6 ms·
Avoiding a Geopolitical open-source Apocalypse
- clwg 2y agoI'm not really following — is the author discussing funding/foundations for Open Source software and supply chain security? The rise of "communities" in other countries doing open source development? Or how the East can't trust the West, and vice versa? The geopolitical aspects and cyber norms discussions are already happening[0] but in ways and at a pace that usually frustrate technical people. I like DHH's take on Open Source[1]: "Using open source software does not entitle you to a vote on the direction of the project. The gift you've received is the software itself and the freedom of use granted by the license." We should welcome these new communities and thank them for their contributions and perspective. As long as I have the freedom to choose, and censorship isn't a barrier I don't see an issue - they can do what they want. With OSS I can at least review the code and form my own opinion on who and what I should trust. [0] https://www.csis.org/analysis/creating-accountability-global-cyber-norms https://www.csis.org/analysis/creating-accountability-global... [1] https://world.hey.com/dhh/open-source-is-neither-a-community-nor-a-democracy-606abdab https://world.hey.com/dhh/open-source-is-neither-a-community...
- AStonesThrow 2y agoHeadline's word choice amuses me, because the literal meaning of "apocalypse" is "uncovering, revelation" which is quite appropriate for anything "Open Source", isn't it?
- squigz 2y agoI imagine you also get amused when people use 'literally' figuratively?
- AStonesThrow 2y agoYes and I return to this series https://youtube.com/playlist?list=PLGVpxD1HlmJ-dLBoRLP91gvRJcFt9CkhQ&si=oVn_u3EgGU-FZLsE https://youtube.com/playlist?list=PLGVpxD1HlmJ-dLBoRLP91gvRJ...
- liminal 2y agoThis has already happened. We won't use software, open-source or otherwise, from an adversarial nation.
- 015a 2y agoI'm not sure I understand why this is an apocalypse. Diversity is great. While I'm sure the CNCF would love a world where literally everything ran on kubernetes, as one example, the reality is that making kubernetes the one tool for everything everywhere all at once will only turn it into a piece of certification design-by-committee garbage (which, let's be real, it basically already is). We should not want one unified world of open source; I love the idea that anyone, whether divided by race, nationality, or just thought process, is out there approaching problems from a different angle and rethinking from first principals. We should share ideas, not code.
- greatgib 2y agoIn my opinion, this article doesn't really have a real argument but is more trying to capitalize on FUD on open source.
- syngrog66 2y agoits complicated by fact that the Russian and Chinese govs run ops to try to compromise software and systems worldwide, partly to help achieve certain goals like stealing IP or acquiring blackmail, to cite just a subset. And while not in a hot (shooting) war with the US/NATO/EU we are de facto in a soft/hybrid one. Current generation is far too trusting of any ole rando FOSS code or SaaS they see pitched. Recklessly naive. If I had the amorality to be a black hat I'd be having the time of my life right now. GitHub alone is one of the best malware injection vectors ever.
- johnea 2y agoWho cares if open source dies? We'll still have free software...
- deleted 2y ago[deleted]
- RcouF1uZ4gsC 2y ago> a sort of United Nations of Open Source that equally represents all. If you think the UN equally represents all, you are mistaken. The UN basically exists as a forum for the major powers at the end of WWII to wield influence with a veneer of respectability (see Permanent Security Council). Ultimately, developers live in nation states, and need to eat, pay taxes, avoid getting throw in prison, etc. Nation states are also well aware of the power of software and won’t ignore it like they did before. Software, including open source is part of the full-spectrum competition. Given the geopolitical rivalries, I have approximately zero hope that open source will avoid these rivalries
- whatshisface 2y agoUp to this point nations have shown no interest in funding open source software and that's likely to continue. (This is despite the fact that Linux fuffills the public benefit argument for science funding better than most research.)
- Retric 2y agoGovernments have minimal incentives to fund things that are working without their funding.
- deleted 2y ago[deleted]
- fsflover 2y agoIt depends on your definition of "working".
- hdjjhhvvhga 2y agoThe EU has been funding open source for years, and Germany just started their own funding program, currently in the pilot phase: https://www.sovereigntechfund.de/ https://www.sovereigntechfund.de/
- 2y ago
- MichaelZuo 2y agoHow does it make sense for there to be ‘splits’ on a regional basis? By definition, there cannot be any effective barriers between any part of ‘open source’ and any other part, assuming they are not made under mutually contradictory licenses. So there cannot possibly be any differences lasting much longer than the time it takes to review the relevant codebase.
- __MatrixMan__ 2y ago"Open source" doesn't require that the readme, comments, issues, and PR's use a language that you know. So depending on who you are, reaching the point where you're able to effectively collaborate could be the work of years. Aside from that though, I agree. I can't see and technical reasons why one wouldn't mix oss from both communities, thereby bridging it into a single community.
- MichaelZuo 2y agoThere are plenty of translation tools available to overcome linguistic barriers with a few clicks. Which is more effort than zero clicks, but hardly a significant barrier. And some of those tools could actually be better, in pretty much any language pair, then the majority of native speakers themselves.
- rightbyte 2y ago"As a community, we must look beyond geopolitical conflicts" Is this even a problem? People in most FOSS projects does not seem to care at all about nationality, race and etnicity. I think most people don't care at all about 'geopolitics' in the first place. It is some pissing contest for the elite. And even if they did, any user can be anonymous, and many projects accept pseudo-anonymous contributions.
