Live data from Hacker News

“Open source” is not broken

nadh.in

61–70 of 259 posts

Re: “Open source” is not broken

#61
post #32

Open source is most certainly broken, and not just due to the various financial, freedom and security issues these two articles focus on. My biggest peeve: documentation is often minimal (e.g. API docs only) or filled with useless toy examples that are effectively just rephrasing of API docs. The entire underpinning of free and open source software is silly: software in this context isn't an academic pursuit producin…

You know, one of those terrible aspects of open source is that if you see a lack of documentation, you can just contribute it yourself. Good luck contributing new docs to literally any proprietary product.

Re: “Open source” is not broken

#62

Earlier quoted context omitted.

Sure, but then I can't prevent forks or folks distributing custom builds unless I start doing DRM notices and litigation. It's infinitely easier to keep it closed source.

Legally you can, and practically do you really think people can't reverse engineer your stuff if they want? Alternatively: it sounded like you just didn't want to support it or deal with pull requests; do you care about unofficial unsupported builds? Edit: And yes, just distributing binaries and not worrying is the least work; I just wanted to point out that you can have it both ways if you ignore "Open Source".

> Legally you can...

Sure, up until the point where you run into people in countries like China ripping off your products and get stonewalled in any attempts at IP enforcement. Alternatively, are you sure that you can really afford the legal expenses of pursuing such enforcement?

I've seen enough stories of indie game developers having their games be stolen an re-uploaded under a different name to know that this is a problem that shouldn't be overlooked, though obviously it's worse in some industries than others.

> ...and practically do you really think people can't reverse engineer your stuff if they want?

No, most people cannot, and that's the extent to which it remains a good point.

You don't lock your door because you're worried about the one person who knows how to pick it out of a thousand, you lock your door to deter the rest 999 people who would go through it if it were not locked.

People talk a lot about obscurity not being security and so on, but to a certain degree it is, just like how changing your SSH port will prevent a number of automated attacks, even if port scanning is trivial otherwise.

Re: “Open source” is not broken

#63

Its probably time for the next generation of open source licensing to make the code not usable for profit making purposes, thus ensuring open source is either funded by the companies that use it or forms its own separate community away from corporations.

How do you practically inforce these licenses? At aquision time in a big code audit? Independent review with mandatory certificates for businesses over a certain gross profit? What are the current ways we catch lisence breach? So many questions... I know that I hate, HATE, thinking about lisences, to the point I typically don't include one, or use some nebulous beer-ware hack. How does a new set of licenses help me?

How does it work now with GPL and AGPL? As I understand it muck rackers dig into distributions of software and services then report any violations they find. Then the copyright holders can choose whether or not to take them to court.

Re: “Open source” is not broken

#64

I recently looked into open sourcing Homechart ( https://homechart.app ). It's free to use already (for self hosting), but some users wanted it to be open source (almost entirely for auditing purposes, but I doubt they'd even read the code). I don't want anyone using it for commercial purposes, and I found a few licenses that would prevent this-- namely Commons Clause, but at the end of the day I didn't see a benefit…

> I don't need the added burden of responding to issues and pull requests

You don't have to. open sourcing does not mean putting it on Github with an open bug tracker, you could simply offer tarball downloads, mention you don't support it, and ignore any email about it.

Re: “Open source” is not broken

#65
Note to author you're arguing with a bronie, so not exactly a cognitively unbiased crowd...

But seriously, this is that businesses are broken and grab a free thing and use it. If businesses were gassing employees because they got free ammonia to clean their buildings we wouldn't be blaming the ammonia producers.

Please, stop blaming tools for the axe wielding by morons users. I'd say educate the users, but we all know thats not gonna change any time soon...

