Techstrong Gang – September 30, 2024
In today’s Techstrong Gang, Alan Shimel, Mitch Ashley, Tracy Ragan, Hope Lynch and Guy Currier get together and discuss the intent of the FTC to crack down on deceptive advertising that uses AI. They also discuss President Biden’s speech at the UN, which warns of the profound risks of AI. Finally, they deliberate whether open source project maintainers result in higher security of open source code.
Transcript
Hey, everyone. Happy Monday. Hope you had a great weekend.
There's been a lot going on. You know, the FTC wants to crack down on people using a AI for bad advertising. So much so that President Biden in his warning of profound AI risk.
And like girls wanna have fun, like the song says, open source maintainers. Just want to get paid. You're watching Tech Junk Gang.
Hi everyone. Alan Shimel here for text org. As I said earlier, happy Monday to you.
We have got a, a great lineup to talk about for this Monday. We, it was an interesting weekend with some news out there, and we've got a Greek bunch of people to talk to us about it. Let me introduce you to our gang assembled gang for today.
First of all, out in, in, uh, Colorado. He's our CTO and Futura CTA and my friend Mitch Ashley. Hey, Mitchell, how was the weekend?
Thank you. That was great. It was great.
I guess we're gonna have to give up on that new Textron gang tag tagline. Textron Gang makes you 10 IQ point smarter. We'll, we'll Have to hold that.
Well, no, we didn't use AI to come up with that, so what's the big deal? Oh, That's, it's all good then. We're good.
Yeah, we're good. Um, next up joining us from New Mexico where she has been working on her broadband. She's the CEO of Deploy hub, and, uh, open source Google, Tracy Ragan.
Hey, Tracy. Great to have you on. Thank you, Alan.
It's always fun to be here and I think it does in increase my IQ every time I do one of these. It does. It does.
And ai ai, uh, again, AI was not used or harmed in the making of that. Um, also joining us, well, she's now, I guess, a consultant, which she, uh, I will, I will be heading into management consulting in the next couple of months. Yeah.
All right. You are, it's our friend and gang member, hopefully at sha. Welcome.
Great to have you here. Alright. Thank you.
Appreciate it. Good topics today. Thank you.
And then last, but certainly not least, he's a consultant too, I guess, but he's also the CTO of visible, not visual impact part of the Futur group. And, and just all around Good guy, Guy Currier. We had to have someone from the Bronx here.
Hey, guy, how are you? Absolutely. Great.
Thanks. Happy to be here. Um, and I'm, I have open sourced my iq and I would like to be paid for that, so, Yeah.
Okay. Put get online. Get online.
Um, anyway, it's gonna be an interesting day here, guys. Thank you all for, for joining me on, on The Gang today. Let's jump right into our first, our first, uh, block.
So the FTC has come down and announced that they are going to start enforcing and, and, and coming down on people who are using ai, uh, for advertising claims. But it's not just saying, we're gonna increase using this, it'll increase your IQ templates. I get the feeling it's using like sort of deep fakes or other kind of AI derived false images, information, audio in, in furtherance of selling something.
Um, but you know, that, that was my take on it, guy. I know you reviewed a lot of this. What he, what do you make of it?
Well, I, the, the lead example that the FTC gave was, um, uh, a company called Do Not Pay, um, which was offering, uh, a service that allowed the consumers in, in their claim to go ensue, um, without needing to consult a lawyer. Um, so I think there's a little bit of depth, uh, to this, uh, um, operation, uh, AI Comply. Um, I think it's probably quite broad in scope, ultimately.
So you have, um, you know, the use of AI to simulate, for example, a celebrity endorsement. That's an obvious kind of a violation. Yeah.
Um, but then in this case, you, you have AI to make a, a claim that is fundamentally misleading. Now, the governing law is that you are not allowed to make misleading claims. Not that it doesn't happen all the time, you know, and there's a question of judgment.
Where's the line of, you know, a, a claim that's, uh, genuinely misleading an a legal sense versus let's say, not misleading in the legal sense, even if ordinarily we would say, you know, it's untrue. Um, the, the important point here is on the recognition that now we can automate the creation of misleading products or misleading claims. We can claim something is something that it isn't, but looks that way.
