27 ms·
Professional maintainers: a wake-up call
- wolverine876 5y agoIs the lack of a micropayments system the real problem, as with journalism, art, etc.? If people could pay FOSS projects with a click, I think they would. They pay Amazon that way, and that's often for useless junk.
- deleted 5y ago[deleted]
- skadamat 5y agoI will take this opportunity to mention Nadia Eghbal's book covering her work researching open source projects & communities. Super relevant: https://www.amazon.com/Working-Public-Making-Maintenance-Software/dp/0578675862 https://www.amazon.com/Working-Public-Making-Maintenance-Sof...
- chadcmulligan 5y agoI am in a minority but I really like buying professional open source software libraries compared to FOSS - there's someone for support is the main thing, and if you count you're time trying to get FOSS to work, then paid software is superior. I use a commercial IDE, with professional libraries for development, it's so much easier.
- neycoda 5y agoRichard Stallman wants all software to be free, which I disagree with, but adding a paywall to open-source will push companies to find a free replacement or build the software themselves.
- tomxor 5y agoUnpopular opinion: Maybe there is nothing wrong with the "status quo", maybe we don't need yet another attempt to finance small FOSS projects where it's hard to explain how money will actually solve any of these issues. Maybe people just need to be more considerate of what they depend upon. And in the case that a popular yet well maintained project has a CVE on day, maybe we need to accept that popularity does not make them invulnerable to bugs, all software has bugs. </ unpopular realists opinion>
- jjoonathan 5y ago"Being considerate" and "accepting" can't fix bugs. Time and money can fix bugs. We need to get these projects more time and more money.
- beiller 5y agoOpen source always trails professional software solutions. Yet always time after time will eventually surpass it as the bleeding edge moves further. Maybe we can view it in such a way that major companies have become too reliant on free open software. If you want secure software, pay for it. The knowledge will eventually flow down to free software because it's ultimately run by hobbyists. I like the way it is and I don't see it changing because so many are just donating free time to open free software. Maybe something we could do is make open source contributions tax deductible (if we could somehow price it accurately)
- rglullis 5y agoNo doubt. The question is who should be paying them?
- finnh 5y agoWould more time or money prevented the log4j bug? If anything that strikes me as coming from too much time spent on overarchitecting something.
- jjoonathan 5y agoThat's more an argument against old-school "no amount of architecture is ever enough" Java -- not so much an argument against the principle that engineer-time can fix bugs.
- watwut 5y agoThis bug was not consequence of not enough developers. And there will never be guaranteed "no security issue" situation. That level of certainly is simply too expensive.
- daemonhunter 5y agoSide note: dang there are salary discrepancies in the SWE community.
- 1_player 5y agoThere are salary discrepancies everywhere in the world. If you mean the salaries across countries, you're comparing apples and oranges. €100k in Berlin goes much further than $100k in Houston (a random big city in the US, I don't think Berlin is comparable to NYC)
- usrbinbash 5y agoNot to mention the person in Berlin has access to state funded medical support, a state funded pension, paid sick leave, paid ma/paternity leave, ... Salaries are lower, but expenses for essential services are simply A LOT less in most of Europe.
- jakear 5y agoTech companies also pay for health insurance, sick leave, and ma/pa leave. Sure pensions aren't a big thing, but increased savings from increased salary can make up for that (not to mention 401k).
- usrbinbash 5y agoThe difference: It's not up to the companies in most of western Europe. These services are guaranteed by law, and provided by the state. >but increased savings from increased salary can make up for that (not to mention 401k). And huge medical bills can quickly eat up even substantial savings...that doesn't happen as easily when medical services are provided by universal coverage. Also, state guaranteed pensions aren't lost if some company in a portfolio crashes.
- JJMcJ 5y ago> pay for health insurance Have cancer, or a premature baby with 90 days in Neonatal Intensive Care, in the USA, and get back to me on your health insurance.
- pixiemaster 5y agowell written. One thought: i disagree with the classification of (senior) software engineer. i think it’s more comparable to a VP of Engineering in a company with n engineers (n = count of committers/involved), so salary estimate are even higher.
- the_gipsy 5y agoPlease define "unsustainable". It has worked great for decades, both for the free market side, and for the FOSS community.
- uniqueuid 5y agoAt the very least, it's unsustainable to maintainers as people, because many are burning out (I have no data, so this is an assumption). As a result, it's also unsustainable to other coders because the OSS ecosystem grows replete with broken and stale code that is no longer maintained and which creates cognitive cost to ignore/prune. Both might grow in a non-linear fashion, which would be really bad news.
- fivelessminutes 5y agoIt has certainly 'worked great' for leeches, if you ignore bombs like this logging bug destroying Western civilization. Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else?
