NSF and Qualitative Research

I wondered if the NSF would be supportive of qualitative research, especially since I have dreams of submitting a grant proposal this summer....if I'm lucky.  Turns out that there was a workshop in 2004 in which this very topic was addressed - and the proceedings are available online here.  Very good to find out!

Google Wave

Christina Outlay sent me an invite to Google Wave, which I intend to learn more about over the next few weeks. So far, it looks like it will be a great tool for managing collaboration on ideas and research projects but time will tell.

Here are a couple of links which give (in this case, both negative) opinions about Google Wave.
Why Google Wave Sucks, and Why You Will Use It Anyway - Martin Seibert. Good points (and not too critical.
Google Wave Crashes on Beach Of Overhype - Scobleizer

----- Repurposing -----

I intend to keep this blog to store ideas and notes on my current and potential research. As a start, I have repurposed 37 old postings from blogs during my dissertation phase and immediately after that. I don't intend to keep this blog weekly current, but as a sporadic storehouse of thoughts.

Two interesting articles from CIO.com

Two things from CIO Insider:

(1) SAP's Ecosystem is thriving.

(2) It is possible to build an Open Source Business.

Beware Complex Systems

Complex Systems, not just hackers, are the biggest problem in Information Systems.

Another blog to keep an eye on

I have had the opportunity to meet Gianugo Rabellino at the 2007 Open Source Think Tank and found him to be quite congenial and intelligent. His blog confirms my impressions of him, as it offers commentary on many issues that I find interesting, especially his frequent and impassioned defense of the BSD and Apache licenses (which is no surprise as Vice President and PMC chair for the Apache XML Project).

OSS Ecosystem Presentation (not by me)

An OSS developer at 55thinking.com has come up with a presentation on open source ecosystems. While I think it is a beautiful presentation, I think it is a good overview of the 'correct' approach one needs to take with respect to getting into open source.

Open Source Ecosystems Research

In doing a scan of open source related news and blogs, I came across Alex Fletcher's blog posting on open source ecosystems. Imagine my surprise, since my dissertation is directly concerned with this very topic (and I've blogged Alex on a similar subject before). I admit it is a fairly involved set of concepts, but it can be boiled down pretty simply. Thus, the paragraphs that follow are a very, very brief summary of the framework and results of my research as it relates to open source ecosystems.

Generically, we can define an ecosystem as it is defined in Ecology: as a set of communities and the surrounding environment forming an interacting system. A community in turn is a set of populations of species living closely enough together for the potential of local interaction, or alternatively, the populations that are found in a defined region. Within previous organizational literature, a community is a bounded set of similar organizational forms (c.f. Ruef).

By contrast, an ecosystem consists of the various populations and communities of these similar species that interact within a given region along with the elements of the environment that affect these interactions. The two terms (ecosystem and community) are a conceptual cluster (Jax 2006) that result in two terms so similar as to be nearly synonymous. Here, we view ecosystems as being more inclusive than communities, reserving the latter for subsets of the ecosystem that exist and interact largely independent of the larger ecosystem.

In software, there are (at least) two communities that matter: the development community that includes those who write the software, testers, and support staff as well as those of the components that are included in the final product, and the user community that includes the end users (OEM/ISV, end users, and consulting partners), not to mention the CEO/CIO/management team of these organizations. The temptation is to combine both sets of people in a single community, but in reality we find that these developers interact with the end users only rarely, especially those for upstream component providers. Pursuant to our previous definition of communities as existing and interacting independently of each other, we find in reality that the developers largely work separately from the efforts of the sales/marketing team on the user side particularly as the organization grows in size.

With that as a background, applying the term 'ecosystem' to open source would include more than downloaders, QA testers, and source code committers. Additionally (especially in the current commercial open source environment), we have to include corporate CIOs, analysts (yourself included, of course), investors/VCs, competitors (e.g. IBM and Oracle), sponsors (e.g. IBM and the Apache Software Foundation), and a wide range of customers from perspectives such as OEMs, ISVs, end users, and more. We continue to define the OSS ecosystem in terms of developers (including the QA testers and committers and others) and users. Forrester Research includes four functions around open source: product development, distribution, services, and marketing. All of these are required by somebody in the ecosystem whether that is a central firm or the members themselves.