As I'm fond of saying, um, on these kinds of, uh, uh, calls on AI right now is simulation. It is artificial, but it's not intelligent. It's simulation.
So therefore, it is designed, it is trained to appear true. I think that there is almost no possible depth you can go as AI develops with something like what the Federal Trade Commission's trying to do, do. The critical question is, is it gonna be effective?
Yeah. And I think this is the PT Barnum rule. You know, there's a sucker born every minute.
This is, this is sucking people into false claims, false advertising, claiming AI will do something that it won't do. In the case of, you know, you, you mentioned guy, they didn't hire a lawyer to chat, and they didn't do any verification of what AI generated was a comparable to a $200 an hour lawyer. They just made the claim and put it out there.
There's another company that writes fake reviews, product reviews. It's kind of another form of a deep fake, and if you will, so it, it is really kind of consumer protection activity. Not saying this is ai or that's not, it's just AI's in the picture of making some false claim or, uh, some kind of fraud against the consumer.
Yeah, I was quite, I mean, when I saw that, it was like, why is AI being in particular, why is AI being targeted here? Shouldn't that be the case for all products and software? Um, should, how does this impact Facebook?
Right? Yeah. If somebody's putting false advertising out there or saying false things, like we know that there, that is happening every single day, is Facebook responsible for that?
You know, the, the, these are pretty hard questions, but I am very happy to see that the government, that our government is stepping in to this area because we have sidestepped it for so long and pass it off to the EU to make decisions. It's time that we do get into the, to the game and start leading the way in terms of, uh, defining what's safe and what's not. And at least we're there.
But I don't think this should be just for ai. I think it should be for all products. Yeah.
And I, I think one of the reasons AI has been called out, but I do agree, uh, there are already rules that would take care of this, right? When you're talking about truth in, in advertising, but the AI help, the Bon, I think it gives, is the, the level of sophistication that they can now apply and how convincing it can become and how truthful it sounds that people who maybe previously would not have been susceptible to it now would, and this market distortion that could happen. Consumer deception, yes, there are rules to take care of that, but I think AI just makes it faster and so much more.
So, you know, trace, I I probably am closer to what Tracy says in that if something is wrong, it's wrong. Whether you used AI or not, I really feel like the theme here, and it's for the next block too, is we're making AI a whipping boy. Right?
You know, if you outlaw guns, only outlaws will have guns, right? Isn't that what they say? Well, if we outlaw, you know, AI only outlaws will use ai, but it, it's, it doesn't stop someone from writing a whole bunch of false, false, uh, Amazon reviews.
It makes it easier to do more, but people could still, you know, crowdsource that. And it's been going on a long time. So, no, Alan, This is only suspicion on my part.
I wonder if the FTC is just doing this in highlighting ai where they've done it to say, yes, we're doing something about AI Too, right? To show we're we're on it. Exactly.
It could be. It could be. And and quite frankly, under the President Supreme Court, you know, I, I could absolutely see a court saying, Hey, the FTC has overstepped their authority here, their congressional mandate, that the Congress never specifically said that you should come down on AI or rule on AI advertising.
This doesn't seem to be a new set of rules. It's more, uh, an effort, um, that, I mean, I, I, Mitch I think you have a really good point. Um, the, there's a certain element of this that feels, um, feels like, you know, pr a PR effort.
Um, and, and there actually is a nice enforcement mechanism there. It's not pure pr, it's not pure, please love the FTC more now or at all, because it's also a warning, um, about, you know, for other companies to be careful about their use of, uh, a use of ai, that law, the fundamental laws and the rules have no nothing to do with ai. They have to do with fraud.
And, um, I think that the critical element of AI here is that it automates the appearance of truthfulness at scale. And that's, that should require a particular effort. But I don't think particular rules or new laws either.
So, well, I do think that there, John Swartz used a term that I keep thinking about. In one of our calls, he called it authorit authoritative bias. And I think kind of as hope pointed out, AI has a mystique to it.
And we saw that as soon as people, as soon as we had investor started to invest in ai, everybody's product became an AI product. Yeah. And somehow, because it has AI in front of it, it's something that's better, right?
But it's not really true. And so there is, there is something to be said about being honest about what you're delivering and if it's ai and if it's, it's really the thing that you're buying. And I do feel like in this, in this category, ai, we do have an issue with AI because this, the spin cycle has been so fierce.