- yjftsjthsd-h 5y ago> It has certainly 'worked great' for leeches, And for communities, and for sponsoring companies, and for some (although not all) authors. > if you ignore bombs like this logging bug destroying Western civilization. ...yeah, no; a library had a bug. Somehow, Western civilization is still here. > Can you explain a bit more how it worked great for the bulk of maintainers / authors who don't see any return on their work, burn out and have to do something else? Can you explain why you think the majority of authors/maintainers burn out?
- fivelessminutes 5y ago> library had a bug That was exploited since April https://github.com/nice0e3/log4j_POC https://github.com/nice0e3/log4j_POC ... this 'bug' is RCE on the logging infrastructure. > Can you explain why you think the majority of authors/maintainers burn out? Please try maintaining a popular FOSS project for a few years and explaining to your wife why you neither have any money nor have any time.
- skeeter2020 5y agoEverything stated about the risks and current deficiencies is true. Meanwhile the OP works for Google on OSS, one of the "untenable" approaches to funding it that is lamented. Nothing else presented is close to an alternative solution; there's no "ask" that would fix the situation, let alone an attempt to lead by example, so what's the point of this post?
- wutbrodo 5y ago> This is what I hope to see happen more and more: Open Source maintainers graduating to sophisticated counterparties who send invoices for "support and sponsorship" on letterhead, and big companies developing procedures to assess, approve, and pay them as a matter of routine so that they can get what they need from the ecosystem. In what way is this not an ask?
- usrbinbash 5y ago>But! Maintainers need to be legible to the big company department that approves and processes those invoices. I imagine this could be a hard sell to people who just want to build some cool software and maintain it. Setting up an account, okay, that may be possible, but that's not the end of it. Companies pay invoices FOR something. That something means contracts, potentially about substantial sums, that means getting legal support to navigate said contracts & obligations.
- throwaway894345 5y agoWe have software licenses and yet every open source project doesn’t employ a lawyer. The solution is probably the same: canned, off-the-shelf contracts. If a company wants to negotiate a custom contract, then the maintainer can decide whether or not it’s worth hiring a lawyer.
- b3morales 5y agoEven if the contract itself might be commodified, the relationship won't be. Business will want what it wants, regardless of what the contract says. Maintainers will certainly be subject to influence campaigns by business, which will sometimes conflict with other "clients". Even saying "no, read the contract" to a persistent VP has a psychological and social cost. I can't really imagine this decreasing the pressure on maintainers: it's basically turning the project into a startup.
- throwaway894345 5y agoI think the idea is to provide a middle ground option between full-on startup and doing free work for corporations. That implies meeting in the middle both on compensation and on work delivered, but it's possible that we'll find new non-zero-sum opportunities.
- didibus 5y agoI feel like the examples of log4j and ua-parser aren't that great, because it would be relatively easy for any other similar lib to take their place, as it's mostly straightforward to implement, even though it still takes time. But there are some things like Kafka, PostgressSQL, Spring Boot, Tomcat, Apache Math, ZooKeeper, the OpenJDK, and all that which are definitely non-trivial and a huge amount of time and effort, and you couldn't just take an extra month or two and have a dev on your team implement a replacement, unlike log4j and ua-parser. I think those would be better example to discuss, and my impression has been that those things often have a company behind them offering support or offering them as a service that in some ways pays for some real devs to contribute to them, but maybe I'm mistaken. Like for example, the author mentions working on the GO team at Google, and Go I would consider one of those big open source projects that truly are foundational and would be non-trivial and huge effort to replace. So that shows that the really big pieces do have companies hired and paid staff behind them.
- tobltobs 5y agoFirst those developers don't get any money for their work, now you also telling them that the work they are doing isn't really valuable anyway? Did you consider the fact that half of your examples of worthy things are using the unworthy log4j?
- WJW 5y agoQuite a few managers I have spoken to will use the exact reasoning ("we could rewrite this in two weeks or so, why should we worry if it disappears?") and do indeed seem to think that the fact that because the OSS dev did not get paid for their work implies that it is low value work. If it was in fact high value, they would have gotten paid for it you see.
- didibus 5y agoAs a developer, if there were no free open source logging library, then I'd be paid to implement one at my work. It be a fun project, but because someone is willing to do it for free, and give it away, it's hard for me to justify to my employer that we should build our own. This is how the value is measured. But if you take a much harder task, like building a performant and safe JIT language runtime like the OpenJDK, you'll see that even in the open source model, people can't actually deliver it effectively for free. It often starts out from a company that later open sourced it, or it's backed by academia, and contributions require deep expertise, so sometimes companies had to have their own staff contribute to it on their own payroll.
