Live data from Hacker News

“Open source” is broken

christine.website

321–330 of 357 posts

Re: “Open source” is broken

#321

This is a good article, and 99% of this article I agree with. I'm going to quibble at something very small, not because I think the author is guilty or anything or because they're doing something wrong, but because this is a general pattern I've been seeing over and over again in multiple takes from multiple people: it feels weird to me to have a criticism of corporate behavior where corporations don't know how to en…

I actually really like what you're saying.

As someone who's pointed 10's if not hundreds of thousands of dollars to open source projects, blaming lawyers is unfortunately not the solution either.

Companies have budgeting and legal solutions laid out, its pretty much a first year problem. Engineering and IT want money to go to those developers. The issue is finding and getting money to these developers in accordance to tax code, jurisdiction/etc, its basically a regulation issue. On top of that, many developers don't want to deal with the tax hassle of getting paid for a $50-200 solution because it opens them up to ID theft and a whole morass of problems.

For the moment the most effective use of my dollars has been to donate to foundations and tag my donation with a "hey, can you use this for $XYZ", and that works. The FreeBSD foundation does a great job of this and thats why I donate money to them every year.

If there was something like this that encompassed more developers, I'd be really keen to see that as well.

Re: “Open source” is broken

#322

Earlier quoted context omitted.

The maintainer never put a $0 _value_ on their work, but a $0 _public price_ of it "as is, without warranty of any kind, ...". It's some (corporate) users and markets that understand this (wrongly) as a $0 value. It's their own evaluation that's failing in the long term. Mentioned that in an other comment, but this is akin to mining companies that extract value from natural resources at $0 price (because the resource…

... which is why countries are putting fishing quotas and carbon markets in place to make sure that doesn't happen. In other words, countries put a market value on things that otherwise wouldn't have it. OSS maintainers needs to do the same. That's my point.

OSS maintainers are the fish in your (adequate) metaphor.

Re: “Open source” is broken

#323

This is a good article, and 99% of this article I agree with. I'm going to quibble at something very small, not because I think the author is guilty or anything or because they're doing something wrong, but because this is a general pattern I've been seeing over and over again in multiple takes from multiple people: it feels weird to me to have a criticism of corporate behavior where corporations don't know how to en…

I actually really like what you're saying. As someone who's pointed 10's if not hundreds of thousands of dollars to open source projects, blaming lawyers is unfortunately not the solution either. Companies have budgeting and legal solutions laid out, its pretty much a first year problem. Engineering and IT want money to go to those developers. The issue is finding and getting money to these developers in accordance t…

So on some level, I agree, and in particular I think that having these meta-organizations and middleperson organizations that essentially act as money-pits and then put in more of the hard work to distribute funds or support -- that's a great idea, and I'd love to see more stuff like that.

And I am grateful for companies that are putting the work in to try and solve these problems, we need more of that, so thanks for the work you have done and thanks for your thoughts on the problems.

I still have a couple of specific, narrow objections overall:

----

> Companies have budgeting and legal solutions laid out, its pretty much a first year problem.

> The issue is finding and getting money to these developers in accordance to tax code, jurisdiction/etc, its basically a regulation issue.

Who's more equipped to solve those problems, companies or unfunded developers building stuff in their spare time? Who has more lobbying resources to change tax laws, Microsoft or Open Source developers? Saying that this is a corporate/business problem is not necessarily the same as saying it's an easy problem, it's just saying that the stuff you you bring up above are company issues, not problems with Open Source. Open Source isn't broken, companies are broken in that they struggle to interact with or support the ecosystem in productive ways.

It's a business problem that budgeting is so rigid that companies can't on-the-fly budget (or never thought to budget in the first place) resources to maintaining infrastructure that they rely on. It's a business problem that businesses don't understand their supply chain well enough to know what they're relying on or how to get in contact with or support the projects that they're relying on to remain stable and secure. These are complicated problems to solve, but let's be clear about where they lie.

