
Sign up to save your podcasts
Or


Adam Monsen
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. In today’s episode, Richard is joined by Adam Monsen, co-founder of the open source conference, SeaGL, and author of the soon-to-be-published book, Steadfast Self-Hosting: Rapid-Rise Personal Cloud, which aims to guide individuals and groups towards personal data control, an important step towards autonomy, agency, and freedom. The discussion highlights the value of self-hosting data, its potential applications, and the benefits it can bring to small and mid-sized businesses. Adam shares that his book is free and open for remixing and reprinting, and it will not only be a guide but also serve as a starting point for tech authors. Hit download now to hear more!
[00:01:36] Adam talks about his book which aims to guide people on how to maintain control over their personal data.
[00:02:33] The conversation moves towards the difficulties faced while extracting personal data from large tech companies, and Adam suggests the use of open source servers and software like Nextcloud to migrate data.
[00:03:31] Adam mentions that the first step towards data sovereignty could be purchasing his book, which provides guidance on setting up personal servers and services.
[00:06:11] Why did Adam write this book? He explains why and shares his experience with self-hosting data for his family and emphasizes that doing this for a group can be empowering and meaningful.
[00:07:27] Richard brings up the shift from cloud to self-hosting by Basecamp and he wonders if Adam thought about pitching any of his book towards businesses to host their own data.
[00:09:53] Richard mentions a group in the UK working to create a standard for APIs to allow users to extract their data from big tech companies and maintain ownership.
[00:11:11] Adam affirms his willingness to contribute and underscores the value of individual data ownership, using healthcare records as an example of a system that could greatly benefit from more seamless data sharing.
[00:12:12] Richard brings up the topic of digital sovereignty, and Adam tells us his view that data sovereignty should be more about serving individuals and small groups, transcending politics, and should be capable of crossing borders.
[00:13:52] Adam tells us where you can find his book online and he reveals that the book will serve as a starting point for tech authors who are stuck or uncertain about where you begin. Also, the book build system itself will be free and open source.
[MUSIC PLAYING]
RICHARD LITTAUER: Hello and welcome to Sustain. I am here again at FOSSY, the Free and Open-Source Software Conference Yearly run by Software Freedom Conservancy.
This is its first year and I'm here in Portland, Oregon, which is just completely sunny. It's amazing. It's actually really nice, especially as Vermont is entirely underwater. But yeah, it's just good to be here and I'm here with a guest today.
I'm Richard Littauer (if you didn't know that already) and my guest today is Adam Monsen coming down from Seattle. Adam, how are you doing?
ADAM MONSEN: Doing very well, Richard. Thank you for having me.
RICHARD LITTAUER: Thank you for coming on. So Adam, we just had a short chat before the podcast. Super cool. One of the founders of SeaGL, which is probably one of my favorite conferences. Free, every time. Stuff that people are passionate about. Seattle GNU/Linux Conference. It doesn't just mean GNU/Linux it means all of open source as a seagull as their mascot. Is it a glaucous-winged gull or an Olympic gull or a Herring gull? Do you have a species definition for that?
ADAM MONSEN: (laughs) I have no idea.
RICHARD LITTAUER: Okay, cool. Anything I missed when describing SeaGL?
ADAM MONSEN: You nailed it.
RICHARD LITTAUER: Excellent. That's because it's amazing. It's coming out November 11th. It's going to be the 11th time.
ADAM MONSEN: Back in person at the UW.
RICHARD LITTAUER: U-DUB! Two fireplaces this year. Very exciting. Salt was keen to share that. So, Adam is one of the drivers behind that. We've already talked about that on the podcast before. Go back to Deb Nicholson's episode, one of the early ones to hear more about that. We're probably going to have another episode coming out in October to remind you to go to this free-to-attend virtual or in-person conference. Super exciting.
Adam, let's focus on some other stuff. I know you're an author. What's the book you're working on?
ADAM MONSEN: I'm calling it Steadfast Self-Hosting: Rapid-Rise Personal Cloud. It's a manifesto for people who care about having their own data. Not necessarily for privacy, although that's a common motive. The fundamental theory I'm trying to push forward this concept of data sovereignty, I didn't make it up, but the idea is you have your own data for not just you, your small group, your family, your community, your project, your school. And with that, you gain power, autonomy, agency, freedom--for the idealistic stance--but, the approach is very practical, very pragmatic.
RICHARD LITTAUER: So I love that concept. In practice, it's very difficult to get your data out of any of the monoliths--
ADAM MONSEN: It is.
RICHARD LITTAUER: --that currently exist. And it's also difficult to have the tools necessary to effectively mine the data in the way that's immediately useful for you. Can you tell me how you take that extra step of saying "get your own data" to, "oh, this is actually kind of cool and useful and fun."
ADAM MONSEN: Yeah. There's no wrong place to start, but it's worth it. It's a worthwhile journey. It's something that's worth debating and questioning. It can be hard. Lately, it's become quite a bit easier. You can take out your data from quite a few places, and migration into different FOSS servers is possible and supported and encouraged quite a bit. I focus on Nextcloud quite a bit--no affiliation--but I think their software is great for hosting and sharing your own files, and they have a connector to grab your data off any of the big public clouds, for example. You can just migrate it right in, and they help you do that right in the software.
