Professional maintainers: a wake-up call
blog.filippo.io
blog.filippo.io
Well, this is exactly what I've been doing around VideoLAN (VLC, x264) and FFmpeg for the last few years. In order to do that, I've created 2 official companies Videolabs and FFlabs (besides the non-profit orgs) and I've gone through all the hoops to get paid (PO, billing, invoices, registering to large companies is a lot of paperwork, tbh, but well..) and we try and bill small to large companies that depends on those projects.
And FFmpeg and x264 are the core of the online video.
So I did exactly what Filippo is saying we should do.
But the result is really not impressive. Seriously, asking for money for support from those companies feels like we're pulling the nails, even if their full business depends on it. Getting 30-50k$ from those companies for support for one year can be very challenging, long or leading to nowhere at all.
So, large SV companies and startup should also start agreeing to pay for open source, when it's the core of the tech.
FFmpeg should be able to pull multiple $M per year easily from all the major corporations that use it. For comparison, $1M is the total yearly cost of ~3 average engineers at FAANGs. And most, if not all of them, use FFmpeg quite seriously.
That's the point, they don't pay, and they don't get support. But they still complain when there is a major CVE.
> For comparison, $1M is the total yearly cost of ~3 average engineers at FAANGs.
I wish we got that...
2) When funding is low, big scary exclamation marks all over the place
3) Include a bulleted list of doomsday scenarios showing what could happen to YOU if a bug/vulnerability is found
4) Add a picture of a sad kitten or crying baby for good measure
Now just subscribe all of the non-tech business people at organizations that use FFMPEG, and wait for them to panic. (Make sure that they need to call you to unsubscribe from the newsletter, especially if they work at the New York Times)
Don't do that bit unless you're sure it's not illegal in your (and their) jurisdiction.
Spam being a thing, and there being laws against it.
> By using this software, you agree to subscribe to our monthly newsletter
(I was joking btw, in case that wasn't clear)
Ah, if only one could "just" get a mass of people's attention and send the message
[1]: From what I've seen this ~50% number seems to be pretty close to the mark across virtually all industries and jobs. I.e. it's pretty safe to assume that the total cost to your employer to retain you is around double your take home pay.
[1] https://en.wikipedia.org/wiki/Payroll_tax#/media/File:Effect...
You've put your finger on the core of the issue with FiloSottile's suggestion. The problem is that to sell something to a big corporation, you need to have something tangible you can sell. What you have are enormous pieces of widely used software, being given away for free. Many companies are going to take that and run with it, and forgo a support contract entirely. You may argue that they want support when there's an issue, but the truth is they're happy enough with the status quo and just complaining a lot.
In FiloSottile's model, a corporation needs to use your software for something specific, but also expects to need changes to it or prioritized issue support and approaches you; you send them an invoice with five zeroes on it as a bill for your services and they are heavily incentivized to pay for it.
Unfortunately that's not the reality for 99.9% of open source maintainers, a figure that includes most creators of popular software like VLC. I've personally contributed to a bunch of projects and maintain some of my own, but it's a hobby. As far as I know no corporations are even using any of them. Figuring out some software niche that no one yet has a product it, building it, and waiting for a corporation to swoop in and drop me a six figure yearly check cannot be a career strategy.
Sure, someone else may start a competing project…
If you want it fixed now submit a PR that I can accept. That’s what I do anyway.
Companies usually have a reason to keep their expenses low. Sometimes they are a public company with fiscal responsibilities. A startup will only have so much runway and is likely trying to reduce expenses.
Given this situation, why will they pay for what they can get for free?
See the article...
When you have contracts and support at a cost you aren't doing the work for free. The article is talking about running open source like a business rather than a volunteer situation. That means, you're not doing everything for free.
Which is _exactly_ what we are doing...
The person you're responding to made it very clear that they were responding to your conclusion that "large SV companies and startup should also start agreeing to pay for open source, when it's the core of the tech". The fact that you have support and services available isn't a "gotcha!" that refutes the point they are making, which is that given that there is also a zero-cost "product" available, then (unsurprisingly) prospective customers prefer that one instead.
Public companies also have accounts for goodwill in their books, don't they?
Also, I'd even say that depending on volunteers for everything when you aren't in dire straits isn't to responsible.
It is not like most of the time randomly. It is like that, because economic system is designed to work that way.
"every state has enacted a corporate statute giving managers explicit authority to donate corporate funds for charitable purposes"
https://digitalcommons.law.villanova.edu/cgi/viewcontent.cgi...
(I am not necessary saying companies should run social support. I don't think so. But they are nor responsible for anything but the profit.)
"Designed" is probably putting it too strongly. But however you characterize the process that got it that way, people did it, and people can change it with enough effort. In fact it is constantly changing, and each of us can decide the direction we are going to push it, and how hard.
"And friends, they may thinks it's a movement." — Arlo Guthrie, Alice's Restaurant Massacree
They got their reforms, so yes it was designed.
The neoliberal faction certainly has had an outsized influence (funny how proposals that the 0.1% want done end up getting a lot of positive attention more often than not), but even so, the economy as a whole is the result of a lot of political compromise and dealmaking, not to mention undirected evolution.
Edit: Same goes for basic politeness or being customer friendly. Can be very good for the stock price long term even if it doesn't matter in this quarters result.
Goodwill in that context is towards the company, an intangible asset comprising the value in its brand etc.
I've worked for multiple public companies and have yet to see this. I have seen different models. For example, when they want a feature in an open source project they may contract with maintainers to pay for work. Or, they may have a maintainer for a project on staff.
> Also, I'd even say that depending on volunteers for everything when you aren't in dire straits isn't to responsible.
Responsible to whom?
People choose to be volunteers. Being a volunteer and hoping for hand outs from companies it's working out well for most folks. Maybe it's time to look at other ways of doing things.
Note, I'm not suggesting what the right way to do things is. I'm just looking at how people are doing things. Expecting them to behave differently isn't likely going to bring about a change in them.
A while back I bought a cheap robot vacuum. Their scheduling feature didn't meet my needs, so I reverse-engineered the protocol and open-sourced a cron-friendly CLI tool and a library so people could do other things with it: https://github.com/wpietri/sucks
Honestly, this was a mistake on my part. It was a demanding audience of home-automation hobbyists mostly without programming skills. The company was thoroughly unhelpful. When my vacuum finally broke, I was relieved, as I had a good excuse for trying to hand off the project. Nobody stepped up, so I shut it down. I just ran out of interest in doing free work to support a company worth billions.
I really admire the community spirit of open source But it's not sustainable if companies making their money off it keep depending on the niceness and generosity of others without giving back enough to keep them happy, healthy, productive people.
I think that's a pretty unfair characterization of the previous post.
Most of us work at such high levels of abstraction we couldn't even name all our dependencies. Which in effect makes us the same sort of consumers app users are: expecting a lot out but not putting anything in.
Very sad if this ever comes to pass. It's a world in which I would never have learned about computers or decided to work with them. I think it makes more sense to charge big companies but keep software free and libre for individuals.
(I don't think this future will happen though: I think it's based on a deep misunderstanding of what drives FOSS developers to do what they do).
- OSS allowed an entire industry to flourish,
- It has had so many contributions that it is easily the category which is the biggest benevolence of the world, and possibly the biggest achievement of humanity,
- It allowed the entire world to go securely on the internet (launch a Debian and it’s secure and up to very high professional standards without effort, try doing that in the legal field),
- Its results are permanent. In 2100, documents written in Office 365 or Adobe will be lost, but they’ll be able to recompile LibreOffice, Chrome (at least Webkit) or Wordpress. Benefits of OSS accrue over time, as opposed to closed-source software which is sold under closed license and DRM.
In practice, I think that only entirely cloud based ecosystems will be lost to time. As long as the requisite hardware can be emulated and there is an archived version of a local viewer, it's possible to interpret a closed source format document. People already do it with WordStar and retro games.
I agree, but how do you distinguish between the two, and how do you make the source available yet compel large companies to pay?
I think mobile was a reprieve for commercial software and UX specialists and the increasingly negative comments on new OS versions indicate it is close to done like desktop.
For every user that likes a change there are 19 that prefer the flow they already learned to stay exactly the same and at least half are looking for exploitive attempts to modify their behavior in anything a publisher changes.
All I see with the FOSS ecosystem is it picking up steam at an extraordinary pace from 2005. Postgres in particular has absolutely dominated its incumbents in recent times, an insane reversal from the situation at the turn of the millennium.
There's a guarantee of correctness, availability of auditability, and a tide of slow, iterative improvements.
The key is supply and demand.
Open source software is often not a trailblazer. Open source is often reactive to a need, and punctuated by a demand for quality, bad treatment by the commercial incumbent, and constant iterative improvement.
See the pattern of so many technologies, Docker following VM ware, open source databases following Oracle (1980s Oracle was a real pioneer).
Open source has always and will continue to be a slow rolling borg that chases commercial software. Projects will never be rushed, but the benefits of an open base has time and time again crushed closed source incumbents.
I've long known people who modified cars. Sometimes they did it as a business. Sometimes they helped friends out. Sometimes the work was on nights and weekends. The car manufacturer never had a responsibility to support them. They never had to support people in forums. Anything they did was their choice. Sometimes as a business and sometimes volunteering.
You didn't have to open source that work. Once it was out there, you didn't need to provide support.
Doing volunteer work and hoping for generosity from companies isn't working.
That's true. The problems brought up in the article all stem from companies relying on open source and then getting into trouble when there are problems with it. They would pay if they had to.
The core problem is that everyone wants something for nothing. Sure companies appreciate that they can get billions of dollars worth of infrastructure software for free. Individuals appreciate that they can get useful software for free (though many don't care if it's FLOSS or illegally obtains commercial). People will take what they can, and pay for what they must. Open source is sometimes better than commercial, and even if the developers were paid industry rates it would be much cheaper because companies charge rent for software - not for development.
I get that it's the dominant experience for you, but please don't confuse that with some sort of deep evolutionary imperative. One of the things that distinguishes humans as a species is how extremely social, how extremely cooperative we are. See, for example, E. O. Wilson's "The Social Conquest of the Earth" for more on where we fit in evolutionarily.
> One of the things that distinguishes humans as a species is how extremely social, how extremely cooperative we are
Where I point out that what you are saying is not true in general. But it is true within a group (say a company) and not between groups (say between companies and OSS maintainers). Groups that corporate well within the group have an evolutionary advantage fighting other groups.
However I am not sure what the point is you are trying to make? My original point is that corporations/people don't throw $ at OSS maintainers for the work they do and expect them to maintain it for $0. That's a clear objective fact. So either treat your OSS project as a business and get paid to do your work or accept that outcome and stop complaining.
https://en.wikipedia.org/wiki/In-group_and_out-group
Now I think we are done here.
This is unnecessarily aggressive. Also, it’s not fun reading a thread dominated by one or more people who are combative.
> If everybody consumes and nobody contributes, how long will that last?
That doesn't answer the GP question, which is all about incentives.
The answer is, at least some parties won't pay for what they can get for free. So the options are:
a) deal with it
b) require payment
c) come up with some way to incentivize more donations
It’s not like there is a parable about killing the goose that laid the golden egg to teach you how to appreciate these things.
Another perfectly good option is for tech people to build strong cultural expectations that people and companies who benefit from a commons should help keep it healthy. Which is what's happening right here in this discussion, so you could be part of that solution if you wanted.
This notion that one has to think about it as a business is just false. That is one way to do it, but open source funding happens other ways too. Your attitude that anybody must be an idiot if they want to solve in a way incongruent with your hypercapitalist fantasies is both rude and ignorant. If anybody's being childish here, it's the person treating them as "whining".