But let me, let me give you a devil's advocate for a second. I, I think things like this can have a chilling effect on legitimate uses of ai. And I'll give you an example.
My oldest son Landons up in Boston in his third year of law school, and he is, uh, he's heavily involved in what they call the legal technology lab at his school, Suffolk University Law School. And what they're working on are, are chat bot interfaces, basically with, with, you know, specific LLMs and then la you know, using larger LLMs as well, that will allow indigent people to better navigate the legal system. They're being, you know, their landlord's trying to evict them wrongfully or not, they have a family law issue, or, you know, some other, uh, even criminal law or, or civil war, whatever, right?
These, there's a lot of people who can't afford lawyers or for whatever reason, don't want to use a lawyer. And not all legal issues should require a lawyer, right? That, that bos it makes whole system more expensive, or BOS down.
AI has the promise of really helping these people. Some of the, some of the, I've seen some of the programs and AppSec that they've worked, you know, in the housing court, for instance, it's amazing. It really, hell, it tells, it tells a, a person how to respond to an eviction notice.
Where's the court? What part of court, what the, what needs to be proved or disproved? You know?
It, it, it's a tremendous tool for people who otherwise don't have access, and I agree, but yeah, especially in law, law and health, it could really transform the way we interact with law and health in particular. Yeah. No, they still have a chilling effect on it, these kinds of things, right?
Are they, does, does the law lie the Suffolk University Law School Technology Lab have to worry about, you know, putting this on social media or something? I don't, I don't think they do. I mean, when, when we're talking about a university that most people would consider a trusted source and not a bad actor, right?
Um, I think they probably are already taking every precaution that would already be outlined. They, they're trying to be ethical. They're, um, they have a standard of transparency.
Hopefully, I, I think they can take a look at it, but probably pass it by. The ones who, um, need to take a closer look are, uh, I'm gonna say it, the ones who are more like just the hustlers. We want to make money.
We want to make money fast. If we're caught and we get, uh, in order to take something down, sure, we'll do it, but then we'll spin something else up, right? Because we can do it really, really quickly with ai.
But I think, again, that just mirrors what we already are dealing with, uh, in cases of fraud, typically. I like Tracy's point too, that by over rotating on the use of the word ai and everything now has AI and AI in it. This may not be a perfect analogy, but it's kinda like natural potato chips and natural cornbread mix, and natural has no meaning, right?
Um, you kind of get to the point where what AI is in it, and why, why do I care, is you just putting it on there because you know it's new and improved, you know, better, faster, cheaper, whatever kind of wording. I don't think that's gonna happen. But that's sort of the, you, you build up this kinda skepticism or cynicism about ai.
If everything is ai, then nothing is ai. Yeah. That, that's a point too.
Well, I think we're gonna have to see how this plays out, right? Right now it's warm than that. So let's see when the rubber meets the road.
Speaking of rubber meeting the road, though, we need to take a break right here and peel on outta here. We're gonna come back and talk about more AI risks, though, coming out of the government, you're watching Text Drug Gang. In a world where every line of code powers the future, every keystroke can introduce new threads.
As software evolves, so must security, it's time to rethink how we protect our digital world. Join the leaders in DevSecOps and AI at the OpenText DevSecOps Virtual Summit on September 24th. Discover how innovation is transforming software delivery faster, more secure and smarter.
From AI driven security to the truth behind cloud security. Get the insights that will keep you ahead of the curve. Don't just watch the future unfold.
Be part of it. Register now and secure your place in tomorrow's world. Hey, everyone.
We're back here on Textual Gang, continuing our, uh, let's meet up on AI day theme for this Monday. ai, which happens to be a great resource for ai, by the way, so check it out. But it was an article, uh, you know, evidently President Biden warned of profound, profound AI risk in, in using and what AI can offer.
And of course, this has triggered yet another round of angst among ai. Well, I think people who are pro ai just take it for what it is, you know, but for people who may not really understand it or, or see conspiracy theories or, you know, have anxiety around this, it, it's, you know, just sets another cycle spinning. Tracy, what, what's your take on this?