RICHARD LITTAUER: Is [Nextcloud] the same as Vercel?
ADAM MONSEN: Nextcloud was a fork of ownCloud.
RICHARD LITTAUER: Okay, different. Okay, got it.
ADAM MONSEN: It gives you like kind of a drop, your own Dropbox or a Google Drive, that kind of thing.
RICHARD LITTAUER: It's great that you tell me how to do it easily. What's the first step that I would want to do as a naive user trying to own my own data? How would I get started?
ADAM MONSEN: Get my book.
RICHARD LITTAUER: Okay. For sure. Very good pitching.
ADAM MONSEN: Well, it is hard to know where to start. It's not that hard to start, but there's so many choices out there that it's hard to know what to start with and what's worth your time. So that's what I focus on in the book. It's designed to be not too long, not comprehensive. It's not like a massive Linux "how to do everything to a server" manual.
It's what you need to do to help the people you care about, your group, help them own their data, help them migrate it in and whatnot. And the first step to that is you have to get a piece of hardware and stand up some services so they can use it, so they can put it behind their phone.
Their phone can talk to it rather than a big public cloud, you're locked in, whatnot. You want to have your data for you to pass on.
We work hard to curate our data. So the idea is you could get my book and get a start at setting up your own server and services for your group.
RICHARD LITTAUER: I've never thought about self-hosting my eBird data first and then using APIs to submit it afterwards.
ADAM MONSEN: Would that change the way you think about your data or what kind of things you'd start?
RICHARD LITTAUER: It would give me a whole lot closer towards building my app so when I'm birding on the highway, which you shouldn't ever do, drive responsibly people.
ADAM MONSEN: Don't do that.
RICHARD LITTAUER: You could just click a button and say, saw a crow at this time, it'll log the location and then it'll save it on my-- anyway, that's just where my brain went. Long time listeners, I apologize for bringing up birds yet again.
ADAM MONSEN: There's lots of reasons to do it though, right? There's a chilling effect when you're trying to share something sensitive with a friend and you usually just give in to like, okay, here's the doc, here's the link.
RICHARD LITTAUER: I use Signal as much as I can.
ADAM MONSEN: Great!
RICHARD LITTAUER: But after that, like docs, like I use Google Docs for this podcast. I really should be using Cryptpad. Don't know why I don't. I just haven't made that switch yet.
ADAM MONSEN: Slightly harder, right? Slightly more hassle and then somebody else sees it and they're a little
I think Nextcloud is one tool that's, it just, it's kind of the current thing that fits that gap, but it does that for a lot of people. It can bring you up to speed by showing you familiar interfaces. Oh, here's a doc, here's a document and I can get at it from the web or from a mobile device and I don't care where it's stored.
But in this case, great. You've done the work ahead of time to set up a server and services. So, you can trust where it is served and it works quite well. I would say for me, I trust it more. It's more robust than when I did put things in the public cloud. I try not to, but again, you asked like where to start, why... nobody's 100% anything. It's worth working on, I would say.
RICHARD LITTAUER: So you're an author. Is this your first book?
ADAM MONSEN: Yeah.
RICHARD LITTAUER: Exciting. Why are you an authority on this subject?
ADAM MONSEN: I've been curious for quite a while. I've been in tech for quite a while and done different things, used other people's servers. I've self-hosted quite a bit over-- for decades, but never, I guess I would say, committed my family to going along with it, going along with this with me. And they agreed to, and I said, I'll stand this up and you can use it and we'll talk through what, I think that is just a key part. Like if it's just for you, I don't care, man. It's like everybody, them their own, that's great. But when it's a group, it can be very empowering. It's more meaningful, honestly, when you're doing it for more than one person. You share.
So what I did was I stood this up, I took the time to do it right and I kept it going. I wanted no unplanned outages for a couple years. I tried to treat it like a real server where I've got customers and everything. Well, my customers are right in the house with me. And I already care about them. So that made it easy to--
RICHARD LITTAUER: 24 seven hour complaint line right there.
ADAM MONSEN: (laughs) Luckily not too many. They're very understanding. They give me a lot of leniency, but they do make use of it also. They're the reason I'm doing this. And I hope they agree when they come see my talk tomorrow.
RICHARD LITTAUER: Segwaying a bit. Love that. It's great. Basecamp recently said that they've switched from being in the cloud to hosting their own servers. And as a result, they're saving $7 million over the next five years because the cloud never works for them.
That's a business operation. That's a business shift. And, you know, I used to host another podcast called Community to Cloud Native where I talked about the cloud and I sort of stopped doing it at some point. But I'm just curious, have you thought about pitching any of the book towards businesses to host their own data as opposed to just individuals?
ADAM MONSEN: Yeah, I think businesses are well aware. You know, when they, at least the ones I've been in, we would always start with needs, budget, and then cost against cloud and self. And generally it comes to cloud hosting because of the convenience. You're just, yeah, I don't care where the servers are, the power, this and that. And then you kind of short-term jump on it. And then you're not thinking long term because, yeah, I think it is generally a short term play just to throw it in the cloud. And I'm not surprised that Basecamp is saving millions.
Other companies, it seems like they get big enough and they have enough commute, compute needs. It's usually compute, not storage that tips them over into hosting their own. But I think the concepts are useful to businesses. I think people working in these bigger businesses, let's say midsize, maybe a little beyond startup, but they are probably already familiar. And those people doing their sysadmin, admin-ing their cloud servers and such, they should walk through this exercise too.
