Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
David Chisnall (*Now with 50% more sarcasm!*)
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange  ·  activity timestamp 7 hours ago

If you're talking to EU politicians about tech sovereignty, there are a couple of things I hope you'll ask them to consider:

One of the problems with the US tech giants is that they are too big to regulate. They have grown so big that they are more powerful than most countries. Only China and the EU are big enough to even consider trying to regulate them (this is one of the many reasons Brexit was a disaster). You don't want to replace a nominally American company that you can't regulate with a nominally French (or German, or whatever) company that is too big to regulate. It is far better to have a thousand billion-Euro companies than one trillion-Euro company:

  • The smaller companies can exert less political pressure on governments.
  • A thousand companies will spread out their hiring far more than one company, brining jobs to more regions.
  • A billion-Euro company failing is bad for the economy, but a trillion-Euro company failing is a disaster.
  • A thriving competitive environment with a dozen companies providing similar products and services gives better consumer outcomes than a single monopoly (or a duopoly like iOS and Android).

Pivoting from big US tech to big EU tech would retain most of the same problems.

And this leads nicely into the second point. Open source was popular in companies because second sources were a well-understood concept. If your business depends on X, you want to be able to buy X from two or more competing suppliers. With open source, in theory, it's easy for a new supplier to provide exactly the same thing. But big open source projects have the same problem as big corporations: they become too big to fork.

As a concrete example, the Chromium team refuses to take patches to support any OS that Google doesn't ship Chrome on. This has knock-on effects such as Electron (and therefore apps that use Electron) officially supporting only platforms that have enough market share for Google ads to care about them (or that Google uses in products or internally).

Open source, in theory, means that anyone can come along and be a second source for Chromium. But Chromium averages about one security vulnerability per day or two. If you are a week behind in upstream merges, you are pretty much guaranteed to have exploitable vulnerabilities. This makes maintaining a fork impossible. Other big projects do take patches but have codebases that undergo rapid continuous refactoring that makes it hard for third parties to build the expertise in the system. Or they have poor onboarding documentation and code comments and so the only way to learn the codebase is to work for the company that sells products around it.

Pivoting from big US tech to big open source projects also retains a lot of the same problems with respect to lock in. Governments should consider the number (and size) of companies that are willing and able to support a codebase when considering whether it meets procurement requirements. If only Google or Oracle (for example) can provide support (new features that the customer wants, merged upstream or maintained for 10 years in a fork) then it should not be considered. If a smaller consultancy such as Igalia can do the same (especially if they can and it's not a project that they have supported for another customer) then it's far more likely to be something that will remain a useful shape as requirements evolve.

Many small companies, supporting many small projects, should be the goal. As soon as a project becomes an essential part of an ecosystem, that should be a signal to fund alternatives.

  • Copy link
  • Flag this post
  • Block
Wolfgang Maehr
Wolfgang Maehr
@njyo@mastodon.social replied  ·  activity timestamp 16 minutes ago

In essence it goes back to #OpenStandards and #Interoperability.

@david_chisnall

  • Copy link
  • Flag this comment
  • Block
Moreno Colaiacovo 🧬🇮🇹
Moreno Colaiacovo 🧬🇮🇹
@emmecola@mastodon.uno replied  ·  activity timestamp 2 hours ago

@david_chisnall I agree. The important thing that authorities should promote is not company size but common standards, so that many different services offered by many companies remain interoperable

  • Copy link
  • Flag this comment
  • Block
Human after all
Human after all
@humanhorseshoes@mastodon.world replied  ·  activity timestamp 2 hours ago

@david_chisnall These US tech companies are regulated by the weakest of the weak Irish regulators in Ireland. The pressure needs to be put on Ireland and not screamed into the void

  • Copy link
  • Flag this comment
  • Block
uis
uis
@uis@pone.social replied  ·  activity timestamp 3 hours ago

@david_chisnall there is another part to it, that current laws ban attempts at enforcing regulation or even common sense by individuals. Take Article 6 of Copyright Directive in EU or DMCA 1201 in USSA, that demands government to send you in prison for sensible things like refilling ink cartridge or playing with your friends game, that publisher(remember, publishers are not developers) decided to not be playable.

  • Copy link
  • Flag this comment
  • Block
CM Thiede
CM Thiede
@cmthiede@social.vivaldi.net replied  ·  activity timestamp 6 hours ago

@david_chisnall multiple great threads happening on this very topic, just sad it's taken so long for people to start thinking critically about it.

https://social.coop/@cwebber/115964484421440911

  • Copy link
  • Flag this comment
  • Block
ananas
ananas
@ananas@scicomm.xyz replied  ·  activity timestamp 6 hours ago

@david_chisnall So much agreed. I would star and boost this multiple times if possible.

Unfortunately we live in a system where building sustainably like this is disinsentivised, but still, here's to hoping.

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 6 hours ago

@ananas

Here is the one-sentence summary for politicians:

Do you want to create an environment where corporations are more powerful than parliaments?

Hopefully that's enough to get their self interest on side.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct