20 ms·
Stop Building on Corporate-Controlled Languages
- the_only_law 4y agoI’m gonna build on what people pay me to.
- anta40 4y ago"I refuse to install android-studio since I am sure it will be phoning home about all sorts of things." I wonder what the OP use to build Android apps. Perhaps simply gradle? BTW, I use Go ocassionally for building API stuff at work, and Nim for personal projects. Since my main responsibility is building Android apps, I don't see myself leaving Android Studio, unfortunately.
- nandalism 4y agoRemember when programming languages were free? When your compiler/editor didn't call back to some corporation every time you compiled code? When our package managers weren't linked to data aggregators watching our every move? When we used free tools to build free software.
- PaulHoule 4y agoHmmm... back in the day there were IBM PL/I, Microsoft BASIC, Borland's Turbo Pascal, ... Post 1990 or so the FSF came out with gcc, gcl, etc. Since then there are free languages like Python and PHP. However, many open source projects are "corporate dominated" for better or worse. LLVM would not be the quality framework it is if Apple hadn't invested in it. Linux got SMP scalability thanks to IBM. No Google, No V8, No node.js. A language like Nim might have no corporate sponsor now but if it catches on it may very well get one.
- optimalsolver 4y ago> When your compiler/editor didn't call back to some corporation If you use compilers/IDEs from megacorps when there are so many great alternatives, you only have yourself to blame.
- ARandomerDude 4y ago> When our package managers weren't linked to data aggregators watching our every move? I haven't heard of this before (other than TFA's bare question-raising). Do you have an example?
- spicybright 4y agoSame here. Doesn't even sound like a problem, it's not like you have to make an identifying account to access it. I'd imagine having the data lets you detect/fix issues faster and flag malicious packages much easier.
- chomp 4y agoGolang out of the box aggregates and analyzes usage metrics of modules whenever they are downloaded.
- mseepgood 4y agoWhich package management system doesn't do this?
- crtc 4y agoTrue, I quickly checked https://rubygems.org/ https://rubygems.org/ https://www.nuget.org/packages https://www.nuget.org/packages https://crates.io/ https://crates.io/ ... they all show download statistics of their packages.
- HideousKojima 4y agoWhich also serves a useful purpose for devs, it's an easy way to avoid typosquatting by making sure you're not looking at a package with a similar name to the one you want but with only 2,000 views instead of 2,000,000
- jeltz 4y agoOn top of my head: CPAN and Debian's since both are distributed with mirrors not controlled by the the main project. It is possible that some mirrors save statistics but there is no aggregation of it. But, yes, most package manager servers track download statistics and as long as they throw away the IP addresses I do not see any harm.
- pixl97 4y agoI have to say that you must be pretty young. You don't seem to remember the days where you used to pay for compilers.
- spicybright 4y agoWe have more options for languages and editors than ever before that directly compete against commercial options. And a decent amount of the time, they're fundamentally better and widely used commercially. I certainly do remember the main options being: buy commercial software, download an inferior freeware, or go through a huge effort setting up emacs to be a low quality version of one of the first 2. Oh, and now it's ok/expected you don't have to use windows for everything, because that was the case for a while. IMO, it's never been easier to use excellent software while avoiding corporate bullshit, so I'm glad we're not back then anymore. Edit: FWIW I'm early 30's programming for about 15-20 years of those (arguably!)
- allenu 4y agoWhen I was a kid, there were no free compilers. You had to pay for tools like Turbo Pascal. You were either lucky if you found a decent free C compiler to download off a BBS or you pirated one.
- notacoward 4y agoWhen the original 128KB Macintosh came out, I started programming on it in assembler because I couldn't afford any of the compilers. Being able to work at that level affected the trajectory for about the first half of my career, and I think for the better. Growing up in a world with free compilers (and complete-enough scripting languages too) seems very different.
- digitallyfree 4y agoIf you're building for a proprietary OS, then yes the tools sometimes aren't free - e.g. iOS development. However we can 100% use free tools to build free software running on a free OS, with the simplest example being C code compiled by GCC running on Linux.
- jeltz 4y ago> Remember when programming languages were free? Yes, now. I also remember when they were not free. > When your compiler/editor didn't call back to some corporation every time you compiled code? Yes, now. Just do not use Visual Code. > When our package managers weren't linked to data aggregators watching our every move? Yes, now. > When we used free tools to build free software. Yes, now. Just do not use Visual Code or Github.
- dlivingston 4y agoWhen was this? Year ~2000 through ~2010?
- nwah1 4y agoTerrible arguments. Golang and Android Studio are both open source, and you could compile them yourself. Telemetry can be turned off in Android Studio, and you can use stuff like flatpaks to isolate the software from your system, and completely turn off networking permissions if you don't trust the settings.
- nwah1 4y agoAlso, you end up with very similar questions for non-corporate languages like Nim because you don't really know who created the software, what their motives might be, and whether the binaries you are receiving are really what the source code says it is. Reproducible builds help, but once you are going down this path of verifying instead of trusting, then it doesn't really matter who built the software.
- giaour 4y agoI have seen this perspective a lot in government and adjacent entities. For them, commercial software and corporate open source has a clear financial motive. If they can't identify why a project exists and continues to receive support, they see a security risk, either via direct compromise or project abandonment and the associated supply chain rot.