Yes, there are tax complications, there are regulations. These are also problems that companies are more equipped to solve than developers are; companies have legal departments that can help navigate taxes, and individual developers do not. It's a business problem that companies don't have mechanisms/infrastructure to distribute support to things they rely on without falling into complicated legal holes. Yes, there are problems of finding the projects that need funding, but once again, businesses are more equipped to examine their own dependencies than developers are to try and figure out everyone who's relying on them and how important their libraries are to those companies.

And yes, you are absolutely correct that not all developers want to get paid traditionally (or even paid at all), and that's a choice we should preserve. But in some ways, that's exactly why this is a corporate problem: it's good that people get into Open Source with different motivations and needs, and it is better for the tech industry to evolve and figure out how to support those developers through nontraditional means (QA volunteering, patches, documentation, attention/promotion, one-off donations, etc), than it would be to try and "professionalize" Open Source. Even in the scenarios where people want literally nothing, and they don't want to be critical infrastructure at all, it's still kind of the company's responsibility to figure that out and to figure out if they're comfortable taking on the risks, or if they need to either use something else or fork the project.

For all of its faults, Open Source works pretty well, that's why companies rely on it. And I think part of that is the messy non-commercial aspects, the accessibility of contributing that means a company might be using a library built by someone who's only 15 (which for sure makes corporate funding complicated), the lack of hard requirements or contracts that mean a developer might walk away from something a company is relying on -- these are not accidents, they're deliberate parts of the system that allow non-professional people to take part in building the commons and solving their own problems. And yet for all of that messiness, Open Source produces software that's good enough that businesses rely on it. So when we have a system that is producing good software that people rely on, but the funding methods and support methods that businesses are capable of engaging with don't always line up with that system -- this is a case where businesses and the surrounding tech industry that should change, not the system that's producing good software that people rely on.

I will note that in the case of log4j, the developers are interested in normal funding -- this specific situation isn't a problem with figuring out in what way to support developers, it's a problem stemming from the fact that businesses don't know how to analyze their dependencies and figure out which parts need support (which is why they didn't realize that log4j devs wanted funding), and that businesses don't know how to donate to those dependencies or that the businesses aren't flexible enough to make those donations using the payment systems that many Open Source developers prefer. So there are broader questions about what projects want support, but log4j is kind of one of the easier examples; if businesses can't figure out how to donate to this project without an invoice process (even if the reason why is complicated and protracted and multifaceted and hard to solve), then businesses really are just broken in this regard.

Re: “Open source” is broken

#324
post #270

Earlier quoted context omitted.

OK. So let’s say I want to participate in open source. I release an open source project on the internet. The way I see it, here are my options: 1. I can release it freely, on a project forge like GitHub, and thus nobody has any obligation to pay for it. I can use dual licensing schemes and/or offer commercial support, or solicit donations, but by and large everyone from your average Joe to the fortune 100 are treated…

Great comment! My message is to the group of OSS maintainers that pick option 3 and then throws a tantrum when it doesn't work. My message is: Option 3 does not work and will never work. Accept it and pick another option.

Apparently, we’re on the same page. However, I think we can still do better than this. While some more organized projects will successfully find a model that helps them meet their goals, initiatives that try to help individuals externally could also (and obviously do) contribute to the solution.

It’s basically the same level of expectations on both sides: nobody is expected or obligated to do anything; they do so because they want to, or because they believe it is a mutually beneficial decision. It’s kind of like the comparison of engineer salary vs open source donations. Yeah, on one hand, open source donations are not likely to pay you enough to live in most cases. On the other hand, it’s money given to you under essentially no obligations. The same reason you can’t really complain much about the support you get from open source maintainers; there was never really any obligations.

But, I believe that open source has proven itself enough to have earned more donations and funding, and that there’s plenty more funding that could be making its way to open source if we could resolve issues with routing it there.

Re: “Open source” is broken

#325

Earlier quoted context omitted.

How many companies paid $0 for log4j2, and then got upset and bashed the authors of it when this bug happened for the cost it caused to their business? People pay nothing for the software, but will expect paid quality support.

They get upset and expect things to be fixed for $0 because that is the value that the OSS maintainer put on his own work . So why is that surprising? It's how a market place works .