At the least people suggesting this should acknowledge that this kind of society has possibly never existing in this entire universe on the scale they want it to exist (larger then dunbar(ish) number tribes). The onus is on them to build a path towards this new kind of society instead of just throwing the ideal out into the ether and expecting it to just magically appear.
As an example, note that the Fortune 500 spend $20bn annually on corporate social responsibility: https://econreview.berkeley.edu/stocks-sustainability-how-th...
That's not because they just had some good feelings. It's because people expect them to be at least slightly non-awful. We can accomplish something similar here. If programmers start insisting that companies take open-source funding seriously, it will happen. Not quickly and not easily. But if people start taking action (e.g., turning down jobs when companies are parasites on the open-source ecosystem), things will change.
Is that a good thing? Yes. Is it enough? Not even close.
The culture needs to change sure, but the change of culture that needs to happen seems effectively impossible unless companies are dragged into it kicking and screaming through organized labor efforts or government oversight/regulation. Those are both of course highly polarized political issues and that aspect of culture sure isn’t getting better either.
I think the quicker, sadder, and easier change is that a lot of Open Source projects just aren’t going to get started like they used to, and are going to have increasingly restricted licenses with stratified feature sets. We’re definitely seeing more of the “Taking my ball and going home” approach by small developers with tiny open source packages these days and it’s sad but also hard to blame them for. Even worse there are an increasing number of groups who attempt to buy projects for sometimes stupid money for the explicit purpose of using them as a Trojan horse to ship malware. They’re preying on the same people who have become incredibly cynical about the whole thing and that’s dangerous for everybody.
The history of the minimum wage isn't that some bureaucrat mandated it and then everybody said, "Gosh, that's a good idea, let's keep it." There was a long period of advocacy for it, a period of persuading people that it was the right thing to do. That was the ground in which all the work for the change grew.
Today, software developers are the key labor force for this change, and we aren't organized. So in practice, the first work we have to do is to persuade the bulk of programmers that it's part of their professional duty to make sure their employers support the open-source projects that their businesses depend on.
Companies will do it if we insist. In the grand scheme of things, it isn't even much money, not compared to what they're paying programmers in salary, benefits, and cushy amenities.
Agreed on this, but the "and companies" thing is a total red herring. Two things to note: even though you mention "people and companies", it's incredibly clear from popular sentiment that the conception held by most people of the problem/solution comes down to the latter (companies) and not the former (people). Focusing on companies at all—let alone allowing it to occupy a majority share of one's focus—is a huge mistake. Depersonalized abstract entities like companies are almost entirely immune to whatever methods of persuasion people have in mind here. Gay rights only just became kosher to "take a stand" on, and even then it's invariably limited to being trotted out as a vehicle for the most empty and self-serving marketing horseshit and other corporate speak that anyone should expect to come out of these institutions. Cultural pressure for open source by way of shaming companies doesn't stand a chance; it has to come down to people.
I've brought up the subject before: why do we rake companies over the coals for their inaction, but ignore the individuals? It's worth reflecting on the relationship between a company and its employees.
A company, no matter how many layers of management are involved, delegates some problem to an employee. That employee surveys the lay of the land and then elects to use some tech that is available from the commons towards solving the problem. In turn, they are rewarded by their employer in both tangibles and intangibles that are considered proportionate to the achievement and budgeted accordingly. Thus, that person is, in a very real way, converting the labor of others into personal gain—in the form of wealth, career prospects/advancement, and personal stature in wider society.
Why is it easy to frame a company as the perpetrator and hard to say anything about any given developer who benefited from this (and did not share)? Because it's uncomfortable, since it's too personal? That might make sense if we were talking about, say, a custodian with limited career prospects just doing their best to keep their head above water and provide for their family already, but that tends not to be the case where software development is involved. The implication here is clear. (Forget, for now, the prior argument I just made about effectiveness for a moment and feel free to focus just on the fairness aspect here, if it uncomplicates things.) If there's any appropriate allocation of social pressure to be meted out—resulting in social expectations to be met—then it needs to come in the form of beliefs like, "hey, if as part of your employment you are singlehandedly making something like twice the US national average of an entire household, and you're not giving away at _least_ 10% of your salary to the people who made that possible, then you're kind of a piece of shit." Is that a stand that people are willing to make, though?
It's acceptable to disagree with this, but to understand why you feel it's justified to defend the individuals involved means that you have everything you need to understand why there is no movement on the problem. Perennially and impotently opining that companies need to quit screwing around and do something already is a ridiculous strategy.
Making something open source is about granting freedoms for users of that thing. One of those freedoms is usually "you owe nothing and can do with it what you wish: sell it, fork it, modify it" in exchange for "the author provides no guarantees and is not liable for this software".
Open source authors that expect some benefactor to appear and sprinkle money so that they can quit their day job and work on their hobby full time are, for lack of a better term, delusional.
The default is that no one will use your thing, no one will contribute, no one will fund you, etc.
Anything beyond that is a fluke.
This is demonstrably not how many people many treat open-source authors. Just look at how the Log4J folks are feeling right now: https://twitter.com/yazicivo/status/1469349956880408583
I do have some open-source code out there where people have been mostly pleasant and reasonable. It's targeted at developers in particular niches and they do act mostly as you describe.
But once it shifts from a peer relationship to a producer/consumer relationship, things can easily get ugly. Ugly in a way that drives people out of open source and keeps people from open-sourcing useful code. You appear to be fine with that. But if anybody's delusional here, it's the people who expect to keep taking from open-source software without worrying about its sustainability.
> Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns.
Why don't they 'resolve' the security issue by removing the feature and then set up a bug bounty for backporting fixes to the shitty feature? Then the companies that depend on it will actually be on the hook for once.
Too much collateral damage for downstream F/OSS? Too unseemly a move, in a moment of ‘crisis’?
I can't think of anyone I've ever met that started an open-source project expecting it to become their day job in short order.
When your project blows up and mints a herd of new gazillionaires, yes, it's reasonable to ask those companies to fund what is now an important community project.
Anybody that says "nope, their money, they do what they want" is spouting the same flavor of dipshittery as "free speech only means the government can't censor, private companies are free to do what they want".
Technically correct and functionally disastrous. Societies worth living in can and do not endure this behavior for long.
Americans used to understand this. Know why there are schools all over the country named after Andrew Carnegie? Because that ruthless capitalist mercenary, after crushing every one of his competitors to dust, invested a large chunk of his fortune on infrastructure for national wealth that would propel another three generations.
'Tis the season, so we've been listening to a lot of Christmas carols.
One of my favorites is Good King Wenceslas, which concludes with the verse: "Therefore, Christian men, be sure, wealth or rank possessing, Ye who now will bless the poor, shall yourselves find blessing."
Charity used to be a behavioral expectation in the West. Charity is not "giving money to somebody else so they can do charity on your behalf" nor is it "paying taxes to fund social programs". Charity is you, directly, investing your resources in your community, with no expectation of return.
Today, this assumption no longer holds. The result is the current state of open source, which needs to figure out a license that extracts value from players big enough to pay it, without punishing upstarts into oblivion (and thus forming a protective moat for existing large players).
Some percentage of net revenue share strikes me as the right sort of license, with sensible caps and/or some sort of shared pooling mechanism.
https://en.wikipedia.org/wiki/Multi-licensing#Business_model...
Can you give some concrete examples? Because I can't tell what distinction you are trying to define, at all.
In which bucket would you put:
1) Giving money to a local hospital
2) Volunteering with a non-profit organization
3) Giving cash to a wandering schizophrenic
4) Buying lunch for someone who's been holding up a cardboard sign at an off-ramp
5) Giving money to the United Way through paycheck deductions.
6) Giving money to an organization that funds research into a disease
7) Giving money to a local organization that gives grants and loans to disadvantaged people to start small businesses.
8) *Lending* money to a local non-profit that gives loans to disadvantaged people to start small businesses.
9) Giving money to a local food bank.
10) Donating blood to the Red Cross
11) Giving money to the Red CrossLook at the shift in attitudes toward the environment in the last 100 years as an example. There was a point where executives thought it absolutely fine to pollute wildly. That consequences were for the little people. Through a mix of culture change and improved regulation, that has changed, and it continues to change.
A more recent example is the trend toward corporate social responsibility, which looks at a broad set of problems and devotes corporate resources toward fixing them: https://en.wikipedia.org/wiki/Corporate_social_responsibilit...
Do they put in enough money? Surely not. But it's indicative of the kind of culture shift we can push for here.
I think it’s a fairly large chunk of history (e.g. all the time humans were a thing) that this applies to. The fact that it weren’t executives but kings, queens and nobles thinking this way doesn’t really change much.
It’s not even necessarily malicious, but you really don’t want to think about the fact your life is so comfortable at the expense of other people.
Specifically, most rulers had some kind of patronage network where they gave out 'gifts' like land, or the right to collect taxes, in return for loyalty. Princes did not generally just sit on a huge pile of money, like a dragon. If they wanted to go to war or build a palace, they had raise taxes, which meant concessions to their power.
Anyway, slightly off-topic! Still, the analogy holds - you don't get to be a prince of the internet without the work of a lot of minor nobles.
Because when you look at actual history, you see long-running mutual relationships. E.g. the English Commons system: https://en.wikipedia.org/wiki/Common_land
Or you could look at the Mexican ejido system: https://en.wikipedia.org/wiki/Ejido
Which descends from the Aztec capulli system: https://en.wikipedia.org/wiki/Calpulli
Historically, leadership was tightly bound to productive land, because that's what everybody needed to survive. Your "nobles" could in the long term only be as successful as the people they ruled over, and the feedback loops there weren't long ones. Were there sometimes bad nobles and bad kings? Sure. But overall, the badness was limited because harming the "infrastructure" of the day, land and people, was felt quickly by people higher up the hierarchy. Sustainability was a must.
That's distinct from modern capitalism in the age of industry and information technology, because the portability of wealth and the long feedback loops mean executives can get quite rich in unsustainable situations. The elevation of an IGMFY ideology to become the dominant view of the moneyed was only recently possible because for most of history one couldn't escape the consequences like people can now.
"IDGAF, it's not me" and "ask for forgiveness, not permission" is not in any sense a minority viewpoint. Even people who insist they don't follow those creeds have the issue of being, more often than not, unreliable narrators of their own actions—not to mention: economically irrational in ways that extend to the economics of non-monetary, give-and-take systems.
> That isn't "the world". It's a relatively small set of people in a relatively small chunk of history that see themselves as entitled to make endless profit ...
Which is a claim that can't be proven either way since you are talking about how people in all of history was thinking. In other words, you are making a claim that is just wishful thinking.
You never need an excuse to ask, but neither side should feel compelled. The transaction is already complete.
Once you give something away, it doesn't matter if someone else gets rich off it. You gave it away. You're not, and shouldn't feel, entitled to anything.
If this bothers you, maybe you shouldn't have given it away for free?
> Anybody that says "nope, their money, they do what they want" is spouting the same flavor of dipshittery as "free speech only means the government can't censor, private companies are free to do what they want".
I don't know how to respond to this. This statement seems entirely paradoxical to me. Yes, it is their money, and they can do whatever they want. And also you accurately describe how free speech applies to private enterprises. Why are you so bothered by this?
There is a question of morality, sure, but that's a fruitless conversation to have. It's one thing to wish the world were different, but another to be angry with people who live in this world. Does this make me a person who merely spouts dipshittery?
You seem to acknowledge that the world is a certain a way, but feel shocked to find, and subsequently rebel against the idea that yes, it is actually that way. I don't understand this at all.