They should have a home lab. They should practice this stuff. They need to learn the fundamentals of sysadmin and containers and all the different ways to host and stuff like that. So I think they could find a lot of use out of this. I don't address businesses directly in this book, but I think SOHO, small office, home office, smaller businesses could definitely make use of this kind of technology just to have their own cloud, have their own cloud, have their own data and the agency that goes along with that.
RICHARD LITTAUER: I'm not an industry expert on this, so this question may be naive. Would there be any benefit towards various small organizations and SMBs funding a cooperative data lake-type thing as opposed to going with allowed cloud foundries, which are going to charge more because they can, even though at scale they may actually have lower operating costs.
Is there any reason to think about running together with other companies to have your own open source data?
ADAM MONSEN: Yeah, for sure. And not my area of expertise, but I would say for sure. Co-ops are great. A number of people here at FOSSY are involved in or running co-ops.
RICHARD LITTAUER: There's a group in the UK called Redecentralize that's been working for the past 5, 10 years on trying to find other ways to access and enable and make a standard of APIs between all the large data giants, Facebook, Twitter, Google, so you can actually take your data out of these things and also put them back in if you want, where it's much more plug and play, but you're the person who owns your data, kind of like you can go to the doctor's office and say, I want all my records and then take them physically out and hand them to your next doctor, which most people aren't aware.
I'm curious, given that you're interested in helping people make the shift towards owning their own data, being sovereign of their own world, have you thought about sitting on any sort of nonprofit board or working for any of this sort of Redecentralize-type stuff to see how we can make a sea change to actually enable better API usage so we can get our data out of other companies?
ADAM MONSEN: I haven't, but if they want me, I'm game, yeah, for sure.
That's awesome. Compatibility is a huge thing. Interoperability. It flies in the face of walled gardens, lock-in, so that's amazing. Do companies participate in this or is it more a third-party effort?
RICHARD LITTAUER: More a third-party effort, foundation-type effort, just trying to figure this stuff out. I was just curious where you were sitting on any of those sort of discussions if you're helping out.
ADAM MONSEN: No, I would though. That's another great thing that we should question, we should work on because our data is our own. I'm glad you brought up healthcare too. I mean, health records, I don't know.
RICHARD LITTAUER: Tragedy.
ADAM MONSEN: My gods. Every time I go to the doctor, I have to gather my own. You'd think that you just, "oh, can you talk to my last doctor and get that?" "Well, kind of."
You do a records request, it's cumbersome, and I've heard in other countries that there are APIs and you have the right to request and not just they send you a CD or a huge sheet of paper, you get digital access. There are free software EHRs that are very interesting. I want to use that. I haven't yet, but I definitely want to gather my own data.
And then when I go to the next doctor, it's just like, oh, here's the stuff you need to help me with this problem right now. Sheesh. Not just for myself too. People I care for, I mean, I'd want to-- the same power.
RICHARD LITTAUER: One more weird question, which is you mentioned the word sovereignty. Digital sovereignty is normally used in open source spaces to mean a lack of reliance on another country's technical prowess. So for instance, the Sovereign Tech Fund coming out of Germany, which is an idea to basically try and make Germany less reliant on American tech.
Now, this could lead towards a balkanization of the space. That's not the goal, but it's one of the ways that the messaging is often used to get politicians to go along with having sovereignty. So I'm curious where you sit on the libertarian access of owning your own data and being sovereign as an individual versus actually thinking about being part of the same team as everyone else and working together to improve data access for everyone using current platforms.
ADAM MONSEN: I think to me, the free software problem or the struggle, has always been international. And I love the idea that if I'm solving a problem in my own country, it crosses borders quite freely. So I'm hoping that my use of the term data sovereignty can overcome theirs.
But no, I was not aware of that. And that's, yeah, I mean, politics will always come into it. But no, I think this is this, why one would hope this would transcend politics and serve individuals and groups, small groups. But I've heard about government switching to free and open source software. And I mean, how wonderful that public code, public funds, public code, that kind of effort is so inspiring. I mean, it makes quite a bit of sense.
RICHARD LITTAUER: Thank you for dealing with my hardball. Sorry to ask difficult questions.
ADAM MONSEN: Keep bringing it, keep it coming. I love it.
RICHARD LITTAUER: Well, actually we are running up on time. So I have a few more questions for you. One of them: where can people find this book?
ADAM MONSEN: adammonsen.com, A-D-A-M M-O-N-S-E-N dot com is a good place to start. I'll keep updates going there. I don't have the website up for the book yet. It is content complete. Now I'm in editing and tech review that kind of, thank you.
RICHARD LITTAUER: That's a lot of work. Good job.
ADAM MONSEN: It's not a huge book. So part of the idea is to run 100 pages printed right now. And I want to stay there, but I want people to be able to get print copies. And I'm working on publishing and distribution. If you're a publisher, actually, please contact me.
That could be interesting, but so far I'm planning on self-publishing. And the book itself--I think this is significant--the book itself is free and open. You can remix. You can rebuild. You can reprint, even. The licenses will be pretty clear in there and hopefully very amenable to sharing.