- numbsafari 4y agoand they aren’t wrong to do so. Browser plug-in author gets bored and sells out customer base is a well tread story. Takeovers of well known packages are another. Most of these ecosystems do not offer proper sandboxing for the things we take from them, so it’s easy for things to grow an appendage that abuses our prior assumptions. Apache’s Java ecosystem is full of consultant abandonware and tripwires.
- kube-system 4y ago> Browser plug-in author gets bored and sells out customer base is a well tread story. Not even just "get bored" but, just a plain matter of incentive. Salaries are a strong incentive against undermining your employer's work. Now, of course, there are people who are incentivized because they are altruistic and good at heart, but that's very difficult to measure. It's much easier to demonstrate aligned interests monetarily.
- anonyme-honteux 4y agoOpen source projects are under financed and their maintainers are overwhelmed. I would rather read proposed solutions about that because that seems like the more important problem.
- alphazard 4y agoThe economics of independently lead open source is still a problem with no solutions in sight. The economics for corporate controlled open source are quite clear. It's a cost saver for corporations to open source solutions to common problems. This gets others to buy in, which spreads maintenance costs and ensures that no one is seriously winning in the domain of the project. Essentially de-risking cost/benefits in the domain of the project. Another problem, which the author didn't discuss, is that corporate controlled software is often designed by a committee, or designed by those with political capital within the corporation. There is not usually a strong selection mechanism for good system designers, or good open source leaders. Go is a happy and rare exception. Projects coming out of corporations are often not as well designed as projects which rose to prominence organically through differential amplification by the community.
- rblatz 4y agoI’d also like to throw another counter example out. C# and Typescript from Microsoft are both excellent languages and are led by Anders Hejlsberg.
- nandalism 4y agoIs that the same Anders Hejlsberg who developed Turbo Pascal and Delphi for Borland, another company which microsoft successfully crushed in the 80's and 90's? (Hint: It is). We could have C# 30 years before we did if it weren't for microsoft.
- philwelch 4y agoC# came out in 2000; Microsoft didn't even exist in 1970.
- alphazard 4y agoI would highly recommend Odin to anyone who has looked at Zig or Nim (as the author did here). Also not corporate controlled, but used in production at several corporations. https://odin-lang.org/ https://odin-lang.org/
- brokencode 4y agoMy problem with Odin is the same as Zig. I think that manual memory management is a bad choice for most applications and only really has a place in very low-level or performance-critical code. To me, the most promising newer languages all attempt to make automatic memory management faster, more predictable, and more scalable. That’s what I think is so compelling about Rust. Koka is a promising upcoming language as well, and there are many others in this space.
- Calavar 4y agoOutside of Rc and Arc, which part of Rust memory management is automatic? The whole pitch for Rust is making manual safety management safer by using more sophisticated compile time checks. It certainly doesn't make automatic memory management faster or more scalable. (Rc and Arc are both regressions from tracing GC in that regard.)
- brokencode 4y agoThe whole ownership and borrowing system is a type of automatic memory management. It just happens at compile time instead of runtime like most automatic memory management systems. Manual memory management is possible in Rust, but is not typically something developers need to interact with. There is typically no need to manually free objects when you are done with them. You just let the system destroy the objects automatically when they go out of scope.
- Calavar 4y ago> There is typically no need to manually free objects when you are done with them. You just let the system destroy the objects automatically when they go out of scope. By deciding where to scope the variable with the destructor/drop function, you've already made a manual decision about memory management. The compiler implicitly inserting a call to the destructor does not automate the decision of when/where to allocate or free memory - its just syntax sugar over the decision that you already made. This is just as true of Rust in 2023 as it was of C++ 40 years ago. With true automatic memory management like tracing GC or reference counting, you have no idea where the or when the memory will be freed as you write the code, and the answer will usually be different over different invocations of the same code. > The ownership and borrowing system is a type of automatic memory management No, it isn't. The borrowing system is completely orthogonal to memory management. You can write a function that takes a borrow, do all sorts of things with that borrow, including forwarding it along to other functions further down the call chain, and the memory backing that borrow could be statically allocated, dynamically allocated with the default rust allocator, or allocated by some custom solution like a slab or pool allocator. The code reads the same regardless of the memory management scheme because you make the decision on how you will allocate (and eventually free) the memory before you ever create a borrow. The borrow checker can help keep you from making use-after-free errors, but it doesn't dictate when, where, or how memory is freed. That's still up to the programmer.
- jeffbee 4y agoThere's a hell of a lot of fuzzy thinking in this article. Exactly what "ecosystem" tainted by Google's articles of incorporation pollutes the author's machine? I know it is the modern style, but I preferred discourse when words had meanings. "Corporation" is not a word that means the thing the author is obliquely suggesting. Their precious GCC is maintained and distributed by a Massachusetts corporation doing business under the fictitious name "Free Software Foundation, Inc."
- rstat1 4y agoI also miss the days when words actually meant something. Back when "spyware" actually meant "steals your data, without you knowing" not "collects useful info to help the developer".
- MichaelNolan 4y agoI don’t see the issue with using corporate backed languages. Java (the language, the core libraries, and the compiler, etc) are all GPL2. GoLang is BSD licensed, c#/dot net is some mix of MIT and a few others. So what’s the problem? There doesn’t appear to be any risk here.
- brankoB 4y agoDid you read the article? The author is concerned about spyware.
- MichaelNolan 4y agoThat just seems like a weak concern though. The code for the java compiler is open source. The code for maven is open source. So how is Nim safer from spyware? If I’m concerned about spyware, then my language and compiler are low down on my list. My OS, my phone, and my network are far higher on the list.