- homebrewer 2y agoWell, it depends. Several nginx core developers were laid off in 2022 for no fault of their own. Then we have examples like this: https://news.ycombinator.com/item?id=35137213 https://news.ycombinator.com/item?id=35137213 I also wouldn't say it's all roses, some of my Russian and Jewish friends have felt very uncomfortable participating in FOSS projects during the past couple of years, although it has cooled off somewhat recently. (I have many in both countries for historical reasons.) It's easy to think there is no discrimination when you're not on the receiving side of it -- some significant minorities in the US should know this very well.
- hdjjhhvvhga 2y ago> I also wouldn't say it's all roses, some of my Russian and Jewish friends have felt very uncomfortable participating in FOSS projects during the past couple of years Yeah, this is something I often argue about with my colleagues. They claim that Russians brought it upon themselves, that they should oppose Putin etc. These arguments are ridiculous when you dig deeper, as an individual in Russia, whether a powerful one like Navalny once or almost unknown like the pianist hero Pavel Kushnir, you mean nothing. You will disappear just like that and nobody will even say a word. Of course when you start advocating the war online and spread putinist propaganda, that's another question. But normal Russians are normal people like you and me, if anything they are more hostages of this terrible situation than Westerners.
- hkpack 2y ago> But normal Russians are normal people like you and me, if anything they are more hostages of this terrible situation than Westerners. By any chance, did you have conversations with Russians recently where they feel like they can speak freely? The vast majority of them support if not Putin himself, then the idea of restoring Russian Empire through the force one way or another. A lot of them blame "west" for all their problems and a sizeable portion still feel that collapse of the west with its values is the thing to be desired. Hiring or working with Russian is a liability for any company for practical reason - from espionage to causing major tensions in the periods of world instability or just when person will "come out" on social media with their views and beliefs.
- lynx23 2y agoAnyone else notice the irony? We're talking about Open Source, right? Then, "will the west adopt chinese software", which has a xenophobic touch. But wait, a paragraph later "Can I sell this to our clients?" Well, you know, I am too long into FLOSS to not notice this corporate bullshit. Its open source, you dont have to be able to sell it, MBA.
- portaouflop 2y agoRight and OSS maintainers live off hugs and kisses. Screaming treason whenever someone tries to make a living off OSS is the main reason the community is so toxic/in constant crisis.
- lynx23 2y agoI am all for maintainers getting something for their work. What I object to, is a guy sitting in the west, xenophobically pointing at the east, and at the same time, asking themselves if they can sell that stuff from over there. Thats a different situation, and you know it.
- emilamlom 2y agoOne reason for the somewhat separate open source ecosystems that the author doesn't touch on is language. In my experience, the dev communities are already pretty separate simply because the languages are so different from each other. Japanese dev communities follow a similar pattern from what I know. While I'm sure the geopolitical issues cause some division, I'd be willing to bet the main reason is much more fundamental and the two ecosystems just naturally developed separately.
- ikanreed 2y agoGoogle is too "helpful" in assuming what I want instead of what I say for me to find it anymore, but there was a Linus Torvalds quote about how it didn't even occur to him to write linux in anything but english, even though that's not his native language. Those days are done. The world now has plenty of internet for any language you speak, and there's no need for standardizing on the "biggest" language.
- emilamlom 2y agoAgreed. I think a lot of native english devs don't realize just how much english permeates every aspect of software. Another post on HN talking about the process of digitizing Tibetan mentioned how line breaks aren't really a thing in that language. But of course, they're everywhere in software and required for things to even function. So many decisions are based on language that go beyond actual communication. It's kinda wild to think about.
- alexisread 2y agoI guess you could look at this as a restatement of the 'Reflections on trusting trust' paper (https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...), in that the whole software chain needs securing ideally (though there is value in even doing parts of it). I don't think that will be possible with federated governance, rather the chain is probably best secured mathematically and in a distributed fashion. Potential use for the blockchain/merkle-clock event log/zksnarks etc. ?
- fsflover 2y agoCan't it be solved with the reproducible builds?
- alexisread 2y agoSomewhat yes, but compilers can inject vulnerabilities, and you also require composable code to avoid composition vulnerability.
- fsflover 2y agoHere's an even better solution: https://news.ycombinator.com/item?id=41368835 https://news.ycombinator.com/item?id=41368835
- saagarjha 2y agoThat’s not really what the paper is about.
- alexisread 2y agoAs far as I can see, the article is somewhat about whether we can trust open source software, given political tensions, language barriers, and malicious actors. To that, the article suggests a central authority with global membership to create trust. If the W3C is representative of that, then regulatory capture is a real possibility, or balkanisation if there is disagreement. Trust in balkanised orgs is of course a problem, and hence trust in the code - the paper deals with a similar issue ie. How to trust code. In this case though, the idea is to be able to verify the code yourself, rather than trust an org. The paper centres on whether you can trust the compiler ie. The bootstrap problem, and while tech alone will never solve the issue, the capability to create trust in the code yourself can be a basis for better layered trust on top. To add to this, signed builds/source on their own are not a solution as a compiler or malicious actor can inject bad code. As such, yes I don't believe a central, or federated orgs alone can be a solution, you're likely to need a solid bootstrap and chain of trust (and maybe content-addressed code) to underpin the quality of the code.