15 ms·
“Our paying customers need X, when will you fix it?”
- yawaramin 3y agoThis is the correct response whenever a corporate OSS user shows up and reveals themselves as such. 'For corporate users, we can arrange a support contract to answer questions. For non-corporate users, support is provided via the community forum.'
- whack 3y agoIs it really rude to ask an OS maintainer when they plan to release X, and explaining why they care about this topic? Emphasis on ask - not demand. The maintainer is well within his rights to ignore or refuse the request. But going on twitter to put someone on blast for "may not be the best way to introduce yourself"? I have no idea who Maximilian is, but he doesn't come across well in this exchange.
- II2II 3y agoEven if you ask once and ask nicely, the question is bound to come up often enough to rate as annoying. Explaining makes matters worse, from the perspective of using another person's time and opening up the communication to misinterpretation (e.g. it may be construed as laying a guilt trip on the developer). So yes, asking a question can be rude.
- l33t233372 3y agoThe Github exchange didn’t warrant sharing, but the email was over the line, in my opinion.
- eschneider 3y agoI've worked on many commercial products that have incorporated open source components (and respected their licenses.) I was always under the assumption that it there was a problem with the open source bits, it was MY responsibility to resolve those problems for my customers, because it was part of the product I was shipping. Full Stop. That almost always meant getting into the code and fixing what I needed fixed and (hopefully) getting a PR accepted so it'd be in the next release. If I needed fixes from the maintainer to support my commercial product, I'd expect that I'd need to pay...something to make it a priority for them. I mean, my problems aren't their problems, right?
- II2II 3y agoYou are correct. Open source licenses, at least the ones I'm aware of, have no warranty clause. That said, it won't prevent people/businesses from asking/demanding a fix from the developer. It simply means the developer doesn't have to remedy the problem.
- papandada 3y agoThis points to such a great communication principle, including one that HN/dang promotes -- if the point remains the same, then take out anything else, especially when it's personal or potentially inflammatory. Now, instead of a fairly simple and straightforward issue as the current top comment points out, this has blown up between parties and on the internet because of the completely unnecessary "extortion" remark.
- johnmyleswhite 3y agoIt seems more interesting to discuss the implied underlying situation here than focus on any individual actor's tone. It seems from the interaction that a part of IBM has (1) taken software that explicitly has no warranties, (2) repackaged it and sold it for profit by unilaterally adding new warranties of their own creation, and (3) attempted to redirect the burden of compliance with those warranties to the original authors (who had explicitly disclaimed any such warranties).
- Ekaros 3y agoAnyone wonders what their actual use case for mitmproxy for them is? For what they are using that type of software? I know infosec uses, but for what are they using it in this case.
- zug_zug 3y agoSounds to me like somebody learned that using an aggressive/threatening tone has been highly effective at their own job and doesn't their negotiating position here is quite different.
- berkle4455 3y ago27 years of it and you get promoted to Program Manager Secure Engineering and Incident Response, IBM.
- Pannoniae 3y agoCorporate entitlement about using open source (and demand support for it) is enormous. I would love if licences with usage restrictions were more popular, and the OSI wouldn't just say "that's not open source!!!". It would prevent these kinds of situations.
- amiga386 3y ago> I would love if licences with usage restrictions were more popular, I would not. Or rather, not if the "usage restrictions" were outwith the varying strengths of share-alike enforcement provided by the LGPL, GPL, AGPL. Freedom for users to run software for any purpose is freedom 0, and Stallman sets out very eloquently why usage restrictions would not help: https://www.gnu.org/philosophy/programs-must-not-limit-freedom-to-run.html https://www.gnu.org/philosophy/programs-must-not-limit-freed... As per the warranty disclaimer, free software is given to you with no strings attached. It is boorish to demand free support and maintenance as well, when you've already been gifted the freedom to make any amendments you see fit. I don't think changing the license would make such boorish people go away.
- the8472 3y agoI think most people don't want to be that anti-corporate. Otherwise they wouldn't use permissive licenses in the first place. And there may be non-license options that are friendlier to open source than corporate. E.g. if someone has a non-trivial issue they must publish a reproducer.
