Live data from Hacker News

NPM Bans Terminal Ads

zdnet.com

41–50 of 377 posts

Re: NPM Bans Terminal Ads

#41
post #11

While I don't particularly like the idea of stuffing ads into npm logs, I don't have the same visceral negative reaction that many people have in these HN threads on this topic. The overwhelming majority of the people complaining about this are well-paid tech workers writing code for well-funded companies that profit off of open source code without providing any reciprocal value to the open source projects in return.…

I think we have got open source funding all wrong. The thing that makes open source great is that, in parallel, half a million projects are ticking along from which we are learning what is good, what is bad, what is the future of our art. It is education. It is research.

We look for 100,000 individual solutions to making rent while FAANG are just sitting there with a quarter trillion plus in cash waiting to benefit from the best everything that emerges from this massive, free R&D pipeline. Take the best ideas, hire the best programmers, copy the best software, adopt the best practices. From top to bottom you could probably find 10,000+ open source contributors across their stacks, and to enable that open source software required even more contributors, and influencing it all was the previous generations of contributors.

I think the best solution is FAANG pay it forward and support the entire opensource R&D pipeline that enables them to hoard so much money. Between them they hire more people than there are open source developers so it's ridiculous they cannot support them all. It's a security issue that they do not support them at all for the most part, like with OpenSSL, like with injecting ads into node modules, like with selling modules to be repurposed as malware. We haven't even found the stuff compromised by state agencies yet.

Re: NPM Bans Terminal Ads

#43
post #27
post #15

Earlier quoted context omitted.

I hadn't heard of Tidelift before until recently, and I don't see it mentioned here in the discussion. Is this the kind of thing you'd like to see? https://tidelift.com/ Something has to be done to ensure that Open Source which plays a vital role in our business ecosystems remains sustainable. There are real business implications if some package we all depend on is under-funded and implodes (we can all name well-know…

OSS is sustainable. I don’t like how tidelift seems to present a partial story. If there some OSS crisis that I’m not aware of? Separately, just because something is an approach doesn’t mean it’s worth talking about.

> I’ve spent over 3,000 unpaid hours over the last four years maintaining some popular open source packages.

> Maintainers do critical work which enables companies to create billions of dollars in value, yet we capture none of that value for ourselves.

From TFA, some Open Source contributors are burning themselves at both ends and they should not be reduced to selling paintings on street corners to make ends meet. I'm not arguing that just anyone should be able to earn a living by writing any code and licensing it permissively, but there are some utilities which should be funded that are not, and their ability to obtain funding on their own should perhaps not be the one deciding factor in whether they survive.

In my day job, I frequently insist that programmers are bad at estimating, but they persist in asking for fine-grained estimates and making their business decisions based on them. If the success of a programmer team or product team depends on each individual programmer on the team's capability to always make estimates correctly, then the effort is likely doomed. This is a foundational idea of Agile. You can prove this empirically with enough experience; programmers should focus on making their programming skills better, not on precision time accounting and making sure that to improve estimation to become more accurate. Those things have value, but working software is more valuable. A programmer skill level may be completely orthogonal to the programmer's estimation skills, and many of us may not have the capacity for improving both at the same time.

Similarly, the success or failure of an Open Source project may depend more on the maintainer team's ability to market the project as a product and derive revenue from it.

So, how can we make this easier and more efficient, without forcing everyone to become better at it, individually? (There may not be an answer, but you haven't really taken any time at all to explain what makes Tidelift "not even worth discussing" in your view.)

Re: NPM Bans Terminal Ads

#44

What's this "standard" package anyway? Looks like it's packing eslint with an .estlintrc and... that's it?

Yes, this developer has 100s of libraries most of which are just code snippets. That was part of the criticism here, it looks like this guy is trying to take advantage of jr devs without providing any real value.

Re: NPM Bans Terminal Ads

#45
post #27
post #15

Earlier quoted context omitted.

I hadn't heard of Tidelift before until recently, and I don't see it mentioned here in the discussion. Is this the kind of thing you'd like to see? https://tidelift.com/ Something has to be done to ensure that Open Source which plays a vital role in our business ecosystems remains sustainable. There are real business implications if some package we all depend on is under-funded and implodes (we can all name well-know…

OSS is sustainable. I don’t like how tidelift seems to present a partial story. If there some OSS crisis that I’m not aware of? Separately, just because something is an approach doesn’t mean it’s worth talking about.

What I see in my day to day life is that OSS is generally behind paid systems. I use a bunch of software that I feel annoyed by because they are not as good and are not developing as fast as expensive proprietary alternatives.

Something that can really boost OSS community would be really good, but all I see in the market today are attacks on OSS. For example the recent amazon-mongodb debacle where a proprietary system is stealing money from an open project.

Re: NPM Bans Terminal Ads

#46
post #29

Doing open source without utilising the the code in some form of paid product is a foolish thing to do. Essentially making someone else rich for free because Software-As-A-Service is seen as the morally superior method of generating revenue. I'm sure we'll be reading many articles about some open source developer building some critical tool or library utilised by half the world. Only to live near the poverty line. Wh…

Doing open source without utilising the the code in some form of paid product is a foolish thing to do.

The entire computer industry was founded on people writing software for the joy of writing software and giving it away for free. 90% of software available through the early 80's worked this way. We called it "public domain software."

(As an aside, the earliest version of the word "hacker" that I can remember was when people would take public domain programs, "hack" out the original author strings, then redistribute the program as their own work. The definition of "hacker" has gone through about five permutations since then.)

Re: NPM Bans Terminal Ads

#47

Earlier quoted context omitted.

