Public Money, Public Code
publiccode.eu
publiccode.eu
/a
In reality though it would be possible to share code between cities, regions and even countries. Some use cases are fairly generic.
Local newspapers, for instance, use CMSes too but there’s still a lot of random bespoke work that goes into them.
A. Most people in government positions don't know/care about open source. Nobody will educate them for the following reasons.
B. Most private implementors don't want to open source stuff because it will make easier for other companies to study their code, making it easy for them to get contracts for updates to that code. Avoiding open source in general also increases the total cost so more profit for the implementing party (fe selling also Oracle licenses is much better than using postgresql)
C. Code in the open is easier to be audited by hackers for exploits. This is even more problematic because government code is supported by private contracts and may be left unsopported for some time due to bureaucracy.
D. This is the most important. Open sourcing projects opens the door for cost auditing. We've seen crazy things like simple CMSs costing millions of euros. Although these may be simple wordpress sites, they get away with them because they can say that they are custom implemented, have huge back office etc. Open sourcing them will reveal the scam.
Source: I work in a public sector organisation in an EU country and have dealt many times with projects by outside contractors.
A. Such initiatives make government aware of the value of open-source systems to the public.
B. Ok, then this legislature would contribute to the reduction of inequality.
C. Better to fix bugs early than wait until they have catastrophic consequences.
D. Are you saying that we should let bad things continue happening?
B. Yes but the private contractors like the current status quo. More profit for them.
C. It's not always possible. Bureaucracy is a very big factor in such cases and it can't be fixed.
D. Of course not. The thing is that there are a lot of people that "profit" from this situation. And unfortunately these are more or less the same people that can decide in favour of making the open source everything move. And because of A there won't be much pressure for changes.
EU ICT workers are 9 mln out of 193mln workforce, this is 4.7%. We are just not aware of our political power.
[1] https://www.nordpoolgroup.com/globalassets/download-center/s...
B, Because they're chasing the market valuation of software companies, not services / consulting companies.
C, Untrue.
D, Sure. Revolving door promotions, conflict of interest, yadda yadda. More reason to advocate FOSS.
And I have to say my personal confidence in the quality of governmental code is higher if it is open source than if it wasn't — because I know some pretty paranoid people who would for sure check that could better than any contractor ever would.
[0] example with the Linux kernel: https://www.theverge.com/2021/4/22/22398156/university-minne...
many bug fixes open new bugs anyway due to poor architecture, this is what we should focus on
the prc is a greater threat than Russia anyway
Every major UK government department has their own GitHub orgs:
- Healthcare, NHS: https://github.com/nhsuk/
- Education, DFE: https://github.com/DFE-Digital
- Justice, MOJ: https://github.com/ministryofjustice
- Taxes, HMRC: https://github.com/hmrc
And on and on the list goes.
Many things are private, but the 10th UK Government Design Principle is "make things open: it makes things better" https://www.gov.uk/guidance/government-design-principles#mak...
Only somewhat positive example from the recent past is the Corona warning app: https://github.com/corona-warn-app
However I have met some truly brilliant people working for the city of Berlin. They're just limited by red tape and diffusion of responsibilities, not to mention the amount of work that needs doing.
Opening the code up to pull requests could give the city IT a free boost from motivated citizens, I think.
If you put no fee, some big actors will create non optimize crawlers and call the service in a loop, wasting your tax money.
A small fee means people will take care of only get exactly the data they need, cache what they need to cache, and refresh only if they really need to, and what they really need to.
Otherwise, it's the tragedy of the common.
In Sweden most government data is public which includes individuals tax records.
That generates things such as news articles "The 50 people in your area that had the highest income last year" with home address and everything and that you can look up income instantly on the web.
Some level of privacy for this would be nice to have.
Then another company get another million to develop same or similiar thing.
Why it is not a required that if you get taxpayers' money, the results should be available for free to everyone, let's say after 12 months of grace perioid ??
You might point out that increasing the output of the sun in the real world actually result in a scorched, uninhabitable earth, and that also that's not how any of this works but hey, no analogy is perfect. And this one is plenty good enough to convince voters.
That money isn't disappearing, it goes to the company but also to its employees.
They then return it to the economy.
What you're suggesting is that the tax payers spend their money and get nothing in return - it's corporate socialism.
Probably depends on the development in question, but in general the ability to resell something to someone else changes the calculations for contract work. If you want me to develop something and then own it is not the same deal as me developing something that I get to sell to someone else, too.