Well, you know, when you're watching, uh, a president from the United States in his last address to the un bring up ai, you have to pay attention. Um, we, software in general is chaos. We are really, and in the AI world in particular, because it's moving at such a fast pace, this is a very chaotic time in the technology.
Um, what I, uh, in, in the article, what I was surprised to see is that the, um, that he, he is really supporting the General Assembly to establish some kind of rules of the road for AI across countries. That's a huge undertaking, to be quite honest. But it may be the first step that we need to, uh, uh, start thinking about in terms of how do we manage AI in particular, in areas where it can really influence, uh, the masses in how they think, uh, in areas of healthcare, uh, in areas of law like we just spoke about.
Uh, so there, there, there's gotta be some level, uh, something established across nations that explains and discusses how AI should be used. Now, how do we prevent risk and dfas and disinformation? That's a different story altogether, but at least we should have some basic standards of how AI can be applied.
Now, why I I question the ability to prevent the, the, the security, uh, problems around AI and security and software altogether is because we are living in such a chaotic environment in, in terms of software development. There are so much going on right now that, uh, software developers who are the first line of defense do not have the skills, uh, or the tools to prevent this. So yes, let's at least start a, a rules of the road discussion across all nations.
Some sort of standard resolution as a basis for making decisions in our own governments. Um, you know, I saw that, uh, Oprah did a thing on ai. I was gonna watch it, but I didn't have time.
And I found it really interesting that a, a, somebody like Oprah would wanna have a discussion with the, the masses about ai. So she gave An AI out to everyone in the audience. You get an ai, you get an ai, you get an ai.
Well, I, you know, sometimes I think, is it hype? Are we scaring ourselves about AI because it's happened from the very beginning? Is it a lack of trust, which I, myself have expressed on this, um, show Mm-Hmm.
Not trusting self-driving cars, not trusting the Salesforce rag to go out and, you know, hit my, uh, potential customers. Uh, so I think there's a lot of things coming together here, but having a real discussion across countries, you know, that are delivering AI solutions to the world is essential at this point in time. I don't know if it's gonna solve anything, but a discussion is the first place to start, and we haven't had many of those.
So how do we move forward from just going from a rules of the road to actually implementing real standards in ai? Well, let's do that for software security in general, and we'll see. I'll be the skeptic on Mr.
Biden here, president Biden and others. You know, I, I'm, I'm sure there are, but I really scratch my head in trying to think what have we done on a global basis in terms of implementing something like this? And the things that, that naturally come to mind are, you know, war kind of activities, the Geneva Convention rules about that.
Things like, like the arms race, the nuclear proliferation. And I can't really think of anything, um, in, in our world that's been successful like that other than what, like, you EU is doing what California is doing. It seems like it's gonna be regional.
You know, I have to dip back into you and I were talking about the new Dune prophecy, uh, series coming out on HBO, you know, it's the thinking machines. We banned them because they, you know, we had the wars and they took over, and we can't have anymore of those anymore. Something really bad happened, and so we're gonna severely control it.
But I, I, I really scratched my head about how would this actually come together, and would we really, would it have any teeth? Would it have any impact? Well, b***h, I'm gotta give you a double credit for making a dune reference, dude.
Let the spice flow. Let the spice flow. Yeah.
But, um, there's a show in November coming out on, on max, right? Do Prophecy, I think it's called. And it's, it's really based on the book, the, the sisterhood, uh, which is the starts of the Benny Jesuit, uh, for dune heads out there.
Don't miss it. But back to, back to AI and President Biden at the un, look, my take on this is what really scares these governments. I don't think it's the FTC stuff cracking down on AI claims.
I, I don't even think it's the software vendors or the software developers having to deal with it in, in their supply chains and, and so forth. I think it's the, the, uh, potential for nation states to use AI for misinformation, disinformation campaigns and, and other forms of espionage, or, you know, to further, you know, kind of nation state aims that is really, we're we're focusing in here on, or that's huge. And warfare Focus, warfare warfare, Just cyber warfare, but physical warfare, um, uh, you know, what, what, what do they call 'em?
Low intensity conflicts or whatever, like, yeah, yeah. I, I have to, uh, I guess uncharacteristically double down on mitch's pessimism in a certain sense. Um, I, I think that these are, these are inevitable efforts.
