There's a lot of different reasons that people ask for open sourcing of Orion / software in general; could I ask you to expand a bit more as to which issues being open source would address for you?
I can assume of course, but I'd rather listen to you articulate it, even if it's usual reasons.
I don't necessarily have to trust each individual app on fdroid or in the Debian repos. I have trust the maintainers are building them properly, and those people are not the same people developing the core app.
Don't you think if Kagi introduced spyware it would ruin their reputation quickly, why would Kagi want to quickly ruin that brand reputation?
The answer is that there is no incentive for 'spyware' on Orion as you can pay for Orion+ to support development.
Hell, WhatsApp started out as a privacy focused messaging app before selling out to Facebook/Meta. Now it's getting ads, nobody believes a privacy focus anymore, it's had a commercial message channel push, and so on. They are far from the first example of a tech company/product trading the mission/brand value for more money.
Bless the VLC developer for refusing offers for millions of dollars to put crap in VLC even though he knows the project could just be forked after and bless Gorhill for the same on uBO but the real trust in these things comes from the code being open source rather than faith the developers would never sell out.
Y’all seem like nice people but trust isn’t automatic these days.
What do you perceive as the risk to "trusting" Orion in this case?
edit: Sandboxing the app also further reduces the surface area for "trust", though I'm unfamiliar with MacOS as a platform when it comes to that.
Also there is point of rugpull, or the product is getting cancelled. Few people will step up to maintain it; atleast until most users migrate to a different product.
Much of it had to do with testimony during the Google antitrust trial. It’s hard to understand how Kagi wouldn’t be ultra-sensitive to guaranteeing there will be escape hatches if it enshittifies. (Your funding model is a great first step!)
Also some of us simply don’t want to learn new UIs and/or risk dealing with an “AI” infused alternative if we have a tool that already Just Works. Switching away from Just Works sucks.
I'm not sure what I'd seek in a browser I'd pay for - but it would be features not present or great in foss browsers.
Maybe email, podcast, rss client, a modal vi like browsing (like vimperator, but first class), a good reader mode/style override, proper editor for text input (like "it's all text"), automatic force support for select text, save as... for images)...
But whatever would be useful enough to pay for, would likely be a pain to lose.
There is Orion+ that can be paid for that keeps development going.
But, sure, I could imagine paying for a browser again - although I don't immediately see what features would be worth paying for.
For opera it was the custom, fast rendering engine and the email client.
Now with basically two equivalent rendering engines, I don't imagine performance in that area will be enough to pay for.
Maybe a smalltalk like developer mode with better debugger and repl support?
The same goes for auditing the final executable. Open source gives two options on that: build it, trust it. The latter may seem 0 gain but, again, it is actually a big difference trying to audit a blackbox for every possible behavior vs seeing what the baseline behavior is supposed to be and looking if any differences occur in the premade binaries. There is a 3rd option: reproducible builds... but I doubt that's a reasonable goal in this case.
I'm not saying Kagi/Orion should necessarily care about providing that level of audibility, just that the response a pre-made binary is as trustable as a binary with its source code falls quite flat.
To be at least somewhat certain of the future, I want to own critical pieces of software, not rent it from someone no matter how benevolent-looking.
While things are well, I want to be able to contribute. There are myriads of minor things that your development teams would never get time to look into. If something is a wart, I might have skills to do it myself and - hopefully - ask you to incorporate my patches. I did that to a few pieces of software I trust and use, and I consider the ability to do this as fairly important, even though I do this very rarely.
And if things go sour, it could be impossible to keep up with long-term maintenance of this complex machinery but I still want that option open too. I want to know that if you folks decide to do something unpleasant to the browser, I’ll be able to begrudgingly take over and still fully own the software at least while I’m investigating the replacement options. Not be at someone’s else’s mercy.
To be persuaded otherwise, I need to be aware about your reasons for not providing users software freedoms and agree they’re serving our mutual interests.
(Needless to say, Orion is a very different product from Kagi Search, which is why I apply different set of requirements. I can switch search engines much more easily than user agent software.)