Some might also consider it undermining their own industry. Instead of building up software companies, it is essentially the government building a huge software department.
Especially if that industry has evolved into suckling at the government's teat. Taxpayer milk is the sweetest milk.
However, you then realize that the military is funded by public money. I'd wager you don't want fighter jet or missile guidance software to be open source.
The idea is way too simplistic and lacks nuance.
I'd be OK with that.
Then again I wouldn't be surprised if the same voices on hearing freedom of information being proposed to raise similar "but military secrets" objections that were completely divorced from reality.
I don’t know why so many activists fail to understand this. If you have a cause that you think is important, putting forward a shitty argument for it isn’t going to help in the long run.
Governments routinely propose policies that are clearly “too far” and then “compromise” to their actual goals — eg, restrictions on civil rights.
Why wouldn’t the same tactic work for activists?
By legalizing narrow avenues for union conduct, we have also heavily disincentivized any behavior outside those avenues. The "fat cat" union reps that live off your dues without contributing anything meaningful to your rights are ultimately an intentional creation of this de-radicalization. Incidentally the Red Scare helped quite a bit by making unions scared of seeming "too leftist" when the existence of unions itself is born out of a leftist understanding of class conflict (not "class" as in how much money you have but "class" as in whether you have to work for a living or people pay you for what you already own).
I find it powerfully frustrating to see these sort of reactions where people act like the very first thing they can think of that might require nuance is this fatal flaw, or that even a robust critique represents some death blow. Critical feedback improves projects so it is bewildering to me to see people treat it as the last word.
I also support making publicly funded code open source. But campaigning for all government licensed code to be made open source by legislation, especially with no indication of what reasonable limits you think that should include, is a fundamentally stupid idea. Microsoft isn’t going to open source windows to retain government licenses, and government orgs aren’t going to stop using windows. This position puts this project in the camp of ideological extremists who are simply disconnected from reality. Including scaremongering about the security of proprietary software is also an incredibly weak and unnecessary inclusion here.
If this campaign were to gain some traction with the public, the only thing it would achieve is attaching supporters of a more reasonable version of this idea, with a stupid and trivially easy to dismiss argument to support it.
> Mostly our administrations procure proprietary software, this means a lot of money goes into licenses that last for a limited amount of time, and restrict our rights. We aren’t allow to use our infrastructure in a reasonable way, and because the source code of proprietary software is usually a business secret, finding security holes, or deliberately installed back doors, is extremely difficult and even illegal. But our public administrations can do better, if all publicly financed software were to be free and open source, we could use and share our infrastructure for anything, and for as long as we wanted.
It seems like you missed how stupid this proposal is. Perhaps you simply assumed that it aligned with your own, less stupid, preconceived version of this idea? In which case you should consider that this campaign is clearly targeting people who are unfamiliar with the entire concept of open source software, in order to properly gauge how harmful it could be.
“Public money, public code” either refers, in the US, exclusively to state governments, or it applies to software developed under government contracts (and possibly other software purchased by government), not just software developed by the government itself.
Isn't this a whole 1st Amendment violation? The law is intended for private parties and the 1st is incorporated to the states since a very long time. Has anyone sued over this?
Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.
Where is the connection to requiring anything to be put in the public domain?
In order to not be unconstitutional, therefore, copyright law should be interpreted as not protecting state works.
Since these "safety valves" exist even for enforcement of the copyrights of private parties, a state government's enforcement would be even more, if not entirely thwarted by the free speech clause.
I don’t see this working other way than government spending money rebuilding each SaaS solution on their own. Then spending more running and operating it all from ground up.
Which would be very costly and no one would like to pay for it with their taxes.
Why not? I can think of some reasons but they mostly devolve to security by obscurity and a whole lot of assumptions to even get there. The actors who want to know are already in the know. At least open sourcing the rest would be a compelling lever to avoid accidentally escalating conflicts.
If you disclose everything about how a targeting system or sensor system operates, it becomes easier to defeat.
But I think there’s a happy medium where the framework and general missile/sensor code is disclosed — but truly critical information like the sonar signature of enemy submarines is protected.
Your comment makes little sense.
> The idea is way too simplistic and lacks nuance.
and you wrote
> There is such a thing as bad faith arguments.