- vmception 5y agoYou can get a closer view of this sentiment in action within communities built on open source with distributed governance. Very many communities in the blockchain space routinely discuss how to compensate the development work necessary, and the recurring theme is that people imagine a nonexistent cheap developer: An engineer with in Micronesia with specialized skillsets. Try to convince these communities about the need for a well compensated team of people including product managers and designers all making 6-figures and honestly people just don’t believe you. The truth is that cost of living discussion doesn’t even matter, people should be compensated on the value they bring (and in those communities that is very easy to quantify.) This has wildly slowed down many projects as UI and usability are completely neglected. Its pretty much only been one year that an engineer in this space can reliably land compensation packages somewhat competitive to a tour in NAAAM
- throwaway5371 5y agono, people should commit security vulnerabilities on purpose; anarchy and chaos should arise reign of chaos
- qnsi 5y agohail eris
- beebmam 5y agoThe solution to this, along with many other socioeconomic problems, isn't going to be solved through voluntarism. This is easily solved with a universal basic income. Some of us would gladly forever maintain and contribute to free software if we had our basic needs guaranteed. I certainly would
- wolverine876 5y ago> The solution to this, along with many other socioeconomic problems, isn't going to be solved through voluntarism. Open source has been incredibly sucessful using voluntarism. We could also throw in political movements; the all-volunteer military, which has existed on and off since the American Revolution; science (the pay doesn't nearly match the efforts and value); non-profits; teaching (same as science); etc., etc. Why do people feel so motivated to sh-t on voluntarism, which has changed the world with great success. Almost every major advance in history has been accomplished by volunteers (depending on how you define it). Declaration of Independence, Newton, Van Gogh, World Wide Web, etc. etc. etc. ...
- deleted 5y ago[deleted]
- smasher164 5y agoI agree that appropriate compensation is necessary, but I don't think it's sufficient. There's a lack of visibility and tooling for dependency management/auditing. I can't even find a proper list of critical OSS along with their donation links. Moreover, there needs to be a fundamental re-thinking of the security model of languages and runtimes, i.e. even if I can eval() user input or load a plugin from the network, it should not be game over. There should be finer-grained access control in programs, both at the type-level and with how they interact with the OS. The global view of "your program can do anything unless said otherwise" needs to change.
- daenz 5y agoI'm an open source author and maintainer of a somewhat-popular python package[0] (~1M downloads/month) that I've maintained for over 10 years. I don't recall ever receiving a donation. I am still maintaining it, but I just don't have time to add the improvements that it needs to keep up with the ecosystem (asyncio, for example). If organizations who use it got together and chipped in some non-negligible amount, I would be much more serious about keeping up with it, but $0, or $5-20/month, is just not realistic incentive to compete with other priorities in my life. I don't know the answer, but that's my thought process. 0. https://github.com/amoffat/sh https://github.com/amoffat/sh
- javajosh 5y agoFirst, I don't use it, but thanks. (I know, being a maintainer is a thankless job, but I'm a rebel.) Second, the OP addresses this issue directly. He's talking about "making OSS maintenance legible" (emphasis mine) to BigCorps via 5-6 figure invoices "on letterhead". It's a grand idea, and I hope it works. The path to not working is too achingly obvious though. Budgets are always tight (even if you're Apple and you have to artificially make money feel tight). What corp officer with budgetary discretion is going to greenlight a 5-6 figure payment to someone who's not doing work directly for the company? I think the key here is that that person is going to have to a) be principled, and b) smart about selling it, by emphasizing the fact that the changes were beneficial to our company, and leave out the fact that those changes were beneficial to every company. It wouldn't hurt if BigCorp got a measurable recruitment bump from it, too.
- daenz 5y agoIf I could figure out for certain which big companies were using my software, I might try the invoice idea for fun. I expect it would be ignored, but I would send it anyways to prove the idea one way or the other.
- josteink 5y agoIf you hosted the package/library yourself instead of in closed silos/package repos, you could directly check the IPs of whoever regularly pulls your stuff. We all opted for centralized package repos though, so now only they know. And they’re not telling us. Just another “free” opportunity lost to centralization, I guess.
- pselbert 5y agoThe only reason I’m able to maintain a reasonably successful open source library is because it is part of an open core business model. Without that I couldn’t justify the development effort or relentless support to myself, or my family. Getting a few hundred dollars a month wouldn’t cut it either. Building a business on a stack of other people’s hobbies isn’t sustainable. I mean, just tell that to anybody outside of tech and watch their reaction.
- julianlam 5y agoAgreed. It is exactly the funding model my project (started with two colleagues) endorses. We incorporated federally and keep an open core. I can't imagine it would be as clear cut for a "library", but it can be done...
- thruflo 5y agoSounds like an opportunity for a seedlegals.com style sass. There’s tipping and sponsorship infra, but is there a service to plug an OS project into corporate-friendly licensing and support invoicing?
