a constitutional democracy with a free market and I consider it successful. The definitions of these words can be the predominant use of these words in the English language. But if you want "constitutional democracy" here use this: https://civiced.org/lesson-plans/constitutional-democracy And for free market here, use this: https://www.investopedia.com/terms/f/freemarket.asp People frequently misunderstand…

> The US is a constitutional democracy with a free market and I consider it successful.

Out of all the definitions you gave, I feel you left out the most important. How exactly are you defining “successful”? Considering the current state of the US, that one seems really important.

Re: Open Source is one person

#138

Earlier quoted context omitted.

I don't know where you're working, maybe you work in some secret lab where everything is air-gapped and not even the pigeons are allowed within a mile of the facility. In which case, what the hell are you doing commenting on a public message board? That is absolutely not how DoD works. The vast majority of code is contracted out. Nobody from DoD side is reading any of the code. It's all a series of affidavits and aud…

Doesn't change the fact that they can just fork it if it ever matters though...

Just forking the code doesn't get you very far. Few of those products have what we would call reproducible builds so good luck trying to create a working release image if you don't have access to the contractor's infrastructure and tooling.

Re: Open Source is one person

#139

Earlier quoted context omitted.

I would love to see a diligently researched episodic series, every episode covering the transition of a popular open-source library/tool/app/site from one maintainer to the next. And that's why I don't run Netflix.

I think this is in the realm of a YouTube series. I mean, what's stopping you from doing it?

Any maintainer pairs want to reach out? I'll give it a shot.

Re: Open Source is one person

#140

> So while NPM has over 4 million single person projects, they have about 900,000 maintainers for those 4 million single person projects. This will be an important data point at the end. Am I missing something or was it not, in fact, an important data point at the end?

I didn't see it explicitly stated, but I think it supports the "overworked" part of this statement:

> Open source, the thing that drives the world, the thing Harvard says has an economic value of 8.8 trillion dollars (also a big number). Most of it is one person. And I can promise you not one of those single person projects have the proper amount of resources they need. If you want to talk about possible risks to your supply chain, a single maintainer that’s grossly underpaid and overworked. That’s the risk. The country they are from is irrelevant.

Post reply on HN