Adware is malware, categorically. I don't give a damn if it's open source. If being adware is the only way software can exist, I'd rather it not exist at all. When those redditor called it sleazy, they were being too gentle.

> Adware is malware This seems like an overreaction. Are HN ads (those links to YC company jobs) malware? According to feross, the ads were just static hardcoded messages. I find it distasteful, but I don't see how it's "malware".

The entire advertising industry is scum. I worked in it for two years and wish I never did. That's a sin I now atone for by discouraging younger developers from making the same mistake, using the harshest language I think dang will permit.

It doesn't matter if there is no telemetry (and if this were to be normalized, there would eventually be telemetry. Such are the economic incentives in the ad industry. When it's possible for telemetry to exist, advertisers will desire it and some engineer will eventually decide to profit from implementing it) Advertising is propaganda inherently contrary to the interests of anybody subjected to it. It's rife with psychological manipulation. FM radio ads have no telemetry, but can anybody seriously deny that FM radio ads are sleazy as fuck?

Re: NPM Bans Terminal Ads

#48
post #29

Doing open source without utilising the the code in some form of paid product is a foolish thing to do. Essentially making someone else rich for free because Software-As-A-Service is seen as the morally superior method of generating revenue. I'm sure we'll be reading many articles about some open source developer building some critical tool or library utilised by half the world. Only to live near the poverty line. Wh…

Doing open source without utilising the the code in some form of paid product is a foolish thing to do. The entire computer industry was founded on people writing software for the joy of writing software and giving it away for free. 90% of software available through the early 80's worked this way. We called it "public domain software." (As an aside, the earliest version of the word "hacker" that I can remember was wh…

I think that's revisionist thinking. I wrote software through that period; I remember it as expensive and closed. The free stuff was exceptional because it was free.

Come on; Linux started in 1991; Stallman was an unknown and just beginning his ministry in the 80s. Corporate software dominated everything, including the IBM PC which was the flagship of Silicon Valley. DOS wasn't free; software for it was for sale everywhere.

Re: NPM Bans Terminal Ads

#49
post #10

I’m surprised Feross was the catalyst here. From his Youtube Instant days always struck me as the type who appreciated and championed FOSS. Seems he decided that the F in FOSS might be, erm, “reinterpreted,” much the way the notion of “free” has been by modern web companies.

For more context, in case anyone is wondering what I was trying to communicate amidst the torrent of downvotes.

Feross is a meaningful voice in open source. I've admired him for a long time, and still do. He's written some thoughtful posts in the past about FOSS specifically, hence the specificity of my comment (see his post from 2010 here: https://feross.org/stallman-stanford/).

Reading his justification for the "funding" experiment (here: https://feross.org/funding-experiment-recap/), I was struck by the fact that he didn't address an obvious slippery slope in his argument for what he was experimenting with, namely,

"For the record, funding had absolutely no tracking, no data collection, and no code from untrusted third parties. It was a console.log with some fancy formatting. Think of it like a newspaper classified ad. We just print it and hope that maybe some folks will see it."

I don't knock his attempt at experimentation with funding models for FOSS developers; however, there's an ongoing history lesson we're all living that serves as a cautionary tale for where ad-funded monetization models can go. Considering corporations are largely involved in FOSS today, could the normalization of monetization of FOSS with the wholly positive intentions of rewarding those who have dedicated their time to developing FOSS software, not evolve into a model wherein for-profit companies use this as a backdoor to monetize their FOSS contributions? For example, imagine compiling Kubernetes and getting an ad for Google Cloud services. Or compiling the Linux Kernel with features committed to the kernel source primarily by Google and getting an ad for a Chromebook as part of the boot sequence.

Sure this is all a bit dystopian, but I'm surprised someone as thoughtful as Feross didn't address the possible unintended consequences of his experiment, even if his original intentions were in no way nefarious.

Re: NPM Bans Terminal Ads

#50
post #11

While I don't particularly like the idea of stuffing ads into npm logs, I don't have the same visceral negative reaction that many people have in these HN threads on this topic. The overwhelming majority of the people complaining about this are well-paid tech workers writing code for well-funded companies that profit off of open source code without providing any reciprocal value to the open source projects in return.…

>, why is it so alarming to think that these maintainers might think of a clever idea like this to make a couple thousand bucks? [...] But instead of attacking the guy for trying, I really wish the discussion were focussed on how the community of open-source consumers can contribute back to the open source ecosystem

You're (possibly unintentionally) distorting/diverting the issue. Nobody is criticizing open source maintainers for trying to get funding in an abstract sense. (We can all agree open source maintainers need income.) However, if the concrete implementation of trying to get money is unwanted and unexpected ads, then the correct focus of discussion is the criticism of that ad delivery method. The succinct version of this is: "The ends do _not_ justify the means."

As hypothetical examples...

- If Pi-Hole maintainers get the "clever" idea to get funding by changing "doubleclick.net" from returning "127.0.0.1" to the ip address for "BuyPiholeTShirts.com", people are going to criticize that "ad". It doesn't matter if Pi-Hole volunteers "deserve" more money, the correct focus of criticism/discussion is the sneaky ip redirect.

- If the maintainer of d3 Javascript library (https://github.com/d3/d3) decides to embed advertising such as "Try LINODE for 30 days!" in "README.md" and inside the source code comments of every js file, the correct focus of discussion is those ads and not whether the maintainer needs money.

The methods of soliciting funds do matter.

So far, socially acceptable ways seem to be Patreon, or getting hired by FAANG, or grants, etc. The "clever ideas" like NPM console ads are not socially acceptable.

Post reply on HN