- morelisp 3y agoI'm not surprised it happened, but I am surprised at the @us.ibm.com sender address.
- UnixSchizoid 3y agoGiven their ownership and treatment of Red Hat I'm not shocked
- morelisp 3y agoI'm sure there's literally any overlap at all between that and this.
- LoganDark 3y agoA general culture at IBM of using open source software without giving back? Seems pretty strong in both cases.
- UnixSchizoid 3y agoexactly what I was going to respond with
- yawaramin 3y agoI'm sure that will come as a surprise to all their open source GitHub repos.
- Cupprum 3y agoThese type of people are the cancer of open-source… Feel free to come up with a PR if its so important to you.
- tzs 3y agoHow would a PR help? The work has already been done and committed. The project just hasn't gotten around to including it in a release yet.
- rahimnathwani 3y agohttps://github.com/mitmproxy/mitmproxy/issues/6051#issuecomment-1636320181 https://github.com/mitmproxy/mitmproxy/issues/6051#issuecomm...
- morelisp 3y agoIs the specific person important to the point? Edit to replies: Both the context and the employer were in the original post. Blasting the actual GitHub issue when it's clear the author specifically tried to avoid that is awful behavior too.
- arghwhat 3y agoTheir IBM email address is.
- jlund-molfese 3y agoI don't think the person matters that much, but it's useful to see the context around the comment
- whynotmaybe 3y agoEspecially the fact that the issue is already resolved and "waiting" for release. IMHO, asking for the next release date is ok. He even added sorta justification as to "why" he asked it. Proposing consultancy services is also ok, just like answering "we don't have a release date" would also be ok. But the email... Can't choose between this guy thinks he is "The Guy Working At IBM", or he sucks at communicating.
- Un1corn 3y agoI don't think the person was important but the employer might. It seems to be IBM which is not surprising I guess, although I'd hoped that RedHat would influence how they work with open source somehow.
- account42 3y ago
- Ralfp 3y agoI’ve had sudden spike of ”when will you fix this” and „I am also affected, this is important!” comments on one of my projects. It was very odd to see sudden interest like that. But around the same time I’ve got an email with apology explaining that company’s boss asked employees to stir up the pot to pressure me into a fix, pretending its affecting far more people than it really did.
- chii 3y agothe best response is to say that your rates are $XYZ/hr and i take cash or cheque!
- dazhbog 3y agoExactly, you ask them to pay, then you see how "important" the issue really is..
- scrollaway 3y agoThere's no 3-digit hourly rate that would get me to deal with cheques.
- Ekaros 3y agoSEPA transfers only...
- pc86 3y agoImagine the level of privilege required to refuse to deal with a slip of paper for $999/hr. Checks are a pain in the ass roughly equivalent to having to clip your fingernails every once in a while.
- scrollaway 3y agoFirst of all, it was a joke. Second, if a job is offering me $999/hr and asks me to use cheques, something's really fucking wrong and it's a scam. Third, "blah blah take a picture with your phone" -- y'all talk about privilege as if you ever lived outside of the US. Where I'm at, dealing with a cheque involves finding a bank that will accept them (Mine sure as hell doesn't), and opening an account there, then most likely depositing it in one of their rare remaining branches because there's no such thing as photo-deposits or w/e.
- qawwads 3y agoThe same kind of people who say gpl isn't free enough.
- UnixSchizoid 3y agoThis is why software licenses with restrictions are useful
- Zambyte 3y agoWhat do you mean?
- m0llusk 3y agoI'm sorry but we have no record of having received your payment.
- teeray 3y agoI wonder at what point this becomes harassment.
- Zambyte 3y agoWhen they try to circumvent you blocking them
- dazhbog 3y ago[flagged]
- nborwankar 3y agoMany people are going to complain about this post … to the manager ;-)
- tiahura 3y agoThe initial post was a simple request to find out if there is an eta. I don’t see a big problem with that.
