Load-Bearing Internet People
esr.ibiblio.org
esr.ibiblio.org
Meanwhile, for those keeping score at home, a quick recap of the ways in which Raymond, esteemed author of fetchmail and maintainer of gpsd, has referred to himself:
* A "load-bearing Internet person"
* "one of the senior technical cadre that makes the Internet work"
* "one of the half-dozen or so most influential people" in open source, "in fact, a lot of people would put me among the top three".
* Hisham ibn-Sindbad (the Black Wazir) in Arabian Nights
* Someone you could reasonably infer is "the most famous programmer in the world" (but Knuth doesn't count because he's not famous outside of CS, nor is Bill Gates because he's not famous as a programmer, nor is Kevin Mitnick or Aaron Swartz).
* A member of a "small cadre of old hands" like Vint Cerf and Dave Taht with "the specialized technical knowledge required for Internet disruption on a massive scale".
* A person "creating the computer code that makes your digital world work"; "every time you use a Web browser, locate yourself on Google Maps, draw money from an ATM, or play on a game console, you rely on computer code I wrote and gave away."
Tears for Larry Ellison aside, I do feel social systems / economies work best when there's a mutual exchange of value, a win-win rather than a win-lose, and the classic simple payment in exchange for software has a certain fairness and sanity to it. E.g. the iOS app store was a lot nicer and high quality before ad-supported / in-app purchases became the norm. Anyway something like ESR proposes here seems promising.
I'm not an open source maintainer myself (except for my magnum opus https://github.com/QuadrupleA/private-secure-sharing-buttons) but seems like a lot of important-project maintainers find themselves in a demanding position with little reward besides ego-stroking or future promise of job opportunities to make money elsewhere.
To boot, the entire idea of post scarcity is preposterous. Until the theorized heat death of the universe, there will always be uneven distribution of resources and some things that are better than others.
Logging is a perfect example, server-side logs are all handled by free frameworks (too cheap to charge for, but everyone needs it), but client-side is often handled by companies (just complex enough to make money on).
The former is often handled by LBIPs like Eric, where-as the latter is either written in house (usually badly) or you get something like Sentry.
That’s too broad of a claim to possibly be true. Many things are required for smoothly running economies, and sometimes a ledger is the problem and sometimes it’s the solution.
And sometimes it's the solution in search of a problem cough cough blockchain cough cough
But don’t throw the others under the bus. Some people have family in places you can’t easily send money to, it’s not a joke.
On the other hand, software that requires rare and difficult to acquire expertise -- software development where competence is insufficient -- faces little threat from open source in practice. This creates two-tier markets that differentiate on the replicability of capability. Products that are replicable by any software developer eventually will be in open source. But there are still large gaps in capabilities between closed and open source in some markets because the average software developer has no obvious way to replicate those capabilities on a purely technical level.
In essence, you can only make money if you are doing hardcore R&D. This strongly incentivizes the creation of new capabilities but also disincentivizes publication of CS research.
You see this in markets like databases, where open source has captured almost the entire market for undifferentiated capabilities, and there is a lucrative high-end market with unique product capabilities that don't exist in open source or CS literature. The trend toward treating CS research as trade secrets, originally started because algorithm patents were impractical to enforce, turned out to be effective at maintaining profitability in high-end software products if open source can't replicate capability.
I don't think so. Take GCC or Clang, for example. While I have taken a lot of compiler courses at university, I couldn't build a production compiler for a real language, without dedicating a decade of my life or so to it.
What Open Source projects really bring to the table is massive manpower over decades. Those projects that become popular, at least. And then no smaller dev shop (or single developer except Fabrice Bellard and a handful others) can possibly compete.
Open source sometimes has a manpower advantage, usually when companies are paying for the development, but manpower per se doesn't address the significant expertise advantage of closed source in many areas. Quantity is not a good substitute for quality.
Citation very much needed here! The average closed source product has zilch expertise advantage compared to FLOSS. And the expertise that is embedded in FLOSS is actually verifiable (as well as, crucially, being resilient over time - sometimes enduring for decades in a "load-bearing" role with no long-term maintenance issues whatsoever), in a way that closed source could never be.
Customers pay for the capabilities and performance that expertise affords. Most of it just manifests as "speeds and feeds" i.e. orders of magnitude more throughput, scalability, etc. In much rarer cases, there are manifest capabilities that don't have an obvious solution in published computer science, never mind open source (e.g. large scale semantic models of physical reality).
2. no single expert can ever recreate linux or clang or the hotspot jvm or many other things, just because of their size.
...no other time mechanism could record the trades happening reliably without duplicates.
Start with the core value added, describe the world with and without in cost/benefit terms, and work from there.
Before it lost funding, Raymond was openly discussing rewriting the whole thing in Go, which sort of gives the lie to the idea that the project was operating in good faith.
The premise of the ntpsec project was that ntpd was an unloved and mismanaged codebase that suffered, as a result, from security flaws. Raymond and his team would take over the code, in something similar to the manner the openssh project took over SSH, and eliminate security vulnerabilities. The project needed funding because ordinary developers wouldn't take on such a thankless task --- maintenance programming on a giant C codebase --- without compensation.