I I think that that Biden's speech on any world leader's speech or speechifying on this is, is necessary and efforts made by, uh, you know, uh, nations and, and transnational organizations to, uh, to, um, regulate and in ai, or they, they must be done. They will be done. They're inevitable.
I just don't think that they can possibly be done fast enough to keep pace with how AI is developing. Um, on an earlier Textron gang, Dave Nicholson and I talked about, um, uh, the, the inevitable other shoe dropping in ai, however, which is to say that, um, it, AI is not an on an inexorable growth and development path, um, to which I would add that it is a tiny footprint in IT and technology plans and budgets right now. It's just extremely promising.
It's getting tons of attention. It's growing fast. My point, though in the end is that the shoe that's gonna drop, um, is partly financial.
Like Dave said, investment is not infinite and forever. People want return. But to my sense, it's even more space and power limited.
Um, EE eventually it might take over a lot of the space and power budget going to, to, uh, Bitcoin. Um, but in the end, uh, it just can't grow fast enough for enough fabs and enough power sources and enough data centers to support. And in the end, there will be a popular backlash to this.
And that is, um, the only thing that could potentially limit it. It's really not a governmental action or otherwise, when there is enough sentiment against it, people will stop producing it as much because there will, there will be less money or profit in it. I don't even know if that's gonna happen.
But, you know, that to me is the only thing that can really stop this. It's the juggernaut of all juggernauts. Well, I think there's a question of enforcement as well, right?
What it's gonna stop. So, you know, I, I live, live in New Mexico, as Alan pointed out. The road that gets to my house is about a two mile dirt road.
Um, and it goes on for another three miles. And there's two other houses on this road. And one of the neighbors decided that they wanted to stop a, a speed limit sign on our road.
God bless him. You know, he doesn't want anybody going more than 25 miles an hour. Well, you know, I drive down that road at 40 miles an hour every single day.
Who is going to enforce in a private road a speed limit? So, how do we enforce in the, in the, in the world of bad actors, how do we enforce those bad actors from complying with what several nations may have gotten together and agreed to at a UN assembly? And that is where our biggest, uh, problems are.
And this is the same problem we're having in all of our, uh, social media platforms. How do we stop those bad actors from spending huge amounts of money on creating, you know, false narratives and shifting the, the emotion and feelings of an entire country? It's really, really hard.
It's impossible. The only way we can do that is each and each individual taking their own responsibility for believing what they read or for entering their password and updating it on a regular basis, right? So it all, it always comes back to the individual.
Um, and we do have some, you know, bigger, broader issues when it comes to bad actors on the world stage using this technology. And I don't see how you can stop it any more than anybody can stop me from driving 40 miles an hour down to my house. You still need to have the models though.
And the foundational models are, are the, uh, to my sense, the, the, uh, I don't wanna use the word foundation again, the linchpin or something of, of the development of AI foundational models take months to train huge data sets. They wanna expand those data sets. We need more data, like it may be synthetic or whatever it is.
And all of that means bigger and bigger systems for training. Um, I don't think we're gonna get another trick, mathematical trick like we got with, uh, with the, the, the creation of the transformers in, in those kinds of ways to shortcut the, the mathematical calculations. So even a sovereign, um, even sovereign funding of that sort of thing is gonna wind up with limits.
I, you know, until we make the next technological leap. Maybe it's quantum, I don't know. I don't know if it's a good comparison, but in some ways, it reminds me of the climate crisis, whether you believe in it or not.
But there's good climate accords. You know, it's an impending threat. I'll, albeit maybe it's more real today than it was, uh, 10 years ago.
I think that's what it is about AI is it's this looming threat. It seems more on our doorstep, but it's not real yet. You know, it's not, nothing bad has happened because of it forcing us to do that.
And when that, would that cause us enough pain or concern or whatever, whether it's threat to humanity or it's just our livelihood for countries to get together and create some kind of accords around ai. Possibly it happens in a lot of science fiction. But, um, you know, in the real world, would that happen that I think there'd have to be some event that would really push us over the edge to make that happen.
I mean, the fact that we can't get our act together on climate change globally does solely with confidence that we can do anything for ai. But of course, that's a whole, that's probably something for Bonnie Schneider and her sustainability practice. Um, I'm, I'm AI whipping void out for today.