I for one appreciate that this site and others are moderated and restrict and remove posts containing hate speech. I imagine that the majority of readers and contributors would agree with me.
> Americans used to understand this. Know why there are schools all over the country named after Andrew Carnegie?
Perhaps it's because I, and the rest of the world, are not American, but I can't say I've ever given a moment of thought to the names of schools in your country, or Carnegie for that matter.
Perhaps America's fetish for capitalism is at the root of these divides. If you want to get paid and work on open source software full time, I can't think of a better way than under some form of universal basic income, but your capitalist infatuations make that unlikely. Charity is not the solution.
oof, I know that feeling - that sadness that comes with the realization that the manufacturer could have saved you so much trouble but chose not to... which you then rewarded with free labor and promotion. I got it every time I disassembled binary blobs in order to get hardware to work with anything beyond Windows. For a long time there wasn't much of an alternative, but that isn't really the case anymore. Setting up a new openpower system was a very strange experience, reverse-engineering wasn't even an option - the manufacturer provided schematics for the board and a wiki directing you to the source code for every bit of firmware (including the ring -3 processor).
I don't regret trying it once. It's possible, after all, that the manufacturer would have said, "Look, there's demand for an open protocol, just like some engineers have been saying. Let's take on that work ourselves." And honestly, they could have gotten away with some very modest support of the project: occasional discussions with engineers and enough free hardware that we could test new builds. But no shits were given on their part, so I also don't regret shutting the project down.
I'm glad to hear things are getting better in some spaces. Let's hope it keeps going that way!
I should've been paying my mother market rates. After all, she and my father have been running at a loss for this whole "family" enterprise.
IMO, open source is (or should be seen as) more of a "friends and family doing favours for each other" kind of human activity. Some people do it for the sheer joy of it, share without expectation of more than a "thank you" (at max), and calling their work valueless is just crass marketism.
> If you actually spend your life only doing things you are paid in cash ... > And in fact I can help you out by reminding you ...
Hahaha I love it when people get all passive aggressive :) It should be obvious to you that the fact that I am writing this, without getting paid for it, show that I don't spend my life only doing things I am paid for. You might want to look into the Econ idea of Utility Value. It has nothing to do with $.
This is the same as the poor log4j devs, getting bashed and still trying their best effort to please everybody.
Lost and lots of open source authors release some work to the open, and then start to worry about everybody's opinions and complaints. But that's a very unhealthy thing to do, IMO.
In essence, this is your own garage project and you've taken it out to the street for people to enjoy or admire. You should care about people's complaints as many f*cks as stacks of money they are putting on your table. Anything else, will end up deteriorating your mental health, one way or the other.
That applies even to existing sponsorships, however. Their existence thus points at more than cold-blooded short-term business interests being at play here. While corporations are in theory seeking only shareholder value, corporations happen to be (made up of) people, who are capable of altruism, and should be encouraged to use it. Just because US capitalism has managed to build a not-entirely-failing system on unadulterated selfishness does not turn that mindset into a virtue, or even reality: as far as I can tell, the dominant reason for sponsorship is that some person with a bit of authority likes the idea.
They may consider it good for marketing, or recruitment, or to secure their supply chain, or just morally called for, or they want to be the fat cat at this years TINYTEC-CON. If you asked them, they’ll give you a reason that totally makes sense for a business and has little to do with reality. And, no, nobody ever got sued or fired for these decisions. So go ahead, do it! You got all the left-padding you needed, it’s right to pad their wallet in return.
(recycled from earlier comment on the topic)
Just look into the amount of simple "wage theft" (employers forcing employees to work off the clock, etc.) that exists in the USA.
Of course, this country fought a war over the issue of free labor from black slaves.
All is good and dandy.
If employees are not getting paid, they'll go and do something else (like another job or growing food themselves) or steal and starve if there are no jobs or resources. They would never work for free because they can't live without eating.
Except, slavery. Sure, the master pays as little as they can to keep the person alive, but staying alive is about the only good thing they get out of life.
No they don’t. That’s why they keep plowing billions into cloud infra and gazillion of saas products. They have an excuse when they think they can get it for free anyway like is the case with OSS but not an actual reason
In a way, you should evaluate each OSS tool/library as if it was a business which further corroborates the blog post's point.
No one makes coach tickets available for free and then asks people to pay after the fact. Certainly no one would do that and then complain that the system is broken because nobody is paying. People, on the whole, do not behave in a way that's compatible with that kind of thing, and the expected outcome there matches the outcome that we see today with (un)-sustainable open source.
Sometimes they could keep hiring for cheap a provider for one of their core needs, but choose to pay much more to have an exclusive contract and guarantee the provider doesn’t get scooped or goes under.
There can be any rationale applied to paying more money than the minimum they could get away with.
Yes, I think this might be a better model, indeed.
But I did not start either of those projects, I came on board later; and those models are difficult to back-fit into an existing project.
If the project improves by making a difficult change then that is still your choice to make. Sure some people will complain, but there is always someone that complains when things change.
Offer your FOSS project with the meanest anti-corporation license you can find (AGPL?) which is not going to bother your user base but it is going to be a major hurdle for any corporation and then offer the software with a corporate friendly license for 100.000 / year.
Wouldn't this work?
Curious if anyone knows.
Open Source is just naïve charity, much like the UK Govt exploited the charity of the public by helping along a Weekly 8pm clap for NHS workers on a Thursday night during Covid Lockdowns. A weekly clap aint going to pay the bills and the rich will say anything to get out of handing over money. Hard lesson but its the truth, they would spend on PR Image control than pay bills IMO.
So sorry, Open Source is something people can practice on and not get paid for except in a consulting role at best.
There is nothing to police. You making changes and not releasing them is perfectly within your rights. You can even distribute binaries with your changes legally.
> So sure whilst the statement is true that Open Source runs most of the internet, the companies using it like Facebook or Google are not under any legal obligation to submit any changes back to the public domain for the greater good under some of those contracts.
That depends. Both named companies have a global ban for anything using the AGPL license family. Except from that, you might be right that they aren't obligated to distribute their changes. You might find, however, that they do so anyways. It's much easier to merge your changes upstream than to maintain an internal fork indefinetly. And by merging the changes upstream everyone else profits.
You seem to have a very warped view of what open source software and free software is about, and what rights the users may have or not have.
Just looking at paid out Bug Bounties gives you an idea of how hard it is to get appropriate levels of remuneration as a vendors own bug bounty is outbid.
https://www.theregister.com/2016/08/11/exodus_intelligence_5...
So whilst the call to arms to get paid for OSS submissions is noble, its still a flawed business model for most "professional" maintainers. I know there is a culture at Uni's to maintain OSS but they dont have the experience which we see in the quality of the code output.
For example, if a company uses ffmpeg on their products and product generates a yearly revenue of 1m then they will pay you 1k.
Current open source agreements do nothing to help smaller companies or the maintainers and honestly I find it stupid and destructive.
Charge larger companies more depending on their revenue and let small size companies with less revenue basically use it for free. Isn’t this more ethical than letting FAANG use these software for free?
So many commercial platforms rely not just on ffmpeg and vlc but also on nginx, php, python, nodejs, linux, mariadb, and everything else you can imagine. We also pay for some very niche things that are simply not available from the open source community.
If my company was liable to have to pay out for each one of these projects we would be bled dry and our business would no longer be profitable. A bunch of people would also lose their jobs in the process.
At my company we have revenue sharing so the idea of having to cut out a piece of the pie for an open source project would not be popular among staff. Most of them aren't even in tech.
Unfortunately, building a business on a limited resource that is -currently- "free," is not a particularly wise decision.
VideoLAN and ffmpeg are amazing tools, but a lot of folks have made a lot of money on wrappers (some of which, are eye-wateringly expensive). I'd be unsurprised to find a number of license violations in some of these wrappers.
History is filled with examples of people making money on resources that are not sustainable. These folks make a lot of money, until they wipe out the resources.
OS is a limited resource.
But that's not how people use them- people commit to a solution not only because it works today but also because they are likely going to keep using it for the foreseeable future. It's the maintenance that is the costly part. Maintaining a library is a lot more involved than producing it and then vanishing w/o a trace.
Ultimately somebody publishing and maintaining a good library is a positive externality for society. It's like giving kids a good education- it helps everyone. So big corporations relying upon open source w/o putting their money up to help allow the actual 'boots on the ground,' so to speak, get the job done, is kind of like getting a good free education as a kid, making a ton of money as a grownup, and refusing to pay teachers along the way.
At some point you have to recognize that a lot of our society operates on the expectation that people will behave in accordance with norms so that we don't have to bake every single thing down into extreme rules and have them enforced by armed goons. You're certainly free to ignore norms and do whatever benefits you the most at expense of others, but if other people did that to you constantly you'd probably end up pretty grumpy. There are lots of ways you can inconvenience someone without breaking the law.
Personally, I gave away a very useful free software package for ~4 years that I maintained solo, and multiple corporations repackaged it to sell to people without ever contributing fixes. Then when I stopped maintaining it for free, they all sent me emails offering to sponsor it (at pathetic rates). Seems like my free labor was worth something after all!
Instead you brought your big dish to a food stall on a street corner that has the sign "FREE FOOD" in large font. Folks of all backgrounds, shapes and sizes show up and soon your food is gone.
If after that, instead of feeling warm and fuzzy that you did the world a solid, you wonder if any of those patrons were wealthy and could afford to pay for what you gave away for free, then maybe next time you should put a price tag on it.
The problem happens when you want to maintain your version with the current version (for security / features) or push those local changes to the project so you can stop maintaining. At that point you have to assign local resources or hope your patches are accepted which takes usually requires a relationship.
As a small business owner I understand this perspective, but if you expand it out it becomes transparently exploitative. "If my company was liable to pay for employees' health insurance, we would be bled dry and our business would no longer be profitable." I pay 25-35% of my income every year via taxes, if I didn't have to do that my profit margins would increase. It's not hard to find someone who claims they're being "bled dry" by taxes. Egress and ingress bandwidth is expensive, imagine if you didn't have to pay for it? Companies like Walmart are able to offer low prices in part because taxpayers fund them by providing food stamps and welfare to their employees.
At the end of the day the stuff you rely on costs SOMEONE money, if you're not paying for it, someone else is paying for it with their time and possibly money. If you can't do business profitably after paying for the stuff you use, your business is already insolvent and someone else is funding it for you.
To put that another way, your profit is derived entirely from arbitraging the value of open source software for your customers. If you were actually paying what the software is worth to you there'd be no money left. Effectively, you are taking some of the value of the work done by open source developers and keeping it for yourself rather than passing it on (that's not a criticism btw, it's how practically every "supplying goods" type business works.)
That's very unfortunate. You're not really creating much value, so I imagine your business is too small for anyone to worry about. In the case of something like YouTube that clearly that isn't the case though; they create far more value from the open source software they use. YouTube absolutely could afford to pay a fair fee for what they use. If nothing else, it protects YouTube from a problem like the log4j issue this conversation has arisen from.
Plus some folks are tweaking and fine tuning it from time to time to be compatible with road 5.2 and with axle 3.1 and so on.
GitLab uses a delayed release (open core). Paying customers get the features first and months/years later they get into the free tier.
When your software is used by billions (1e9), a adequate/fair share may be around 0.00001% (1e-7) with huge variability, but try paying 2c for your favorite logging library, 3c for gcc, 1c for task manager, 0.1c for a tool you never heard of ...
The way this industry has evolved is a complete dumpster fire, where the dudes that glue the pieces together are paid 10X the value the dudes that actually built the hard part!
I won't give names, but some very large cloud providers and some very large chips vendors.