A reimplementation of NTP in a different language is not at all the same project --- as you can see from all the NTP projects that already exist in Go and Rust, for which nobody appears to be begging contributions. Not to mention the obvious fact that people don't run new implementations of NTP in Go or Rust because they can't, and so abandoning the ntpd codebase eliminates almost all of the purported value of the project to the Internet.
I think it is really inertia. Time synchronization goes unloved at a lot of places.
But that's besides the point. Pushing a hostile fork of a popular project, raising money for it, and then abandoning the codebase entirely for a rewrite takes a "special" kind of chutzpah.
> Where there’s no profit stream, markets are not going to directly solve this problem.
The market is a process of matching suppliers with consumers, and contrary to the previous statement, it has solved the problem, by finding a very cheap supplier: you.
LBIP are admirable selfless people, but I think this attitude is as misguided as a parent doing their kid's homework for them. The rest of us won't care to find a better solution until we start feeling the pressure, and we won't feel it while the load is being born by them. And the author is essentially asking regular individuals to throw a few tips to the LBIPs, so that the current broken model can be maintained. I'm not sure we wouldn't be better off letting it fail.
Also, this might be better described as Load-Bearing Individual Participants. If only to avoid distraction around what counts as internet-critical.
Beyond funding, what happens when they get burned out or take a vacation? Walls have many bricks. What makes these people unique? I'd expect anyone in a senior position to be working on growing people to help share the load, open source or corporate. There's only so much you can do by your self.
The key idea: that he is an ILBP (or has been in 10 years) is absurd. He is not, and he claims he's not hurting for money.
This attitude denies support to projects like NTPsec, for which he's the technical lead, your take on this concept only applies to current maintainers of existing projects.
Even then, he's converting GCC to git, the latter indirectly bears a great deal of "Internet Load".
So no: they don't get my support. Why would they? Same with DNSsec. Useless project, please desist.
You can find it in the thread on his blog post titled (I am not making this up) "Thinking like a master programmer, redux".
Another fun fact: Cure53 audited ntpd and ntpsec concurrently, and found an instance where ntpsec rewrote a function and managed to regress out a patch for a security vulnerability, reintroducing it into their codebase. (By the way: overwhelmingly, with I think just one exception --- not counting the regression above --- the significant findings in that report applied uniformly to both ntpsec and ntpd).
Additional fun: until 2017, the ntpsec project apparently didn't even enable system/runtime mitigations like ASLR (according to the "Fix/Validation log" in the Mozilla SOS project).
Conclusion of that report: "While the NTPsec project emphasizes cleaning up its ancestors’ flaws, the difference regarding quality between the original code and the current implementation was not as great as anticipated."
Apropos of nothing at all, if someone were to gather his greatest hits into some sort of collection, it should probably be named Bearin' Load
It started early... https://lists.debian.org/debian-user/1999/04/msg00623.html
And here is a generally well-sourced summary: https://rationalwiki.org/wiki/Eric_S._Raymond
Lovely. To inject some psychological precision, only his narcissism can be considered a personality disorder. Being old, white, or male... no. Not yet.
There is a general and valid concern in our industry about a liberal orthodoxy that makes it at least socially unsafe to express political thoughts. People who share that concern should have an even bigger problem with Raymond, who is an attention-seeking caricature of conservative or libertarian belief. People who have couched their bigotry in far more careful and subtle language than Raymond have found themselves ostracized from conservative circles, and for good reason.
I think the better way to engage with Raymond is on his manifest deficiencies as a professional engineer and technologist, and wouldn't want to start a rebuttal to his request for donations with his politics. But I also wouldn't want to let stand the idea that the opprobrium he attracts is rooted in orthodoxy or tribalism.
Do you have references to more information on that?
It's possible to be an arsehole and not have a PD, and probably most arseholes don't meet the criteria for PD.
While that's great and all, for me at least it doesn't justify why I should send them money every month.
I think the Open Source model needs to evolve, and if these people want monthly income, they should be "showing their work" a lot more. Put out a regular (weekly or more often) YouTube or blog series. Maybe stream your work on Twitch (like I do :) ). Provide some active community involvement. Then I would be far more inclined to donate to someone, rather than having to wonder all the time if I'm paying for them to work on this stuff, or if I'm paying them so they can go on an extra vacation next year for work they completed years ago and have mostly ignored since then.
I then had quick Google and it seems a few years back some were seeing a conflict between ESR's Internet Civil Engineering Institute and something called the Core Infrastructure Initiative[1] which it seems is pulling in millions.
Perhaps it just lost out.
But I'd think talking a little about their interesting work might serve to better convey what they do to those who are aware of it and reach a wider audience. What ESR has tried obviously hasn't worked, would a half hour chat about their work once a year or a twitch session, or whatever else really make no sense under any circumstance?
I would say it’s morally equivalent to not buying a product because they haven’t updated their blog in a long time and you can’t tell if the company is still active.
I think there should be a "like" button on Facebook so that users can communicate more positive vibes on the internet. Maybe even make it easy to "like" things by embedding some code on web pages so that the positive vibes spread to the web as a whole.
In both cases it seems we're ignoring important and obvious consequences of the concept between the quote marks.
Edit: clarification