- jmvoodoo 3y agoI think it's simply a cultural difference, and the message was interpreted by the developer as "give me a date that is close to now to satisfy me" which may or may not be accurate depending on FrugalGuy's intent. But also, the idea that the devs might not care to set and be held to a date seems to be lost on the asker. They probably have not considered that this relationship is not a vendor relationship and asking for something like a date commitment is "out of bounds" for the relationship between them and the OS developers. Lack of understanding and empathy on both sides for something that probably could have been turned into a fruitful relationship if it had been handled differently (not that it couldn't still, but that certainly doesn't seem like the direction things are going).
- fieryskiff11 3y agoWouldnt anyone first check up on themselves upon a rude response from an otherwise helpful (they maintain one of the largest network sniffers) dude?
- sowbug 3y agoIt was more than that. It tried to influence project priorities by characterizing the impact. The response stated that another way to influence priorities is to pay money. Nobody was being unreasonable. The follow-up email demonstrated low EQ.
- ncallaway 3y agoI think the big problem with the initial post is the follow up email.
- mgaunard 3y agoAnother reason not to use third-party libraries.
- Arch-TK 3y agoI've just realized, if you don't want your code to be used for commercial purposes, instead of using the GPL, just claim your project has a critical risk vulnerability.
- hgsgm 3y agoGovernment contractors, not all commercial users.
- account42 3y agoDepends on the use, but there are a lot of cybersecurity regulations that apply to regular companies and this is only getting stricter as time goes on.
- taskforcegemini 3y agobut then non-commercial users may also jump off
- BonoboIO 3y agoAnd don’t tell them where exactly.
- bragr 3y agoI don't think his characterization of this interaction is accurate. A plain reading of is question is he was just asking when the next released was planned, and without knowing more about what their native language is, and how they normally speak, I don't think you can really read anything more into it, especially over text. And frankly from their perspective, your response does kind of read like extortion, e.g. "shut up or pay me". The thread already indicated that this was fixed and waiting for the next release [1] so I don't see how your response is appropriate to the asking when that was planned. I can certainly understand why this guy is frustrated as an open source maintainer, but snapping like this doesn't help anything. [1] https://github.com/mitmproxy/mitmproxy/issues/6051#issuecomment-1498535463 https://github.com/mitmproxy/mitmproxy/issues/6051#issuecomm...
- zimmerfrei 3y ago>> The thread already indicated that this was fixed and waiting for the next release Making a release is work too, so the response looks OK to me.
- morelisp 3y agoThe initial comment was just barely on the side of acceptable, it's not demanding but is a bit entitled. The private followup email is maidenless.
- tspike 3y agoMaidenless?
- LegitShady 3y agoIt clearly has no maidens.
- justin66 3y agoThe maidens are the first ones to flee a discussion involving IBM personnel. It's just common sense.
- ryaniscool 3y agoThere is a subtle difference between "I would like to know when this will happen so I can make plans"and "I need this done because I'm being paid for your work, please hurry". If the requester left out the background information, the tone of the request would have been more of the former and less of the latter.
- fogof 3y agoI disagree that this would have been the right thing to do. There's nothing wrong with explaining why something could be useful in an open source project - if the reason seems like something important that a lot of other users of the software would also need, the maintainers of the software might want to know about it so that they can add the feature or fix the bug sooner. It can also help if there's some way of working around the problem. Calling the developer extortionate was unreasonable, but I don't think there's anything wrong with the first message.
- Fordec 3y agoI'd say I expect better of an IBM employee, but I plainly don't.
- bravetraveler 3y agoPM gone astray, wow. I can understand asking - even being a bit robotic in doing so. The first time. The email is too much, you got your answer. To get a firm date you need a contract
- deleted 3y ago[deleted]
- supriyo-biswas 3y agoWhile the behavior from "FrugalGuy" is immature and childish, a better way for the mitmproxy maintainer would be to post a polite but firm response, one that leaves no room for error or drama such as this one: > As per the mitmproxy license, the software is provided as-is without warranty, and project maintainers are currently constrained by other priorities and deliverables. > As such, statements on the Github issue tracker are not considered as sufficient justification for the prioritization of issues. The only way to prioritize issues would be to enter a support contract, available [here], the terms of which we will be happy to discuss further.