- runjake 4y agoThere's some risk. A language and it's tooling can be GPL or BSD-licensed, but if it's corporate-controlled, the following things can happen: - The corp still doesn't need to take direction, nor input, nor patches from the community. - The corp can steer the language and frameworks wherever they want. Sure, you may be able to then fork it, but is that fork going to gain any traction? Probably not. And it definitely will not work on that corp's Official Operating System platform.
- rstat1 4y ago> The corp still doesn't need to take direction, nor input, nor patches from the community. >The corp can steer the language and frameworks wherever they want. Sure, you may be able to then fork it, but is that fork going to gain any traction? Probably not. These both apply to not-corporate projects as well.
- 4y ago
- runjake 4y agoThis post is, as other commenters have alluded to, a case example of why you should upvote based on the article's content, not it's title. Great title, very poorly-articulated article. tl;dr: It wants you to use Nim for $reasons.
- jchw 4y agoMy response to the plea in this article is simply "No thanks." If Go gets that bad, I'd be happy to use an ungoogled fork of it, or migrate to another toolchain or language, or whatever needs to happen. But until then, I'm not going to preemptively switch ecosystems and banish technically good options from my tool belt because I have fears about what could happen. I want production quality toolchain and runtimes. That's hard. Go has a high quality library of cryptographic functions. Hard. Go has a fast usermode thread scheduler with preemption on many platforms. Hard. Go has an incredibly low latency GC that doesn't need much tuning for most workloads. Very hard. Some of those hard solutions are self-inflicted by the choices made in the language, but the fact that they are solved so well is what makes it valuable. A mediocre implementation of Go would have less value. A mediocre implementation of a random language with a tiny ecosystem by comparison would be even harder of a sell. I am by no means trying to say that Nim is low quality or not interesting for anyone. In fact, I actually think Nim is cool. It is not the only other smaller programming language I like. I have a strong affection for Zig as well. There are unique properties that make these languages desirable. Zig comptime is really cool for example. I like stuff like this. But: I also think Go is a great piece of production-quality software. I know many people hate the language now, especially now that the honeymoon has thoroughly ended. But I still like it. I feel highly productive in it, the ecosystem is good, and at the end of the day, I know I can make reliable and fast software in it. Corporate control is a shame, but the truth is that corporate control is not the problem at all. The problem is funding. Because anyone can fork Go, but can you pay maintainers? Can you run the CI, the website and playground, host the CDN with the downloads? Etc. Sometimes the answer is yes, especially with how much GitHub subsidizes a lot of those things, but in general the answer is no. "Corporate control" is not the problem itself. Governance is just an outwardly visible consequence. The true control comes from maintainership and stewardship. Because if nobody is stepping up to the plate to take that role, then whoever is doing it today effectively has control over the project.
- goodpoint 4y agoCorporate control is very much a problem. A big one.
- Tozen 4y agoBased on the article, the person appears to be also talking about privacy, security, and freedom. Where the corporate tools can unexpectedly and stealthily be phoning home or the direction they go in are corporate controlled too much. This is less of an issue with truly/more so free and open source tools like Nim, Vlang, Free Pascal, Odin, Dlang, etc... They don't have the same kinds or levels of corporate gotchas attached to them. They are more "tools of the people". In various languages, corporations are more akin to users and donors, than they are dictating the direction and forcing their way, despite what the majority of users may want.
- bulatb 4y agoAlternatively: "Stop complaining no one eats their vegetables and make a vegetable that people want to eat."
- pessimizer 4y agoPeople don't know what they want to eat until aggressive marketing convinces them to have a taste.
- nix23 4y ago[flagged]
- DrewADesign 4y agoYeah? I guess Big Garlic Bread is out there somewhere twisting their mustaches and watching the dollars roll in.
- bulatb 4y agoI guess moralizing could be seen as an extremely ineffective form of marketing, if it's done at people rather than problems. That's an interesting angle, thank you.
- tenaf0 4y agoI never liked these arguments.. We can’t live without some trust, it is simply impossible the same way we can’t avoid all risks in life. Putting our head in the sand doesn’t solve anything. As for the concrete languages mentioned, Java is probably the safest bet out of managed languages, not only does it have a proper specification (both the language and the JVM), it can be carried forward by multiple companies single-handedly, it is that critical piece of infrastructure. Also, even from an incentives point it doesn’t make sense to put backdoors or whatever, as they themselves use it very heavily, so each big company in effect “checking” the others.
- autodev1 4y agoI feel this way about TypeScript. That said, I see its value. We use it at my company. TypeScript is open-source but created and (I think) pseudo-owned by Microsoft, which has had terrible ethics over the years, including the 3 E's [1] [1] ""Embrace, extend, and extinguish" (EEE),[1] also known as "embrace, extend, and exterminate",[2] is a phrase that the U.S. Department of Justice found[3] that was used internally by Microsoft[4] to describe its strategy for entering product categories involving widely used standards, extending those standards with proprietary capabilities, and then using those differences in order to strongly disadvantage its competitors." https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...
- lucasmullens 4y agoTypeScript is the least concerning one. If Microsoft somehow does something so outrageous that you can't stomach using TypeScript anymore, just compile it to JS permanently and call it a day.
- cosmotic 4y agoThese Microsoft examples are 20 years old. The company has changed leadership to a team that embraces open source years ago and I think they've done a pretty good job demonstrating this embrace. They have adopted open source Java, they further open sourced .NET, they've embraced Linux containers in Azure and WSL on windows, etc. Might be about time to reconsider this perspective of 'hate Microsoft'. Full disclosure: I work at Microsoft and these things I listed are a big part of why I moved there this past year.