> They get upset and expect things to be fixed for $0 because that is the value that the OSS maintainer put on his own work. So why is that surprising? It's how a market place works.

The "work" you're talking about is the development of the software. The post you replied to was talking about support:

>> People pay nothing for the software, but will expect paid quality support. [Emphasis added -- CRC]

Valuing what's there to freely download at this instant in time is one thing; bugfixes on top of that are support, which is a different thing.

If you get something for free, you don't have to pay for it; if you want something more on top of that, you may have to pay for it. That's how a market works.

Re: “Open source” is broken

#326

Earlier quoted context omitted.

What law mandates that companies can't donate to someone on Patreon or help triage bugs or dedicate QA/security time to identifying issues? What law mandates that companies have to ignore maintainer burdens? Each company made an individual choice to use infrastructure that they weren't funding/supporting, to effectively transfer bug-testing and security reviews onto unpaid maintainers. Then the infrastructure they we…

The law that mandates that companies can't donate to someone on Patreon or help triage bugs or dedicate QA/security time to identifying issues is the requirement for CEO's to demonstrate good judgment in managing the company by maximizing profit for shareholders. The law that mandates that companies have to ignore maintainer burdens is similar, but much more obtuse, mainly concerning commercial and workplace agenda i…

> the requirement for CEO's to demonstrate good judgment in managing the company by maximizing profit for shareholders.

this is an inanely incorrect urban legend of a claim. The business judgement rule overrides it except in amazingly egregious circumstances, and paying the maintainers of business-critical upstreams would be profoundly unlikely to be such a circumstance.

Re: “Open source” is broken

#327
post #71

Earlier quoted context omitted.

"I think the real fix is that dependency management tools like NPM and Maven need to make it much easier to "override" dependency package names so that, if a critical issue is discovered, you are not at the mercy of the current maintainers of that package to quickly get a fix into production." I'm probably mistaken, but I thought in maven managedDependencies was exactly this. Please correct me if I'm wrong.

Maven/Gradle does exactly that. Provided the dependency you're replacing is compatible with the new one (same packages, same methods, etc), it's fully transparent. It's just that once again, the web world is running with awful tools that keep making the same mistakes that have been done years before them.

Upvoted for that last sentence.

Re: “Open source” is broken

#328
post #173

Earlier quoted context omitted.

> Can we make fix the places where it's broken? Also, Yes. Two problems: 1. How is it broken? As I and others in this thread attest to, the thing that makes open source so powerful is, in fact, the lack of legal and moral obligation to do anything in exchange for the right to use the software. Not having obligations is a two-way street. Same for donations; donations do not give you any additional assurances. 2. If it…

I feel like a lot of this isn't that individuals are the ones who should be forking over money, but rather corporations who are making tens of millions or billions who rely on this stuff as a core to their stack, but do nothing to support the ecosystem monetarily.

Tax the corporations and publicly fund free software.

Re: “Open source” is broken

#329

Earlier quoted context omitted.

> No one is entitled to money. There's nothing broken about that. If you want to make money it would be a good idea to make a business plan. This attitude totally ignores how hard it is to actually run a software tooling business and collect when you have a free/community offering. Take the Obsidian note app, for example. It's technically free until you start using it for revenue-generating, work-related activity per…

People pay $ all the time for things they value. If people choose not to pay $ for work you do then accept that they don’t find it valuable enough to spend $ on.

We've gotten to the point where users might have, for example, tens of millions of dollars worth of pirated music on a single hard drive.

It isn't really a reflection of the valuation of the music.

Re: “Open source” is broken

#330
The argument made by the author is pretty marginal and not well thought out.

The complaints made have little to do with the open-source community-- they have to do with the (valid) complaint that capitalism's current incarnation is non-functional.

If anyone truly thinks open-source is broken I strongly encourage them to stop using any devices they have that employ open-source software. This would likely include your phone, tv, automobile, and... well... basically almost everything that has software on/in it. Many of these devices manufacturers don't adhere to the licenses, which is unfortunate, but most open-source people (IMHO) tend to be more into "getting cool shit working" than "hiring lawyers to bitch about attribution".

Post reply on HN