- pc86 3y agoThis doesn't seem substantially different from what they actually said, except a bit more rude (maybe that is the intention?) so I'm not sure what this gives you that the actual response doesn't.
- stefan_ 3y agoNope, that is as crazy as the original guy. You are not owed politeness in response to your tone deaf request.
- supriyo-biswas 3y agoI agree you're not owed politeness in this situation, but it prevents the ensuing drama after such things have been said, which is very draining for the people on the receiving end of said drama.
- hibbelig 3y agoI found the response polite and firm…
- wg0 3y agoI think a year's salary of an engineer (which is NOTHING at certain corporate scales) would make the fix happen in matter of weeks and it is only fair. OR if you absolutely don't want to pay then other way would be to allocate one of your own engineer for few months to patch the parts you need for the paying customers and contribute upstream. EDIT: SORRY - This one year one engineer compensation is just my own limited incorrect estimation. I am no position to say what's exactly worth in but I would estimate few months of effort for an engineer that's NOT familiar with the code base, probably.
- frostburg 3y agoApparently they would just need to build a newer release, the fix is already done (but I suspect that doing so would evoke other compliance issues, which is probably why it wasn't done; obviously this isn't the open source project's problem).
- yieldcrv 3y agouse this post if you feel like both parties are overblowing it with hyperbole snowflake button
- deckar01 3y agoHave developers forgotten how to publish community forks to package managers? I believe the reason projects wait for releases is to allow the community to find bugs and the release to stabilize. If the community is rushing the publisher, they would be better off cutting their own beta releases, because a primary namespace semver does not magically make the changes stable.
- arp242 3y agoReading the issue[1] I think the IBM request is a lot more reasonable than this tweet makes it seem. The issue is that a mitmproxy dependency has a CVE, mitmproy updated the dependency (in March), but hasn't made a stable release yet with this update (last release from Nov 2022), and IBM guy is asking "when do you plan to tag a release? Do you have a timeline for this so we can communicate this to our customers?" Notably it's NOT asking for a fix; "when will you fix it?" is not accurate as there is nothing to be fixed. It's just asking "when do you plan to make a new release with this dependency update?" I don't think that's an unreasonable question. I also don't think it's unreasonable to ask for a support contract if you want these kind of fixes shipped within a certain timeframe, but the question is a lot more reasonable than it seems at a glance and immediately coming back with "email me for a support contract" seems a bit over the top to me. I could have asked this question and I think most people here could. [1]: https://github.com/mitmproxy/mitmproxy/issues/6051 https://github.com/mitmproxy/mitmproxy/issues/6051
- mhils 3y agoAsking for a release date is a perfectly reasonable request! My response was highly influenced by the context. I came back with "email me for a support contract" because 1) I previously stated in the thread that we will not ship a patch release for this[^1] and 2) the commenter emphasized the impact on their paying customers. So this was all I had to add there. I agree that I could have phrased this more nicely, but I personally don't feel my reply was totally over the top. [^1]: the CVE itself is bogus and we don't use that part of the dependency.
- politelemon 3y ago> the CVE itself is bogus and we don't use that part of the dependency. A trend I'm noticing, compliance and infosec teams only caring about checklists and not able to understand nuances of CVEs. They only see the number. Thus the boneheaded pursuit and odd expectations spilling into the open source ecosystem.
- woofcat 3y ago
- deleted 3y ago[deleted]
- neonsunset 3y agoI think even more disheartening here would be giving a response the commenter requested and then not even getting a "thank you" in return, which happens all too often.
- brightlancer 3y agoThe original question was polite and gave his reason for asking. The developer's response was not helpful and a bit snarky. A better response? "No, I don't have a target date; this is X on my priority list, after my paying work. If your company is willing to contract me for support, I can prioritize the release. Email me if you'd like to do that." Companies pay for software all the time. Just make it easy for them to do so (IIRC that was posted on HN a little bit ago) and direct folks to that if they need priority support. Otherwise, it can appear as if the developer has a "first one's free" mentality, where the user is now dependent upon broken software and the developer wants to charge for the fix. "But the corporate guy's e-mail was rude and aggressive!" Yes, but his original questions was not; it was mhils who first responded like a jerk.