Because I also want to help other tech authors that are stuck, stumbling, not sure where to start. This is a starting point. The book build system itself is going to be Free and Open Source Software. You can build your own book with it. You could fill in the chapters and start your own.
Thank you Richard so much for the time to talk.
RICHARD LITTAUER: You already answered my second question, which is I can find you at adammonsen.com.
Any other socials you want to plug?
ADAM MONSEN: Nope.
RICHARD LITTAUER: All right. Well, thank you so much. You can find that link also in the show notes. Adam, thanks for taking the time today. Good luck with the book!
ADAM MONSEN: Thank you, Richard.
RICHARD LITTAUER: Listeners, I hope you have enjoyed this podcast. If you're curious about FOSSY, where these were recorded, go to sfconservancy.org to the Software Freedom Conservancy's website, where you can learn more about it. It's been really, really fun to be here and have these great conversations about free and open source software. Of course, if you've liked this podcast, please let us know. Like us on Apple, Spotify, or wherever you're listening to it. Email us at [email protected]. Give us any thoughts or comments or queries or complaints. We would love to hear them.
And of course, please tell your friends. Word of mouth is the single best way to get more listeners on this podcast. And hopefully, you think that that's something we should have.
If you would like to donate, you can go to Open Collective to SustainOSS, where you can donate to the production costs for this podcast, which is not free. So that would be super, super great. And of course, you can join in the conversation yourself by going to discourse.sustainoss.org to go chat.
And you can follow us on Twitter @SustainOSS, on Mastadon, and, I believe, on Bluesky. So thank you so much for listening and take care. Bye!
[MUSIC PLAYING]
Special Guest: Adam Monsen.
Support Sustain
Daniel Stenberg | Dan Lorenc
Richard Littauer
Today, we are switching things up and doing something new for this episode of Sustain, where we’ll be talking about current events, specifically security challenges. Richard welcomes guest, Daniel Stenberg, founder, and lead developer of the cURL project. Richard and Daniel dive into the complexities of Common Vulnerabilities and Exposures (CVEs), discussing issues with how they are reported, scored, and the potential impact on open source maintainers. They also explore the difficulty of fixing the CVE system, propose short-term solutions, and address concerns about CVE-related DDOS attacks. Dan Lorenc, co-founder, and CEO of Chainguard, also joins us and offers insights into the National Vulnerability Database (NVD) and suggests ways to improve CVE quality. NDS’s response is examined, and Daniel shares his frustrations and uncertainties regarding the CVE system’s future. Hit download now to hear more!
[00:01:00] Richard explains that they will discuss Common Vulnerabilities and Exposures (CVEs) and mentions that CVEs were launched in September 1999, briefly highlighting their purpose. He mentions receiving an email about a CVE related to the cURL project, which wasn’t acknowledged by the cURL team.
[00:01:50] Daniel explains that the email about the CVE was sent to the cURL library mailing list by a contributor who noticed the issue. He describes the confusion about the old bug being registered as a new CVE. discusses the process of requesting a CVE. He also mentions the National Vulnerability Database (NVD) and how it consumes and assigns severity scores to CVEs.
[00:03:54] Daniel discusses the process of requesting a CVE which involves organizations like MITRE, and he mentions the National Vulnerability Database (NVD) and how it consumes and assigns severity scores to CVEs.
[00:06:21] Richard asks about how NVD assigns severity scores to CVEs and specifically in the case of CVE 2020, and Daniel describes the actual bug in curl, which was a minor issue involving retry delays and not a severe security threat.
[00:09:57] Richard questions who at NVD determines these scores and whether they are policy makers or coders, to which Daniel admits he has no idea and discusses his efforts to address the issue. He expresses frustration with NVD’s scoring system and their lack of communication.
[00:11:18] Daniel and Richard discuss their concerns about the accuracy and relevance of CVE ratings, especially in cases where those assigning scores may not fully understand the technical details of vulnerabilities.
[00:14:37] We now welcome Dan Lorenc to get his point of view on this issue. Dan introduces himself and talks about his experience with the NVD, highlighting some of the issues with CVE scoring and the varying quality of CVE reports.
[00:16:11] Dan mentions the problems with the CVSS scoring and the incentives for individuals to report vulnerabilities with higher scores for personal gain, leading to score inflation. Dan suggests that NVD could improve the quality of CVEs by applying more scrutiny to high-severity and widely used libraries like cURL, which could reduce the noise and waste of resources in the industry.
[00:18:23] Richard presents NVD’s response to their inquiry. Then, Daniel and Richard discuss NVD’s response and the discrepancy between their assessment and that of open source maintainers like Daniel who believe that some CVEs are not valid security issues.
[00:20:44] Richard asks if anyone offered to fund the work to fix vulnerabilities in important open source projects like cURL when a CVE is reported. Daniel replies that no such offers have been made, as most involved in the project recognize that some CVEs are not actual security problems, but rather meta problems caused by the CVE rating system.
[00:21:40] Daniel explains his short-term solution of registering his own CNA (CVE Numbering Authority) to manage CVEs for his products and prevent anonymous users from filing CVEs.
[00:23:04] Richard raises concerns about the potential for a CVE DDOS attack on open source, overwhelming them with a flood of CVE reports.