No invoicing, no approvals, it runs, you get paid in fairly direct proportion to the actual run time. This might actually be a real use-case, not that I think about it (of course, then there will be a war to strip it out, violating the license, etc.)
Do you have reps that can wine and dine high level people? From my observation this is where the money is.
It’s not as if altruistic motives, are what drives big corp.
Open source often originates in big corp; k8s, Rust, and all the ML … none of them are exactly wart free or blowing minds as promised. Just the next evolution of a big corp financed mess from the 90s.
The response to big corp complaints is they get what they pay for. And since austerity for the masses, all your agency are belong to us, fuck big corp
Many open-source project maintainers wouldn't go to the length of setting up companies like you've done, The paper work and compliance don't cut slack for building an open-source product.
Perhaps there's a need-gap for services which maintain those for open-source projects and acts as a middle-men between the maintainers and the Account Payable of companies?
I see an opportunity to create a "create-a-company"-as-a-service, to help tons of other maintainers to do this with ease.
Two examples, off the top of my head:
1) Here's how Open Collective looks, for jMonkeyEngine (a lovely Java game engine that's also a bit underfunded and underutilized): https://opencollective.com/jmonkeyengine
2) Also, here's the Patreon of Godot (a more hyped and better funded engine): https://www.patreon.com/godotengine
Why would large enterprises not just use a tool like that, if they already use the likes of AWS or other IaaS/PaaS/SaaS offerings?
But i definitely agree that a lot of open source is underfunded and as a consequence many can't work on it full time or even every day, because things are dire financially otherwise: https://staltz.com/software-below-the-poverty-line.html
Not everyone has cushy jobs that make them $100k a year, i make closer to $21k in Europe now, about which i wrote on my blog: https://blog.kronis.dev/articles/on-finances-and-savings
It feels to me that perhaps the solution here is to have something like a bot on GitHub/GitLab, that adds a comment to issues: "If you'd like to express to the maintainers how important this issue is and draw more attention to it, then submit a payment here: ... Payments so far: ... (possibly with messages by supporters)"
Most people don't care about Open Collective or GitHub Sponsors or whatever, they just want to make feature requests or bug reports. If their attention is captured and the ability to make their own request/report more visible is offered to them as a part of that process, maybe things would be a bit better? I've definitely heard the sentiment expressed that micropayments have the potential to improve how we interact with others on the web in some ways, i'm just not sure how viable that is.
> But! Maintainers need to be legible to the big company department that approves and processes those invoices. Think about it: no company pays their law firm on Patreon. You'd be amazed how much harder it is to explain "what the fuck is an open collective?" for a $10k donation, compared to paying a $100k invoice to an LLC that filed a W-9 or W-8BEN and takes payment through ACH. The trick is that you can easily incorporate a pass-through US LLC and open a business account for it even if you're not a US citizen, it's not rocket science.
And yet, these companies basically pay monthly to AWS, which isn't all that different on a conceptual level. Needing a LLC just to receive donations of any sort is ridiculous, why can't these companies just be more humane, instead of drown the idea of doing anything good into needless bureaucracy?
It's like a scene out of Brazil: https://en.wikipedia.org/wiki/Brazil_(1985_film)
The mission of Open Collective is clear even on the main page: https://opencollective.com/
A lot of companies have a lot more controls on purchasing than they do on employee salaries. So a manager who has ten $100k developers reporting to them might only have $10k they can spend at their own discretion.
And the unix philosophy of having many small tools and libraries means practically nobody is _just_ using one open source product. So even if you can get your bill to someone with a million dollars to spend, if they have to share it between 1000 open source projects it's not going to go very far.
That's what FOSS should mean anyway. The old definition can be renamed into exploitationware.
I guess we can discuss what should be, but AFAICT it's just not FOSS according to the OSI or the FSF.
It's a grand idea, and I hope it works. The path to not working is too achingly obvious though. Budgets are always tight (even if you're Apple and you have to artificially make money feel tight). What corp officer with budgetary discretion is going to greenlight a 5-6 figure payment to someone who's not doing work directly for the company? I think the key here is that that person is going to have to a) be principled, and b) smart about selling it, by emphasizing the fact that the changes were beneficial to our company, and leave out the fact that those changes were beneficial to every company. It wouldn't hurt if BigCorp got a measurable recruitment bump from it, too.
* In really big companies it's possible for admins to buy routine stuff below a threshold just to save on paperwork. So there's a scam in which someone sends out a bunch of $100 invoices for "printer paper" -- account payable assumes the department code was left off by the vendor but it seems legit so they pay it. Seems like a hard way to collect money.
In terms HN would understand, it's a stateful firewall for invoices that prevents paying orders that didn't originate from your company.
We all opted for centralized package repos though, so now only they know. And they’re not telling us.
Just another “free” opportunity lost to centralization, I guess.
I'm sympathetic to the view, but there really are some things that are better centralizing. Reducing code into binaries is something that a "fair" 3rd party is going to be better at than the 1st party. Why? The 3rd party central source is (presumably) mechanically cloning and building, whereas the 1st party is doing much much more. Effectively the 3rd party offers a better guarantee to the end user that this binary corresponds to that particular source.
Also, the Way to measure who's using your code is to put runtime telemetry in there. Distasteful, but so common now with every kind of software, it's crazy. Yes, even OSS CLI programs phone home now (heck, ohmyzsh phones home every time I open a terminal!). For a generic server library, you'd add a check to make sure it's the most recent version and print that out to stdout on startup.
See, it's not user hostile it's to keep them informed of updates! /s
are you talking about the update check that by default runs once every 14 days[1], or is there something else?
obviously these tools amplify their user's productivity. corps are organized to be economically productive, hence they benefit enormously from free power tools.
hobbists benefit too, but since their productivity is low they benefit relatively little in terms of economic surplus.
(sure, I might do my taxes using free software, but my taxes are also trivial, two lines and that's it. sure, I might whip up a blog/website using free software to share stuff with people, but again it's economic productivity is already zero, it doesn't matter if now it's a technologically amazing site.
and sure, I work as a freelancer using these free tools, but again my productivity is very limited compared to, relative to the systems I work on for corps.)
the solution is probably a mix of a bit of wealth tax and consumption taxes.
Do you know which organizations these are?
No idea whether it would help but clearly staying exactly
> I've maintained for over 10 years. I don't recall ever receiving a donation. I am still maintaining it, but I just don't have time to add the improvements that it needs to keep up with the ecosystem (asyncio, for example). If organizations who use it got together and chipped in some non-negligible amount, I would be much more serious about keeping up with it, but $0, or $5-20/month, is just not realistic incentive to compete with other priorities in my life.
may be a good idea.
Even if that would not help this project then making people aware about problem in general would help.
I would be pretty skeptical of projects that try to keep up with the ecosystem, if they are adding things just to keep up (rather than because they need them). The fundamental advantage of Free Software is that the people writing it are doing the ultimate dogfooding. A Free Software project that is adding functionality they don't need is no better than a company in terms of knowing what "customers" want or how to evaluate whether they did it right.
(Usual disclaimer, n=1, etc)
Now the best way to get a job is leet code, leet code, and more leet code. Rather than spending <5 hours a week working with real code and producing real value on open source projects - most career minded engineers will simply focus on leetcode.
Not many people patch esoteric software that's been around for 10+ years because it's particularly fun or because there is specific business value in it.
Maybe more broadly: The only way to prove that you're good at X, is to do X well. An artist is only as good as his portfolio. The same is true for all creative jobs.
I'm thinking that these proxies (see all attempts at standardised testing) are a disease of our time.
I have seen first hand developer that are just okay or below average successfully deliver on open source, because you have infinite time, no constraints, no stress and get to choose exactly what you do or contribute. But in a work environment they struggle, given ambiguous problems they struggle, given time constraints they struggle, given changing needs and demands they struggle, working within a team they struggle, given something outside their area of knowledge they struggle, etc.
Moreover, with industry moving towards agile, having project and developing in a company are massively different kind of work.
Mediocre candidates getting leetcoded by mediocre companies may be a highly visible pattern but on industry scale I am not convinced it is the dominant mode.
Not only does it feel like I'm stolen value, open source work tends to be the most interesting, and as more and more is done and offered for free, my work becomes less and less interesting, and the job becomes more about connecting and configuring all these open source systems together.
Needing to contribute free work in open source before getting a job therefore sounds like the biggest of scams to me.
But overall I'm not in disagreement with you, you could say open source is done as part of the greater good and advancement of technology and computer science, and not for personal capital gain. That also means that it isn't meant to be a sustainable career path, or job that you can do full time though.
We benefit far more than we can ever repay.
As a user I agree, things would probably be more expensive if nothing was open source. But as a developer, I disagree, my employer would simply need to pay for the stuff I use, or they'd pay me or another developer to build them one. And this is precisely what the article argues, that companies should pay for it. If there wasn't any open source logging library, the maintainer could either work for a company that offers a paid one, start his own company, or work for a company that pays him to maintain one for them.
Good point, but you would have a much smaller industry and platform without FOSS, and there is no way you could build all the libraries, tools, etc., yourself. Even FAANG depends on FOSS. If everything had to be paid for and professionally developed, licensed, etc., there would be much less around, and nobody could fork and innovate - there's a reason people develop and use FOSS.
Lowering the barrier to entry by being able to leverage a lot of free stuff probably helps make the industry bigger in having more startups, but I also can't say for sure there wouldn't be more jobs or higher paid jobs otherwise.
In the end, I'm not trying to push to end FOSS, but I'm trying to bring to front the contradiction I'm seeing of people wanting FOSS but also wanting FOSS developers paid a full wage. It seems fundamentally at odds, if you want people working on logging libraries to be paid full wages, stop making FOSS logging libraries.
Yes, valid and important point. We could look at how other industries develop. Software + Internet is especially condusive to 'free' products. Other industries must at least share knowledge, which arguably is embedded in FOSS software.
> I'm seeing of people wanting FOSS but also wanting FOSS developers paid a full wage. It seems fundamentally at odds, if you want people working on logging libraries to be paid full wages, stop making FOSS logging libraries.
An inarguable logic ...
On the other hand, from the viewpoint of all of humanity, it is great that there exists a huge amount of software that is useable by everyone for free.
Yes, having open source competition means you'll have to either build a superior product that customers are willing to pay for, or find another niche. That's a good thing.
Good has many dimensions. I'm saying that as a developer, FOSS means people don't need to pay you to build those things, only to use them, and that's why FOSS developers themselves don't get properly compensated, because they chose to build it for free.
You could say FOSS is a good thing if you talked about computing progress, or barrier of entry for a startup wanting to build an app, or as a great source of example to learn from, etc.
As for your comparison, I don't think it holds, because very rarely are FOSS contributors hobbyists, most of them are professionals. So it is much more akin to a professional window engineer giving away free schematics for unbreakable windows, which means that companies manufacturing unbreakable windows no longer need to pay a professional window engineer to make schematics for them.
Of course, the smart glazier would figure out that giving away the schematics for a window-breaking device is in their interest.
Commoditize your complements, as the saying goes.
Too much of what we do, from education (standardized tests) to banning of users in places like YouTube, is centered on efficiency or administration. Aim for the center of the bell curve, ignore the collateral damage and reach those target metrics, as the mantra goes.
It'll get much worse before it gets better, if it ever does.
It's fair to describe software engineers as a profession of the professionally lazy. "This takes too long to do, therefore I code."
I think it's better to reinterpret the problem based on what Leetcode does well, and try to invent something that does it better.
The old world of make some giant Github project a company might appreciate, or might ignore entirely, holds little attraction to me at this point.
If by harder, you mean sitting down and having a real conversation, then yes, I suppose it's harder.
