2
2 Comments

Open-sourcing your project, pros and cons

Hi all,

I was wondering what were your thoughts on open sourcing your work, or part of it.

Context
My app is MediaTag, an easy & flexible way to organize anything digital. I have no plan to open source all of it, but it works with an extension that requires fairly high permissions, at least the kind that makes me think twice when it is from someone I don't know.

Current Solution

  1. In order to reassure users, I've decided to open source this extension. The code is visible here at https://github.com/mediatag/extensions. So it is not that the code in itself is interesting, but its presence should help raise trust.
  2. I've also extracted a basic version of the extension, which has less feature, but does not require any permission at all. So users who do not trust me might find it easier to start with that.

Pros & Cons:

Pros

  • As mentioned above it reassures customers.

Cons

  • It reveals non public APIs.
  • It may give ideas to competitors.
  • It may reveal bugs (gasp!)

So at the moment, there seems to be more negative aspects. But maybe I am seeing it the wrong way?

What do you guys think? Has any of you experience in open-sourcing his work?

  1. 2

    I don't agree with your cons:

    It reveals non public APIs.
    Introduce a facade which encapsulates your private API.

    It may give ideas to competitors.
    Do you really reveal anything that cannot be found out without the source? Are you using any magical ideas that your competitors cannot come up with on their own? I know that sometimes developers fear opening their software but is the source of the extension so valuable (without the source of your core product) that a competitor could gain a real advantage?

    It may reveal bugs (gasp!)
    So what? A bug won't go away if it's closed-source. I would even consider this more a pro point then a con one.

    I believe you are overthinking the cons.

    PS: the first link on https://mediatag.io/help is broken.

    1. 1

      Thanks for your feedback Rixx,

      Introduce a facade which encapsulates your private API.

      That only offsets the problem, as users can use this facade and the problem stays the same. And I'd rather not add unnecessary work to my plate. There is a clear difference between the api that the app uses between js and server, and the one that users will be allowed to build upon. But I agree, that's unlikely that this can be used for nefarious purposes.

      Are you using any magical ideas

      No, nothing is magic, all a bunch of 1s and 0s :) But there is a difference between having a starting point and not having any.

      A bug won't go away if it's closed-source

      I agree again. But there is also a difference between a bug that is server side, that one user may encounter once, and one that is publicly displayed. The former probably cannot be exploited while the latter is more likely to be.

      So yes, I may be overthinking the cons, but it is certainly good to hear alternative views. At least it's good you didn't mention any other.

      And thanks for the heads up about link, just fixed it.