- turtlebits 4y agoI'm not sure I believe this. IME, the developer experience of .NET on Linux and Mac platforms is definitely subpar compared to Windows. I've tried to get started on F# several times and have always run into bugs and incomplete/inadequate documentation.
- nickcox 4y ago
- javier_e06 4y agoThere is salt on my kitchen counter but I don't put much concern and exactly how it got there. Some transactions (go ahead download our cool stuff) over the internet comes with strings attached, some don't (very few). The aggregate effect of for profit entities embedding themselves across hardware they don't own but in one fashion or another, start controlling, is harmful. On whose behalf my router and my pc are churning computations and transferring bytes anyway? Should compilers and computer language be like salt. Now you have it, use it, no strings attached. I'm so glad that spices can't be licensed.
- deleted 4y ago[deleted]
- com2kid 4y agoQuestion about Vale's positioning, where does it exist relative to Zig and Nim? At a brief glance Vale seems closed to C than C++, which seems to put it in some of the same use cases as Zig, but perhaps a bit higher level. Is that an accurate assessment?
- verdagon 4y agoZig is great for low-level use cases like embedded, especially where performance is a high priority and memory safety doesn't offer as much benefit as in other domains [0]. Nim's also geared towards systems programming, though it does so with an RC foundation. It's features are well-designed and complement that pretty well. Vale's more geared towards the higher-level cases (games, apps, servers) where memory safety, performance, and developer productivity are all priorities. It's meant to be more of a "software engineering" language, focusing on keeping things loose and decoupled in the large, while offering tools like regions [1] (not done yet) to eliminate overhead everywhere it can. [0] https://verdagon.dev/blog/when-to-use-memory-safe-part-1 https://verdagon.dev/blog/when-to-use-memory-safe-part-1 [1] https://verdagon.dev/blog/zero-cost-memory-safety-regions-overview https://verdagon.dev/blog/zero-cost-memory-safety-regions-ov...
- zozbot234 4y agoRust will probably encompass most of these use cases eventually. Features like e.g. RC with efficient cycle collection as found in Nim, or generational regions as found in Vale, will simply be implemented as add-on crates in Rust, complementing the existing borrow checker.
- verdagon 4y agoThere are some design decisions mean Rust can't work with generational references and regions, unfortunately. They're incompatible with their form of borrow checking. In Vale, each struct has a generation in theory, but they are often merged with their parent struct. It requires some pretty interesting logic which can't be implemented in Rust. Regions require truly immutable references, which Rust doesn't have. Their shared references are unfortunately foiled by the RefCell escape hatch. Additionally, the rest of Vale's future design prioritizes developer productivity more than Rust has, in my opinion: - A coroutine-like mechanism instead of Rust's async/await function coloring, and structured concurrency which doesn't involve the Sync/Send "data coloring" problem. - Vale's borrowing is done on the region level and on an opt-in basis, so users can decide to only use borrow checking where it makes sense. - Linear typing ("Higher RAII") which allows for different static checks which aren't quite as infectious as aliasability-xor-mutability. I love Rust, but it has some quirks that make it much more suited to low-level development than these higher user cases. I don't see how Rust can fix them, but there are some smart people working on it and I hope they figure out a way, because the world needs a fast and safe language that's easy to learn and focuses on productivity, even if it's not Vale ;)
- DontchaKnowit 4y agoDidnt read the article but based on the headline I agree. Currently working for <small but influential company A> doing real time surveillance on an enormous amount of data. Using a proprietary language owned by <a competitor company B> Technically, theres no conflict of interest because we, as a regulatory body, are a seperate business entity from the company A- but honestly what interest does company B have in addressing our concerns with their software? They arent incentivized to fuck us over nut they have no incentive to help us out either. We are running into so many problems. And I know for sure that we could, with about a million dollars worth of billable hours in total, create a product vastly superior to cokpany Bs product. But progress marches on and were already bought in. So we just deal with the problems.
- macintux 4y agoI was unpleasantly surprised when I installed Dart last weekend and received a warning about it reporting back to Google Analytics by default(?!), so I can definitely sympathize with the concern.
- arcanemachiner 4y agoI would expect no less from the king of data mining. I'll use Google's developer tools, but the first thing on my mind when I install them is "Where's the opt-out for the analytics?"
- Invictus0 4y agoTake off the tinfoil hat.
- anononaut 4y agoCome off it. This isn't 2001 anymore. Corpos dominate tech in every facet. Data harvesting has never been more egregious and rampant. This data can and has been used (read weaponized) in ways nobody could have predicted. It's important we cover our asses and wash our hands when we make decisions about long term projects. To dismiss these concerns and opinions as crazy is disingenuous or at worst borderline malicious.
- charcircuit 4y agoThe only reason why software didn't have telemetry before was because software engineering was in a less mature state. Being against software that has telemetry just shows you would like to use software using substandard engineering processes.
- znpy 4y agothe article seems to be mainly about Go, but iirc Amazon now employs most of the Rust steering committee, so much so that there was an ex contributor complaining about it a while ago. Java used to be backed by Sun Microsystems, but now it's really open source. Nowadays (iirc) Oracle and Red Hat are the main contributors.
