Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We need to move towards “zero trust” for APIs.

SaaS can provide “open core” or better yet simply sell a hosted version of their fully open source code. If the provider fails to provide, you can fall back to self hosting.

The API equivalent would be open sourcing the data. This is the OpenStreetMap model. If the API provider fails to provide, you can fallback to the underlying data.



That's asking too much. SaaS should give an option for you to export all your own data in a simple, parseable format (like JSON). That's about it. They don't owe anyone their source code, and they don't owe any ethically sourced data (such as employees researching and manually entering).

API access needs better terms. Like guaranteed access for X years at $Y price with Z days notice if there's a change, where Z > 3 months or so.


This was the hope behind the StackExchange data dumps, that the community at large could always take their contributions elsewhere if the service jumped the shark.

Well, before the SE organization tried to kill the data exports off in an attempt to commercialize it towards AI companies, but thats a whole other issue.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: