5 ms·
The US spends $30-60 billion a year on agriculture and subisides [1]. This is controversial for all the obvious reasons. Without subsidies we'd waste less food
by cletus 3y ago
The US spends $30-60 billion a year on agriculture and subisides [1]. This is controversial for all the obvious reasons. Without subsidies we'd waste less food but overproduction of food is an intentional objective of these programs. Why? Because if there's a major drought or crops are lost to ice or snow or flooding, Americans won't starve. It's why we have things like the US government having a reserve of over a billion pounds of cheese [2].
People not starving is a national security interest.
It's getting to the point where the software we rely on is also a national security interest. The US government should be paying to maintain and improve this software. Security risks in Linux and core packages threaten to shut down key infrastructure.
Paying developers to maintain open source projects that are actually used could be an incredibly effective use of tax dollars.
[1]: https://usafacts.org/topics/agriculture/#581290c9-a960-49aa-a4f9-ab52dec5bbdd https://usafacts.org/topics/agriculture/#581290c9-a960-49aa-...
[2]: https://www.deseret.com/2022/2/14/22933326/1-4-billion-pounds-of-cheese-stored-in-a-cave-underneath-springfield-missouri-jimmy-carter-reagan/ https://www.deseret.com/2022/2/14/22933326/1-4-billion-pound...
- chjj 3y agoI'm not sure why people keep misidentifying the problem as "lack of funding". Lasse Collin was doing fine as a maintainer up until Jia Tan showed up. He was psy-op'd into believing there was a crowd of angry people eagerly awaiting a new release when there wasn't. No real person was unhappy with the way he'd been maintaining xz.
- Cthulhu_ 3y agoFunding aside, single individuals being responsible for software is not a good thing, see bus factor.
- transportgo 3y agoBut if he was paid he might not have given up control
- udev4096 3y agoHe never mentioned about any financial problems, it was more about his mental health
- mwcampbell 3y agoAnd would mental health issues have kept him from working on xz if that had been part of his day job?
- yunohn 3y agoI’ve been in similar burnout situations, and the difference between work and side projects did not matter to my mental health. The money was not an issue, it was headspace and fatigue.
- chjj 3y agoOkay, sure, but rather than trying to solve a problem by throwing money at it (or worse, trying to solve it with government intervention), maybe it's better to think of other mitigations. For example, maybe developers need to be made aware of potential psyops by attackers (the publicity surrounding this issue probably made some progress on that front).
- diggan 3y agoI'm not saying money would absolutely fix the issue, but I could also see it helping. If Collin was approached by a government that said "Hey, the thing you're maintaining is important, if you want, we'll fund 2 additional full-time maintainers that can contribute based on your guidance", maybe Collin would be in a better position to ensure the Jia Tan contributions were genuine and proper.
- chjj 3y agoThere's probably a number of things that could improve the situation. Mindlessly throwing money and government at a problem almost never improves things. Which government bureaucracy decides how much Lasse Collin should be paid? Based on what metrics? This is a giant can of worms.
- rebolek 3y agoIf I was the maintainer and was approached by government telling me, "hey, here are two folks who're going to be two new full-time maintainers and we're funding them" I certainly would be worried.
- diggan 3y agoSimilarly, if the government approached me and said "Here, embed this black-box binary into your build process", I'd be worried too. But luckily, no one suggested this, nor what you wrote about :)
- irdc 3y agoGetting help for mental health issues is a whole lot easier if you have the money.
- lenerdenator 3y agoIIRC the xz package was maintained by an individual in a place with at least some socialized healthcare, but correct me if I'm wrong (I'm not trying to be snarky here, please do).
- dboreham 3y agoPerhaps socialized medicine is the solution.
- Gormo 3y agoSocialized or politicized?
- sofixa 3y agoThe EU realised this like a decade ago, and have had a couple of programs around it that have been small steps in the right direction, but not enough - such as EU funder bug bounty programs, giving grants, mandates that the EU should use specific open source tooling for specific needs (e.g. VLC).
- vb-8448 3y agoIt seems very stupid to me. How long will it be before the government starts pressuring these maintainers to do the things the government wants?
- Gormo 3y agoFor example, introducing their own backdoors.