- ilc 4y agohttps://en.wikipedia.org/wiki/Google_LLC_v._Oracle_America,_Inc https://en.wikipedia.org/wiki/Google_LLC_v._Oracle_America,_.... I disagree that Java is an Open language. Experience says otherwise.
- shadowgovt 4y agoI don't think I understand the ask here. Author's claim is they're concerned about corporate ownership of the languages but the examples they cite of concrete issues is the system "phones home." Well, so does Python every time I pull a pip package in. So does every package manager. Is there an implied "I don't trust the phone-home features of package management systems supported by corporations" that doesn't apply to non-corporate-supported development ecosystems? Why is that?
- nandalism 4y agoPip is separate from python itself. With a given language can I download packages with curl and install them myself? I think I can trust curl. The problem is not only that the tool connects to the networks, but who is behind the tool. Google is a company whose business is collecting all the information on people it can. I don't think those in control of python/pip have the same incentives.
- vluft 4y agothere's nothing preventing you from downloading go code manually without the package manager and using it that way
- throwaway894345 4y agoOr even easier--pointing your Go tool at a package proxy of your choice.
- vluft 4y agoyup; you can easily run your own or just set GOPROXY=direct to use go modules without a proxy at all.
- deleted 4y ago[deleted]
- btown 4y agoIronically, a small programming language is much more vulnerable to telemetry-code injection by its maintainers than a large one like Go, where multiple non-Google-affiliated members of the community are actively following each commit made to the compiler source code. As long as you build your compiler from source (and have always done so, per Reflections on Trusting Trust) then you benefit from those eagle-eyed auditors for free. That said, it's important that the language have good governance with representation from firms other than the original creator.
- gnarbarian 4y agopostulate: languages that provide the most utility are more likely to be controlled by corporate interests because corporations that depend on those languages have a stake in its future and will invest in it. this includes web standards, openGL, and basically anything with a governing board composed of multiple large entities.
- manv1 4y ago"GCC, in turn, allowed the development of new languages like Perl and python" wut?
- JonChesterfield 4y agohard to implement languages in C without a C compiler
- jansommer 4y agoInstall those languages in a VM if you're concerned about things they phone home about. Not sure if the metrics being sent is the biggest problem unless you're super paranoid about intellectual property theft.
- EMM_386 4y ago> Not sure if the metrics being sent is the biggest problem unless you're super paranoid about intellectual property theft. Exactly, there seems to be a high level of paranoia with some developers about any software that "phones home". I can see possible fears stuff being sent in crash reports if you are working on highly sensitive software or really worried about IP theft, but other than that I don't think telemetry in products like VS Code is sending the contents of your hard drive to Microsoft. They use that limited information to improve the tooling, which benefits everyone. Maybe I'm just getting old and tired, but I leave it on and am not overly concerned with it. I used to be a lot more critical of things like this, but everything is so interconnected these days it's not worth the battle. Besides, I'm sure every megacorporation already knows my entire life story by this point with all the really invasive tracking that goes on on the web and on my phone.
- sergiotapia 4y ago>Unfortunately this is no longer true as compilers and editors now have integrated package managers. We expect them to communicate on the network and we don't really know everything they might be communicating. I really agree! Elixir is my main workhouse language, I love it and the Phoenix platform as well. I also really enjoy using Nim. It's _fast_ and looks great, easy to write too. Nim is one killer web framework away from the main stage. It will capture a lot of attention once it has a batteries included web framework. Think Rails, not Sinatra.
- snowpid 4y agoAlso even if phoning home is a concern: Thanks to GDPR Google has to say what they save. Even if they save more, they need a way to ask for permission and to delete if I don't want that. Of course Google could dismiss the law but then they have to pay massive fees.
- JustSomeNobody 4y agoI'm confused. When I go get ... is it "phoning home" to Google? I could wireshark it, but since we're all here...
- crtc 4y agoIt accesses the module proxy proxy.golang.org, which is run by Google. If you want to opt-out of this module mirror, you can turn it off by setting GOPROXY=direct. The proxy has a clear privacy policy: https://proxy.golang.org/privacy https://proxy.golang.org/privacy It collects anonymized usage metrics like other package registries (rubygems.org, nuget.org, crates.io) do.
- JustSomeNobody 4y agoOkay, thanks. Seems harmless enough and has an opt out.
- horsawlarway 4y agoI think this is a fairly misguided rant, and ignores the real priorities (and risks) that I have as a developer - both personally and professionally. I'm happy to use languages funded by corporations - the incentives for them are clear, they fund development and work on the tooling and spec for their own use-case - they garner additional support, momentum, and goodwill by releasing the language under an open definition (and sometimes also release an open version of the tooling around the language). I don't really know what the author wants from a package management tool. At least personally - I fully expect it to communicate with the package host provider, and for them to track information about what I'm downloading... It's a network based tool that fetches remote resources someone else is hosting (usually for free). Decent package managers will also support self-hosted repositories, and allow configuration for 3rd party repositories. I also don't find this sort of tracking particularly malicious... not any more than I would find it both reasonable and sane for a store to be tracking how many customers they get a day, and to pay attention to what their hot-selling items are. Further - GCC is absolutely and example of a corporate provided language being adopted and tooling developed outside that corporation's control. Not sure what the author is smoking... but C was developed under corporate control at Bell labs of AT&T. Further - there's still a wild amount of closed source tooling around C that comes out of Microsoft, and is absolutely high quality (and not cheap). Mono is an example of this for C# - Corporate language, open implementation. Javascript was developed by Netscape (another corporation) and now has dozens of different runtimes. Some open, some less open. ---- Basically - What the fuck is the author talking about?