- ufmace 3y agoI agree that the response is a bit snarky and escalates the situation. However, unpaid open-source project maintainers aren't obligated to be scrupulously polite at all times no matter what. If you want professional corporate interactions, then pay professional corporate prices. I'm also sympathetic to not wanting to commit to a specific release schedule for an open-source free time project, with implied consequences if it isn't met.
- brightlancer 3y ago> However, unpaid open-source project maintainers aren't obligated to be scrupulously polite at all times no matter what. If you want professional corporate interactions, then pay professional corporate prices. It would have cost mhils nothing to be polite and the idea that "if you want polite then pay for it" justifies abusive behavior. I've personally seen far too many co-workers state that they're paid for their technical skill rather than to be polite, or even that they're not paid _enough_ to be polite. mhils ITA.
- atoav 3y agoThe maintainer didn't answer the question. But I don't think it was snarky. If you want a problem solved in an open source project you (and your financially very solvent customers) rely on the minimum would be to offer some way you can help or provide resources.
- richwater 3y agoSome idiot just commented on the Github issue attacking the guy and telling him "Welcome to Hacker News". That commenter is equally stupid. Has no involvement with the project and nothing to gain by being inflammatory.
- mhils 3y agoOP here. To be clear, I don't mind the release question at all, it's valid! But the context should be along the lines of "we have an interest in this, how can we help make it happen" (contributions or $) and not "you are causing problems for our customers". I don't want the requestor to have a miserable time because of a badly-worded comment, I want large companies to have a healthy relationship with FOSS.
- harrid 3y agoBut it was an extortion attempt
- smoldesu 3y agoExtortion implies an illegal abuse of power to obtain property. A cursory glace at the MIT license (which mitmproxy is licensed under) proves you wrong: > Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software [...] It's all there, black and white, clear as crystal. They knew what they were getting into when they agreed to the license of the software they use. Hell, IBM could fork the project and sell the code back to the original developer, if they wanted. If they disagree with the license, well... caveat emptor: > THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
- petee 3y agoDemands for output are met with request for compensation. Was there a threat made? No, so not extortion, by definition. If they said, "Since you asked I want money or ill plant a backdoor to ruin you", sure thats extortion, but that didn't happen.
- 3y ago
- s3p 3y agoThe dev's response on Github was unhelpful. The original comment just asked for a target date for the next release. Why didn't he just tell them? And if he didn't have a release scheduled (which I believe is the case here) then he should have just said so. Instead, he gave zero context and just asked for money. I agree that the person from the original post sent a VERY rude and useless email, but it's not like it was unprovoked.
- andrelaszlo 3y agoThe initial message was polite and just asking a question. On the surface. If you read between the lines, it can also sound quite entitled. 1. "Our customers..." - apparently it's part of their services or products in some way, which means they are getting paid for the mitmproxy developers work. Of they have a problem, they should ask "how can we help fix it?", not "when will it be done?" 2. "...in regulated industries [...] are prohibited by regulations..." - these are clients with deep pockets, which makes point 1 sound even worse. Also implying that their clients problems should somehow be a priority for the project maintainers. If I hadn't read the reply I would have guessed from the tone that they're already sponsoring the project somehow. It sounds like a friendly but somewhat frustrated paying customer to me . 3. "...s/w with known High and Critical severity vulnerabilities" a bit of a stretch but this could be interpreted as "your software is terrible and full of unpatched vulns". I'm not writing this to say that the IBM guy is a bad person. I'm sure he's just trying to get his job done and communication is hard. Just trying to convey how messages that are following all the "rules" (be polite, don't make demands, don't call people names, ...) can still be interpreted as rude. The "I hope you don't find this follow-up to be offensive -- that's certainly not my intention" part of the email sounds like someone that is aware that they're sometimes unintentionally offending people. The intent behind the response from mhils is pretty clear to me. He points out that he's not being paid, that he doesn't appreciate the message, and that you can't make any demands unless you're willing to contribute somehow. The problem is, I think, that this type of language isn't clear to everyone. The follow-up email just shows that the message didn't get across. I don't know the IBM guy, maybe he's just entitled, but living around several very intelligent autistic people has made me see how common these types of interactions are. I think us non-autistic people can get better at recognizing the situations and adapt our communication to be more direct and precise without a lot of effort. It's often the case that the person on the other end is already spending a lot of energy on adapting. Not excusing anyone's behavior of course. I just think this interaction could have had a lot of other outcomes.