[00:24:20] Daniel comments on the growing problem of both legitimate and invalid CVEs being reported, as security scanners increasingly scan for them. Richard reflects on the global nature of the problem, and Daniel emphasizes the importance of having a unique ID for security problems like CVEs.
Special Guests: Dan Lorenc and Daniel Stenberg.
Support Sustain
Ben Hutton
Richard Littauer
Hello and welcome to Sustain! The podcast where we talk about sustaining open source for the long haul. In this episode, Richard introduces us to Ben Hutton, a Specification Lead for JSON Schema at Postman. They discuss the evolution and diverse applications of JSON Schema, its funding, and the importance of open standards for interoperability and innovation. The episode delves into real-world use cases, community feedback, and the 10-year vision for JSON Schema. Join Richard and Ben as they explore how JSON Schema is shaping the development stack and its potential impact on various industries. Hit download now to hear more!
[00:01:00] Ben describes his work on JSON Schema at Postman. His work entails leading the project, finding ways to move forward, creating visions and roadmaps.
[00:01:50] Richard brings up the question of understanding the market value for a Schema like JSON and asks Ben to elaborate on the improvements and ways they are moving forward. Ben explains how JSON Schema has evolved over time to cater to more use cases.
[00:03:22] Ben explains that Postman funds his work because JSON Schema is used by The OpenAPI Specification, a standard for defining the interface and data structure of APIs, which is a part of Postman products.
[00:04:20] Richard asks about the number of maintainers and community members for JSON Schema, and Ben tells us there are about five or six core maintainers and a community size around 15,000.
[00:05:16] What’s the importance of open standards and why do they need continuous improvements? Ben explains that the team helps developers understand and use JSON Schemas and supports the implementers of the Schema across different programming languages.
[00:07:24] Ben discusses a use case with Six River Systems, illustrating how JSON Schema helped different teams within a company to define their data structures and communicate more effectively, preventing bugs and misunderstandings.
[00:09:29] We hear why open standards are important, as Ben states that standards are vital for creating value that people can use and ensure interoperability and they can also spur innovation.
[00:11:51] Ben explains that JSON Schema was initially a personal draft within the IETF, but due to lack of alignment and communication issues, they’ve decided to publish their own standards while still maintaining some principles from the IETF.
[00:14:51] What’s the difference between JSON Schema and JSON? Ben explains JSON is used for API calls, and JSON Schema defines the stricture of expected JSON data. He also speaks about managing radical change requests, maintaining standards, and the value of community feedback, and he reveals an official JSON Schema test suite and a new tool called Bowtie.
[00:18:23] Richard asks about the funding and progression of JSON Schema, given its foundational role and slower pace of development. Ben describes Postman’s evolution from a basic API client to a comprehensive API platform.
[00:20:01] Ben mentions other companies, such as Retool and Airbnb, that support JSON Schema due to its utility in their own offerings, and he talks about Microsoft’s usage and a pending case study on how GitHub uses JSON Schema internally.
[00:24:09] Richard asks Ben about his 10-year vision for JSON Schema. Ben envisions JSON Schema being used throughout the entire development stack, from inception to defining data structures and models. He tells us about a case study they used from Open Metadata.
[00:27:18] The topic of financial needs for JSON Schema is brought up and Ben is content with current funding but admits they need to assess financial stability. He also tells us about future plans improving compliance and supporting the ecosystem to ensure interoperability across different languages and backgrounds.
[00:31:12] Richard asks about potential threats to JSON Schema, and Ben mentions that biggest threat would be if something were to replace JSON, and simplicity and ease of learning are key strengths of JSON and JSON Schema.
[00:33:47] Find out where you can learn more about Ben and JSON Schema online.
Special Guest: Ben Hutton.
Support Sustain
Josh Simmons
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. In this exciting episode, we welcome guest Josh Simmons, a notable figure with an illustrious career in the open source community. We hear about Josh’s important contributions, particularly his involvement with OSCON as a community manager and now, a co-organizer and program chair of the community track. Josh also outlines his talk on health and safety policies in the diversity, equity, and inclusion track, focusing on minimizing risks and promoting inclusivity at events. Josh also introduces his exciting new venture, Open Chapters, a consultancy designed to support and elevate open source projects, community organizers, and institutions. If you’re curious about the dynamics and challenges of open source communities, this episode is a must listen! Hit download now!
[00:00:41] Josh talks about his involvement in OSCON as a community manager and how he’s now involved in the community track, as a co-organizer and program chair and mentions his fellow organizers. He also mentions his upcoming talk on health and safety policies in the diversity, equity, and inclusion track.
[00:02:14] Richard shares his experience of traveling and getting COVID twice, and asks Josh provides an overview of health and safety practices.
[00:05:05] Josh shares about his newly launched consultancy with Julia Ferraioli called Open Chapters, which focuses on social and technical systems in open source projects.
[00:06:00] He explains his ideal clients for their consultancy for profit or non-profit organizations looking to benefit from or contribute to open source and free software.
[00:07:03] Josh discusses the “community manager trap” and how they plan to avoid it by providing coaching, strategy, and educational materials to mentor new community managers into those roles.
[00:07:50] Josh acknowledges the resource disparities in open source and his hopes to level the playing field.
[00:10:40] Richard presents a devil’s advocate stance, challenging the approach of trying to help maintainers and suggesting that they should be encouraged to set boundaries instead. Josh agrees with Richard’s stance and highlights the importance of maintainers and suggesting that they should be encouraged to set boundaries instead.