Guys, let's take a break here. Let's come back and, you know, talk a little bit about open source. You are watching Textron Gang.
Hey, everyone back here, uh, text John Gang on this lovely Monday. You know, to para paraphrase the one and only Cyndi Lauper girls just wanna have fun and open source maintainers just wanna get paid. They haven't been for, uh, for, you know, many years, but it's becoming more of the norm.
Tracy, you're our open source guru expert here. What do you think open source maintainers getting paid make a big difference? Oh, I have so many opinions.
I stop, Don't even lie. I could go on for quite some time. Um, first of all, many open source maintainers are paid because they work for companies like IBM and Google and Apple who pay them to work on open source project.
Thank God they do. Um, secondly, uh, there are hobbyists out there who put a lot of amazing time in, and there aren't, there isn't a good structure for actually getting them paid. Um, so I'm, yes, open source developers, if they could get paid, they should get paid.
Uh, but it's not, that is not what we created. When we created the open source world, we created a world of hobbyist. And if you're good at it, you might get something that gets funded, um, or becomes super popular, like a Jenkins.
I mean, coast Case showed us the way, right? Uh, but there's, there's a whole other topic around this with foundations like the Apache Foundation or the, a Linux Foundation being able to provide a way to do that. So give me, I'll give you an example.
Um, deploy Hub, uh, with the help of Ripple, we got a, a, a grant, we took that grant, and we said, we wanna pay open source developers to do work on this part of the product for some blockchain work. We had no way of getting it done. It took us almost eight months, eight months to figure out how to pay an open source developer from around the world.
Uh, Linux Foundation. You'll, if you go out there, it'll say, here's raise money to pay your open source developers. But when we went to use it, they didn't really have a way to do that.
And finally, gi uh, GitHub stood up and said, Hey, we, we can do that for you. So we probably were the first, one of the first real open source tools coming out of a small company that was able to work with GitHub to, to give them the money and allow them to us to identify pull requests so that the, the open source developers could get paid. But once they created that pull request, it took, it takes almost three months to get your money.
So there's not a good structure for it. Um, and for the most part, hobbyists are probably gonna continue to be hobbyist unless there's a way you can create some kind of a funding button on your open source project. And that becomes a problem because where are you paying them all over, all over the world.
You can't even pay somebody in the US who's working in a particular country. It's if they're sanctions. So it's a big, it's a, it's a big puzzle to solve, but it's a critical one because those hobbyists, if they have the option to get paid, they would get paid.
And we would love to pay them with some of the grant funding we've gotten in the past. But it's been a quite a journey to get it done. But also, I think, to your point, Tracy, when you were saying it took eight months, right?
To find someone volunteering for open source projects is great, but there would be so many more people, honestly, who would participate if they knew they were compensated for their time. And the number of people who are actively involved, at least from what I have seen, um, feels like it's trending down. Whenever I have conversations now with younger people in tech, there's a, a young man who contacted me last week if he wanted some advice, every time I speak to them, I say, have you considered joining an open source project and making contributions?
You know, I never thought about doing that. I, I don't know where to start. I don't know where to begin.
But also they say, well, but I have work. I have school, and it's free. And, you know, I don't feel that passionate about it.
So passion is fantastic, but it's as critical as open source software is to doing business. I would love to see, um, as Tracy mentioned, there are organizations that have people on staff. When I was at Red Hat, when I was at CloudBees, same thing.
People on staff who are making contributions. But it's great to get other people also engaged who maybe are not working at large technology organizations. You know, we're fun.
We have mechanisms that might be able to be reconstituted for this. Why not GoFundMe open source projects, or maybe we create a, uh, sort of like the artist Guild, right? People come together who have trouble assembling the resources to do what they're passionate about.
Maybe there's some form of open source maintainers Guild. We can start one at Textron down. But there should be ways where we can, um, you know, go seek funding to support projects that we want to have done.
Now, you know, there'll be popular ones that won't be popular, ones that won't, won't work for everybody, but maybe it's something like that. I mean, just, you know, the entrepreneur, entrepreneur in me is thinking out outside the box here. There's, there's gotta be ways we can do some things here.
Well, I think GitHub solved it. They solved the problem for us. Thank goodness.
