Live data from Hacker News

We all depend on open source. We will defend it together

akrites.org

131–140 of 257 posts

Re: We all depend on open source. We will defend it together

#131

Earlier quoted context omitted.

It's the same easy as falling out of a plane without a parachute. Gravity will do all the work but you'll not like what happens at the bottom.

Isn't it easier just not to board the plane, who really enjoys being at an airport?

You were never at an airport. You fell asleep in your bed and woke up on the plane. Fighting the people taking you somewhere you don't want to go is definitely more work than falling out of the plane. It just has a specific advantage.

Re: We all depend on open source. We will defend it together

#132
post #129

Defending open source should begin with real, tangible support for both the projects and its developers. Not just words. With my OpenBSD developer hat on, getting new hardware in the hands of developers is really important, many of us are hacking on 5-10 year old thinkpads that need replacing. https://www.openbsd.org/want.html The OpenBSD foundation is ~50% away from its fundraising goal for 2026! https://www.openbsd…

Also in addition to funding the open source projects you use, if you can, please consider directly supporting individual contributors/developers personally who work on those projects, many are volunteers and even a small monthly contribution could mean the difference.

https://brynet.ca/wallofpizza.html

Re: We all depend on open source. We will defend it together

#133
post #108
post #90

Earlier quoted context omitted.

I would be glad to learn if you are willing to explain, this what I found from trusted sources, but it would be great to know if there’s additional nuance.

Akritai were locals who were to be used as the defenders of the borders instead of deploying regular Army or mercenaries. For this reason they were given land (so as to have skin in the game) and tax breaks. When the tax breaks stopped the Akritai rapidly vanished. These are also mentioned in Wikipedia pages. So, in terms of a security project an Akritas would be you running an EDR agent on a machine that you own, no…

Com'on, it's not that bad. The idea of these organizations is that, since they're using and testing this software, "we'll see any issues first, we'll let you know, and we'll deal with it." The quoted part bears some resemblance to the tasks of Akrites.

Remains to be seen whether history will repeat itself: when the tax breaks/ free AI use stops, will anyone keep doing this?

Disclaimer: I have had nothing to do with this initiative, and was not consulted on the name.

Re: We all depend on open source. We will defend it together

#134

Earlier quoted context omitted.

Its worse. Open source will be hijacked by hype warfare companies to extract free labour and build the things they want instead of the things we want.

Oh that ship sailed over a decade ago. Industry appeasement is a big part of what killed Drupal.

What killed Drupal, and what replaced it? WordPress?

Re: We all depend on open source. We will defend it together

#135
post #127
post #78

After reading this. I realize how different Asian and Western consciousness really are. My entire technology stack was built on Microsoft's ecosystem, not on open source. This was Microsoft's attempt to expand their base for the corporate hiring market and OS market share. Conversely, open source was a huge barrier for me. When I have a product I've built, I have to get past open source, but accessing open source com…

Great comment. Really interesting to see "scratch your own itch" described as an "aristocratic hobby". If the language barrier disappeared overnight, would the situation still be the same, do you think? What would an Eastern open source movement look like, and why hasn't one developed?

hmmm I'm not sure about Japan on this point, since I haven't communicated with Japanese developers very frequently.

But regarding Korea and China: in China, there's Gitee, which has a very robust open source environment, but it's not really 'Western style open source' it's more like corporate projects being made publicly available for free. In other words, companies release assignments and people gather to work on them. That's the dominant model. (And that becomes part of their employment portfolio. So it feels very much like an incubation system for corporate projects.)

For Korea, I think it's largely because the absolute number of Korean speakers is smaller than English speakers. As a result, Korea's tech infrastructure generally lags behind the English speaking world. It feels like: English trends emerge -> a few years later, once they stabilize, Korea starts adopting them!

The usual pattern here is that the people curating these English trends for Korea are Koreans who have worked at FAANG-like companies and come back, so they have a strong influence. But I don't necessarily agree with their perspectives, which is why I came here to see what the raw data from the West actually looks like.

On top of that, Korea's IT projects are mostly government-led (because the domestic market isn't that large), so the government essentially acts as a VC. And within this government-led incubation system, only the final winner takes everything. Given that kind of environment, I wonder if that's why open source doesn't really take off.

