3 ms·
The entities that most benefit monetarily from OpenSource are companies that sell products and services based on them. Why would they contribute to this? It's a
by kseifried 6y ago
The entities that most benefit monetarily from OpenSource are companies that sell products and services based on them. Why would they contribute to this? It's an added expense they don't have to pay. In fact a major tenant of OpenSource is that you can choose to make money or give. it away for free, but you generally have to release the source code, which is what the companies want, so again, why would they pay for it? To make a more sustainable ecosystem? Hahaha.
As for individuals funding this, Open Source developers are not cheap, to make it worthwhile (e.g. comparable to a part time contracting gig) we're talking a minimum of tens of thousands of dollars per year per developer. We're not going to get anywhere near these numbers with individuals contributing.
I write this as the guy that tried to help the OpenSource world by assigning CVEs for security issues (several thousand...), I'd have had to charge 1-200$ per CVE to make a living at this while I was doing it. That's not going to be sustained by personal donations. And even though a CVE will easily save companies a few tens to hundreds of dollars (time spent tracking all these issues when they don't have CVEs...) there's no way I'm going to get companies to pay me.
The good news is that this doesn't really matter. We've had many decades of OpenSource, there's enough good people working on this because it's their passion/hobby/day job that it's mostly sustainable on average, but specific bits may be sickly, and that's ok.
Some related listening and reading:
Episode 205 – The State of Open Source Security with Alyssa Miller from Snyk
https://opensourcesecurity.io/2020/07/12/episode-205-the-state-of-open-source-security-with-alyssa-miller-from-snyk/ https://opensourcesecurity.io/2020/07/12/episode-205-the-sta...
Episode 185 – Is it even possible to fix open source security?
https://opensourcesecurity.io/2020/03/02/episode-185-is-it-even-possible-to-fix-open-source-security/ https://opensourcesecurity.io/2020/03/02/episode-185-is-it-e...
Episode 182 – Does open source owe us anything?
https://opensourcesecurity.io/2020/02/10/episode-182-does-open-source-owe-us-anything/ https://opensourcesecurity.io/2020/02/10/episode-182-does-op...