[00:12:47] Find out where you can follow Josh, Open Chapters, and his health and safety policy work online.
Special Guest: Josh Simmons.
Support Sustain
Stuart Geiger
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. In today’s episode, we’re joined by Stuart Geiger, and Assistant Professor at University of California, San Diego. Stuart shares his unique expertise on “invisible work” in the open source communities, discussing his research funded by the Digital Infrastructure Fund and emphasizing the importance of documenting and valuing such efforts. The conversation delves into the gendered aspects of invisible work, the intersection between capitalism and open source work, and the emotional impact of burnout in emotionally demanding and undervalued roles. Richard and Stuart also explore the motivations of open source practitioners, potential links between religious backgrounds and open source evangelism, and the intriguing implications of large language model AI in the open source world. Hit download now to hear more!
[00:00:32] Stuart tells us his focus area and explains that he also studies a range of decentralized, volunteer-based, peer production communities.
[00:00:57] Stuart was one of the first recipients of funding from the Digital Infrastructure Fund, aimed at researching the unseen aspects of open source software.
[00:01:31] What does Stuart mean by “invisible work?” In open source projects they are things that aren’t tracked on public code repositories. He shares that they have conducted over 50 interviews to learn more about the “invisible work”, and discusses the importance of documenting “invisible work.”
[00:04:56] Richard and Stuart discuss the need for environmentally friendly alternatives to in-person meetings or conferences. Stuart suggests using tools like Open Collective to and the All Contributors project.
[00:05:57] Richard asks if there are parallels between invisible work in open source and societal invisible work, particularly regarding women. Stuart affirms this and mentions that some of this labor can be gendered, especially work marked as more social. Richard and Stuart brainstorm a slogan to describe the transition from non-contributors to contributors in open source projects, so if you have any suggestions send an email.
[00:08:48] The topic about the intersection between capitalism and open source work is brought up, and Stuart discusses burnout, explaining that if often occurs in professions that are emotionally demanding and undervalued.
[00:11:29] Richard asks Stuart if open source practitioners see it as a calling. Stuart explains that some do while others are motivated by business necessity.
[00:12:57] A question arises around the potential religious backgrounds of open source evangelists, and Stuart shares he has not specifically investigated this connection, though he has observed comparisons with political activism.
[00:14:22] What is Stuart working on right now? He mentions exploring the implications of large language model AI in the open source world.
[00:16:32] Find out where you can follow Stuart and his work online.
Special Guest: Stuart Geiger.
Support Sustain
Ben Hur Pintor
Richard Littauer
Hello and welcome to Sustain! The podcast where we talk about sustaining open source for the long haul. Today, Richard is joined by guest, Ben Hur Pintor, a key player in the world of open data and mapping. Ben shares insights about his work with BNHR, a consulting business helping others harness open source and open data, and SmartCT, a nonprofit working on sustainability issues. He details their unique approach of using games to educate about open source and data concepts. Ben highlights partnerships with universities, shares about their Civic Literacy Initiative aimed at making more effective use of data, and discusses the challenges faced by people from the Global South entering the open source/open data space. He also tells us about Pista ng Mapa, an annual conference that celebrates open mapping in the Philippines. Download this episode now to hear more!
[00:01:16] What is BNHR? Ben explains it’s a consulting business where he helps people find value in open source and open data, particularly open geospatial and mapping.
[00:02:21] Ben talks about SmartCT, a tech nonprofit that helps local governments and civic society organizations deal with sustainability issues. They put citizens at the heart of their services and promote openness.
[00:03:24] Richard asks Ben why he saw the need for SmartCT, and he explains that many cities and municipalities in the Philippines were starting smart projects, but there was a lack of innovation and communication between them.
[00:05:40] Ben mentions they are focusing on building offline first and open tools that are easy for local government units to use, and he tells us about their projects, a card game designed to help people learn about open source and open data and they’re creating a smart mobility board game.
[00:09:14] Richard wonders if Ben has found traction with these board games and if there’s any drawback to this approach. Ben acknowledges the risk of making the concept seem too childlike but argues that these tools are designed to simplify the introduction to open source and open data concepts.
[00:13:20] Ben confirms past partnerships with local universities and student interns and shares a shift in focus due to changes in travel restriction in the Philippines. He highlights the importance of networking and partnership to their organization.
[00:15:00] We start a conversation on the Civic Literacy Initiative (CLI), which is an educational project co-founded by Ben. He tells us its goals, focusing on shifting from siloed capacity building to something more impactful, and their intent to support civic organizations and philanthropic bodies to make better use of data regarding capacity-building activities.
[00:17:47] Ben provides more detail about CLI, emphasizing its role in open data around capacity building, open consulting, and the building of the School of Data network.
[00:18:59] Richard asks Ben about his perspective on open data and open source as well as the sustainability of open source in the Philippines. Ben acknowledges the overlap and distinctions between various open movements and shares his own journey through them and he discusses the tight-knit community in the Philippines and their collective efforts pushing for openness.
[00:23:18] A question about the possible barriers for individuals from the Global South to enter the open source/data space, and Ben explains that entering the open source space is more challenging and how more support is needed.