I mean, I'm, it, it's, you know, I feel like it's a testament to deploy on something We actually got done to get our, our, our tilles could con contributors paid for working on the blockchain. But it was a, it was a task. And if we hadn't have been passionate about getting it done, it wouldn't have happened.
And it required the Linux Foundation for me, pounding on the Linux Foundation to reach out to the GitHub and say, is there a way we can put this together? So they had sponsorships, right? They have, they have a, a contributor sponsorships, and that's, that's what they, that's how we used it.
We, we set it up through sponsorships. But there is a, you know, when, you know, I'm on a lot of open source boards and I'm on a lot of open source meetings, and there isn't even a, an acknowledgement from some of the contributors working for the big company. So we're getting paid, paid that there's hobbyists on the calls.
They don't even recognize that. They assume that everybody on the call is getting paid that day to work. They don't realize that I'm taking off an hour and I'm gonna have to put an hour later in to make up for it.
Right? They don't understand that. And to hope's point, the university system is a really good way for, for, uh, young developers to get more experience.
And in a way they can get paid for it. If the university systems allowed them to open to contribute to an open source project and get school credits for it. There's no better way to learn about being a software developer than being in an open source project.
But the university systems don't even teach them about an open source, uh, community. And if they could, if, if one of their, if one of their, their classes was, you gonna have to join an open source project, you're gonna have to do, you know, over the course of a semester, you're gonna have to do X number of pull requests. You're gonna have to do one or two blogs for doing derail.
Boy, would they get some really good experience in working with the community and then meet people who are coming from these big companies, um, and as a networking effort, right? So I, I really believe there are ways to make open source, uh, pay for, its for committers to get rewarded in some way. Um, but we have to change the way we think about it because most open source right now, when you think about it, comes from big companies.
And the hobbyists get forgotten. I have to admit, I, I get, I get real puzzle about, um, this, uh, situation. I've, it's something I I I've scratched my head about for years.
The, the best analogy I can think of, um, is, is really imperfect, which is, you know, sort of like social and content creation and such, where there are enthusiasts and hobbyists who contribute in some way to the public discourse. Meanwhile, YouTube is raking into Cajillions, um, from this free content on the one hand, and then offering VIGs back on the other. Um, but in many cases, uh, you know, maybe this model is changing somewhat, but, you know, YouTube stars become mainstream regular stars paid by studios and whatnot.
Um, it, there's a clear difference here, which is that by its very nature, the contribution I'll stick to YouTube is very public and available, and a whole audience can pile in on some of the most critical software development work happens in a much more limited community. But I do think, Tracy, maybe this is part of what you're saying, clarifies things a little bit, um, which is that, uh, the, the appreciation, uh, that, you know, consumers of social influencer content provide this fandom, you don't really have such a mechanism on the open source side. The developers get experience, they can tout their contributions, but it's all done in this very private way.
Um, and, and the last thing I'll say is that the, the, I think the, the way it aligns the most, the, my analogy is you still gotta know how to build your resume, promote yourself, promote your brand, and all that stuff as an open source contributor. It just, it just doesn't all fit. It's, it is, there's some missing element here.
One, one thing this calls to mind that was interesting to me, uh, this week, I think it was in New York, prob no, or Chicago, other cities, but City Bike, one of those, uh, bike rentals where if you move bikes like U-Haul, you move the bikes from the lower demand areas to the higher demand areas, you get credits and you can cash those credits in $4. And some people are making six, $7,000 a month moving bikes during the day. Do they love those bikes?
No. Are they passionate about bikes? No.
Are they passionate about the money? Yes, absolutely. They are, right?
They're, they're competing to do this. Um, now acknowledge, they're saying, saying they need to solve this problem because this was not their intent, but it is working to, to get people engaged and to get people move things around. But one of the, the other points, um, that I don't think we've touched on as much, but I I definitely want to call out, is the advocacy around having some type of standardized model, um, a standardized framework.
So people are fairly compensated. So if I am working on Kubernetes, and that is bankrolled, and, you know, we know dollars are flowing versus a, a much, much smaller project, um, do I need to figure out a new completely from scratch? How will I be paid?
What does it look like? You know, what should I expect? I think that would also be a barrier, even if we move toward, uh, more compensation, having something that's at least a loose framework would definitely be a help.