- Gormo 3y agoIt's not valid to regard the potential of negative consequences in any sphere of human life as a "national security risk". It's not valid to presume that the only way to mitigate risks is through top-down political intervention. And it's absolutely not valid to presume that making FOSS communities dependent on political subsidies would not have much worse and much longer term consequences than the problems we are trying to mitigate. In fact, it's entirely possible that the political intermediaries who control the purse-strings would have an even greater capacity to introduce their own backdoors or otherwise compromise security in pursuit of their own ambitions. What you're proposing here might well represent trying to keep out one set of threat actors by handing the keys to the castle over to another set of threat actors. And this would be on top all of the other problems it would cause: convergence toward homogeneous monocultures, project priorities being distorted by political incentives, vested interests using political influence to suppress competition from FOSS projects, etc. It's worth pointing out that the swift detection and remediation of the xz backdoor by the community almost immediately after the threat actor pulled the trigger on their two-year long con represents a resounding success of the FOSS "many eyes" model, and it's not clear what politicians throwing money around would add to the equation.
- acdha 3y agoYour argument falls apart when you remember that the U.S. federal, state, and local governments are critically dependent on open source software – not just directly in things like Linux servers or Chrome/Edge/Firefox but also open source components used in appliances or compiled into commercial software. It is quite reasonable to argue that even a narrow approach of improving only components they run would be justifiable on those grounds and it’d be a tiny part of, say, NIST’s budget to fund developers directly or to pay some group like the Linux or Apache foundations to support an open source maintainership team.
- illiac786 3y agoI fail to see how you addressed the previous comment here. You ignored 80% of the points made. Donations is fine, but it needs to be “no strings attached”, otherwise I agree with the GP that the risk of weaponising FOSS may become even greater. I do agree that the US government is critically dependent on FOSS by now though. But “why throw money at it if it ain’t broken?” is the prevalent mentality, especially when everyone can have their own definition of “broken”…
- lenerdenator 3y agoDoesn't .gov do a bit of that already? Part of the problem is, no one knows who's really working on what. If you asked some of the most knowledgeable people in the GNU/Linux ecosystem who maintained xz before last week, there's a real chance they couldn't have told you, not without some investigating first. And that would only have gotten them a name, not the maintainer's personality, resources situation, etc. There needs to be a census of sorts over the stuff that goes into the GNU/Linux ecosystem to see who needs what.
- sylware 3y agoIt may be paying for minimal (including the SDK), but able to do a good enough job, ultra stable in time reference software/network protocol/file format maintainance. It excludes nearly all software out there (even open source, and closed source are de-facto excluded), because most "developers" are only a bunch of scammers heavy on planned obsolescence. That includes software "maintained" by the academic sector, like your have with MIT media labs and the nice "donations" from bill gates (to probably steer it the way he wanted, I would not be surprised this is not alien to c++ in gcc... one of the biggest mistakes in open source software), that revealed in the epstein files. To say the least, it is far from ez. If you are an _honest_ dev, you know it is extrutiatingly hard to justify a permanent income.
- throw4847285 3y agoAgricultural subsidies are a terrible example because they're so corrupt. The cheese reserve doesn't exist because it's gonna protect Americans from starvation. It exists because the dairy industry massively overproduces. Only a small amount gets converted into cheese. Millions of gallons just get dumped[1]. The dairy industry is entirely unsustainable, especially given that the government keeps the price of milk low because it's considered vital for children's development, dairy lobby propaganda with no basis in fact. And these massive subsidies don't even help small farmers. The only way to keep up with the absurd artificial demand is massive factory farming of genetically engineered super cows bred in a lab to produce as much milk as possible with a life expectancy a third of a normal cow. [1]: https://www.wsj.com/articles/americas-dairy-farmers-dump-43-million-gallons-of-excess-milk-1476284353 https://www.wsj.com/articles/americas-dairy-farmers-dump-43-... (I guess this isn't really relevant to the OP, but I recently read a fantastic book about the dairy industry and now I can't shut up).
- jart 3y agoWhy are you advocating for the government to take control of open source projects? Is anyone here naïve enough to believe that, after being persuaded of the national security interests of these projects, they're just going to hand over money to the random people who maintain them to keep doing what they're doing? The U.S. Govt isn't Santa Claus. Look at what they did to the farming industry. Most people used to be farmers and now there aren't many farms at all, since most of it's being done by big companies. Applying that idea to open source means the government would use regulation to prevent community developers from having their software used in production, and all future work on open source code would have to be done by engineers at big tech companies. In many ways that's already the de facto system we have today. So if you get the government involved, it'll just become law, and the lone wolves in open source who big tech doesn't want to hire will be fined, sent to jail, etc. Read "Everything I Want To Do Is Illegal" by Joel Salatin.
- deleted 3y ago[deleted]