Edit: Value is a poor word here, now that I think about it. Let's say mostly pointless activities that generally don't apply to work they'll be doing with that skill. It's like playing baseball to practice for tennis.
The only reason why OSS has seen the up-pick it has is because major companies profit from it. Microsoft didn’t embrace open source because it had a change or morals, it embraced open source because it started making so much more money from enterprise orgs switching to Azure compared to selling us licenses for on-prem alternatives. Facebook and Google don’t share their massive front end-libraries and extensive tools because they are nice, they do so because it helps them dictate web-development and being able to on-board new hires who are already familiar with their tech.
If anything, I think it’s more likely that we are going to see a big player pick up a NPM alternative and make sharing packages much harder. I think the fact that no one has done this, should tell you all about how little the enterprise industry worries about the status que.
I don’t think it’s necessarily healthy, and I sympathise with OSS maintainers who don’t get paid for their work, but I don’t think it’s a massive issue either. The OSS world is still better than it ever was, and your tech stack isn’t actually in danger if you review that code you use.
In-house development, software BOMs, rising of standards and multiple rounds of code review are the processes that the industry is shifting towards and for good reason.
I haven't done a lot of consulting lately, so I haven't seen much in-house code in the last few years. But my experience is that the average in-house codebase is worse. And that makes sense from the incentives. Open-source projects that want more than one contributor need to be approachable enough that people join in. Whereas with most in-house code, people commit to working on it without ever seeing it. Switching to work on another open-source project is easy; switching to another job is hard. Open-source authors get to decide when to release; in-house code is generally driven by execs. And so on.
In fact one can safely say that top companies that attract top talent also have methodologies in place that lead to better than average code quality.
Most in-house code is crap.
"Works good enough" is how our world generally operates unless under strict regulatory guidelines.
... keeps resulting in shit code, too! There's no evidence standards of quality are rising. In my own extremely limited view of in-house software -- i.e. my own professional experience -- code quality is crap, standard quality practices are very low and actually worse than in FOSS projects (I've seen someone mention more than once that "this crap PR simply wouldn't fly if this were an open source project, it's so bad nobody would want to review it!"), absolutely dumb bugs keep hitting production, and people think of automated testing as "that thing we don't want to do".
In-house code is just code you don't know is garbage because you cannot look at the code.
Companies genuinely don’t care about the software they use, as long as it works and isn’t hacked. This is especially true in non-tech enterprise.
At my former place they still had hundreds of ASP Webforms with custom in-house ASP libraries that were utter shit, but they worked.
Companies genuinely don’t care about the software they use, as long as it works and isn’t hacked. This is especially true in non-tech enterprise. At my former place they still had hundreds of ASP Webforms with custom in-house ASP libraries that were utter shit, but they worked.
What I’m postulating is that this is the alternative to the current status que.
I’d personally love for NPM to review their packages, or for a big player like Microsoft to step in and make a more limited platform with reviews, but I just don’t think anyone is going to be willing to pay for it.
But the same is true of open source. I thought you wanted non-shit software.
In-house software is easily exploitable and full of security bugs as well.
I work in non tech enterprise. You’d think that things like the ransomware scandals, GDPR, the increased risk-awareness would have improved the business processes or management awareness or all the things are “corporate digital maturity” but the pressure to get things done fast with minimal resources has frankly never been higher.
In that environment we’re always going to have shit-software. If anything I agree with you, which is why I said that I thought that the current status quo was the best ever.
Where the GNU project always fell short in my opinion was that it thought there was a difference between free to use and free as in beer.
There was an abundance of people who predicted where the internet would head once big corporations got into it. There is an entire genre of cyberpunk authors who did after all, and I guess Stallman gets credit for trying to stop it, but it always comes down to money.
It’s very easy to fool yourself into thinking differently, but the harsh truth is that everything you do for money is being weighed and evaluated by someone in the management chain whom, at the very least, considers if you’re worth your cost, every three months.
I just don’t see how OSS is supposed to have changed in that regard. Maybe it was more ideological when it was mainly paid for by academia, but someone still paid for it, and considering how much OSS has improved in the wake of corporate capitalism taking over, academia don’t appear to have paid enough.
That’s easy for me to say of course, I have no solutions, but I still think we’re better off now than ever.
Tell that to everyone who depended on Log4j for the past 8 years!
it's a good thing even if MS benefits more than others. it's not a zero sum game.
the problem is on the other end, where the produced economic surplus is distributed to a very few.
Maybe there is nothing wrong with the "status quo", maybe we don't need yet another attempt to finance small FOSS projects where it's hard to explain how money will actually solve any of these issues.
Maybe people just need to be more considerate of what they depend upon. And in the case that a popular yet well maintained project has a CVE on day, maybe we need to accept that popularity does not make them invulnerable to bugs, all software has bugs.
</ unpopular realists opinion>
The reason is that the whole JNDI string interpolation feature by itself opens a door to a whole world of layered complexity which you can't comprehend. And even if you could comprehend it all Java could add some feature to JNDI which introduces an issue which wasn't there when it was all tested.
Anyone who knows anything about JNDI would've immediately recognized that this was an incredibly bad idea, as JNDI attacks are well known around black-hat circles (LDAP is just one of the things you can do once you have JNDI available).
Yet, here we are, several years later, acting surprised this thing existed and thinking that tests would've helped!? What kind of tests, exactly?!!? I think I am to blame myself, as many other Java developers who actually use log4j, has a good understanding of how it works, knows JNDI and LDAP, yet never connected the dots and noticed what this incredibly stupid feature was making possible.
It's not completely novel, projects such as openssl and sqlite do offer paid consulting, but it's not normalized among companies to pay for doing so. If Filippo can normalize having OSS be treated as paid consulting engagements I think that would be wonderful for the community.
Adding features do not reduce likelihood of bugs, if anything the opposite.
It's very difficult to come up with a paid model that specifically encourages a preventative strategy towards bugs and security flaws. Currently the best we have is getting people who care about those things to build software.
Then, maybe a year later, that feature is no longer the hot new thing and it becomes abandonware inside the application. If you're app isn't cloud based you have no idea if you can rip the feature out or not as you have no idea how many people, if anyone still uses it.
What's needed is for open source libraries to somehow get "rated" by security experts before they get used by businesses. If those businesses using it paid for that, and then paid someone to fix any issues found, then I think we would have a working solution. Just paying for features would just make things worse... have you ever seen companies paying for security features, though?? No, I haven't at least... they pay for business features that will make them money, they hope, security is kind of just implied (and they might lay the blame entirely on the developer if they actually had a business relationship with them - which may be a big nightmare, actually, for OSS developers - and I am one of them myself... you can no longer use a license that just says you're not liable to anything bad that happens).
I have an analytics package which is apparently being evaluated by the military of a large country. Even if secure code, now the maintainers themselves are under attack.
For I am definitely a weaker link than a soldier or agent or gov department. Did not expect such usage when creating this project. If said government had seen how this was developed and tested, they would probably physically destroy the machines it is installed on.
I refuse all donations/tips for three reasons:
- as per above, your donation is generally insignificant. it's just overhead in tax accounting
- people donate "with strings attached": AKA "here's $2, but I'd really love this feature"
- receiving donations wouldn't be fair to any current or past contributors that made the projects what it is
The last point is especially true in the OSS landscape. The most front-facing programs get the donations, but the low-level libraries and infrastructure that make them possible get nothing. Heck, I've seen forks with a few superficial tweaks receiving donations and reaping the benefits while the original projects is chugging along slowly at the hard-to-build infrastructure that nobody else wants to do.
Bug bounty sites fall almost universally in the last category in my eyes.
Hard disagree on that. Maintaining (bug triage, pull requests review, bug fixes…) is actually the hard work and the part that deserve the reward IMO.
When I contribute to an open source software to fix a bug/add a feature, my reward is that the software I use has an annoying bug gone/the feature I want. I don’t need any reward. On the other hand, the thankless maintainer deserve it.
In terms of fairness to past contributors, I put the sponsorship on my personal GitHub account and not on the repo for the project I maintain.
Don't really want a commercialization of OSS maintainers. Does not seem in the spirit of OSS, but a convoluted way to contract a single dev to work on your stack. If you are this big company, ping your developer advocate, set aside a budget, and have them go through your dependancies and reward accordingly.
What bothers me way more, is when companies take OSS and then do not adhere to the license. Not as in forgetting to attribute you, but publishing a patent based on your code and approaches. That's easy enough to kill your motivation if you are doing it for free in the first place.
If money becomes an incentive for OSS maintainers, then they will start replying to the emails they constantly get, to buy their extension or use their CDN. Your company bet the house on a poor Polish CS student for logging or useragent parsing? Your, and only your, problem. OSS keeps on working.
I'm starting to do something different at my company. I'm finding the package maintainers for the non-commercial stuff we use in our product and making a donation. I'm also going to start asking the maintainers to invoice my company for support where that is possible to do.
Seems doable, but still hard without centralized control and PR.
Risk is on your end, so you pay for it. A 10k contract becomes a 12k contract. You clarify your risks, your mitigation method (NDA), and that the extra money is for the legal liability the consultant takes on.
Maintaining business relationships with $megacorp is one of the primary reasons OSS maintainers (maybe just speaking for myself, but I don't think so) do their OSS work, and don't develop proprietary software and market and sell it around a business venture.
If you start writing up contracts or accepting direct payments with any strings attached at all, the dynamic is completely changed.
Should OSS devs optimize for my (probably quite rare) use case? Probably not, but the feeling when making a patch for something that I like is still different when the maintainer runs it as a business compared to when they run it as a hobby.
(This is what the whole discussion seems to be about btw. Some people like to program in their free time as a hobby and other people would REALLY like guarantees about the software that cannot be made without losing the essential hobby-ness of it)
This can lead to corporate capture. We see this in some projects already.
Could you share some examples that weren't corporate projects to begin with?
The first 1/2 already exists. It's the companies which need to change.
I say this from experience. I'm self-employed, with my own company. For the first 15 years my plan was to provide commercial support for open source packages I worked on. I had an LLC, an accountant, I paid a designer for a logo, etc.
I co-founded the Biopython project and offered commercial support for it, with a couple of other Biopython developers under NDA so we could work on commercial projects that used Biopython.
Any interest? No.
I started an open source package for high-performance molecular similarity search. This got some funding, mostly from personal contacts at companies which wanted new features. And people used it.
In fact, at one conference a speaker gave a talk based in part on the results of my software. He commented correctly that it's very hard for a company to spend money on software they get for free.
I commented, correctly IMO, that I offered support contracts, and support is easy to justify to management if they really cared.
(Over the course of the conference, I learned what they liked best of "free software" was it is 1) available for no cost, and 2) doesn't come with string attached - they didn't want to care about upstream.)
My story isn't unique. I'm not the only one to try the "sophisticated counterparty" route. LLCs are cheap.
The real onus is on the big companies. And since that's not going to happen, I now offer proprietary licensing for my once FOSS-only software.
To my understanding, most people who want to get paid a reasonable amount to develop FOSS go one of two routes.
1) Service-oriented, à la the Cygnus Solutions (now Red Hat) approach. FOSS developers get paid to fix bugs, add features, answer questions, and provide training. This has been my approach.
2) Employer cost savings. Work as an employee for a company which saves money by developing software, but where the employer is not interested in bringing it to market.
See the section "Professionalizing the role of maintainer" of the linked-to essay for other examples of what a company might get through funding a FOSS project. ("security practices, like two-factor authentication and mandatory code review", etc.)
None of this is "work with a price tag of $0", and the very essay we're talking about gives counter-examples to your interpretation.