- mixmastamyk 4y ago> particularly malicious... not any more than I would find it both reasonable and sane for a store to be tracking how many customers they get a day, and to pay attention to what their hot-selling items are. This is substantially less than what code running on your machine can do, which is basically unlimited its spying capabilities. Yes, this is a problem in itself that needs to be fixed. Otherwise you appear to willfully misunderstand. These may not be your priorities, but taking offense and framing them as "crazy" does a disservice.
- 4y ago
- danielmarkbruce 4y agoThis appears to be extreme aversion to risk. From a cost/benefit, it doesn't make sense.
- stephc_int13 4y agoI tend to agree with this type of stance against corporate ownership. Simply because ownership is power. Power in the hands of individuals is harmless as it is mostly Brownian motion; on the other hand, power in the hands of huge corporations (or governments) can turn nasty very quickly. This is the reason I stopped using VSCode even if the tool is very good. Ownership is too important, with heavy long-term political consequences to be ignored or traded for short-term convenience. Basically, anything running "in the cloud" or slowly converging to run there should be a red flag. Without being paranoid or a luddite, you can do everything with mostly local-tech or at least diversified enough to avoid giving too much power to a single actor.
- scarface74 4y ago> This is the reason I stopped using VSCode even if the tool is very good. So you’re not going to use the tools that you think are the best and most productive and instead depend on the kindness of strangers volunteering in their free time? And before you cite “Linux”, look at who the top contributors are - all corporations. Yes and how deep down are you willing to do everything on your own and does it give you a competitive advantage - ie “does it make the beer taste better”?
- mixmastamyk 4y agoThere have been great FLOSS dev tools for decades—it's one of the few areas with "an embarrassment of riches." Other areas so-so, but dev tools are top notch and ubiquitous. Definitely one area we don't have to compromise principles. It's also important how its distributed, if in a main distribution at least a pair of eyes or two have looked at the source.
- scarface74 4y agoThe dev tools that are not developed or supported by a for profit corporation that are “top notch” are not “great”
- nandalism 4y ago
- scarface74 4y agoYes and instead build on languages and frameworks with no guiding principals or cohesive strategy like the clusterfuck of the front end ecosystem and Node.
- tonmoy 4y agoAs someone who uses committee/consortium developed languages, I would like to remind the author how insane such languages can be
- vindarel 4y ago> I'm focusing on compiled/statically-typed languages here so will be skipping over Common Lisp (a venerable language we should all seriously consider) <3 CL is compiled and SBCL gets us many type warnings and errors, and Coalton can get you as much compile-time type checking as you wish (Haskell-like on top of CL). https://github.com/coalton-lang/coalton/ https://github.com/coalton-lang/coalton/
- brianolson 4y agoYeah, I don't want to use the Microsoft language (C#) Certainly not the Oracle Language (Java) I like the Google Language (Go) and it's BSD so maybe safe-ish? I'm not in that ecosystem, but I'd use the Apple language (Swift) if I had to. Maybe the JetBrains language (Kotlin) is okay? I hear lots of buzz about the Mozilla language (Rust), maybe they have a good history of open source stewardship. The Guido language is pretty friendly (Python) ;-) But I'm pretty done with the Larry language (perl)
- FireInsight 4y agoKotlin is not just okay, it's pretty great IMHO. Elegant and expressive, feels familiar. The only reason I only use it when I need to is JVM, and the fact that googling anything Kotlin-related brings up results android. Just answering your question^^
- ignoramous 4y agoCompletely agree. Outside of Android app development, AWS uses Kotlin for its backend systems: http://web.archive.org/web/20200706214913/https://talkingkotlin.com/qldb/ http://web.archive.org/web/20200706214913/https://talkingkot...
- Narishma 4y agoRust isn't a Mozilla language. It started there but it has it's own foundation and isn't under Mozilla's stewardship.
- bmitc 4y agoWhy do some software engineers work and think this way? There are a ton of things in society built on corporate-controlled and even proprietary languages and software tools, from buildings to bridges and more. There are quite a few open-source projects and packages that I would love to be corporate controlled so that I could get some help and support that I would gladly pay for.
- trinsic2 4y agoThis is a good idea. Corporations primary interests don't align with the needs of the public.
- FireInsight 4y agoI thought this was _just_ a rant, but apparently it was a rant (maybe a bit misguided) AND an argument for what's also my favorite programming language; Nim. As long as you're fine with whitespace-based syntax, Nim will bend to anything as well as C at least, add on top of that compilation to JS (not WASM, just plain old JavaScript), you _could_ develop everything with Nim. Alas, I don't do that either. I still love Golang, and the extensive support and familiarity of JS on the web keeps it as my main language. Someday I'll need a program again, that'd be as easy in Python as in Nim, and where the development wouldn't benefit from the effortless concurrency of Go.
- badrequest 4y agoJeez, I hope this person didn't write this blog on a device made by a corporation! And I certainly hope it's not hosted by any corporation in any way!
- nottorp 4y ago> remember when programming languages were free? Cheap maybe. Turbo Pascal was 49.99. Linux was at 0.01 and very few people had access to hardware that could run gcc. I thought it will be a rant against corporate controlled languages because you can't rely on them long term. Instead it's that the ide or package manager phones home. Well so does apt or macports? Edit: actually Turbo Pascal predates Linux 0.02 by 8 years.