Re: “Open source” is not broken

#66
post #58

I recently looked into open sourcing Homechart ( https://homechart.app ). It's free to use already (for self hosting), but some users wanted it to be open source (almost entirely for auditing purposes, but I doubt they'd even read the code). I don't want anyone using it for commercial purposes, and I found a few licenses that would prevent this-- namely Commons Clause, but at the end of the day I didn't see a benefit…

On Android, the potential downside (companies stealing your app under alternate names, bundling adware/malware, and even issuing fraudulent takedowns) outweigh the upsides. Consider allowing some trusted users in your community audit/demo access? The developer of the AetherSX2 emulator for Android worked with the PCSX2 team (Open Source parent software) and YouTubers/other established media in the emulation community…

That seems like a good compromise. I thought about looking for third party attestation services, but it would be a point in time snapshot and probably prohibitively expensive.

At the end of the day, the code is written in Go (highly reduced attack surface), doesn't need to be exposed to the internet (works fine locally or over a VPN), and functions perfectly fine with outbound internet access blocked (no phoning home or tracking). I built it the way I want self hosted software to work.

Re: “Open source” is not broken

#68
post #47

The problem is Free as in Beer and Free as in Speech are related. The issue is not $1 downloads so much at is the overhead, pain and issues that come along with it. It's hard to manage and control downloads, usage, and the legal issue might be that any hint of licensing problem makes it 'no go' from a corporate perspective. So the gap between 'Free Beer and Speech' and 50-cent Beer and Speech is enormous.

If it's free as in freedom then the first downloader to pay $1 can just mirror it and allow free downloads. Free as in freedom always necessarily denotes free as in beer as well. It's not an accident or side effect.

But the mirror may be less convenient. This works for OsmAnd+ for example: it's FOSS, free (as in beer) on FDroid, but costs 25$ on Google Play.

Re: “Open source” is not broken

#69
post #55
post #7

Re the author of "open source is broken": The irony of bashing open source on a websiate using systems/code/infra containing thousands of open source lines of code which I am sure he hasn't paid for... has probably escaped his attention. Honestly, I am not sure why there is an argument anymore. Let people write or use free or proprietary software as they see fit. You all know the pros, you all know the cons, make a d…

As the author of that article, I am starting to prefer they/them pronouns. It would be nice if you could update your comment to refer to me correctly, however this is not a demand. There is a lot more happening behind the scenes than you know of, I make a tiny fraction of my donations public knowledge.

Edit: another person pointed out that the actual comment sounds like an ad hominem, which i do not condone. However, some of the phrasing made me think, hence the question (more clarification below).

> The irony of bashing open source on a website using systems/code/infra containing thousands of open source lines of code which I am sure they haven't paid for... has probably escaped their attention.

Hey, what are your thoughts on the OP's argument, though?

I read your article and it did seem to have plenty of truth to it, much like other articles that i've read in the past: https://staltz.com/software-below-the-poverty-line.html

Personally, i use a lot of open source software and i definitely won't pay for most of it, many people out there won't pay for any of it. I don't find that ironic, i find it sad. There is no obligation or anything to encourage anyone to donate to the authors, most people don't care.

If i went to work on Monday and suggested that we as a company throw money at open source, i'd probably be looked at funny. In the company, near the holidays we have an initiative where employees vote for charities and each vote gets 100 EUR donated towards them... but curiously, no one even considers something like that for open source projects, despite there being hundreds if not thousands of those in their dependencies.

I think it's probably a cultural issue to some degree, simple psychology otherwise.

Re: “Open source” is not broken

#70

It feels like we moved from a world where open source software was develop by a community, to one where most of us are just consumers of the code. I don't know if where actually more contributors 20 years ago, relatively speaking, but much of the code was also less complex. Open source is still remarkably successful and the only reason why the whole Log4J RCE is such a big deal, is because the library is hugely succe…

I think you are absolutely correct. The best way to contribute to Open Source software is to literally contribute to it.

We don't need to turn OS maintainers into service providers that sell support contracts to enterprises.

Enterprises could just contribute to projects in kind, eg. by auditing a library, by fixing a bug, or by writing some docs.

Post reply on HN