Furthermore, I tried selling FOSS software for a fee ($30K, not $0), and simple commercial licensing doesn't work either. Commercial proprietary licensing addressed certain economic problems that commercial FOSS licensing didn't resolve.
Moreover, the linked-to essay even called out services which companies COULD pay for.
But there are some things like Kafka, PostgressSQL, Spring Boot, Tomcat, Apache Math, ZooKeeper, the OpenJDK, and all that which are definitely non-trivial and a huge amount of time and effort, and you couldn't just take an extra month or two and have a dev on your team implement a replacement, unlike log4j and ua-parser.
I think those would be better example to discuss, and my impression has been that those things often have a company behind them offering support or offering them as a service that in some ways pays for some real devs to contribute to them, but maybe I'm mistaken.
Like for example, the author mentions working on the GO team at Google, and Go I would consider one of those big open source projects that truly are foundational and would be non-trivial and huge effort to replace. So that shows that the really big pieces do have companies hired and paid staff behind them.
Did you consider the fact that half of your examples of worthy things are using the unworthy log4j?
This is how the value is measured.
But if you take a much harder task, like building a performant and safe JIT language runtime like the OpenJDK, you'll see that even in the open source model, people can't actually deliver it effectively for free. It often starts out from a company that later open sourced it, or it's backed by academia, and contributions require deep expertise, so sometimes companies had to have their own staff contribute to it on their own payroll.
Log4j is a good example, anyway. It's an old library, very old. And a lot of other software depends on it. So the effort of replacing log4j is not proportional to it's feature list, but rather to the feature list times the number of projects already depending on it. (The replacement exists, btw, called slf4j, usually with logback, written by the same author as log4j.)
Java Logging is a subject in itself (I won't say "interesting subject" although it is interesting, in the same disturbing way the lifecycle of a tapeworm is interesting.) but I would argue that these logging libraries are old and have evolved over time in ways that are hard to anticipate or recreate. (Rewriting things also leads you to the xkcd "standard proliferation problem" - https://xkcd.com/927/)
The real problem is that it takes time, like real calendar time, to understand an implementation fully enough to fix it, and no-one wants to do that, because it's a job as critical as it is thankless.
Building a business on a stack of other people’s hobbies isn’t sustainable. I mean, just tell that to anybody outside of tech and watch their reaction.
I can't imagine it would be as clear cut for a "library", but it can be done...
#2 was the big sticking point. RedHat made a lot of money accepting that legal responsibility, but very few others were willing to do so. It made using software difficult (and a lot of us just ignored the policy).
But if you follow this advice, you may end up accepting legal responsibility for the software, and that may be bad.
I thought that was a joke. What did the warranty disclaimers say on your system?
I also don't think the problem it solves gives the greatest benefit for the amount of work required. I think making it easier for companies to pay open source contributors is the right approach. For any company that builds software, finding and paying the open source projects they use is a massive amount of work and there's nothing that helps with that. If there was much less friction to paying maintainers, more companies would do it.
I would love to see a tool that, given a pool of money, will collect dependencies from projects in any language (extensible), find the authors (git commit history, etc.), find where they accept contributions (extensible), and pay them, based on both computed and hand crafted weights.
Making it easier and making it a common habit. Companies need to realize, that paying maintainers/contributors pays off for them.
> I would love to see a tool that, given a pool of money, will collect dependencies from projects in any language (extensible), find the authors (git commit history, etc.), find where they accept contributions (extensible), and pay them, based on both computed and hand crafted weights.
Looking at https://flossbank.com/, this seems like just what you describe. I don't know how it works exactly, though.
Definitely agreed.
> Looking at https://flossbank.com/, this seems like just what you describe. I don't know how it works exactly, though.
That looks ... related, but I _detest_ that it relies on injecting ads into package managers. It's also not extensible.
I think an open source tool would be preferable so that incentives don't get skewed by for-profit motives.
I would also prefer if the payments didn't go through a single company. Paying developers through GitHub Sponsors, Patreon, Flattr, or whatever their preferred mechanism is.
The first release of DateTime was in 2003. In 2008, I added a "DONATIONS" section to the docs, and around that time I started adding it to everything I released. It was basically just a link to web page with a PayPal button it, so not very professional.
Over the years since I started doing this, I'd estimate I've gotten somewhere between $1,000 and $5,000 (PayPal doesn't offer historical data far enough back to know for sure). On the one hand, that's a lot of "free" money. OTOH, this is software that has been used by absolutely massive companies, including Amazon (which I know for a fact used a lot of Perl in the early days, including things I worked on). So even $5,000 is an incredibly small fraction of the value this software generated.
Almost all of these donations were $100 or less and seemed to come from individuals. I can only recall one instance where someone asked for an invoice first, after which their company donated $500 (or maybe 500 euros), which was nice.
So this is just another data point.
And then I realized that this link has been broken since some time in 2018. Doh!
I'm fixing it and adding a "email me for an invoice" bit as well. It can't hurt.
With that said, I could totally see how paid OSS work as the norm would be a catalyst to improving the status quo. It would certainly lead to more and better OSS projects. Even if the current OSS ecosystem doesn't like it, it will 100% lead to new projects and new devs pursuing the money.
Maybe part of the solution is to form agencies which work with OSS devs to pursue contracts/sponsorships/donations from commercial users of their projects? The legal/business/sales part of the process is non-trivial. This makes me think of "content creators" on social media that make a ton of money producing free videos/streams. OSS devs are maybe like the B2B version of that? :P
When I built it, it was great to learn about some interesting new tech, and scratch a personal itch. But by far the biggest reason I keep maintaining it is the community. Every once in a while (maybe once a month or so) someone randomly comes up to me (in person, or in a chat) and says thanks, and tells me about how this tool saves them a huge amount of time and makes their life so much easier.
Would I want to be paid by a company, in exchange for providing features and support to them? Fuck no. That would kill any joy I had in doing this. Why would I want to ruin the fun by having to adhere to a timeline set by some corporate project manager?
If a company wants to help, what I'd much prefer is that they help out with the boring stuff. Pay someone smart to triage bugs for me, provide first-line support, write user docs, all that stuff so I can focus on the fun parts.
My 2c are that the problem is there, not specifically to OSS. The whole industry is looking down on maintenance and maintainers.
Keeping things working might not be a great career, but it's equally important as creating new stuff, and guess what: some people don't want to create but like to debug and maintain.
A parallel might be drawn with the right to repair electronics. When we will get back the culture of repairing stuff, then we will value more the act of repairing. Because now, it's an art of repairing that very few afford.
This is easily solved with a universal basic income. Some of us would gladly forever maintain and contribute to free software if we had our basic needs guaranteed.
I certainly would
Open source has been incredibly sucessful using voluntarism.
We could also throw in political movements; the all-volunteer military, which has existed on and off since the American Revolution; science (the pay doesn't nearly match the efforts and value); non-profits; teaching (same as science); etc., etc. Why do people feel so motivated to sh-t on voluntarism, which has changed the world with great success. Almost every major advance in history has been accomplished by volunteers (depending on how you define it). Declaration of Independence, Newton, Van Gogh, World Wide Web, etc. etc. etc. ...
The people responsible for the logging library security are 100% the people who decided to integrate that piece, not some open source person who provides a patch and his three sponsors.
The Log4j library has a LICENSE.txt with clauses "7. Disclaimer of Warranty." and "8. Limitation of Liability."
The wake up call is that programmers should take responsibility for everything that they integrate, including all that they recursively integrate. If you put it in the image, it's your fault.
I imagine this could be a hard sell to people who just want to build some cool software and maintain it. Setting up an account, okay, that may be possible, but that's not the end of it. Companies pay invoices FOR something. That something means contracts, potentially about substantial sums, that means getting legal support to navigate said contracts & obligations.
An engineer with in Micronesia with specialized skillsets.
Try to convince these communities about the need for a well compensated team of people including product managers and designers all making 6-figures and honestly people just don’t believe you. The truth is that cost of living discussion doesn’t even matter, people should be compensated on the value they bring (and in those communities that is very easy to quantify.)
This has wildly slowed down many projects as UI and usability are completely neglected.
Its pretty much only been one year that an engineer in this space can reliably land compensation packages somewhat competitive to a tour in NAAAM
In what way is this not an ask?
To keep my sanity, I had to enforce strong boundaries: No, you are not a customer until you start paying me like a customer (lots of entitled users think they can have the same relationship with an open source developer as they do as a customer of a company). No, telling me how you’re an important person or part of an important organization doesn’t change my tune, unless you’re willing to show me the money. No, you do not have a better idea which features would make my open source project more popular than I do. No, I will not support you for free via email; if you want support, you either pay me or we do it on the public mailing list. No, that’s not a security bug; that’s a feature request, and, no, I will not implement it just because you want me to.
Because I have done all of this, I am able to continue to maintain my open source project today, because the boundaries I have set up are basic self-care: Trying to please every random entitled Internet user leads only to burn out and abandoned open source projects.
I see from your posting history that you’re pushing variations of this “they didn’t pay for this, so your time and effort is worthless” notion. I can’t be sure you’re not trolling; I will assume good faith and think you actually believe this ridiculous argument. Frankly, to pretend that free code with for pay support doesn’t exist comes off as entitled to me.
Let me explain to you how classic open source works.
The idea behind open source is this: The relationship between users and developers is different with an open source project. In return for getting code for free, instead of having the relationship a customer of proprietary software has, where the only way to implement a feature is to ask the original developer to implement it, we instead have a relationship where you can get any feature (or bugfix) you want, by simply providing a patch or pull request. The code is free, but the support is not free.
Linux is a classic case of this: Sure, you can get the kernel for free. Sure, you can download a distribution for free. But, as soon as you ask for support, the company tells you they will change you so much $$$ per networked computer to get service and support.
It works really great when a lot of developers and companies contribute patches and bug fixes for free, in exchange for getting the software for free. It works not so great when entitled users think they have a customer to company relationship with open source software.
Hence, the hard boundaries, and the resetting of expectations. I used to have a “I don’t support my open source project for free in private email any more, and if you reply to this demanding support, I will make this email exchange public on the mailing list” canned reply. I only had to make the exchange public once over a decade ago; most people got the message. I even occasionally had someone throw me a few bucks.
My project? I still maintain it, because my boundaries keep me sane. I’ve only have had one rude entitled user whose bug report I had to delete from GitHub in the last decade; since then I just lock the conversation after giving them the “no, I don’t support that” spiel.
OK and I will assume you are not trolling and that your explanations of things I already understand was done with good intentions and not being condescending.
You clearly don't understand my argument and are offering a straw man interpretation. So in the spirit of explaining things, let me try again. It is a simple argument and shouldn't be hard to understand:
If you give away your work for $0 and demand nothing in return (no $ service contract, no $ licensing fee, no $ monthly maintenance contract) then the result will be $0 for you.
It is a really simple argument. A 5 year old will probably get this. But for some reason a number of FOSS commentators don't get this very simple point. They give away everything for $0 and then get upset, throw their toys around and refuse to play with the other kids, when companies then pay them exactly what they asked for and nothing else.
And since you made an effort to explain to me how open source works (clearly me reading The Cathedral and the Bazaar twice and various other Open Source books doesn't qualify) I will now explain to you how markets work:
Things don't inherently have value. You might have spent 30 years slaving away on your precious code, while thinking pure thoughts of enlightenment every single key press, sacrificed your family in the name of the deity of FOSS, but do you know what? Nobody cares. The value of something is what people are willing to pay for it. That's what a market is.
So what happens when you give away your precious code for $0? What happens is that people will value it at exactly that: $0. You yourself are signaling to the world that your work has zero value. So you and your work will be treated that way.