The problem is not necessarily in identifying or quantifying these members of the ecosystem at large, but in fully defining their contributions and inducements. In other words, what do they provide and why do they do so? For instance, why does IBM participate in the Geronimo project and what do they provide? How they provide the sponsorship and services they provide is a tactical issue that can be identified from the various analyst and media reports. But the reasons behind the decision are not always so obvious. Would IBM have participated in the Apache project so heavily if the ASF had standardized around the GPL license instead of a BSD derivative? Would they have participated in Geronimo specifically if JBoss had not done so well? Have they been able to appropriate the anticipated benefits of the Gluecode acquisition yet?

Similar questions can be asked for any participant in an open source ecosystem. In the final analysis, it boils down to a question of the health of said ecosystem. What makes one ecosystem more healthy than another? What I have found (so far) in my research is that the health of an open source ecosystem is based on three issues. One, how much productivity (vigor) exists in terms of the capital being invested, produced, transformed, and exchanged. It is important to note that capital includes more than just money, but intellectual/human capital, reputation capital, and more. Two, how organized is the ecosystem. A loosely connected band of developers and users are not as healthy as one in which the communications and exchange pathways among the members of the development and user communities are solid and repeatable. Third, how resilient is the ecosystem. Mere stability implies that an system can remain at a given level of functionality but resilience implies that it can adapt and recover from significant changes in the system.

In a later post (or send me an email at dewynn at uga dot edu for an advance "Cliffs note" summary), I will discuss the concept of a 'mechanism' and how successful (healthy) open source ecosystems have been able to develop and use specific types of mechanisms to improve and maintain their health.

More on SW Ecosystems (long)

In this article, the author presents ecosystems as consisting of the partners that surround and support a software package. In this blog posting, the author presents several different components of open source ecosystems, including ISVs and other downstream firms. In yet another article, Business Week includes customers, stack aggregators such as SpikeSource, and (to some degree) the VCs. In a typically comprehensive fashion, Gartner defines an open source ecosystem explicitly as
the set of policies, processes, individuals and organizations that can influence, support, staff, finance, train, and educate users and developers of a community for the purpose of making it self-sustainable over a period of time that is compatible with the life cycle of technology investments for the user community.

Finally, Forrester Research says that
"An open source ecosystem is emerging that serves the same functions as a traditional software company — but through multiple organizations. In the past, your software supplier would supply the software, support, maintenance, training, and consulting. The new open source ecosystem provides these services through communities, companies, consortia, and other means. As a result, customers have access to the same services they are used to from traditional suppliers, but they have to understand how to make the open source ecosystem work for them." (note: I do not have access to these Forrester reports as they costs $795 which is not in my budget. However, slides corresponding this first link can be found here.)

Forrester also says that
An open source ecosystem is emerging, however. Though this open source ecosystem is made up of many new types of organizations, such as communities and consortia, the organizations deliver the same four functions as closed source vendors: product development, distribution, services, and marketing. This map of open source players will enable firms to follow a practical approach to build their own open source ecosystem to suit their software needs.

All these quotes leave me with the impression that (a) there is something to the concept of an ecosystem in open source and more generally, in software, (b) the ecosystem concept must include a wide range of participants/units/members/etc., and (c) there is a lot of resource flow in a healthy ecosystem but measuring it will be a hot mess. And I'm just the man for the job.

The needs of the Security Profession

CIO magazine published an article on the new required skills for security professionals, including a business acumen (perhaps an MBA) and a basic understanding of psychology. Interesting reading to keep in mind when we begin to build a security curriculum"

Successful Open Source Companies

Yes, the focus of the title of this post is on the companies, but I would argue that much of the discussion is (of course) on the ecosystems surrounding them. Two links here, which I will do my best to summarize a little later (but I did not want to lose the links):
I'm sure there are other posts out there (in particular,look through Matt Asay's interesting and voluminous blog posts), but these will do for now. I'll recap and summarize later.

Last post (for tonight) on the OSS ecosystem

Matt Asay discusses a ZDnet article on the "War of the Ecosystems" that makes several points that I should keep in mind when developing a presentation on this stuff.

Further on the "open source ecosystem" chain

Speaking of the blog by the "Director of Ecosystem Development for the Eclipse Foundation", he posted an entry discussing an interesting study on the success of OSS projects, in which he made the following comment:
To me, success would be a healthy ecosystem with lots of commercial and non-commercial activity. This would be pretty difficult to measure, not only to find publicly available data, but because it's not clear how to measure the "health" of an ecosystem. There is hopefully an opportunity for research in this area moving forward. (emphasis added)

BINGO! I think I have an interested reader here...I DEFINITELY need to give him a shout out when I get close to an answer.

