4 ms·
FWIW, while this specific act may not be enforcing significant regulation, software developers need to understand that there's a ticking clock. Modern civic eng
by staticassertion 4y ago
FWIW, while this specific act may not be enforcing significant regulation, software developers need to understand that there's a ticking clock. Modern civic engineers went without any significant regulation, and then that changed. Software is young, it's in the phase where people aren't dying too often for the public to care. But breaches are leading to massive privacy problems, real wars and conflicts are increasingly leveraging software defects, and the impact and scrutiny will only grow.
If you want to avoid having to pass tests, having to maintain insurance, having to do a bunch of bullshit, all just to be a software engineer, get started on fixing things now.
It is absurd that anyone can anonymously provide open source code, with no assurances whatsoever, and that can end up in critical software. And you might be saying "well, it's up to people to audit their dependencies" - and maybe you're right. But I would challenge that everyone has the right to publish code for distribution purposes with zero responsibility.
Publishing code to Github? Sure, go for it, anyone can do it. Publishing packages to package distributors ? No, that crosses a line. I don't want legal requirements, I don't want identification requirements, just to publish and distribute code.
If we want to avoid that we're going to need to step it up - that means, yeah, basic measures like strong 2FA to distribute packages should be a requirement. Signing packages should be a requirement. Acknowledging and triaging vulnerabilities should be a requirement. If you aren't willing to do the above, which is frankly trivial, you shouldn't be allowed to publish software for distribution purposes.
I think we need to start taking a bit more responsibility for the work we do. "NO WARRANTY" doesn't mean "No obligations", it just means no one has a legal right to pursue damages due to your software, you should still do some things.
edit: K I'm rate limited so I can't have this conversation with all of you, thanks again Dang
- yjftsjthsd-h 4y agoI'm going to disagree, I think. The problem isn't on the push side, it's on the pull side. People throwing random-quality code in github is fine. People deciding to amalgamate that into distributions and publish it is fine. The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it, and that is the problem. NO WARRANTY is partially about legal issues, but not exclusively - if people share their code for free, they don't owe anyone anything. If you don't like that, you're free to offer them enough money to actually accept your standards.
- staticassertion 4y agoI think a lot of people will disagree, which is cool and I'm fine with that but I do hope that this discussion can be had. > The problem is that somewhere someone who is supposed to be held to some standard decided to pull that code in without looking at it Why is it that there is no standard applied to those who publish code for distribution purposes? Why do we want that to be the case? Again, publishing to Github or some source repository is fine, that should never ever be restricted, but publishing with the express intent for others to use it? I don't get why we're trying to ensure that that's something that shouldn't at least imply the bare minimum of assurances. > if people share their code for free, they don't owe anyone anything My point is that they don't legally owe anyone anything but we should impose a moral standard in lieu of a legal one. If you are saying "here's this code, I've packaged it up and sent it out for distribution" I think it should be perfectly fine for us to say "did you do the bare minimum to make this code acceptable for others to use?". I don't get why we say "you have no ethical obligations in open source", why do we do that? Who benefits? I get not having legal obligations, but once you're distributing code for use it seems absurd to say that you have no ethical obligations. You chose to do that, you chose to distribute it, you didn't have to do that. And while I do think that the obligation exists regardless, I also feel that if we don't step it up here, these things are going to be forced on us. I'd rather we do it ourselves.
- mwint 4y ago> but we should impose a moral standard in lieu of a legal one I agree with you, but these moral obligations tend to get enshrined in law eventually (or quickly! See Covid)
- staticassertion 4y agoThey're gonna get enshrined into law eventually one way or the other. If we do it ourselves and we're effective at limiting the damage we cause we'll be able to maintain control over our own processes. If we don't it will be taken out of our hands.
- peteforde 4y ago> It is absurd that anyone can anonymously provide open source code, with no assurances whatsoever, and that can end up in critical software. While you're welcome your position and your ideas on how to solve these problems, I believe that the logic you're applying punishes the provider and not the consumer. Nobody is forcing anyone to use OSS without auditing every damn line, if that's their requirement. Telling people that share their hard work with strangers for free that they have an ethical responsibility to accept vague "obligations" - as defined by lobbyists and politicians - is not an idea with wings.
- staticassertion 4y agoNobody is telling them to share their work and distribute it to others as a package. As I said, I don't think there should be any restrictions on anyone to publish code.
- peteforde 4y agoI don't know what your background or interest in this issue is, but I'm glad that the overwhelming majority of people do not find this perspective to be reasonable or compelling. In the meantime, if you don't like the MIT license, don't use software published under it.
- staticassertion 4y agoLicensing is completely irrelevant to this discussion.
- unity1001 4y ago> Modern civic engineers went without any significant regulation, and then that changed There is no analogy. The only reason why other engineering disciplines are not adopting software practices is because the other engineering fields are not easy to iterate. You build a bridge. And then you could maybe get some funding to improve one part of it a decade afterwards. Because it is too expensive and cumbersome to do it. When IoT, AI, nanomachines, 3D printing proliferate, you will see how that will change. Devices and buildings will be possible to iterate, and they will have versions that get incremented as they are improved. ... As for obligations, the existing law already covers it. From GDPR to payments compliance, everything is there. And a lot of the best practices are invented and standardized by Open Source, actually. ... What Open Source still lacks is the mindset to approach end-users and consumers and be able to get them on board. Open Source needs to take the route of 'no backwards compatible changes', and even 'add, never deprecate' (like JSON project) along with the habit of hiding complexity from end users and making things easy. Then we can create a truly Open Source world in which there will be infinite new possibilities.
- n42 4y agoI don't entirely agree with you (nor do I totally disagree), but I wish this comment was not so heavily downvoted. This is a good perspective worth discussion. Importantly, this is also how a lot of people outside the industry will see it.