- acqbu 3y agohttps://nitter.net/maximilianhils/status/1680193548212228097 https://nitter.net/maximilianhils/status/1680193548212228097
- acqbu 3y ago[flagged]
- villgax 3y agoAssuming this is Ron Craig from IBM, the bastions of funding open source projects & not winning outsourcing contracts by using FOSS software without donations. Just pathetic
- lopkeny12ko 3y agoWhy maintain, publicize, and promote an open source project if you're not willing to maintain it? I also work in a highly regulated industry. IBM's request is reasonable.
- isbvhodnvemrwvn 3y agoI don't owe you anything. You can fork the project if to put feel like it. If not, fork off.
- account42 3y agoIBM's request would be reasonable if they already had a support contract. As-is, as-is means as-is.
- TillE 3y agoWhy use an open source project if it doesn't meet your standards? Do your own work, or pay someone to do it.
- yawaramin 3y agoWhy maintain it if you're not willing to maintain it? Great question. I think it answers itself.
- SergeAx 3y agoContext: the fix is already in a main branch, waiting for a release tag. I wonder if it is possible to fork the repo as is, build the product/library on question and use it? What is the procedure to convince the regulator that CWE is fixed and it's okay to go on?
- villgax 3y agoRon Craig has been at IBM for 27+ years! Really speaks volumes for the organization sadly. Horrible conduct
- shri_krishna 3y agoMore and more convinced that full FOSS is not the way to go. It is a thankless job. There has to be a mixed license where it is Free until Revenue X$ and after that one has to acquire commercial license. It doesn't matter what the software is. Once you reach a certain threshold of revenue you have to pay for commercial license. Period.
- 0xbadc0de5 3y agoPR or GTFO
- amiga386 3y agoThis sounds very much like the idiocy of "infosec" lunkheads who know nothing about what they're "fixing" but if an automated system tells them a CVE exists, they've absolutely got to have it "patched". They don't look into what the claims of the CVE are, or whether their specific use case is vulnerable. They don't know, they don't care, they're not even programmers. All they know is a box needs ticking. A similar thing happened with h2database - a "security researcher" found that if you do something you're told not to do, then bad things happen.. but they demanded and got a CVE allocated anyway. Anyone who looks at it realises it's bullshit, but the mere existence of a CVE is all that matters to these idiots. What the h2database developer said about it: https://github.com/h2database/h2database/issues/3686#issuecomment-1448502155 https://github.com/h2database/h2database/issues/3686#issueco... > I struggle to understand why I should feel the slightest shred of sympathy for "major corporations" that are using a volunteer-developed open-source project. Feel free to get your corporation to pay someone to deal with this, or pay for a similar commercial library.
- gbpz 3y agoGod yes. I work in a regulated industry, and here's the flow: InfoSec raises vulnerabilities that show up on reports that get managers scared. Developers have to continually update to accomodate. Even for non-prod deps. You can raise exceptions, but that's a completely separate can of worms. Managers wonder why dev work is slowed down.
- mcpackieh 3y ago> This sounds very much like the idiocy of "infosec" lunkheads who know nothing about what they're "fixing" but if an automated system tells them a CVE exists, they've absolutely got to have it "patched". They don't look into what the claims of the CVE are, or whether their specific use case is vulnerable. They don't know, they don't care, they're not even programmers. All they know is a box needs ticking. They may know and understand all of this and still not care. Maybe their performance is judged by how quick they can get checkboxes checked, with overzealous approvals harming them more than overzealous rejections. They may be empowered to make exceptions when the specific circumstance warrants it, but that might require them to fill out even more paperwork to justify their decision. That extra paperwork slows them down and harms the metrics by which their performance is judged.