The Open Source Forge trend

BTW: another sign of OSS growth is the tendency toward a 'forge', as used by Ruby, SugarCRM, MuleSource, and others in addition to the original - Sourceforge. From what my 'insiders' are telling me, this is a developing trend.

More on Open Source Ecosystems

There are other sites out there discussing the phrase 'open source ecosystems'. Here are a few interesting ones:

  • An interesting post by one of the guys who helped develop Ruby on Rails, which is a great new OSS language for Web 2.0.

  • A news article about the importance of third parties such as Pervasive to form an ecosystem around open source projects (in this case around PostgreSQL.

  • A 2005 research article by IBM stating (among other things) that an open source project "needs to build an ecosystem" in order to reach a critical mass for viability.

  • What looks like a wiki-evolving definition (or is that 'wikivolving'- is that a word yet? should I TM it?) of an open source business ecosystem on ObjectWeb.

  • A blog from a guy whose job is Director of Ecosystem Development for the Eclipse Foundation. (I ought to try to ring him up sometime just for a chat)

  • A presentation on Collaboratively Evolving Ecosystems in the context of government-sponsored open source projects, essentially laying out the case for moving from "N*build to 1*build + N*improve" (an interesting way to look at the benefits of OSS.


All this to suggest that I am certainly not the originator of the term nor the only one interested in it. Here's hoping I can add to the conversation in a truly meaningful way.

Linux Ecosystem to be worth $40B, per IDG

According to this report by IDG, the Linux ecosystem will be worth $40B by the year 2010. The actual figure is not as interesting as the fact that they used the term 'ecosystem', which is pretty cool.

My favorite Wikipedia page

OK, it is not related to my dissertation (at least not directly), but I like this Wikipedia page very much. Especially the quote from Dr. Frankfurt's book:
It is impossible for someone to lie unless he thinks he knows the truth. Producing bullshit requires no such conviction. A person who lies is thereby responding to the truth, and he is to that extent respectful of it. When an honest man speaks, he says only what he believes to be true; and for the liar, it is correspondingly indispensable that he considers his statements to be false. For the bullshitter, however, all these bets are off: he is neither on the side of the true nor on the side of the false. His eye is not on the facts at all, as the eyes of the honest man and of the liar are, except insofar as they may be pertinent to his interest in getting away with what he says. He does not care whether the things he says describe reality correctly. He just picks them out, or makes them up, to suit his purpose.

Classic. Reminds me of what most scholars do (whether they know it or not) when they write.

Oops...perhaps that's bullshit.

Marc Fleury has left the building

Its official - Marc no longer works for Red Hat. After selling his company for $420M in 2006, what else was there for him to do? He has long despised the role of middle manager, which in many respects he would have become - albeit a very high position in that middle. He would no longer really be 'the man', but only 'the man sitting next to the man'. I could not see Marc going out like that.

Besides, some reports have him personally getting as much as $150M out of the deal, which is pretty darn good after he started the company in 1999. I would love to be so lucky, but I cannot think on that scale. Kudos to Marc, but I can't wait to see what he comes up with next - in addition to his techno DJ career, that is.

Security Breaches and compensation

The University of Georgia had a security breach recently, which was very lightly covered by the media. In response to the breach, you get the standard fare of apologies and news releases (just like we saw in the Ohio University breach last year...but no remuneration for credit report freezes or any other incurred expense by the people whose information was compromised. Why not?

Help! We're under attack!

Posted on CNN and elsewhere, 3 of the 13 'key Internet computers' were were under attack by a massive hack attack. According to the CERT center,
At approximately 0001 GMT on 6 Feb 2007, several root-level DNS servers began receiving a large volume of malformed DNS queries. This initial attack appears to have been a warm-up for a much larger attack that began at 1000 GMT.

DNS servers G (U.S. DOD Network Information Center), L (Internet Corporation for Assigned Names and Numbers), and M (WIDE Project) appear to have been the most severely impacted although none were ever unreachable. The servers were operational and reachable even with the high volume of traffic.

Fortunately, we internet users did not know what was hitting us. Unfortunately, this is becoming more and more likely. Buckle up.