Porsche Open Source Platform
Porsche’s new open source portal is welcomed as a small step by a traditional automaker, but many note it currently exposes only web and design-system tooling rather than the embedded software that actually runs its cars. Commenters debate whether carmakers could or should open up ECU and safety‑critical code, citing complex proprietary toolchains, liability, and regulatory constraints on one side, and transparency, security, and right‑to‑repair arguments on the other. Broader themes include skepticism about “OSS‑washing,” differing attitudes to Android vs Automotive Grade Linux for infotainment, and the role of CLAs and corporate culture in shaping meaningful open source contributions.
Scope and impact of Porsche’s open source initiative
- Most visible projects are web- and design-focused (design system, site tooling), not vehicle-control code.
- Several commenters see it as “big headline, small impact” or “OSS-washing,” but others view any move by a traditional OEM as a positive first step.
- The site itself throws client-side errors for some, and the required CLA draws criticism.
ECUs, embedded software, and feasibility of openness
- Many argue the real value is in embedded systems (ECUs, safety-critical controllers), which remain closed.
- ECUs are typically built via proprietary model-based toolchains, layered middleware, and code from numerous suppliers and consultancies; OEMs often don’t even have full code rights.
- Shifting this stack to FOSS is described as a decade‑plus, industry‑wide paradigm change, not something a single brand can unilaterally do.
Safety, security, and regulation
- One side emphasizes safety/liability: automotive standards, third‑party certification, and complex failure analysis make open modification of critical systems risky for bystanders.
- The other side argues openness would expose bugs and cheating (e.g., emissions scandals) and ultimately increase safety, highlighting limits of certification and weak regulators.
- Automotive security is widely described as poor, with heavy reliance on obscurity; some argue this is exactly why security‑critical code should be FOSS and user‑patchable.
Owner control vs public risk
- Strong right‑to‑repair sentiment: if you buy the car, you should be able to inspect and modify its software, with warranty voided as needed.
- Counterargument: a hacked car operates on public roads, so “your” risk is imposed on others; law and social costs justify restrictions.
- Some propose a separation: open/readable safety code, but tightly controlled deployment and flashing.
Infotainment, Android, and attack surfaces
- Questions about Porsche using Android vs Automotive Grade Linux; examples given of other OEMs’ Android stacks being buggy or Google‑dependent.
- Infotainment is often logically separated from safety systems but has been used as an attack beachhead; some cite Hyundai/Kia theft issues.
- Several ask why at least center-console software and protocols aren’t opened, given it’s nominally non‑safety‑critical.
Aftermarket and open ECUs
- Multiple open or semi‑open aftermarket ECUs are cited (e.g., Speeduino, RusEFI; Megasquirt noted as not truly open).
- Retrofitting old engines is described as mostly a hardware/sensor integration problem; once inputs/outputs are reliable, it’s tuning/configuration.
Corporate incentives, culture, and ecosystem
- Many see little business incentive for OEMs to open internal code, given legal risk, IP entanglements, and lack of perceived sales upside.
- Some argue standards and OSS could help commoditize supplier software and reduce licensing costs, but entrenched contracts are a barrier.
- Discussion of German firms’ hiring practices (German‑language requirement) vs more English‑friendly hubs like the Netherlands; seen as affecting their ability to build strong software teams.
- VW Group politics and ownership structure are described as complex, making a group‑wide OSS push unlikely.
Design system and web tooling
- Open‑sourcing Porsche’s design system puzzles some, since copying the brand look is restricted anyway.
- Others note practical reasons: third‑party contractors and ecosystem integrations need easy access; public registries and GitHub issues are simpler than private registries and internal Slack.
Porsche brand perception and legacy support
- Some say this initiative nudges their likelihood of buying a Porsche upward.
- Porsche is praised for heritage support: new infotainment for 20‑year‑old models and unusually long, extensible manufacturer warranties on used cars.
- Compared with other brands that abandon software quickly, this is seen as a strong differentiator, though engine design issues on some models are also mentioned.