You might not like it. You might wish that the world was full of enlightened people who would all magically see things your way. But that is not the case. So accept it and move on. If you want to make $ doing FOSS then put that in the licence and sue anybody who doesn't pay.
My argument is this: People are unreasonable when they expect free hand-holding support just because the software is free. I never argued in this thread that people should pay for my open source software. What I am saying is that people are being unreasonably entitled when they expect to also have free professional level support (e.g. private email support), using ISC and RedHat as real world examples where open source software is free, but professional support costs real money, e.g. https://www.isc.org/support/
If you try to tell the ISC that their gold level support should be free using the trollish [1] logic that, since the software is free, it has no value, so the support also has no value and should also be free, they will politely and professionally laugh in you face.
Ignoring the fact that free market fundamentalism [2] requires have a lot of holes in one’s logic to believe (roads, police, and, in most first world countries, medical care)—that’s another discussion for another day—there exists, in today’s free market, free software without free support.
Now, in terms of whether we would be in a better world today if those “no commercial use” licenses were not excluded from open source around two decades ago—I remember the KDE-vs-Gnome flame wars all too well, as well as the BitKeeper license flame wars which resulted in Git—I agree that is a legitimate point, but that ship sailed out to sea a long time ago. There’s also the ethical issue of FOSS developers who give away their code, but then turn around and complain that those with big pockets should pay them. Both of these issues have nothing to do with the issue I am bringing up: Free software != free support, as much as entitled users wish to think otherwise.
[1] Trollish, because telling open source developers that their software has no worth comes awfully close to the “no personal attacks” rules ycombinator has.
[2] There are a lot of free market fundamentalists out there that think the free market will magically solve all problems. Maybe you’re not one of them, but with all this going on about how something which costs $0 has no value, that comes off as free market fundamentalism to me.
I agree. I don't argue that people should expect support to be free. What I am arguing is that if you don't put a market value on your work then you are signaling to the world that your skills and hours are worth $0. Even though your work clearly has intrinsic value for companies/people.
> Trollish, because telling open source developers that their software has no worth comes awfully close to the “no personal attacks” rules ycombinator has.
Not at all. The work open source developers do clearly has intrinsic value. It is useful. That's why people use it. However it has $0 market value when maintainers give it away for $0. And that has real world consequences.
> There are a lot of free market fundamentalists out there that think the free market will magically solve all problems.
I am not one of them.
Indeed, big companies using my open source looks really great on my resume.
Both the GPL and AGPL are restrictive enough that it’s a reasonable business model to say “GPL if you won’t pay, non-GPL if you pay” and make money. The Juce toolkit, for example, is GPL if you don’t pay, but non-GPL if you do pay.
Moreover, isn't this what's happening to most software, everywhere? Cases-in-point:
Compilers - when's the last time you actually paid for a programming language? I know for me: SAS C in the mid 1990's
Databases - any new solution would likely use a free DB.. and why not?
Digital audio workstations - "free" ones seem to come out monthly
Graphic editors - 2D and 3D alike - the free varieties are getting better every year
Developer IDEs - From console editors to full GUIs to online offerings; all free
Even the business model of "hoping to make server software so good that everyone wants it" fails when hosting services just grab it, re-package with their own branding and profit.
JetBrain's IDEs are considered as the "best ones" and they're indeed paid.
Visual Studio which is great for C# development is free too, but not for business.
On the other hand if you look at companies that build value-adds on top of open source, then the number is huge. It starts Facebook and includes a wide number of enterprise software companies like VMware, companies like Cloudflare, etc. They owe a lot of their success to open source and are major contributors in the aggregate.
It's therefore really limiting to assume that open source necessarily has to be maintained by for profit, enterprise software companies. Most successful companies build SaaS or other value adds over their open source projects that actually solve business problems. The reason: that's what enterprise customers want to buy. I've run two companies in the database space that take this approach. We're not very worried about competition from Amazon.
We've gotten complacent that open source just exists and is maintained and it's sunshine and rainbows. We've been able to build amazing things on the backs of these maintainers, but you have to factor in that they don't owe you anything. So keep that in mind when you're just gonna install some random library from the public package repository because "not invented here" or something.
Why pay for the cow when you get the milk for free? There’s no incentive for anyone to pay and this has become best practice.
Anyone remember the uproar over CentOS being retired?
There’s this unrealistic expectation that maintainers be paid without a real business model, but that’s what needs to be done.
Become a business or being part of a business, and find a cost model that is both appealing to customers and self-sustainable.
All which comes with non-engineering headaches, but there’s no avoiding it.
What may help here—and the missing ingredient—-is the lack of a professional, trade organization.
In fact, this would solve a number of pressing problems in our industry.
Moreover, there needs to be a fundamental re-thinking of the security model of languages and runtimes, i.e. even if I can eval() user input or load a plugin from the network, it should not be game over. There should be finer-grained access control in programs, both at the type-level and with how they interact with the OS. The global view of "your program can do anything unless said otherwise" needs to change.
Do you want to force every single company that rely on FOSS to pay? Change your license.
Stop using permissive licenses like MIT or BSD and license your project with GPL. Companies will have 3 choices: use your GPL licensed code and make their software GPL too, which they don't want to; pay you in a dual license scheme, so they can keep their code proprietary; develop themselves every piece of code they need. They don't want the first option, so they will pay you or they will pay an employee. In both cases, they will pay.
It has worked great for decades, both for the free market side, and for the FOSS community.
As a result, it's also unsustainable to other coders because the OSS ecosystem grows replete with broken and stale code that is no longer maintained and which creates cognitive cost to ignore/prune.
Both might grow in a non-linear fashion, which would be really bad news.
Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?
And for communities, and for sponsoring companies, and for some (although not all) authors.
> if you ignore bombs like this logging bug destroying Western civilization.
...yeah, no; a library had a bug. Somehow, Western civilization is still here.
> Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?
Can you explain why you think the majority of authors/maintainers burn out?
That was exploited since April
https://github.com/nice0e3/log4j_POC
... this 'bug' is RCE on the logging infrastructure.
> Can you explain why you think the majority of authors/maintainers burn out?
Please try maintaining a popular FOSS project for a few years and explaining to your wife why you neither have any money nor have any time.
And yet, Western civilization is still here.
>> Can you explain why you think the majority of authors/maintainers burn out?
> Please try maintaining a popular FOSS project for a few years
The majority of projects aren't popular, so you're comparing apples to oranges. For many, I suspect most, projects, the user base is tiny and low pressure.
I don't understand this argument. Nobody starts an open source project - and posts it in the open to share freely - expecting to make any money. Are there even any significant amount of projects with a donation or a Patreon page?
Webnovels I read on RoyalRoad all have it and are much more successful that I would ever have thought given that the stories are all coimpletely free and all any one who pays a story author gets is a few chapters ahead of others, but I can't remember any of the numerous OS projects I use one way or another to even try to make any money.
I did see burnout in some projects. I once joined as co-maintainer of a medium sized project and was left as the sole maintainer because the main author just up and left and was unreachable (we only heard of him again over a year later, and he never touched that particular project again).
All the stories I saw had nothing to do with money at all though, just getting fed up with the expectations. In "my" project's case it also was the large amount of complexity and technical debt that made the original owner's attempts at adding and/or refactoring a huge time sink, and he probably would have been better off to start again from scratch (it's what happens after adding more and more features in a complex cross-mobile phone platform library project's code).
None of those "disillusioned open source maintainer" stories I saw ever included any attempt of making money with it. Disappointment of not being able to get money from anyone only ever comes from people starting a commercial project (a new company), if that kind of disappointment exists for freely shared open source software then I must have missed all instances of such a thing happening.
> It has certainly 'worked great' for leeches, if you ignore bombs like this logging bug destroying Western civilization.
All of life and especially commercial life in anything slightly sophisticated or at scale is "muddling through" to some degree. The same as biological life actually.
So overall I agree with the previous statement that it worked quite well. Nobody should be called a "leech" for using projects that were meant to be shared openly and freely, given the license and method of distribution (e.g. freely on Gitlab or Github).
Yes, it would be very good if more people started to contribute to software they depend on, but to call them "leeches" is not only against the spirit of free software, it is counterproductive as it will probably lead people to the idea that proprietary/closed source is better.
No... projects want contribution more than money, the idea of paying the author is that they can then continue to contribute in the long term by proxy for the payers.
But FOSS-systemwide, I give much more than I take. It just needs leechers, who systemwide, give nothing back, to do the same.
If you ask five different people to evaluate your contributions, how much would they agree? How much would these people be interested in contributing as well and/or paying for you to keep doing what you are doing?
The point I am trying to make: people express their preferences differently, and that is a Good Thing (tm). Market dynamics are a Good Thing (tm). Each of these critical RCEs work as shock on the whole ecosystem which makes it a little bit stronger. I'd rather have a dozen of RCEs on popular-but-amateurish maintained projects than a little totalitarian forcing everyone to "stop being a leech".
"Look around and notice how the world actually works"...
In other words open source as it was practiced was sustainable up until the point it got taken advantage of too much by big players not putting things back into the system. At this point it has become unsustainable.
Perhaps this could work for any company size, but I guess it depends on what is your core business.
This particular class of problems (same as the sqlite fts tokenizer exploit and most of openssl exploits, even lots of the sendmail exploits) are just obscure unused features. It happens even in CPUs themselves. (e.g. https://www.youtube.com/watch?v=lR0nh-TdpVg)
Removing code is twice harder than adding code, why do you think paid maintainers would improve anything? Just look at the code written in FAANG or any enterprise, and those maintainers are very well paid, imagine this code being public, we will have 1 new exploit per day per company... and that is assuming non malicious developers that can be shipping trojan code https://lwn.net/Articles/874951/ (it is also hard to assume all millions of developers are non malicious, even if we assume 1 in 100000, things look really bad)
Less code is the one solution. Regardless if open source or enterprise code.
We are stuck, and change is needed, but money is not a solution, and might even be the cause of the problem. (incentive to write more code)
Basically kill free open source. Make every "new open source" (NOS) program dual licensed, free for non commercial use and paid for conmercial use.
He proposed companies paying 1% of revenue to license this software. But it would all go through a proxy company that would gather payment and send it to participating companies, I dont remember how it would be split.
I think this is actually a way forward. I would feel better building on top of this kind of stack vs npm ecosystem
I don’t want to start a philosophical flame war about licenses, but this idea makes sense to me. The details will likely take work to iron out, but why not have open source licenses with a clause for companies with over a certain amount of annual net profit. Does anyone have examples of this in practice? As far as I know, licensing models like Mongo or Elasticsearch are a bit more binary.
I’d be fine letting individuals, small businesses, and startups use the software for free in perpetuity unless they hit some metric like “greater than $x in annual profit” or whatever. I guess a counterpoint to this might just be that companies that get to that scale would just develop the same thing in-house instead.
I've been appalled at the way that older, more experienced developers are treated, and am not surprised at this.
There's a really good chance that many of these bugs were introduced by developers that are now older, and more cautious. In some cases, these may be the harsh lessons that caused these developers to become more conservative, these days.
A conservative (not political "conservative," practical "conservative") approach is generally best, when maintaining infrastructure. Be careful, test well, don't "push the envelope" too much, and, for God's Sake, don't add new stuff, until you have the old stuff completely tested, documented, and supported.
New stuff can be added via forks, and introduced via carefully-vetted PRs.
I keep thinking of the Linux core kernel project as an example of how to do it right, but I am not very involved in that ecosystem, so it may be a case of "the grass is greener on the other side of the fence."
I can tell you that I take each of the tools I make, very seriously. A quick shufti at any of them will tell you that. No one really uses them, but that's fine with me. I write them for myself.