Why is it a bad faith argument? GP clearly admitted that no straight forward solution that treats every case the same is going to be good. That is the same you argued for.
If I can't exercise my 2nd amendment right to open source cruise missiles, am I really free? (fnord)
Consider this: your trying to build a grants management system for Defense contractors in Afghanistan. You want to make sure that public money is not going to terrorists sanctioned by the US government. There is a forensic accounting software platform widely used by firms that audit the banking industry,but it is closed source and sold to firms commercially. Should the government spend money on making new software or license the existing software that works extremely well? Should the configuration for what the government creates on that software be open to the public, and open to competitors to imitate? Should they demand that the source code is released? Also what about national security?
Would AWS release all their source code to retain their largest customer, the US government?
I agree that the amount of closed source software used in government projects is staggering and a legitimate barrier to government IT working properly. But the broken process that governments spend money is a bureaucratic nightmare. I am not sure their would be technical downsides, but absolutely their are political ones.
The only thing that I could imagine being an actual downside is the retention of confidential information in the interest of national security or public trust. That is a political minefield already, and open source code can help with security, so I don't even think that is the largest hurdle.
I don't see anything about copyleft style policies here which you seem to be referencing heavily, where are you getting that from?
Yes. Companies would comply with whatever requirement to have the US government as a customer.
Completely different situation.
Should other divisions that are also publicly funded also have their work available to the public? Perhaps HR should have a GitHub repo for all of their communications?
I think it'd make more sense as part of a unified effort - like all EU countries agreeing to provide one digital ID service. But that itself is a much bigger issue due to differing levels of digital services, bureaucracy, etc.
I still support it though, and donate to FSF Europe every year with my company donation.
To actually get meaningful benefit from it you need to design it with multiple use-cases and deployment models in mind, document it, and build a community around it.
If you have a bunch of publicly-funded teams that are desperate to do that work but held back by rules saying their code has to be private then forcing it public is a huge win.
But actually I think most such teams are just trying to get their project off the ground or keep it alive. If you make them publish the code they'll do so and then carry on developing an undocumented system that solves their exact usecase and none other, and is tightly coupled to their particular production environment.
I think to really get open-source happening successfully you actually need to foster a culture that values and incentivises the extra work it entails.
Nonetheless, this would be a great first step. So bravo!
Sharing America's Code
Unlock the tremendous potential of the Federal Government’s software.
Code.gov is the federal government's platform for sharing America's open source software. Our mission is to help agency partners and developers save money and increase quality by promoting code reuse and educating and connecting the open source community.
https://www.nextgov.com/it-modernization/2018/02/defense-dep...> In 2016, then-President Barack Obama’s Federal Source Code Policy pushed agencies to use open source software. Among other things, the policy included a pilot program requiring agencies to publish 20 percent of code written by the government.
> The U.S. Department of Defense (DoD) faces unique challenges in open sourcing its code. Unlike most software projects, code written by U.S. Federal government employees typically does not have copyright protections under U.S. and some international laws. This can make it difficult to attach an open source license to our code. The Defense Digital Service (DDS) has been working with DoD and the open source community since early 2017 to develop a guideline for supporting open source software (OSS) within the Department.
U.S. DoD Open-Source Software FAQ (2021), https://dodcio.defense.gov/Open-Source-Software-FAQ/
> This page is an educational resource for government employees and government contractors to understand the policies and legal issues relating to the use of open source software (OSS) in the United States Department of Defense (DoD).
David Wheeler (now at Linux Foundation working on software supply chain security via OpenSSF), "Open-Source and the Department of Defense" (2009), https://dwheeler.com/essays/dod-oss.pdf
DoD memo “Clarifying Guidance Regarding OSS” (Oct 16, 2009)
OSS is commercial, commercial must be preferred
DoD must develop/update capabilities faster; OSS advantages
Source code is “data” per DODD 8320.02; must share in DoD
DoD-developed software should be released to the public under certain conditionsFWIW, I've used the term "citizen-owned software" for the same concept.
On the stump, every one just grokked "citizen-owned software". 15 years ago, I ran for office, advocating election integrity ("private voting, public counting"). Including replacing COTS with FOSS. My audiences were donors, politicos, editorial boards, and lots and lots of normal people. Explaining "FOSS" was a non-starter, so I switched to "citizen-owned software", which needed no explaining.
Happy hunting.
1. What exactly do we mean by open source here? Some of the benefits would even come with a source-available model. Others would need actual permissive licensing.
