Live data from Hacker News

“Open source” is broken

christine.website

221–230 of 357 posts

Re: “Open source” is broken

#221
post #52

Open source users are the welfare queens of our times. As long as open source software exists, these lazy degenerates with no skin in the game will feel entitled to keep demanding more and more. Open source software needs to die.

I know what you want to say, but "welfare queens" is really a bad way to phrase it. > The "welfare queen" stereotype is driven by the false and racist beliefs that places the blame of the circumstances of poor black single mothers as the result of their own individual issues, bringing forward racial tropes such as their promiscuity, lack of structure and morals, and avoidance of work. [0] [0] https://en.wikipedia.org…

And of course, the Wikipedia propaganda is considered absolute truth, while my factual real world experience is 'flagged' by some SJW virtue signalling city slicker, who is angry at anyone who speaks truth.

You cannot argue with cold, hard truth obviously, or you would be doing so, instead of flipping your wig and downvoting/flagging my post.

Here, let me tell you more about these people you obviously know nothing about. I've met, interacted with them, spent months in jail with them. I know exactly who they are and what they are about.

They swap tips and stories and plots and schemes for signing up to as many welfare programs as possible. The more checks one has coming in, the higher one's social rank is within this system. EBT cards are used to buy certain items, like 24 packs of soft drinks being a major one, which are used as a sort of currency, exchanged at half price for hard cash, which is often taken straight to the drug dealer. Fact.

There is a pride among the group based on how much they can rip off from society vs. how little actual productive work they do, ideally none. 'Hustles' are the primary form of work, usually involving drug dealing.

Theft and robbery is another primary occupation of this crowd. They steal whatever isn't nailed down, and sell it on Craigslist. When confronted, they brag about it and show no shame or remorse whatsoever, like the one guy I went to school with for example whom I noticed doing this.

They spend their lives in and out of jail--and they are proud of this. They love going to jail. That's where all their buddies are. The only thing they like better is going to prison, because it's a lot better than jail, with much more to do, more hustles to run, and more criminal minds to link up with. Fact.

Having returned from jail/prison, they continue with the same life choices. Proudly.

They do things like steal large air conditioner units from schools and churches, or catalytic converters from cars, or copper wiring and plumbing from houses, and melt them down for scrap. To buy meth and heroin. Fact.

Every one of them thinks the world owes them something. The sense of entitlement is apparent in their every word and action. People with honor and dignity who prefer to do actual work are like an alien species to them, treated with scorn and contempt.

I've personally been ripped off, robbed, and screwed over in countless ways by this crowd. Matter of fact, my shop was robbed just the other day. They took several metal items that I desperately needed, like two radiators, one of which is for my generator. I'm not rich. I'm living hand to mouth, literally eating out of dumpsters to survive. They don't care. The only thing they care about in the world is themselves.

And is it any wonder they turmed out this way, when everybody in the entire country from President and Bankers and CEOs on down is exactly as selfish and uncaring? Who do you think molded them into such criminals?

Please, downvote and flag me some more, so you can prove how selfish and disconected from reality you are also, presumably isolated in your big city enclave in some coastal city. Out here in flyover country we have no such luxury.

This country is burning, and frankly, that's exactly what it deserves. Maybe when the destruction finally reaches your doorstep, you will finally get a clue.

Re: “Open source” is broken

#222

Earlier quoted context omitted.

> You say that as if you even know your full dependency chain. Reality doesn't quite work that way. No one knew their codebase even relied on leftpad until it broke millions of applications the world over when it got pulled. We're professionals - we in fact simply can do that with some elbow grease. Doesn't take a genius to understand how software is built.

The only professionals who actually do this are in heavily regulated industries that require it, which are often criticized as being stuck with "ancient tech". It seems there's currently two ways to tackle this issue: move fast and break things, or move slowly and don't break things.

I'm not saying you need to audit every line of code.

I'm saying it should be trivial to fork any dependency in your tree.

Every project I've ever worked on has met this - but I'm a Nix guy.

Re: “Open source” is broken

#223
post #176
post #144

Earlier quoted context omitted.

> It does because now I pull in a dependency How would proprietary software make this better? You wouldn't even have anything to pull in! Is your argument "having the source code and the legal rights to fix this bug even when nobody else wants to or even can fix it is not good enough because not everyone will use my fix"? Because good luck with proprietary software then!

My argument is not closed source. My argument is that "just fork it" does not magically fix all problems. Closed source makes this worse but "fork it" is no answer either. I believe I made this very clear on my very first comment.

I misunderstood you then. I agree with your statement. Open source doesn't solve all problems, just some. There are hard problems about dependency management and vulnerabilities that are not magically solved by something being open source, I agree.

Re: “Open source” is broken

#224
post #195

This is a good article, and 99% of this article I agree with. I'm going to quibble at something very small, not because I think the author is guilty or anything or because they're doing something wrong, but because this is a general pattern I've been seeing over and over again in multiple takes from multiple people: it feels weird to me to have a criticism of corporate behavior where corporations don't know how to en…

Author of the post here, can you please turn this comment into a blogpost? It is lovely and I love it.