Re: We all depend on open source. We will defend it together

#136
post #124
post #78

After reading this. I realize how different Asian and Western consciousness really are. My entire technology stack was built on Microsoft's ecosystem, not on open source. This was Microsoft's attempt to expand their base for the corporate hiring market and OS market share. Conversely, open source was a huge barrier for me. When I have a product I've built, I have to get past open source, but accessing open source com…

The Personal Computer culture in the SV developed from the counterculture in the valley: https://kbsm.org/technology/california-tech-culture-that-sha... It then hopped on the Free Software movement with redefining it as "open source" while the Internet was booming. And all of that is now being reaped by the corporations the "tech-hippies" themselves helped to create.

If anyone's interested in this: "From Counterculture to Cyberculture" by Fred Turner and "What the Dormouse Said" by John Markoff.

Putting my nostalgia-tinted glasses on, it's sad how far we've strayed from that.

Re: We all depend on open source. We will defend it together

#137
post #78

After reading this. I realize how different Asian and Western consciousness really are. My entire technology stack was built on Microsoft's ecosystem, not on open source. This was Microsoft's attempt to expand their base for the corporate hiring market and OS market share. Conversely, open source was a huge barrier for me. When I have a product I've built, I have to get past open source, but accessing open source com…

It is a distortion to frame the problem as corporate vs. open source. These corporations compete with open source but they are often sustained by it, and in any case they operate within a space that is impacted by it. A healthy open source community is generally to their benefit. The inverse is also true, to the extent that corporations support and integrate with open source, it benefits from a healthy commercial mar…

That's a Rihgt However, what I'm curious about is that this project governance feels more closed than open source, rather than truly being open source. Your point is valid too. I admit my thinking might be a bit too binary.

Re: We all depend on open source. We will defend it together

#138
post #59

Earlier quoted context omitted.

Commercial entities latch onto useful open-source because it is a successful product they simply cannot compete with.

why would they compete with it when its open?

To secure network effects for themselves. This is one of the reasons the ASF was founded.

https://httpd.apache.org/ABOUT_APACHE.html

> We realize that it is often seen as an economic advantage for one company to "own" a market - in the software industry, that means to control tightly a particular conduit such that all others must pay for its use. This is typically done by "owning" the protocols through which companies conduct business, at the expense of all those other companies. To the extent that the protocols of the World Wide Web remain "unowned" by a single company, the Web will remain a level playing field for companies large and small. Thus, "ownership" of the protocols must be prevented.

Re: We all depend on open source. We will defend it together

#139

The most important information is this: > participants will contribute engineering resources If it works out as planned, we will see. Apart from this, I am not overwhelmed by the claim of this project. It favors centralization and corporate circles, exactly the opposite of what the hacker ethics promotes for good reasons.

Doesn't seem very inclusive. Seems to be another layer to centralize the inbound vulns, gather intelligence and handle them in secret.

It may also turn into another source of pressure. Maybe they manage to sort out the real vulns, but then they come in as high priority to the maintainers.

Many maintainers are already exhausted from their normal work, sans AI noise. Even if they supply fixes, it still requires review.

In best case they could reduce noise but the work is still there. The industry needs to generally fund OS projects to give them the agency to handle it on their own. That's is likely best for quality. If there is still need to filter AI noise then they can add that, but not as a secret opaque thing that controls it all.

Re: We all depend on open source. We will defend it together

#140

> We are joined by Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, NVIDIA, OpenAI, RapidFort, Red Hat, Rust Foundation, Sonatype, Vodafone, and Zscaler A lot of open source folks are going to be very skeptical, rightly so, of this group of players. > ... to find, fix, and responsibly disclose vulnerabilities in critical open source softw…

You realize that the companies listed employ many of the core open source maintainers for large projects? It is project-specific, but 80% of Linux kernel development is from paid corporate employees. Similar for kubernetes. All the load bearing infrastructure is already handled by these companies... literally no one else is going to have the resources or experience to redirect large efforts on securing F/OSS.

What would you propose otherwise?

Post reply on HN