- deleted 4y ago[deleted]
- unethical_ban 4y ago>Python Syntax: Nim syntax is vaguely like python, indenting and colons for block structure I am an ops automation person quarter-time, and I use Python for all my work. I wish Python did not make whitespace significant. I won't pretend I was going to learn Nim tomorrow, but knowing it is whitespace-aware takes my interest to zero. --- Now on-topic, having RTFA, the complaint is "I don't want a corporation having analytics about my usage". >Something I read recently and my own experiences with the golang package proxy reminded my how much I trust the golang tools on my machine, and yet how little I should trust them. Why not? Why not trust them? What pictures of your vacation, what personal source code are they leaking?
- yashap 4y agoThe author specifically calls out Google/Go, Apple/Swift and Microsoft/C#, around tools that do compilation and package management spying on you. It's worth noting that this potential exists in both corporate-controlled and non-corporate-controlled languages, but ... have there actually been any incidents of Go/Swift/C# doing anything sketchy here? IMO this argument needs specifics, because non-corporate projects can do the exact same thing. The other concern is: > Using java for free software was the first misstep. We were warned against it but ignored those warnings. Much later the oracle/google battle showed how precarious it is to build on languages controlled by corporations. There's certainly an argument there, but it also happens with non-corporate open source. To give an example: - Scala (programming language) was released in 2004, as a non-corporate open-source project - Play (web app framework for Scala and Java) was released in 2007, as a non-corporate open-source project - Akka (actor system lib for Scala and Java) was released in 2010, as a non-corporate open-source project - Key people in these projects form Typesafe (now Lightbend) in 2011. A company that provides premium support and tools around open-source projects, largely centred around Scala/Play/Akka - A few months ago, in 2022, Lightbend changed the Akka licence, made it proprietary ("Business Source Licence") and very expensive at large scale Software that starts out as more "pure", non-corporate open-source can still turn the tables on you and charge large licensing fees later. But at least if it's open source from the start, it can be forked, e.g. for Akka, there's this Apache fork that was started after Akka changed its licence: https://github.com/apache/incubator-pekko https://github.com/apache/incubator-pekko . This is the key open source protection, and it's true for both corporate and non-corporate projects - if the maintainers start doing things people disagree with, anyone can just fork it.
- hgsgm 4y agoI don't see the benefit of eschewing a proprietary runtime and them running your program on a proprietary OS owned by the same company.
- yashap 4y agoAre you referring here to Apple/Swift/iOS/OSX, and Microsoft/C#/Windows? If so, good point, if you're writing iOS mobile apps, or OSX/Windows desktop apps, you're pretty tied to Apple/Microsoft regardless of the language you choose. Not so applicable to Go - ppl mostly use it for writing servers running on Linux.
- mark_l_watson 4y agoI liked the article, while disagreeing with a few parts of it. I agree with the main premise, having independence from large corporations, in the same way I like individual countries to be autonomous and not beholden to other countries (and one world order/government agencies like World Economic Forum can go to hell…) I would add Python, Common Lisp, and several Scheme implementations to the list at the bottom of the article. Nim looks like a very nice language but as a niche language it probably lacks broad classes of libraries that I would like to have available.
- phendrenad2 4y agoThe post fails to connect the dots to explain why I would want to "stop using corporate-controlled languages". The author mentions that they stopped using them because they "phone home about all kinds of things". But that implies that I dislike any and all "phoning home" (which is the vast majority of instances is simply anonymous statistics to help you, the user, find the most popular packages) enough to shun it. But I also don't think that the author's intention was to convince, and this is more of a "I'm better than the rest of you and here's why" piece.
- EMM_386 4y ago> But that implies that I dislike any and all "phoning home" (which is the vast majority of instances is simply anonymous statistics to help you, the user, find the most popular packages) enough to shun it. I totally agree with this. This "phone home" scenarios aren't rummaging through your file system or reporting back what websites you are visiting. It almost seems like there is an underlying level of paranoia, or people are working on extremely sensitive stuff that they are concerned will be reported back or caught up in some poorly anonymized telemetry reports. I personally leave telemetry on and am not concerned with it. If it helps improve the tools I am using on a daily basis, go for it. This is different than the analytics on the web which know everything from what food I like to what music I listen to and a lot more. We're talking performance metrics and stability issues, not what I may want to purchase today.
- RcouF1uZ4gsC 4y ago> remember when programming languages were free? This is actually the golden age of free programming languages. Previously, if you wanted a high quality compiler, you had to either get it from the vendor of your operating system or license one for a lot of money. Now, you have access to multiple high-quality compilers. In addition, even if you had a free compiler, you would have to pay for floppy disks or a cd-rom. Now you can download it for free. There is also a lot more information for learning about new programming languages thanks to the Internet. Finally, you also have access to libraries/frameworks like LLVM that make it much easier to build your own compiled languages. For example, Rust probably would have taken much longer to get where it has, if it was not able to leverage the LLVM infrastructure early on for things such as optimizations and cross-platform compilation. Now with regard to corporate control/backing of languages, if you look at computing history, you will see that most successful programming languages have been backed by some corporation (there are exceptions, though). Fortran was backed by IBM. C and C++ was backed by AT&T and later Microsoft (especially for Windows). Pascal was backed by Borland. Java was backed by Sun. Rust was backed by Mozilla. The question is not so much if a corporation backs a language but rather how it goes about building a community around the language. IMO, I think Mozilla did a very good job of building a very broad community around Rust so it became more than just a Mozilla language.
