Open Source Software Projects: Distinguishing Real from Fake – Marc Linster, EnterpriseDB
EnterpriseDB CTO Marc Linster explains how to distinguish a real open source software project such as the Postgres database from a fake project being advanced by a single vendor that lacks any real community support.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Mark Leominster. Who's CTO for Enterprise DB and we're talking about what constitutes fake open source, and we're going to jump into that right now Mark, welcome the show. Thank you Michael.
Thank you. Very countless open source projects and they all have slightly different licenses or so, it feels and it's difficult to navigate. But what exactly from your perspective is a real open source project what defines that versus some of these other so-called initiatives that might be out there.
Yeah. Okay good. Well, it's a favorite topic of mine.
So I think there's two aspects that that are important to understand first. It's the lice right an open source projects should have an open source life. So a license that is recognized by The OSI, so that users when they adopt this this open source project or decide to participate know exactly what they're going to get themselves into That's the first thing and there's a number of projects out there who claim to have an open source license, but in reality, it's more of a source available license.
And yeah, you can read The Source, but you have very limited rights to do with the source what you want or use it in the way you want it to so that's the first thing she'll be very aware of that. If somebody says, oh yeah Source available. You can read source.
That doesn't mean open source. The second aspect is Is there a community behind it or is this a company who's taken a marketing approach to say yeah, we're gonna make our source available open because that's a good marketing trick. Right?
It's very very popular to be on open source, but it's just one company controlling. It's just one company contributing it to it. And as one company you can decide to do with this license whatever they want to do because They own the whole thing an examples like that have happened.
Right you look at for example mongodb they changed in 2018 from a GPL which is an OSI recognized license to something that they call server side public licenses. Which is not a recognized license and is much more restrictive what you can do with it. It did that or Market reasons not just marketing but Market reasons Market pressures, but they could do that because they're the only company they're the only entity behind this project or at the by far the majority.
I should say the only one but by far the majority so that's a that's a project where the sources available but everything is controlled by one commercial entity who's also the majority of supporter and provider of of the IP and the code. Okay, so that so those are two characteristics the right license and is it a single company controlling the whole thing and there's a number of those out there where a single company controls everything? And that's when a company can change the license like what manga did or cockroach did for example?
Do you think organizations are getting savvier about this? Because it seems like there are a number of models driven by a primarily Venture capitalists where they create that open source version, but it's not exactly the full version of the software and it doesn't come with a whole lot of support and there isn't a community. So do you think organizations are evaluating that more closely than they might have in the past?
I think there is a there's a growing awareness for what it means when when you have open source software that really, you know is not really the right the right the right license or is controlled by a single company. I think there's a growing understanding that if you have if you have open source projects that are supported by a big communities like Linux or postgres or python or anything that is supported by the Linux Foundation. Then you are protected from those those changes in in the course, right?
Whereas, you know, the projects that can happen. So we see a growing understanding of that that open source actually means something and that Community Driven open source is where the big value is for the independence longevity and the innovation We see a lot of various consortiums involved in open source projects and some open source projects are not involved in the Consortium and sometimes the bylaws are somewhat different what should people be thinking about when they see these consortiums and these open source projects. What should they understand?
Well, they should understand first. How viable is the open source project because I could say tonight. I'm going to create a new open source project.
It's let's call it Mark's garage and Mark's garage is one developer he issues code and maybe the code is great. But there's only one person. This is not a vibrant project that you can build on.
Right? So you need to understand how many people are contributing to this how many organizations are contributing to this? Look for example at postgres.
We publish every year a detailed analysis who the companies are that are supporting postgres for postgres 15 the version that came out in the fall of last year 144 companies had more than one person actively contributing to the project. So that means that if you build on postgres today, it's not just Enterprise DP. I mean, yeah, we're a good sized company, but it's not just us.
There's also NTT Fujitsu Microsoft VMware Google AWS. You name it right 144 companies. So which means that when you're a CIO or developer and you're betting on postgres, that's a pretty safe bet because even if two or three of those entities would decide tomorrow, I'm done with postgres.
