An unexpected benefit of open-sourcing our code
blog.cloudflare.com
blog.cloudflare.com
In the meantime as a user of BAM I'm very very very grateful for faster zlib as it makes life a lot better with the current large installed base of programs that use BAM and data sets in BAM. These sort of improvements really do make a meaningful difference in the same way that switching to SSDs from magnetic disks didn't improve the implementation of my software but makes my computer a lot faster to boot up and compile things.
https://github.com/cloudflare/zlib/blob/31043308c3d3edfb487d...
It's great material for anyone interested in these types of low level optimizations.
Do you know what the file extension inc stands for?
It's a fairly common extension for a file containing C implementation code (and not just headers) that is intended to be #included by some other file.
Edit:
Here's an example of a .inc file being used
https://github.com/cloudflare/zlib/blob/31043308c3d3edfb487d...
Double Edit:
git log --all -p contrib/amd64/longest-match.inc
It was merged directly into deflate.c
The social benefit is that some members of the society can get fun from a AAA game if they want.
Star wars Jedi Knight [3] had the source released.
Note that all the AAA games that I'm aware of that have been open sourced are older games, I don't know of any in development AAA games that are open source.
[0] https://github.com/id-Software [1] https://github.com/EpicGames/ [2] http://unknownworlds.com/ns2/natural-selection-source-code-r... [3] https://github.com/grayj/Jedi-Academy
Unknown Worlds only released the source code for the NS1 mod for Half-Life--and as Valve has yet to release the Gold Src source code, that's of questionable utility.
For example, IE had a major, major issue regarding SChannel that more or less trivially gave attackers an ability to run arbitary code at either admin or SYSTEM level. It was scary. It was reported privately and then patched. Never in this process did anyone have the source code to analyze and publish an early PoC like they did shellshock and heartbleed. When the patch was released, it was a binary, so no one could just compare the old code to the new and figure out exactly what the problem was and launch an attack. Sure, they could analyze the binary, but that gives limited and often unusable results. Or at the very least puts up enough barriers to buy time for patch installs.
Its funny, years ago we used to worry about our Windows servers, now only worry about our linux servers. FOSS's transparency is ugly when it comes to exploits because they go from discovered to in the wild very, very quickly. Even when they don't, once the patch is released, the hackers have the exploit instantly, and that means if your organization can't patch for a couple hours, you're screwed. The recent Drupal exploit is a good example of this. It went from published to bots hacking Drupal installs within seven hours. Millions of sites were affected.
In fact I'd say it might be better that a relatively new app (especially ANY APP that powers servers) to remain closed source until given the green light by security researchers. And even then...
Imagine if Facebook open sourced the code running their social network? I guess the question could equally be ... is there ever a social good from centralizing your social network and not letting it be distributed across all machines in the world?
I would say security.
On the other hand, I note that proprietary software is flawed with tons of 0 day (I'm thinking about Flash lately), whereas the self-proclaimed most security-oriented open-source projects only have a tiny number of unsafe code (I'm thinking about OpenBSD "Only 2 remote holes in the default install, in a heck of a long time!")
Except no one uses the default install and these types of claims just incentivize making the default as sparse as possible. Things change when you deploy your stack, use ssl, etc, etc.
Sorry but this is plain false, people doing vulnerability research for closed source software do compare the binaries to understand the patch.
(I can't immediately name an example of this)
I remember being amazed by AOLserver which I was surprised to discover is now open-source; possibly by that point it was too late though? My impression was that everyone used Apache because it was FOSS, but that could be wrong.
Though I haven't had problems with poppler, so I don't quite understand what is bad about it.
With an open source google algorithm there would be possibly 1000's of lesser google's (lesser as in inferior search) the lesser googles might even get eclipsed by Bing or some other proprietary search which has the resources to improve it's search.
And second, I think (but cannot prove) that people need time to adapt to technological progress, which is also driven by software. For example, we cannot figure out how to integrate Google Glass into our social norms over night. And we needed time to respond to the Snowden revelations. Who knows how we will handle drones and the IoT? Accelerating progress has upsides and downsides.
(I feel this is more about hardware than software, though. More efficient Big Data might be scary?)
Just don't connect your things to the internet. Problem solved.
If the only way to develop your product or service is to generate a return on investment, and society will benefit as a result of the provision of said product/service. I think in many cases it's safe to say that society has benefitted if you generate a return on your investment.
Having said this, in principle I would advocate for an enthusiastic open-sourcing strategy once the societal benefit has been realised. Practically, it's a bit more complicated than that. For example: are you able to continue to generate a greater societal benefit by maintaining a monopoly on your source code? (Tough to answer, I'm sure).
And even once you're at the scale where you can compete head-to-head with those people, you still might want to keep things proprietary so that you can encourage ethical and aligned behavior across the industry. Because the stakes are much higher than falling asleep happy because you maintained the "purity" of the open-source-software movement.
You'd still share your changes to zlib and other non-core components, though. Because of articles exactly like this. But none of the secret sauce.
As a side note, it is not at all my intent to imply that any of this refers to the finance industry. Not at all. Nope. (But if this piques your interest, send me a message at the email in my profile.)
Which is entirely the case in software.
So throwing the code up on github isn't really "open sourcing" it.
The question then becomes: is it a net social benefit to spend the large effort to truly open source a particular code base? And the answer is that it depends.
In any event how would you measure "social benefit"?
Unfortunately this isn't true. IE still does not support deflate as specified in the RFC, with a zlib header. It only supports raw deflate.
https://www.ietf.org/rfc/rfc2616.txt
deflate
The "zlib" format defined in RFC 1950 [31] in combination with
the "deflate" compression mechanism described in RFC 1951 [29].
This has lead to most browsers also accepting raw deflate, to be reverse compatible.Some versions on my system even use the SW crc32 variant, macports on an i7: 200x slower
A few years back, I got an e-mail that one of my open source tools was being used as a monitoring solution on a hospital ship. I felt pretty damn proud too, not having imagined the impact of open sourcing a project could have.
I wrote a quick blogpost on the matter back then; https://ma.ttias.be/this-is-what-open-source-is-about-mobile...
yikes. I didn't realize anyone actually used -O3 in-production. Isn't that widely considered to be a BadIdea™?
It looks like Debian policy is to build at -O2 with exceptions for building at -O0 or -O3
> The files used for this kind of research reach hundreds of gigabytes and every time they are compressed and decompressed with our library many important seconds are saved, bringing the cure for cancer that much closer. At least that's what I am going to tell myself when I go to bed.
I realise it's not meant entirely seriously and I applaud any effort that helps speed up the exchange and storage of information and this type of research. But "bringing the cure for cancer that much closer" I find a bit of a stretch.