[00:27:40] Ben tells us all the details about his project, Pista ng Mapa, Festival of Maps, which is an annual conference that celebrates open mapping in the Philippines.
[00:33:14] Find out where you can follow Ben and his work on the webs.
[00:12:48] “To me the biggest difference with working in this side of the world and also in the global south, in terms of the baseline capacity and the baseline knowledge for openness, open data, open source, open standards, we’re not there yet.”
Special Guest: Ben Hur Pintor.
Support Sustain
Aaron Wolf
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. Join us on a captivating journey with guest Aaron Wolf, the co-founder of Snowdrift.coop, as he unravels the story behind the innovative crowdfunding platform for open source projects. From his initial resistance to founding something, through his eye-opening Linux experience and a friend’s prompt to solve a pressing problem, Aaron details how he ended up creating Snowdrift.coop. Learn about the platform’s unique funding model, the early challenges and progress made over a decade, and its exciting recent developments. Despite not being a programmer, but a music teacher, Aaron finds parallels between his profession and the open source world, while he passionately advocates for the open source process in other industries. Discover the ups and downs faced by Snowdrift, the challenges of running a campaign, its current standing as a debt-free entity with a dedicated team, and a recent major milestone is revealed. Download this episode now!
[00:00:29] Aaron tells us about himself and being a co-founder, and how his friend encouraged him to act on a problem he was complaining about which is the lack of funding for public goods. He was frustrated with certain software limitations and desired improvements, which led to his idea for Snowdrift.
[00:03:38] How does Snowdrift work? Patrons pledge to donate more to a project when others join the crowd that gives together, a method they call 'crowdmatching'. Aaron expresses his reluctance to start something like Snowdrift due to the complexities involved, but his friend convinced him to give it a shot.
[00:04:47] Aaron talks about the challenges faced and progress made over the past 10 ten years, and the importance of early adopters. He also tells us he’s not a programmer but a music teacher and discusses the similarities he sees between open source software and the process of creating music.
[00:06:26] He talks about his frustration with the copyright system and how it hampers creativity, discusses his belief in the need for an open source process in other industries, like music education, and discusses the obstacles encountered when trying to use open source software and run Snowdrift as a co-op. He shares the Snowdrift gained early attention and interest but struggled to secure funding.
[00:09:30] Aaron shares that despite difficulties, Snowdrift is debt-free, has a small, dedicated team, and 156 patrons with real money.
[00:11:52] Richard and Aaron discuss the difficulties of applying for and giving grants. Aaron mentions they have not focused much on this aspect as it requires a lot of time and expresses that their work is still relevant and needed as it was 10 years ago. He also reveals a recent major milestone.
[00:13:55] Aaron mentions their early effort in reviewing around 760 crowdfunding sites to understand the landscape. They found many people working on similar projects but not collaborating, leading to many of these projects disappearing after a few months.
[00:15:31] Aaron highlights Open Collective as the closest to their own project, and mentions the benefits of Open Collective, including their legal foundation and handling of money, which Snowdrift has struggled with.
[00:17:37] We hear about Aaron’s talk on the nature of public goods and why coordination is necessary for their type of solution.
[00:18:02] Find out where you can follow Aaron online.
Special Guest: Aaron Wolf.
Support Sustain
Joe Castle
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy.
Today, Richard speaks with Joe Castle from SAS, a global analytics and AI company, about the fascinating world of open source software. Joe, who supports the federal team at SAS, shares the company’s journey from its roots as a statistical software company in the 1970s to its current role as an AI leader. We’ll dive into SAS’s integral involvement with open source software, how it supports and contributes to the community, and its ambitious plans for future engagement. Explore Joe’s unique insights into the motivations and sustainability of corporate open source efforts and discover how SAS balances financial incentive with authentic community engagement. Tune in for an exciting conversation about SAS’s shift towards greater open source integration and its commitment to building superior products, and ongoing discussions about making Python packages a first-class citizen in SAS. Hit download now!
[00:00:30] Joe explains his role at SAS, explaining how he supports the federal team at SAS and how it involves business development with government executives and advocating for and developing open source software.
[00:00:54] What does SAS do? Joe describes it as an analytics and AI company, and SAS clients are not just federal governments but also span industries such as banking, insurance, and more across the globe.
[00:01:51] Joe discusses how SAS uses and supports open source. Their product suite allows integration with Python, R, Lua, and JavaScript.
[00:03:33] Richard asks Joe to explain where SAS fits on the spectrum of corporate influence on open source. Joe tells us that SAS is involved in all aspects of open source usage, development, and contribution.
[00:05:36] Joe talks about SAS’s evolution from being a statistical software company to an AI company and how open source figures in their AI offerings. Developers can use Python to develop AI models using SAS’s packages and run it through their large compute engines.
[00:07:09] Joe explains his talk about the architecture of the CAS (Cloud Analytic Service), which is a Python package that allows for the sequential processing of large datasets.
[00:07:57] On the question of open source vs closed source, Joe says it depends on the context. While SAS has proprietary algorithms for model processing, developers can use their own python code to interact with these models.
[00:08:30] SAS’s primary audience includes data scientists, developers, and data engineers who have an understanding of Python and R.
[00:13:46] Richard inquires about the experiences of SAS in the realm of open source. Joe tells us they’re competitive motivations and they want to help users and capture a wider audience by signaling that they are open source friendly. He brings up the financial incentive for companies to engage with open source.