- pklausler 4y agoWay before Borland existed, Pascal was created at ETH Zurich and enjoyed its early rush of popularity from free (minus media & shipping charges) distributions for CDC hardware from the University of Minnesota and for the P-machine on many platforms from UCSD.
- mikewarot 4y agoUCSD Pascal was famous for being slow and crashing. Turbo Pascal was faster than any other compiled language available, and it kept getting faster. Had Borland not gotten greedy, Delphi would still be widely used.
- ozim 4y agoCompiler was one thing - debugger that would let you step through the code was serious expense. All the tooling we get nowadays for granted was insanely expensive.
- michaelsbradley 4y agoNim … relies heavily on exception handling as opposed to golang's explicit rejection of exceptions If exceptions aren’t your cup of tea, look into using stew/results and questionable instead: https://github.com/status-im/nim-stew/blob/master/stew/results.nim https://github.com/status-im/nim-stew/blob/master/stew/resul... https://github.com/status-im/questionable#readme https://github.com/status-im/questionable#readme Re: std/db_sqlite, you’re probably better off using sqlite3_abi: https://github.com/arnetheduck/nim-sqlite3-abi#readme https://github.com/arnetheduck/nim-sqlite3-abi#readme
- Thaxll 4y agoI would say "Stop Building on immature language"which is exactly what Nim, Crystal are etc ...
- WalterBright 4y ago> I'm not so sure about the openness of D-lang so I've left it out D is the most open language you will find. It is Boost licensed, which has the least restrictions of any language you'll find: https://www.boost.org/users/license.html https://www.boost.org/users/license.html The compiler is 100% Boost licensed. Nobody pays me a dime for D.
- nandalism 4y ago(The one and only WalterBright! What an honour.) Terribly sorry about that. I've moved you into the list. It's been a long time now but I really did like D and its meta-programming features.
- WalterBright 4y agoThanks for the quick correction!
- distortedsignal 4y agoThey should, but that's another issue.
- philwelch 4y agoIs there any evidence or context that I'm missing for his claim that the golang command-line tools are "Google spyware"?
- 1vuio0pswjnm7 4y ago"I had some problems building Zig from source, so moved on to Nim (which I also failed to build from source as it set my laptop on fire). I gave up at this stage and installed the pre-compiled binaries for Nim. So, just by luck I ended up choosing Nim for a deeper look." GCC will build from source on NetBSD, even on low resource computers. It has been quite reliable for me over the years.
- raydiatian 4y agoWho controls JavaScript?
- thesuperbigfrog 4y agoThe trademark: Oracle https://tsdr.uspto.gov/#caseNumber=75026640&caseType=SERIAL_NO&searchType=statusSearch https://tsdr.uspto.gov/#caseNumber=75026640&caseType=SERIAL_... The standard: ECMA https://www.ecma-international.org/publications-and-standards/standards/ecma-262/ https://www.ecma-international.org/publications-and-standard... The implementations: browser vendors, Npm, and many others https://en.wikipedia.org/wiki/List_of_ECMAScript_engines https://en.wikipedia.org/wiki/List_of_ECMAScript_engines
- up2isomorphism 4y ago“C come from corporate.” The author does not bother to understand history about Bell Labs and why that organization is probably most true in the sense of “free in spirit “ even it is nominally part of the AT&T.
- leftcenterright 4y agoGenuine question: How did android turn out to be such a privacy nightmare while still being an open-source project? "I am sure it will be phoning home about all sorts of things." is 100% true in case of Android.
- fluoridation 4y agoBecause (to my knowledge at least) there are no hardware vendors flashing unmodified Android builds into their phones.
- kitsunesoba 4y agoOk, show me a "truly open" language that feels as nice to write, is as well balanced, and is similar technically to Swift and I'll consider it. As far as I know no such thing exists. This is why there's pressure from within the Swift community to improve cross-platform support and the number of use cases Swift is viable for rather than rallying around some other more open language, and I'd assume the same is true for the communities surrounding any corporate-founded language. People flock to these languages because they're filling needs that other languages don't.
- raydiatian 4y agoThe logic of this article. 1) Forget how members of hacker community earn a living. 2) Tell hacker community about your favorite programming language, tell them to use it and not CorpoLang™. 3) Forget how members of hacker community earn a living.
- pjmlp 4y ago> C also came from a corporation but it came free with every unix install and soon after I started using it, Richard Stallman et al. gave us GCC, a free C compiler. Until Sun decided to create user and developer SKUs for UNIX and everyone else in the UNIX space followed, along. Only thereafter did GCC start to get really used, until then it was largely ignored. This also ignores that WG14 participation isn't free beer and for GCC/clang to be compliant with ISO someone has to actually buy the standard documents, the free draft and final versions aren't 1:1 the same. > GCC, in turn, allowed the development of new languages like Perl and python. No corporations in sight! We got a lot done with these languages. It's not like we are incapable of creating ecosystems without corporate "help". We have proved that, with countless projects in the past. Perl and Python came to be didn't had anything to do with GCC, and both were at one time or another sponsored by corporations.
- henry_viii 4y agoAnother alternative to Go is V. Differences between Go and V: Syntax https://github.com/vlang/v/wiki/V-for-Go-developers https://github.com/vlang/v/wiki/V-for-Go-developers Features https://vlang.io/compare#go https://vlang.io/compare#go
- daviddever23box 4y agoGo => Google => spyware is a bit of a stretch. Come back once you've grown into your big-person pants.