So, I, I got a couple of thoughts on this. Surprise. com.
We have an article, I think Mike Ard wrote about it. And the real point of the article was, or one of the big points of the article was that compensated maintainers to a better job of making sure the source code is secure and not they're non compensated, right? And so, beyond the, the public good of people getting paid for what they do, it serves a greater public purpose in that we have more secure open source software, which is something we all wanna have, right?
So that's number one. Number two, though, Hey, I am all for people getting paid for their time. Let me say that upfront.
I'm a capitalist. You work, you should get paid. However, part of my heart dies listening to this story because I've been an open source supporter for many, many, many years.
And quite frankly, it wasn't the guys getting paid by IBM who made Linux, though, IBM contributed a lot of code to Linux. KK didn't for Hudson and make Jenkins to make money. Hudson, right?
Sun was getting bought by Oracle and, and everything else that was going on, and Hudson wasn't responding to what the community wanted, and so they forked it. Um, Mitch, you were not about the Blue Sky, right? Well, Mitch, you and I went through this with Snort and, and, uh, and Nexus and Nexus and everything else.
What drove open source, what made open source was that p word passion. So many founders of open source projects, I know it was a hobby, or they saw a problem and they wanted to fix it, and they wanted to share that fix with everyone. And that's why they started these open source projects.
It wasn't about the money. Now, today, it's gotten corrupted to Australia. I don't know if corrupted iss the right word, but it's, it's gone, it's gone commercial, right?
They sold out to the man, whether it's the Linux Foundation or whoever the man's going to be in this particular Citadel versus the bizarre, remember? Exactly. And, and, you know, and so everyone says, Hey, if I'm gonna get involved at open source, we go bucks here, right?
I wanna be the next, uh, you know, name a, an open source business model where people made a lot of money. Um, I think it is a great exercise for students, right? It would teach them about community, it would teach 'em about how software is built.
It would teach 'em how to get a job and how to network. However, you can't fake passion. And I think passion is, is a necessary critical ingredient in open source success.
I, I don't think we've quite formalized open source that you add a pinch of Red Hat and a pinch of hash sheet and a little bit of license change over here. And voila, you got a successful open source project. It takes passion, Tracy, you know, that you're, you're on these boards.
It takes money too. Today, unfortunately, It takes passion. You really have to believe in what you're delivering.
And, you know, I didn't mention the security aspect of that article because I questioned it Really. I, I really did. I questioned it because the open source e you know, every, every developer that I know who is at least committing to the TIUs project, um, is as concerned about op uh, about security as anybody who's paid being on it.
The other thing I wanna say is now, you know, we're doing a really, Orillia is doing a really good job of tracking and, and exploiting and showing vulnerabilities across all these projects. And many of the Linux Foundation projects who have, have big time companies paying for that to open source to be developed, they're not, they still have a big zero and a fat red zero in the open SSF scorecard, right? So they haven't implemented open SSF scorecard any more than anybody else has.
So, uh, secure the, the open source security problem, um, sort of got clobbered when AI came along. There's not a lot of funding going into it. There's not a lot of interest in it.
Uh, so that, I think it's, that's a bigger problem. I don't think it's just that the hobbyists are less worried about security than people who work for a large company. So I just questioned it.
I, you know, there may be good statistics to back it, but that's not been my experience. Agreed. Hey, gag, we're where we're, I think we're at the end of our time here for today, but what a great discussion and what a great way to end it.
Um, for those of you out there, I'll tell you another little secret. I've been interviewing and working with founders and entrepreneurs for 25, 27 years. You know, what the single common characteristic I've seen in every successful startup and startup entrepreneur, passion.
If you don't have passion for what you are building, whether you as a star, as a founder of a company, or even just a contributor, if you don't have passion, find something that you're passionate about and do that. So Tracy Ragan the perfect example. Yeah.
Thank you, Tracy. Thank you. Thank you.
You luck. I'll leave you all with that. Vince Allen Shival for Text Drunk Gang guy, hope Tracy Mitchell.
Thank you. Thank you out there for watching. We've got a full lineup of text Drunk TV coming your way following this, so stay tuned for that.
We'll be back tomorrow with another gang uh, edition. Until then, have a great day, everyone. Bye-Bye.