It doesn't need to be open source to do that, but it really helps. Ideally you'd publish source and have reproducible builds, so that users could look at the code to see that it's not doing anything objectionable and a handful of people could make sure that that code matched the official binaries.
> You can audit the application's behavior with standard tools to verify that it isn't "phoning home", etc.
Can you? Practically? Lots of programs are easy: You put them in a sandbox with zero network access, or very carefully restricted access, and that eliminates 90% of likely problems. But this is a web browser; it's purpose is to connect over the network, all day every day, to arbitrary, dynamic domains in large numbers, such that I would seriously question whether it is in fact practical to audit in a black-box approach.
Source: "Trust me".
As another person mentioned, telemetry could be sent out Sundays @ 2:00am, so my use of standard tools to verify that it isn't phoning home on a Tuesday afternoon is useless. This is just one isolated example.
>it doesn't need to be open source to do that, nor would making it open source obviate auditig the final executable anyways.
Trust is not a single bit that is flipped from "Fully trust" to "Fully distrust". Things become more trustworthy when the source can be reviewed, and less trustworthy when an employee says "We don't do this, trust us, but we're keeping the box closed because ~reasons~".
In my eyes, Kagi has a lot of trust-building to do, despite being the darling child that can do no wrong in many HNers eyes (for whatever reason).
I think a blog post on Orion's transparency is enough. The fact that there is Orion+ is enough to warrant no need to have tracking or 'enshittification'.
If you like Kagi and Orion, supporting development by paying for it makes sense.
Open sourcing everything of Orion means that Orion+ will be open source which defeats the point of supporting development of Orion directly.
I've seen projects start open source, change to closed source and then add in the enshittification later. It doesn't matter if the code is 'open' the source code would eventually be unmaintained and have security holes which there is no time in the world for anyone else to maintain.
I think this is an odd/slightly-disingenuous statement.
I mean, I'm on linux, so I'm not, I'm happily paying for kagi though, and would pay for Orion+ if it was available to me :)
I would also very much like it if Orion was open source, it would make me feel a lot better committing to and recommending a browser if I had actual assurances it's behaving appropriately, beyond a company saying "trust me", no matter how nice/cool they seem at the time.
Honestly, I kinda wish Orion+ was the only option, I think having a free option (and the incentives that can create) is kind of antithetical to Kagi's whole raison detre.
Kagi isn't 100% open source but you still use it and recommend it?
How do you know they aren't spying on the backend?
The same is not true of browsers, to the extent you can even build/use privacy conscious versions of Google's browser project because Chromium is open source! To trade that away for closed source on the promise of another company who was only able to build a browser because of an open source engine is an unnecessary step backwards and should be bothering people, as much as Kagi appears like the nice company for now.
I don't know about the others, but I'm an Orion+ lifetime purchaser just because I like what they are trying to do and it's a good phone browser for my work phone. I'm not sure I follow why specifically people who pay are supposed to be uninterested in it being open sourced?
> If you like Kagi and Orion, supporting development by paying for it makes sense.
> Open sourcing everything of Orion means that Orion+ will be open source which defeats the point of supporting development of Orion directly.
Sure, one should support the development costs. Can you elaborate why you feel that relates to Orion being freeware vs open source or why it defeats the point of Orion+? The two aren't differentiated by functionality, Orion+ is a token of development support.
> I've seen projects start open source, change to closed source and then add in the enshittification later. It doesn't matter if the code is 'open' the source code would eventually be unmaintained and have security holes which there is no time in the world for anyone else to maintain.
Open source isn't a promise that the code will be maintained forever, nothing can guarantee that, it's a promise if the company decides to go closed source the community can decide what to do. Or, even if you don't care about that, a promise of easy/public auditing and hacking. Just look how many Chromium/Firefox build customization, UI tweaks, and forks people have made despite the possibility Google stop contributing to Chromium in the future.
Can you help me understand what about the questions make you uncomfortable?
I am completely unaffiliated with Kagi. I find it concerning that we've come to a world were we can't ask questions without it being taken as something hostile to the person/people/idea being questioned. Is that not what science is?