I'm not doing this anymore. It's okay. It's okay.
There might be a little blip but for the rest, this project is just going to be trucking along the same thing for other community driving projects like Linux, for example, right? I mean, it's just not dependent on a single entity and is not governed and controlled by single entity and that is very very important. Our security issues bringing this to a head because we had log for J and suddenly people realize wow where all dependent upon thing that's maintained by three or four people who are doing their best, but it's not their full-time job and they're not sitting around waiting to deliver a patch on a weekend.
So is that kind of bringing around a larger conversation about what's in our software Supply chains? Well, it's that that is certainly true. So for US banking Financial Services insurance is our largest industry segment, and there's a growing awareness that open source is great.
Right? It reduces the cost significantly. It's a leverage for Innovation, but you need to have the support partner.
Because if you build on it and something goes wrong and every soccer has bugs also because it's very few, but I'm you know, there's always there's always something that could be improved. And if you use in production, well, if something goes wrong, you want a knowledgeable person on the phone working on your problem like almost immediately. Right, you can't just post something on mailing list and and hope that within a day or two or three you get an answer back.
You have to make sure that there's a viable commercial entity behind it that is equipped and committed to support you. Because you know you may think that oh, yeah when something goes wrong, I'll go figure it out. But even a service level agreement 15 minutes or a knowledgeable response 15 minutes when things go wrong, that's 900 seconds and that's a long time when it's the end of the quarter and your database stopped working and you can't ship because there is something gone wrong.
Then 900 seconds are really really long time. So this awareness that it's a it's an engine for Innovation. It's a way to take cost out but you have to do it in a responsible way.
You can't just bet on it bet that it will work and that, you know, if something goes wrong you can figure it out. So we're seeing we're seeing the growing adoption of Open Source. I mean it started with exits then they went to the Webster and it went to the application server.
Now, it goes to the database server, right? But all of that happened with support. Companies like red hat or Suzette didn't invent invent the next but they made Linux usable for the Enterprise and the same thing is happening with postgres.
When I started with postgres 10 years ago. I had to evangelize from postgres. I don't need to evangelize for postgres anymore postgres is everywhere.
The question is just how much can you do with it in a responsible fashion? And that's where then commercial entities like Enterprise DB come in who work with the postgres community and provide this rapper around postgres in terms of support in terms of of services in terms of tooling that help you make sure that you can use this great open source project, but use it in a responsible way. That line between developers who download Open Source software and attempt to drive some Innovation and the need for a more curated version that somebody actually pays for support and is kind of embraced more the sea level within an IT organization.
We're seeing the open source governance changing right? I mean When I got into open source, 15 16 17 years ago. The biggest concern was around fire licenses.
Don't bring fire licenses. Don't bring JPL into our office and you know, that's really bad and good corrupt our license and all that kind of stuff. Now the open source open source initiatives are becoming much more constructive where they where they help developers figure out.
What is the right open source that you can use. Yes download it right? But please make sure that you download the right thing that that the code gets scanned that we know where this is coming from what is included in this package?
So right I mean companies have to become or are embracing open source much more but with that Embrace also comes much better understanding for what is it that we're that we're bringing into our products into our it environment as much more of an understanding there how valuable this is and it is worth investing in making sure that it works. And then not technically works but works in the Enterprise. Do organizations need to think more about how they might contribute to these projects if they want to use this software.
It seems like there's a lot of folks who are consuming open source software, but for whatever reason they don't have the mechanisms or the talent to contribute, but then again, you know, we always need documentation. So is there somebody out there who needs to think through what the role of their organization is within an open source community. I think so.
I mean we're seeing open source used also as a talent magnet, right? It's not just that you use it and and and take the cost out and and benefit from The Innovation, but it's something that that makes you as a company attractive to developers, right? I mean for example from Postman we know from the the stack Overflow survey that then last year postgres was declared as the most wanted most used and most loved database software.