2. Some public sector funding is strategic in the sense that the government wants to fund developments in some particular sector of the economy to help bootstrap the strategic industry (for instance the space sector in the UK works a lot like this). In this case its not clear what advantage there would be in mandatory open sourcing... But perhaps say you can keep it closed for 12 months after the end of the funding, then mandatory open sourcing? Gives a 12 month head start seems generous enough.
3. There is a reasonable argument when bidding on a contract where a vendor says: we won't implement this from scratch, but we will fund this by selling the same solution to other customers, and as such we can deliver this cheaper than other bidders but only as closed source. This seems valid (i.e. its a build vs buy decision essentially) and I think government organisations that have real budgets will need to make these tradeoffs occasionally. But perhaps there should be a mandated minimum discount that needs to be achieved (i.e. we're willing to pay 25% more for an open source solution, if you can't outbid that then we are obliged to choose a more expensive but open source supplier).
https://www.gov.uk/service-manual/technology/making-source-c...
https://www.dta.gov.au/help-and-advice/digital-service-stand...
I remember a long decade spanning thread about the Brazilian government trying to shoehorn their super ca root into Mozilla cert database. Lots of arguments like "we audit ourselves and cherry pick a very strict number of academics to see our code and security methodologies".
I don't think it's everything they work on, but it's a step in the right direction.
Labor has value and needs rewarding, not just capital.
Looking at the mess of customizations asked for software by companies doing the same thing, I can't imagine it would be different for counties/municipalities.
(edit: Please don't misunderstand, I am not against publicly funded open source, I am just not sure if all the arguments for it hold up that well)
Of course large scale software collaboration isn't impossible without open source. But my impression is that it greatly simplifies it.
Besides, if the software is open source, other non public actors can also benefit from it.
I don't want public information systems to be dependent on open source bloat and kludge.
The website has another message that publically funded software should be open source, but that's not always possible. The government may not have the rights to even do so if they outsourced some of the development. The software is often niche and would not benefit others. In fact it can be a security risk because attackers can look for security vulnerabilities or weaknesses in systems. Attackers have a much bigger insensitive to look for security problems than security researchers because there won't be a bug bounty, it isn't software they personally use, and it could be some rare piece of software no one knows or cares about. If most talented developers are working at private companies, that means that the remaining developers who chose to work for the government are likely more prone to have poor security practices. If attackers know the supply chain of the software they can attack it. If these are open source in the sense they take contributions attackers can contribute vulnerabilities. Open sourcing code is also extra work that has to be done and will make the software more expensive to make and maintain.
>Tax savings
>Similar applications don't have to be programmed from scratch every time
Buying existing software means you don't have to program it from scratch. Sharing projects with other agencies doesn't require open source.
>Collaboration
>Major projects can share expertise and costs.
This doesn't require open source either. The government if they didn't have an income stream from leaching off it's population would be incentivized to figure this out.
>Serving the public
>Applications paid by the public should be available for everyone.
Most of the software will be useless to the public.
>Fostering innovation
>With transparent processes, others don't have to reinvent the wheel.
This is just the collaboration point. The government isn't innovative in the software field.
This is a fallacious logic.
> Open sourcing code is also extra work that has to be done and will make the software more expensive to make and maintain.
Not if there is an established standard and practice of writing code in an open source way.
> Not if there is an established standard and practice of writing code in an open source way.
I've worked on closed source corporate software most of my career and then primarily corporate-sponsored open source in the last two years. In my own limited experience, it is strictly less work to have closed-source software. There's less concern / hesitations / hand-wringing over mover quickly when you have the illusion of privacy, and relatedly having a requirement that (almost) everything (eventually) becomes public only adds steps. Certain things always have to happen privately (examples include: internal discussions that include organizationally privileged information, certain CVE handling steps, fully secured builds with proper corporate attestations, and internal project-tracking) so you wind up with a private set of systems to maintain as well as the public ones.
Maybe there's some orgs out there that "do it right" in terms of having OSS projects not add overhead, but I doubt it's possible in orgs with as much need for privacy and security as most fortune 1k co.s and governments.
To the contrary, governmemt is where the need for transparency should be at its highest. Putting "efficiency" or "speed" above transparency about the inner workings of publicly-funded and publicly-made (by government employees) software is insane.
There should not be any expectation of privacy for government employees in the field of records and information.