6 ms·
Dominic is wrong. If there's no authority, then there's nobody taking responsibility. This is a perfect example of how lack of organizational structure simply d
by programmarchy 8y ago
Dominic is wrong. If there's no authority, then there's nobody taking responsibility. This is a perfect example of how lack of organizational structure simply does not work in the real world. Dominic's other projects like scuttlebutt are likely doomed to fail as well because of his wrongheaded views about organization.
For a successful counter-example, one can look at the well-structured, hierarchical organization behind Linux. Lieutenants gain authority based on the merit of their contributions, and are responsible for reviewing the work of other developers. Authority works, has worked for thousands of years, and will continue to work for thousands more.
- lsc 8y ago> Dominic is wrong. If there's no authority, then there's nobody taking responsibility. This is a perfect example of how lack of organizational structure simply does not work in the real world. Maybe, but the sort of people who are not jerks (i.e. who don't get too much pleasure out of having power) who are willing to lead for free are... very rare. Fundamentally, non-commercial open-source needs to evolve organizational methods that require less leadership, just because there aren't a lot of good leaders willing to work for free.
- codetrotter 8y ago> other projects like scuttlebutt are likely doomed to fail as well because of his wrongheaded views about organization. Define failure. I don’t know Dominic and I haven’t looked into the Scuttlebutt project beyond being aware of its existence and what it is, but... He talks about creating a community where anyone is welcome to contribute. It is perfectly fine for an open source project to have the development process and the community as its raison d'être. Just because a project doesn’t outcompete every single alternative doesn’t mean it’s failed. Just because a project isn’t even used by more than a handful of people doesn’t mean it’s failed. It all depends on what the goal of the project was in the first place, and what the goal of the contributors are.
- skore 8y ago> He talks about creating a community where anyone is welcome to contribute. Yes and in this case, that was exactly the problem. > It is perfectly fine for an open source project to have the development process and the community as its raison d'être. Conway's law is not an instruction manual.
- onion2k 8y agoThe problem was that too few people contributed. A contribution to an open source project doesn't have to be a pull request. Glancing over the code you're pulling down rather than assuming the maintainer is infallible counts just fine. Very, very few people do that in the JS ecosystem though. When a package gets 2m downloads a day and it still takes 2 and a half months to find a problem, a huge number of developers have failed to do their part.
- brobdingnagians 8y agoA security hole and backdoor is always a failure in a software product. Having someone else control your system is just about the worst you can get. It has nothing to do with relative definitions because it always degrades every other objective the project could or does have. If a model of leadership leads naturally and often to security holes, it is time to reconsider the model. If it is a common library, then it is even worse. Open source that is used widely is _even_ more important to protect because the impact can be so much greater.
- Aeolun 8y agoI don’t know, if I write open source software, the only definition of success I use is whether or not I had any fun writing it. Anything else is gravy.
- testvox 8y agoLots of projects, including windows and linux have had security holes that allow remote control of your system. Security flaw does not mean failure, its always about weighing the cost of security flaws against the utility the software provides. Even a completely compromised system can provide utility to many users.
- komali2 8y agoThis sounds like "if it's not perfect, it's a failure." I'm actually not aware of a single piece of software that didn't at some point have a production security vulnerability. Facebook failed. Google failed. Amazon failed.
- albinofrenchy 8y agoLinux has a giant user base, a giant installation base, and a giant pool of talented devs willing to take on unpaid work. If this is an indictment of anything, it's an indictment of the entire NPM ecosystem -- it's been the wild wild west for years; haphazardly using whatever NPM install gives you is baked into the culture. Sure, Dominic is an active participant in that culture but it seems to me that it is impossible to have a largely unmoderated volunteer system with as many packages are actively used without things like this happening. Keep in mind, this is a case where the system worked, more or less -- an observant user caught the issue, and made a public issue of it. Who knows how many packages have slipped by like this?
- Matthias247 8y ago> Linux has a giant user base, a giant installation base, and a giant pool of talented devs willing to take on unpaid work. And also important: It even has a giant number of paid maintainers, for who this is their main job. For those the incentive to continuously maintain things is different than for someone who gets nothing expect more work out of it.
- deleted 8y ago[deleted]
- newnewpdro 8y ago> Linux has a giant user base, a giant installation base, and a giant pool of talented devs willing to take on unpaid work. Linux didn't always have a giant user base, and it wouldn't have gotten there without strong leadership having a sense of pride and responsibility.
- jolmg 8y agoI'm curious if anyone knows how it really has developed. Has anyone documented the history? Do I understand correctly that right now it's a hierarchy with Linus at the top and levels of "Lieutenants" managing increasingly more detailed levels of subsystems. How was development organized before? Are the developers that are paid mostly on the top or the bottom of the hierarchy? Are the proportions of paid developers very distributed among different companies or does a major portion of them belong to one company?
- sorisos 8y agoI would rather see it as if contributors gain _trust_ based on their contributions, which is not necessarily the same as authority.
- always_good 8y agoIf a contributor's end goal is to publish a backdoor, then making them wait 0 or 100 commits to the project before trusting them doesn't change the end result. In fact, if you had the energy to do the attack at all here (which took some work), having to fake trustworthiness doesn't require much more effort. Just look like a super enthusiastic contributor, put work into the readme, bike-shed over some issues every month, and bam.
- 21 8y ago> Lieutenants gain authority based on the merit of their contributions Meritocracy is an outdated discriminatory practice. https://postmeritocracy.org/ https://postmeritocracy.org/ https://www.theguardian.com/commentisfree/2017/mar/20/meritocracy-inequality-theresa-may-donald-trump https://www.theguardian.com/commentisfree/2017/mar/20/merito...
- ummonk 8y agoTo be clear, you're arguing that people should be judged on their identity and background rather than the merit of their contributions?
- throwanem 8y agoYou are feeding a troll. Please don't.
- rosser 8y agoSkimming those links, I think the position is that people are already being judged on their identities before they're judged on the merit of their contributions, not that they should be. The extent and congruence of the findings regarding, e.g., blinded vs non-blinded resumes alone should put the lie to the idea that a true "meritocracy" is something humans can actually meaningfully do at this point.
- lambdadmitry 8y agoThat's a contrived "no true Scotsman" right there. Also quite a few people argued that democracy should be replaced by dictatorship on similar grounds: "look at America, it's clear that democracy is shit". Imperfect realization doesn't mean the ideal is invalid (except when that imperfection is inherent to the ideal). You can argue for more equal, more meritocratic community; tearing it down because it's not already perfect is disingenuous and destructive.
- zeroname 8y ago> Meritocracy is an outdated discriminatory practice. Of course merit is judged subjectively (like anything else), but what exactly is the alternative? In particular, I don't find anything actionable in that manifesto in regards to decision making.
- harrisonjackson 8y ago> that doesn't have a strong measurable reason I think that's the key here - organization/hierarchy is important as a project scales up, but he didn't want to stifle a new contribution without good reason.
- resters 8y agoBut in the absence of a trusted, well-structured organization, authority rests on the shoulders of those using the library as a dependency.
- jekrb 8y agoScuttlebutt already works, people use it and are building on it.
- watwut 8y agoWhat happened is that Dominic gave ownership to the only person who wanted it: "he emailed me and said he wanted to maintain the module, so I gave it to him. I don't get any thing from maintaining this module, and I don't even use it anymore, and havn't for years." At every single point, there was authority and responsibility. It is just that authority turned out to be bad actor. It was situation where former authority was not interested in being authority anymore, since former authority gained nothing from it and had other work.