10 ms·
> Whenever someone refuses to show source code I always think, "what are you hiding in there?" There's usually something. There's a dilemma that developers fac
by computator 9y ago
> Whenever someone refuses to show source code I always think, "what are you hiding in there?" There's usually something.
There's a dilemma that developers face when deciding to release source code that's bigger than fear of software theft or the desire to hide something evil in the code. It's a fear of being scrutinized, ridiculed, or humiliated over the quality of their code.
Imagine 2 programs that do something useful and are functionally equivalent. Program A is closed source. Program B has source code available for inspection. Suppose on inspection, program B's code turns out to be bloated, ugly, poorly organized, and with many potential bugs or defects. B's reputation is screwed. However, for all you know, A's code is just as bad or worse. But you don't know for sure.
Bloggers and reviewers will write that no source is available for A.
Bloggers and reviewers will write that program B's code sucks.
The consumer reads that "program A doesn't give you source code" and that "program B's code is garbage", but are otherwise functionally equivalent. Which do you think will have greater influence on most consumers and their purchasing decision?
That's one major reason why more developers don't release source code. I wish I knew a way out of this dilemma.
- daurnimator 9y agoThe way out is to assume the worst: if no source is available, then assume they're hiding it due to it being "bloated, ugly, poorly organized, and with many potential bugs or defects".
- ianai 9y agoAs someone whose deployed and supported lots of enterprise software and hardware, that's got to be absolutely correct.
- executesorder66 9y agoThe project with open source code can be improved by anyone. The project with closed source code can remain terrible forever even if there are programmers willing to improve it. Here's an example: Looking for a WebExtention alternative to greasemonkey on Firefox. (I know a port is being worked on, but let's ignore that for now) Your options are tampermonkey (closed source), and violentmonkey (open source) Tampermonkey has been around longer, and probably has more features. Which do I choose? I choose violentmonkey, because for all I know tampermonkey's code is garbage, and full of spyware. If violentmonkey doesn't meet my requirements, I can make it meet my requirements by coding the feature myself, or paying someone to add the feature.
- ConfucianNardin 9y agoAnd here I thought Tampermonkey was open source, but apparently they went closed since I started using it...
- majewsky 9y agoYeah, thanks for calling that out. I removed it just now.
- jcbrand 9y agoI'm skeptical that this is actually as big a reason people don't want to open-source their code as you assume. In any case, there are good solutions for it. Firstly, if you know from the start that you're going to open source the code, then you'll make more of an effort than (perhaps) usual to ensure that the code is well-organised, well-tested and elegant. At least within your current level of competence, but that's all anyone can hope to do in any case. Some humility is also required in my opinion. I know many people subscribe to a fake-it-until-you-make-it philosophy, and there's some value in that, but when it comes to open sourcing your code, it's good to check your ego and to be open to suggestions and criticism. There will always be people who are more knowledgeable and better than you at certain things. Best IMO is to accept this (and their criticism if you're lucky enough to receive it) and to see you how can learn from them and improve. BTW, I speak from some experience. I have had some nominally embarrassing experiences with OSS where other people highlighted relatively obvious security issues with code that I wrote and which I thought was of high quality. However, in turn I got free QA from knowledgeable people and in the process the code improved further as I fixed the problems. Also, as some people have mentioned already. OSS that is popular gets improved all the time. I.e. if you're lucky, and your code doesn't languish in obscurity, then you'll get patches and pull requests to improve your code. So the way out of the dilemma... if you're really just being held back because you fear criticism and ridicule, is to ignore the fear, be humble, and to still open-source (perhaps after doing some cleanup, but not to the extent that you use it as a crutch to avoid open-sourcing). You'll probably realize that the fear was totally unfounded or in the least exaggerated.
- sbarre 9y ago> Firstly, if you know from the start that you're going to open source the code, then you'll make more of an effort than (perhaps) usual to ensure that the code is well-organised, well-tested and elegant. This is assuming you even realize that your code is un-organized and inelegant. There is no doubt tons of software out there written by journeyman developers who don't know best practices or good coding techniques, but just know how to "ship it".. And, honestly, there's nothing wrong with that..
- collinmanderson 9y ago
- TeMPOraL 9y agoI'm not sure if it is a major reason, but it definitely is a consideration. N=1 - I feel those thoughts about my work myself, occasionally. However, my experience with released software is as follows: - Open sourced code I've seen is pretty shitty. So is closed source code I've seen. - Programmers working in open source don't care that much if otherwise good projects have shitty source code. - Bloggers and reviewers writing for general audience don't mention source quality at all. Hell, half of them probably don't understand what source code is in the first place. And it's OK, because general audience doesn't care about internals either. - Reviews of application source code are very rare.
- yAnonymous 9y agoThis is a non-issue and you are projecting your own fears on others. I work on very large projects and frankly, some of the code is utter crap. Still, if someone came along and criticized it without offering patches, they'd be the one looking stupid.
- graphitezepp 9y agoI have not been here long, but my current company has absolutely no culture of shaming code. People do some pretty egregious things, and not just in terms of adherence to style, and their work is still lauded if it runs fast.
- amelius 9y agoYou forgot to mention security issues.
- meerita 9y ago> There's a dilemma that developers face when deciding to release source code that's bigger than fear of software theft or the desire to hide something evil in the code. It's a fear of being scrutinized, ridiculed, or humiliated over the quality of their code. But there are really few examples in the world made by one developer. Where's the fear of being scrutinized when you have a team of developers who are "supposedly" doing "code review" all the time?
- kerkeslager 9y agoThis "dilemma" is great. I'd rather find out my code is garbage and be able to learn and fix it than not know and continue writing garbage code. Fear of that criticism being public is just an ego thing. If you write something people use you will be criticized, if not for the code then for so everything else. Closed- source doesn't help with that. Some say the only way out is to kill your ego, but that's pretty difficult to do. I think a smaller step that's easier is to simply stop attaching your self-worth to your code. You wouldn't hate a learning programmer because they're bad at coding. Extend that same feeling to yourself--unless you think you know everything, you're still learning. People might not like what you make, but that's an opportunity to figure out why, so you can do things differently next time.
- Fnoord 9y agoWith lower end software (like 'firmware') the reasons could also very well be legal. You may think of copyright infringement there, but I'd more think in the lines of licensing other software [either by source, or proprietary] as part of your software. Examples could be library, or firmware of specific hardware chips as part of an end product's hardware. Lack of open drivers is a serious problem in embedded land; specifically, it keeps phones on old Android versions where security fixes aren't backported.