I’m reminded of the number of times I’ve had vendors sit across the table from me and argue that our fixed requirements for <whatever> are just a preference or a nice-to-have. This generally doesn’t bode well for their prospects.
> Trust with regards to...?
I took this to be a good faith ask for clarification
> Orion doesn't have any telemetry... You can audit the application's behavior with standard tools to verify that it isn't "phoning home", etc...
I took this as a statement if what I could do, not specifically what I should do instead of getting it open sourced.
Maybe I read it with more good faith intention and curiosity than I should have. I see your point on how that could be perceived as push back, but I landed somewhere different from where you might have.
That statement also said you have to audit binary even if the code is open source. Which isn't entirely true as other comments pointed out - reproducible builds - but the idea doesn't seem like pushing back to me. It was to point out that open source doesn't automatically imply any level of trust when it comes to security/privacy.
That way the software would be audited and it doesn't have to be open source.
Trust of Kagi search is already there w.r.t both the tool and the company but it is not transferable to Trust to the Orion Browser.
tl;dr: I'm a tinkerer, an idealist, and someone who wants to retain control over my digital life and deny influence over it to the likes of Google, Apple, Meta, et al. at pretty much all costs, and there are absolutely good enough open source options that I couldn't bring myself to use a proprietary browser unless I absolutely have to.
To elaborate…
First off, there are a few reasons I always prefer to use open source software:
- I like being able to open things up, see how they work, chops bits off them, attach other things too them, use them in unexpected ways and general use (and abuse) them however I see fit. After all, I can do that with all the physical stuff I own, so why not the digital stuff too…?
- Code costs nothing to copy and is trivial to copy perfectly. This means that the potential compounding benefits of everyone sharing not only their complete software products but individual libraries, algorithms, and solutions to common (and not-so-common) problems are huge. When we use and contribute to open source software we help build those benefits for everyone.
- Closed source code is always open to being abandoned or moving in a direction we don't care for with nothing we can do about it. When it's open source, the question is "will I submit a PR", or "will I maintain a fork" (even if just for me). When it's closed, the question is "will I build a replacement". These are not the same category of thing! I can start running a fork any time[0]. Building a replacement may take months or years, if it's even feasible. But there are individuals who run their own fork of my favourite text editor (Helix).
- I'm a big believer in the value of communities and efforts made primarily for the benefit of one's community rather than financial gain. Open source can act as a kind of insurance against the latter.
Secondly, I think this is all uniquely important for browsers because the web is so dominant and it's therefore so important to me (and I think to Kagi's mission) to protect that platform for everyone, for all time. Even though Chromium and Webkit are open source, Google and Apple exert huge influence and control through their ownership of Chrome and Safari. Firefox is better but even that project is not free of Google's influence, which is steadily making the web worse for everyone.
Kagi probably won't be the next Google, in that respect. As a long time payed user of Kagi[1], I really do believe they want to build a good browser that does not abuse an exploit it's users. But Google's motto used to be "Don't be evil", and many of us believed that for a while too. My point is not that Kagi will or is likely to become evil, it's that when Firefox/Zen, ungoogled Chromium, and maybe one day Ladybird and others exist, *I can't invest time, effort, and attention into something that could in theory go down such a path without the community even retaining the option to fork it[2]. This is especially true when using a closed source browser would also simultaneously weaken those more open efforts, however slightly, by subtracting from their community.
So there you have it. I hope that's helpful.
[0] Case in point: I've used Firefox for years. Sometime last year I start using Zen (a fork/derivative of Firefox) alongside it with no drama or fanfare. Now I rarely open Firefox.
[1] Honestly, I couldn't imagine going back. It's a genuinely excellent product and I believe the company is generally doing, and certainly trying to do the right thing.
[2] Just look at the cautionary tale/disaster that is Arc/Dia. For a while I was worried I was missing out on something special. Then Zen came a long and I worried less. Then the whole Dia thing… boy am I glad I didn't invest my time in that.