Thanks so much :) No promises on timing, but sure, I'll do my best to write something up.

And thanks for commenting as well; I'm honestly really relieved that this apparently didn't come off as too critical, I was somewhat worried about that. It's a weird situation where your post is one of the better ones about Log4j2 that I have seen today, and there's stuff there that I really appreciated you writing and articulating, particularly around your hesitation to make things that companies would start relying on. But it was also the only one that got up to the top of HN that I saw when I logged in, and... I kind of went back and forth whether it was right to complain about a broader trend underneath it, given that the actual substance of your article really isn't falling into the trap I was complaining about.

Anyway, just reiterating that you wrote a good article and a good take, and it's not even that the title is egregious or worth a rant in isolation, it's fine. It was just the Nth title over X months that I've seen about Open Source funding that happened to be phrased as the Open Source problem, directly after I finished reading a different article that was suggesting that Open Source devs all need to learn how to set up their own LLCs and invoicing departments.

Re: “Open source” is broken

#225

Earlier quoted context omitted.

I mostly agree with your argument. But, if we just de facto accept everything for how it has been in the past. Then we stop making things better, for everybody involved. Is Open-Source thriving? yes. Can we make fix the places where it's broken? Also, Yes.

If you give your work away for $0 then the world will expect to pay $0 for it. That’s it. It isn’t rocket science. If you value your work make companies pay for it.

Doesn't the reverse hold true too? If you rely on software you paid $0 for and it fails you, you got what you paid for.

Re: “Open source” is broken

#226
post #88

Earlier quoted context omitted.

> no one -- especially corporate users -- gets to complain Do corporate users of open source really do all that much complaining without contributing? IME the people with the biggest complaint/contribution ratio in open source projects are individual devs (or trolls) who are not participating as a representative of any company.

In the case of core-js the issue isn't that "nobody is contributing", the issue is that there is one guy with commit authority and he's an asshole who reportedly spends most of his days rejecting PRs from people he doesn't like. IBM, Oracle, Apple, Microsoft could submit all the PRs in the world and it won't do any good if he says "I don't like your coding style" or "this takes core-js in a direction I don't like." O…

Why does that make him an asshole? It's his project, he's free to do as he pleases with it. Even my very modest open source projects sometimes get people demanding I fix or change something. It's ridiculous. It's like there's this unspoken expectation that all available software rise to meet all needs.

Re: “Open source” is broken

#227

Earlier quoted context omitted.

Yes 'free' means 'the little people work on that'. There's no real way to secure finegrained node.js or python etc deps, since you have no clue if the original author who signs his sources should be trusted, or was malicious from the start and just biding his time, let alone everyone who contributed to every package. What would help is independent audits and where needed help with hardening like fuzzing and asan / va…

Those audits are your duty. We've did this in programming a long time until recently the JavaScript craze took over.

FOSS programmers owe you nothing, please read the license.

You can keep dreaming otherwise and enjoy a steady stream of security problems from your leeching.

Re: “Open source” is broken

#228

Earlier quoted context omitted.

Sure you can fix it, change the "log4j" in your dependency list to "wyldfire-fixed-log4j". You can't do that with closed source (either because you care about legalities, or because you have no way of obtaining a compilable and readable source code).

The problem is, my dependencies also have dependencies. If the problematic dependency is any more than one degree of separation removed, you're back to square one.

A nightmare in Node world perhaps (our latest simple web server has over 2,000 dependencies).

In the Java world it’s much simpler with a few excludes in your POM. Especially for libraries that keep stable interfaces, such as a logging library.

Re: “Open source” is broken

#229
post #173

Earlier quoted context omitted.

I mostly agree with your argument. But, if we just de facto accept everything for how it has been in the past. Then we stop making things better, for everybody involved. Is Open-Source thriving? yes. Can we make fix the places where it's broken? Also, Yes.

> Can we make fix the places where it's broken? Also, Yes. Two problems: 1. How is it broken? As I and others in this thread attest to, the thing that makes open source so powerful is, in fact, the lack of legal and moral obligation to do anything in exchange for the right to use the software. Not having obligations is a two-way street. Same for donations; donations do not give you any additional assurances. 2. If it…

I feel like a lot of this isn't that individuals are the ones who should be forking over money, but rather corporations who are making tens of millions or billions who rely on this stuff as a core to their stack, but do nothing to support the ecosystem monetarily.

Re: “Open source” is broken

#230

Earlier quoted context omitted.

I think this argument massively ignores the underlying message of this blogpost: addressing that the human beings that make and use software aren't always treated as, well, human beings. > A maintainer goes to jail for vehicular manslaughter and a bugs needs fixing, no problem The author didn't seem to hint that open bugs in core-js or its usefulness to its community of users are / is problematic. They hinted that ma…

If you give away your work for $0 then people/companies will value your work accordingly and pay no more than what is asked. What is so surprising about that? Do you pay more than what is asked for when spending $ yourself?

How many companies paid $0 for log4j2, and then got upset and bashed the authors of it when this bug happened for the cost it caused to their business?

People pay nothing for the software, but will expect paid quality support.

Post reply on HN