Okay, so postgres has become the developer magnet. If you use postgres, you create an end linuxn containers and kubernetes Etc. You help create an environment that attracts the talent that you want to have because everybody is engaged in digital transformation and digital transformation requires speed engagement and Innovation.
So you need to get the right Talent. Well, the next step is that this Talent would actually like to collaborate with folks not just inside your company, but with the best of the best that are spread around the internet and contributing to the tools that they use so that they don't just kind of write their own library in Python, but they can actually write something that gets put out there and there are other smart people who make who help make it better. So opposed so so open source is it is a magnet but we know from a lot of companies that they're actively thinking about.
Okay, how can I allow my people to contribute back? This is not an easy thing for for a lot of Enterprises because that's a it's a completely new way of thinking that the IP that you pay somebody for suddenly he or she is gonna you know release that out into the into the wild and and other companies might benefit from it. It's a different way of thinking but we see that more more companies are seriously engaging in that thinking and really trying to figure out how do I do that?
Just because it creates an environment of innovation that they need to have. And a lot of organizations you start to see and you touched on this but it's a formal office that manages their interactions with open source communities are going to see a lot more of that. I'm convinced.
Yes. Yeah. Yeah, because the cost I mean the one side the cost advantage of Open Source is so significant, right?
I mean when you say a CIO today, the number one software cost at a CIO is likely to have is database. By moving from a closed Source database to an open source database like postgres. They can cut that line by 80% Okay, their number one cost line for software.
So this frees up a tremendous amount of money, and if you need to invest a wee bit a couple of people to create an open source project program office to enable that to allow you to get from close to our systems to open source systems. That's absolutely the math absolutely works. It's not like you have a five-year payback or something.
You have a really short-term Payback. Are you rid of all worried that because of all these security issues and Licensing issues? And what's a real open source project?
And what's not that there might ultimately be a backlash against open source of I don't think so. We don't see anything like that. Right?
I mean all the stats all the data show that way over 90% of companies today are using open source, right if you think about it Linux I mean, let's just everywhere today. The next is open source. I mean the world is running on open source, it's not I mean everybody got so used to the next that nobody's thinking about it anymore, but it's open source anyone's everything.
So that concern that the moment to have had that concern was. 15 years to go now everybody everything almost everything has moved on to that platform and yeah, 15 years ago. A lot of people said, he won't work won't work long at fired and stuff.
Well, the only people who did get fired were the ones who didn't make the move. So I think history has shown that this is the way to go. Yes, you have to do it with care and support like, you know, he worked somebody like Susie or red hat when you go on the Linux right?
Very few companies will just kind of download the bits from the internet and say we were gonna figure that out. That's just not the way to go but you still you go on open source, but you make sure that you have the right partner who if you need something if something goes wrong, you can call them and they'll help you they'll give you a reasonable distribution. They give you good good documentation to give you training.
Okay, and the same thing is happening in in so many other areas of Open Source. So Mike to your question. No, I'm not concerned about about a backlash and specifically the security aspects.
I'm I I believe that especially when you go after software that is Community Driven and the true Open Source process like postgres Linux. The security risk is actually much much smaller because you have a process that is inspected inspectable and is inspected. I know that from experience by thousands of people.
Somebody submits a piece of code and there's something wrong or vulnerable whatever would this piece of code? It's not just that the QA Department two or three people look at it. It's thousands of people looking at it and believe me.
They're not shy about telling you what's wrong with it, right and telling you about that and it quite a let's say direct way. So I am less concerned around security issues in open source Community Driven open source projects, right? Then I am concerned about closed Source projects and I come from a closed Source environment.
But if it's not a Community Driven project if it's just two or three people in the garage or one company who runs the whole process and just makes their Source available. Then you don't have any of those guarantees. All right, folks.
Well, as always it's important though look before you leave because just like there's fake news. There's a lot of other fake stuff in the world as well. Hey, Mark.
Thanks being on the show. Was a pleasure good conversation. Thank you.
All right back to you guys in the studio.