[00:15:27] Joe provides an example of a large financial customer who’s using their software for significant data processing and analysis.
[00:16:21] What’s Joe most excited to open source? He admits that some proprietary elements will remain closed due to business reasons. However, he mentions that there are ongoing discussions about making Python packages a first-class citizen.
[00:19:06] Find out you can follow Joe and SAS developer stuff online.
Special Guest: Joseph Castle, PhD.
Support Sustain
Vagrant Cascadian
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. In this episode, Richard invites guest Vagrant Cascadian to delve into the world of Reproducible Builds. Vagrant walks us through his role in the project where the aim is to ensure identical results in software builds across various machines and times, enhancing software security and creating a seamless developer experience. Discover how this mission, supported by the Software Freedom Conservancy and a broad community, is changing the face of Linux distros, Arch Linux, openSUSE, and F-Droid. They also explore the challenges of managing random elements in software, and Vagrant’s vision to make reproducible builds a standard best practice that will ideally become automatic for users. Vagrant shares his work in progress and their commitment to the “last mile problem.” Hit download now to hear more!
[00:00:47] Vagrant talks about their work at Reproducible Builds and details their responsibilities, including removing timestamps from Debian packages to enable reproducibility and maintaining infrastructure on ARM-based machines.
[00:02:25] Why do reproducible builds matter? Well, they allow verification that the source code matches the binary code that runs on a computer, enhancing security and preventing potential exploits. Also, they are important in scientific principles and for developers during code refactoring.
[00:03:41] The Reproducible Project is made up of a few developers under the Software Freedom Conservancy, but also includes a large community working on different projects. The project receives funding from various grants and sometimes corporate sponsors.
[00:05:56] We hear about the challenge of managing random elements in software to achieve reproducible builds. Vagrant talks about their goal to make reproducible builds a standard best proactive in the industry, benefitting software users.
[00:08:27] Vagrant shares their challenge in educating people about reproducible builds while also trying to make it a standard practice.
[00:09:09] How can open source projects help? They can help by setting up reproducibility testing in their continuous integration frameworks.
[00:10:24] Richard asks how large companies can benefit from and contribute to reproducible builds. Vagrant mentions how companies like Google find value in reproducible builds as it saves time, energy, and money by not having to rebuild things when they know they don’t have to.
[00:11:56] Vagrant mentions that they’re in the proof of concept phase of making Debian 96% reproducible, which includes over 30,000 source packages and over 50,000 binary packages. Richard asks about the project’s expected completion date, which Vagrant responds it’s his last mile problem to some degree, but they’re close.
[00:12:51] Find out where you can find Vagrant and Reproducible Builds on the internet.
Special Guest: Vagrant Cascadian.
Support Sustain
Denver Gingerich
Richard Littauer
Hello and welcome to Sustain! Richard is in Portland at FOSSY, the Free and Open Source Software Yearly conference that is held by the Software Freedom Conservancy. In this episode, Richard hosts Denver Gingerich, a member of the Software Freedom Conservancy and Founder of JMP. Denver dives into the backstory of JMP, the initiative to make phone numbers as flexible as emails. They explore Denver’s role as the Director of Compliance at the Software Freedom Conservancy, where he ensures companies comply with open source software licenses. Then, the conversation takes a turn to tackle a range of software compliance controversies, from Vizio’s violation of GPL to John Deere’s restrictive software that hinders farmers’ right to repair their machines. Denver provides an invaluable perspective on the work being done to protect users from software licensing malpractices. Press download now to hear more!
[00:01:22] Denver tells us how he started JMP and the motivation behind it.
[00:02:52] Richard asks Denver about the funding model for JMP and how he supports himself financially, and Denver explains his role at the Software Freedom Conservancy, a non-profit charity based in New York.
[00:05:35] The Vizio lawsuit is talked about and Denver outlines how GPL enforcement lawsuits traditionally focus on copyrights but argues that the direct harm is usually done to the users of the software who receive it out of compliance.
[00:06:58] Denver shares that he’s not a lawyer by training, but he ended up in his role after reporting a GPL violation he encountered with an Insignia Blu-ray player to Bradley Kuhn at a conference.
[00:08:44] Richard asks if XMPP, the protocol uses by JMP, has license or compliance issues, and Denver explains that it’s not a software license issue and that XMPP, made through the IETF, doesn’t pose any licensing concerns.
[00:09:48] Richard discusses companies with bad track records in software licensing compliance and the right to repair, using John Deere as an example, and asks how anyone could know if a that company is violating software license agreements. Denver explains that the first step is to investigate what software is used on the machines. He also highlights the issues with modern agricultural technology.
[00:12:20] Denver tells us there are around eight employees at the Software Freedom Conservancy.
[00:12:47] Richard wonders about potential lawsuits against John Deere and Denver clarifies while they haven’t sued, they did make a public post about their concerns after private discussions didn’t lead to resolution.
[00:13:41] Richard asks if there are similar user protection efforts in other countries, and Denver assures there are, citing examples in Germany and mentioning other organizations, such as FSFE.
[00:14:50] Find out where you can learn more about Denver’s work and the Software Freedom Conservancy.
Special Guest: Denver Gingerich.
Support Sustain
From the publisher's feed