I find it difficult to blame developers individually. Individuals working at these companies aren't going to see it as their role to send some of their own after-tax income to maintainers via GitHub Sponsors unless they are unusually charitable. But I could definitely see my company sending thousands out the door (pre-tax) every year to the maintainers of the libraries we depend on.
For example, imagine your team is 15 people. Have the company budget for and send an additional one developer's worth of salary out annually to the open source maintainers, divided among the libraries in a proportion agreed to by the development team. Yes, it's an additional cost line item, but it's the right thing to do and it won't break the bank.
Open source has reduced costs dramatically for all of us who use it in our dependencies list. A nominal cost line item on our annual budgets is more than fair.
But ultimately the problem is the same: engineers, i.e. employees, don't control the money. They don't have agency to direct the money toward functions other than enriching the people who have the money.
They may have more agency relatively speaking than free software developers, but on an absolute scale, you can measure this kind of agency in dollars, and it's a pittance.
Maybe they could donate some of their own salaries. Maybe they could get employer matching. Still doesn't seem realistic, but it's closer.
I'm starting to think, how could my next project provide the same value, and get paid for it?
For example, donating 25 or 50 cents every time I visit gofiber/fiber would be fine with me.
However, there is no way to feasibly charge small quantities of money without the majority of it getting raked in processing fees. For example, Stripe charges 30 cents plus 2.9 percent (last I checked), meaning only ~20 cents would make it to the maintainer(s).
The same issue exists with rewarding content creators. You either donate a non-trivial amount of money (often recurring) like $10 a month (which means you have to keep track of that expense, which is arguably an even greater disincentive for donating), or you don't donate at all.
[1] https://github.blog/changelog/2021-04-06-custom-amounts-and-...
The state offers a guaranteed job and collects tax.
Just as it does to maintain the roads.
Toll roads became public roads .
Earning six figures is a chore and frankly gets boring after a while. But if you had enough to keep the wolf from the door …
One thought: i disagree with the classification of (senior) software engineer.
i think it’s more comparable to a VP of Engineering in a company with n engineers (n = count of committers/involved), so salary estimate are even higher.
This is a model that MPAA and RIAA use. And their equivalents in countries that have functional copyright legislation. Most first world countries have one. Don't get me wrong, they are mostly rent-seeking racketeers, but if you try to weasel out of paying for stuff you're using for your own profit, you're bound to get one.
Either some law pertaining to maintenance of "digital commonwealth" or some other nice name is passed in enough countries so other countries have to follow suit if they want to be in good company, and organizations with teeth, one per country, are set up to make sure the "digital commonwealth" tax is collected from everyone, big and small. They will even distribute money among creators, by usage or something.
Microsoft would probably love to be such an arbiter. They have Github. They have all the stats. They know if your company had been naughty or nice, how many times they downloaded your stuff, and how many times their employees were demanding shit in issues. It's child's game to join the party, just have an account with them.
Or we just piggyback on the existing copyright legislation and give RIAA and their likes more power and custody of making sure OSS maintainers don't starve. They will surely protect their interest with eagerness, who wouldn't like more profit?
Of course, companies will try to fight tooth and claw. They will tell you all sorts of doomsday scenarios, how the poor megacorporations won't be able to afford it, how they will have to raise your subscription fees. Gee, haven't we seen those crocodile tears when free roaming in EU was going to be established? We also know how it ended: they all sucked it up, complied, maybe their profits took... well... not a hit, but a nudge maybe. Companies who have to buy music know how to pay the music tax to copyright racketeers. They will get used to that.
They will also be happy to pay just one entity and be done with it. And if you dare start a company using F/OSS, you're in for the largest financial hit. The little man always suffers the most in such schemes.
Free for open source works really well for hosted pricing. I don’t know what legal barriers there are, but a free for open source/explicitly paid license for corporate use model would probably help alleviate a lot of this.
Edit: and of course such a license could waive fees for contribution, stewardship, good faith involvement that keeps the project healthy.
I have asked if he has a version that addresses the history of these ideas, and how they've worked out - because the history is a very long one.
I would suggest moving away from permissive licenses, which are "just take my stuff." Companies don't even throw in their alterations.
Stallman was 100% right about the importance of software freedom, and strong copyleft. AGPL more of the things. AGPL your latest Rust libraries.
The problem is no one wants to work on the day-to-day issues that need maintaining to keep the project afloat. Sure companies will pay to incorporate this feature and that feature and the community will submit this bug-fix on this new widget, but day-to-day maintenance to keep the code base alive is left to bit-rot. It's like the newspaper website for your local town. There are links to and from older stories that lead to broken webpages, but no one wants to update the links yet new content is posted on the newspaper's site each day.
This isn't a problem of shaming businesses. This is a government and multi-government concern. It's a national security issue. There should be BILLIONS of dollars of funding coming from all portions of governments: the military, universities, regulatory agencies, research agencies, any and all departments using IT systems.
Corporations don't even need to fund it. They just need to have the government fund it.
That would make it easier to develop and maintain such software, and it would make it easier for people doing other things besides software development (yes, they exist) to open up their artware without starving.
Then there wouldn't be a need for the insane "professional" formalism described in this blog post.
Instead, you could set up a structure where open source authors set up an LLC, and then get a salesperson hired on a revenue-based retainer. The salesperson then actually goes out and talks about "supply chain attacks" and "open source sustainability" to the target companies and tries to close deals with them. Maybe they can even work on stuff like "vendor approval assessment" and other paperwork. Maybe the salesperson hires more people that actually do the paperwork and sales development, and the salesperson themselves only does the closing. That way, the maintainer continues to write code and now it's a salesperson who actually brings in the revenue.
You can even set up a marketplace startup which caters to this whole workflow. 2 user types: open source authors and salespeople. Open source authors can create an LLC with a click (integrate with Stripe Atlas?), then they go into 'Call-for-salesperson' directory, put out a listing saying we're so-and-so open source project with 10k stars on GitHub, come represent us. Then on the supply side, a salesperson sees the listing, writes up a proposal which might include a percentage fee they'll receive from the sales (say 25%). After receiving a few offers, open source author can choose who to go with. Maybe if it doesn't quite work out with this salesperson, they go back and re-list.
Just a quick idea on how this can be solved with a marketplace model. Everyone in this structure is happy: open source authors get money, salespeople get their percentage fee, corporations get sustainable open source projects.
I am not a lawyer and know little about open source but is it possible to create a new license that allows free use up to a certain revenue level?
Some similar things have happened to mysql (to mariadb) and mongodb (to whatever the fork is called).
Dual licensing it like MySQL did is one way to approach it, but plenty of people were happy enough with what it did that they didn't pay for it.
Different projects have different prices, but you can pay more.
The money is forwarded to project maintainers was wages, but a "tax" is applied so that some money is redirected to small but growing projects.
Projects that see sufficient income would be certified as having certain level of guaranteed support, based on the fact that they essentially have a staff to maintain the project. The entity would ensure and manage this. Some of the money would be used to fund this process.
Corporations ever do anything voluntarily if the alternative is tangibly worse, evidently more expensive, or existentially threatening, especially in short to middle term.
Spinning up an AWS instance costing $10 a month is trivial because the buisness has decided to empower employees with unlimited funds to spend on it.
So how can I spin up a $10 a month "instance" which goes to say ffmpeg developers, or apache developers, or openjdk developers, or whatever, with only a small overhead going to AWS and the majority of that money going to the people my business relies on.
E.g., Gemini.
1) It's really difficult to donate to Open Source; 2) Companies don't get enough value in exchange for donating – They are businesses and think in dollars & cents; 3) and, Devs much prefer to write code rather than chasing companies for donations & sponsorships.
As a result of these dynamics, OSS is very mispriced at the moment. Unfortunately that is going to impact quality and we shouldn't be surprised by the Log4j bug.
Most of these companies spend more on greenhouse services to keep plants in their offices than they spend supporting the F/LOSS stuff that they built their product around. That's how it should be viewed.
The Faangs probably have on the order of 100m boxes running Linux etc. It would be totally reasonable to expect they would pay someone $1/year/box to help maintain all the F/LOSS in there.
https://www.amazon.com/Working-Public-Making-Maintenance-Sof...
OSS is communism applied to software: it doesn't make sense and it doesn't work. After a few generations of idealistic people who sacrificed themselves and worked for free to give us foundations, most of OSS nowadays is just: - Advertising to let engineers know that company X is cool and you should go work for them - Ways to keep your staff motivated (who doesn't want to become a OSS rockstar?) - Advertising to sell an actual business
I'd rather live in a world where companies are building and maintaining software and reselling it to other companies. Unfortunately we made it sound uncool, somehow.
Pay your invoice, get your token and npm install @user-agent-experts/ua-parser
I'm not necessarily against open source and I certainly benefit and contribute to it; OSS also has the benefit that more people can spot bugs and end users can fix your shit when it's broken.
Still, I would never maintain something that allows companies to use it for free. It doesn't make any sense, no matter how much code the companies are publishing.
Any company that cannot afford to go without your software for 24hrs per year should pay full whack for a commercial license.
Commercial use should bring with it a much difference set of obligations than non-commercial use.
Salaries are lower, but expenses for essential services are simply A LOT less in most of Europe.
>but increased savings from increased salary can make up for that (not to mention 401k).
And huge medical bills can quickly eat up even substantial savings...that doesn't happen as easily when medical services are provided by universal coverage.
Also, state guaranteed pensions aren't lost if some company in a portfolio crashes.
Have cancer, or a premature baby with 90 days in Neonatal Intensive Care, in the USA, and get back to me on your health insurance.
If you're in a good tech company in Europe you generally end up having private healthcare, a private pension with employer's top up and extended ma/paternity leave.
The problem is that taxes in the USA are still fairly high and comparable to the ones in EU - you would expect some services for the amount of money you're paying. That said, having lived in countries with state run services all my life, I don't think the solution is state run services, but cheaper private services. The problem in the USA is that governments and insurance companies inflated the cost of healthcare ridiculously. Similarly the cost of universities in the USA has been inflated following government intervention.
Talking about state run services: Between waiting times, poor support and the lack of competition the quality is pretty bad, despite what the state propaganda will tell you. Having lived in the UK and in Italy I cannot but laugh hearing that NHS or the SSN are "the best healthcare systems in the world". The amount of bad experiences I had is ridiculous (some of which could have damaged my family health, had we not had the money to pursue private treatment). Universities in Italy, which are pretty cheap at 3-4k€ per year, have several deficiencies and, despite having a handful of great professors who do it out of passion (maybe while running a profitable business on the side), it has its fair share of problems. Not to mention the amount of freelancers in Italy who pay pension contributions every month who will never see a penny for their money.
There’s tipping and sponsorship infra, but is there a service to plug an OS project into corporate-friendly licensing and support invoicing?
The picture paints a picture of complexity through layering and centralized liability through the one lone leg. Even if that one leg were well staffed and funded, it is still a centralized liability. There are any number of problems that occur when you have a single spot liability, beyond just “we’re depending on a few people’s goodwill.”
I wish we lived in a world where when we see that picture we stress less about the paucity of volunteer developers and instead observe, there should be more legs right there, redundancy would be good. Interoperability would be good. I wish we lived in a world where when we saw that complexity we said “it’s nice to reuse, but simplicity of algorithm and design should still trump quick select complexity.”
The file formats, protocols, design patterns, languages, that should get people excited on HN are the ones where you can learn/implement/understand it in a day. Not the ones where we build artificial mountains of complexity and then celebrate those that put in the time to become gurus sitting atop of the arbitrary mountains we’ve built.
The showcase can be a simple OpenSea widget showing the NFTs owned by a particular address.
reign of chaos