Instead of creating something with the purest intent of doing it for sheer joy or scratching your own itch, suddenly everything becomes about money and now every second you spend on the project gets evaluated as a way to maximize monetary gains and if things don't work out to your internal expectations you're constantly comparing yourself to others or thinking negatively about how much time you've put into something and how little compensation you're getting from it, which is a horrible feeling.
* The code aspect is very important. I'm all for figuring out ways to generate income around open source projects, but if the code is the core of everything and your core is only moving forward because you want money, you're setting yourself up for failure, burn out or worse.
Once a free or OSS project becomes really popular, you suddenly start getting a lot more people asking suppor questions, asking for new features, calling your project crap because it doesn't do X, etc.
I think that's the point where burnout starts to be an issue, because you have to spend so much time to satisfy your users, and because you invariably have to put up with crap from very rude users. At this point, you might start to think about monetising your project - after all, you're spending a lot of time on it. And of course, it's extremely likely you will fail here.
One bigger issue is that usually open-source projects are fighting against well-funded for-profit projects who will not hesitate to do everything they can to destroy your project.
It's not a money issue in this case, in front of you you have very determined people who will do anything legal or illegal to protect their cash-cow.
For example, OpenOffice if not shielded by Oracle would have been killed long time ago by Microsoft's pressure.
...is great for as long as the joy or itch lasts. But the same problem still occurs, at some point a single maintainer is going to lose enthusiasm or have other itches they want to scratch. This becomes especially true when maintenance starts to feel more like a chore.
And in open source projects it can get even worse. Github users can be especially demanding and there are often those who express their demands in very "confrontational" ways. Faced with that it can be difficult to remain invested.
I'd love to be able to say "people appreciated all the work I did the past year, so they paid me $12 for this awesome annual meal"
* yay! That's definitely a sign of appreciation.
* going by hourly rates, how much of your time should $12 get?
Why not allow others to help share the burden?
Do things for free, even build open source libraries that are used by large companies. But get paid nothing, even perhaps not be able to pay rent.
Then praise all the large companies earning millions leveraging open source software.
Serge quickly discovered, to his surprise, that Goldman had a one-way relationship with open source. They took huge amounts of free software off the Web, but they did not return it after he had modified it, even when his modifications were very slight and of general rather than financial use. “Once I took some open-source components, repackaged them to come up with a component that was not even used at Goldman Sachs,” he says. “It was basically a way to make two computers look like one, so if one went down the other could jump in and perform the task.” He described the pleasure of his innovation this way: “It created something out of chaos. When you create something out of chaos, essentially, you reduce the entropy in the world.” He went to his boss, a fellow named Adam Schlesinger, and asked if he could release it back into open source, as was his inclination. “He said it was now Goldman’s property,” recalls Serge. “He was quite tense. When I mentioned it, it was very close to bonus time. And he didn’t want any disturbances.”
Open source was an idea that depended on collaboration and sharing, and Serge had a long history of contributing to it. He didn’t fully understand how Goldman could think it was O.K. to benefit so greatly from the work of others and then behave so selfishly toward them. “You don’t create intellectual property,” he said. “You create a program that does something.” But from then on, on instructions from Schlesinger, he treated everything on Goldman Sachs’s servers, even if it had just been transferred there from open source, as Goldman Sachs’s property.
(At Serge’s trial Kevin Marino, his lawyer, flashed two pages of computer code: the original, with its open-source license on top, and a replica, with the open-source license stripped off and replaced by the Goldman Sachs license.)
[1] https://www.vanityfair.com/news/2013/09/michael-lewis-goldma...
I'd say it's a subset of a much more general situation. I don't know how best to analyze that situation. But some things seem clear: What we live in is far from a meritocracy. The current system does not incentivise moral behaviour. The current system does not incentivise productive behaviour. A lot of people will try their best to act morally and be productive anyway.
Edit: Specified Chrome instead of password managers in general. Chrome doesn't use HIBP as its source.
The value of HIBP is not the actual code, I’d assume that’s fairly boring. The value is the database of leaks and the credibility to be contacted when new data dumps show up. None of this can easily be replicated.
The problem is he has been a complete failure on the business side. If he marketed it as 'you can fire 50% of your customer support if you stop account cracking using our service', charge per requests, and provided a bunch of code integrations there's no reason this couldn't be used by thousands of businesses, including top companies which have serious account cracking problems.
It's probably reaching a point where the return on announcing breaches is declining, and the potential value of selling data of questionable origin to a legit entity is very challenging. The dataset gets less valuable every day because anyone can start collecting breaches today, and the value of old breaches goes down -- who cares about an Adobe account leak from 2012?
The barrier to collecting leaked dumps and compiling a database from them is not that high. Many of the security outfits and large tech vendors are doing it already.
> Many of the security outfits and large tech vendors are doing it already.
Certainly, not doing so would be negligent. But that, too, doesn't make HIBP obsolete - there's value in having such a database that's openly queryable via an API and under independent and trusted stewardship.
HIBP also offers features that go beyond what a browser/password manager can do: It offers monitoring for entire domains that you manage. I have all our domains that we're using for email registered at HIBP.
(1) https://blog.mozilla.org/futurereleases/2018/06/25/testing-f...
A feature that many developers have to disable because you can't make Chrome ignore certain entries for localhost. For local development I have stuff that spins up a server of, let's say a CMS, and it uses the usual default credential "admin/admin". Yes Chrome, I know that this is an insecure password that has been breached, but this is a freaking development system, leave me alone...
The only way to avoid these messages is to disable the feature globally and that option is hidden deep in the extended settings.