- mwcampbell 5y agoThis post didn't go the way I thought it would. When these discussions get going, I always feel a little guilty because my tiny company doesn't pay for all the open-source software we use. I suppose we should, but it would be hard to make a business case for that, since the software is already free. It would be easy to conclude that this is a problem for the big, rich companies to solve, but I'm suspicious of advocating any action that I'm not willing to do myself.
- reidrac 5y agoI don't know if this makes sense: sponsoring one of the open source projects your business depends on, could that work as PR? Perhaps this could work for any company size, but I guess it depends on what is your core business.
- bhauer 5y agoI feel as if engineers at firms that build systems that use open source libraries should campaign internally to create budget line items for paying non-trivial amounts to the maintainers of those libraries. I find it difficult to blame developers individually. Individuals working at these companies aren't going to see it as their role to send some of their own after-tax income to maintainers via GitHub Sponsors unless they are unusually charitable. But I could definitely see my company sending thousands out the door (pre-tax) every year to the maintainers of the libraries we depend on. For example, imagine your team is 15 people. Have the company budget for and send an additional one developer's worth of salary out annually to the open source maintainers, divided among the libraries in a proportion agreed to by the development team. Yes, it's an additional cost line item, but it's the right thing to do and it won't break the bank. Open source has reduced costs dramatically for all of us who use it in our dependencies list. A nominal cost line item on our annual budgets is more than fair.
- DarylZero 5y agoThis makes more sense than blaming the developers. But ultimately the problem is the same: engineers, i.e. employees, don't control the money. They don't have agency to direct the money toward functions other than enriching the people who have the money. They may have more agency relatively speaking than free software developers, but on an absolute scale, you can measure this kind of agency in dollars, and it's a pittance. Maybe they could donate some of their own salaries. Maybe they could get employer matching. Still doesn't seem realistic, but it's closer.
- mbrodersen 5y agoWhy should they? Open Source developers give away their work with a price tag of $0. So why should anybody pay more than $0 for it? Do you pay more than the asking price for things you buy?
- emptyparadise 5y agoIt's morally right. Not everything in the world is a business transaction.
- deleted 5y ago[deleted]
- er4hn 5y agoFilippo, I think that what you are proposing is an unusual, even radical idea. I hope you are able to follow through on it for yourself and that you can inspire others to do so by seeing the path you are marking.
- lumost 5y agoOnce upon a time, the best way to get a software job was to demonstrate your ability to build useful open source projects. 10 years ago the Principal Engineers I would work with had super sized open source portfolio's which leant them both credibility and experience building products people liked. Junior devs would search (sometimes in vain) for issues where they could contribute a few PRs Now the best way to get a job is leet code, leet code, and more leet code. Rather than spending <5 hours a week working with real code and producing real value on open source projects - most career minded engineers will simply focus on leetcode. Not many people patch esoteric software that's been around for 10+ years because it's particularly fun or because there is specific business value in it.
- ogogmad 5y ago> Now the best way to get a job is leet code, leet code, and more leet code. Rather than spending <5 hours a week working with real code and producing real value on open source projects - most career minded engineers will simply focus on leetcode. Maybe more broadly: The only way to prove that you're good at X, is to do X well. An artist is only as good as his portfolio. The same is true for all creative jobs. I'm thinking that these proxies (see all attempts at standardised testing) are a disease of our time.
- didibus 5y agoI'm not sure I fully agree. Doing open source doesn't mean you do it well. You have no sense of how quickly, efficiently and independently they managed to achieve it. I'd much rather hear from prior experience, and probe about situations and scenarios they were in, projects and problems they contributed too, and hear the story of how they went about it, how long it took them, what they did in the face of setbacks and pressure, etc. I have seen first hand developer that are just okay or below average successfully deliver on open source, because you have infinite time, no constraints, no stress and get to choose exactly what you do or contribute. But in a work environment they struggle, given ambiguous problems they struggle, given time constraints they struggle, given changing needs and demands they struggle, working within a team they struggle, given something outside their area of knowledge they struggle, etc.
- jedberg 5y agoWhen I worked at eBay, our policy was that we had to use RedHat and that any open source we used had to be provided by RedHat or we had to get a support contract from someone else who would be willing to 1)Support the software and 2)Accept legal liability if it failed. #2 was the big sticking point. RedHat made a lot of money accepting that legal responsibility, but very few others were willing to do so. It made using software difficult (and a lot of us just ignored the policy). But if you follow this advice, you may end up accepting legal responsibility for the software, and that may be bad.
- AnotherGoodName 5y agoThat edit to the XKCD image is pointless since it's the same joke but worse. https://xkcd.com/2347/ https://xkcd.com/2347/
- dash2 5y agoI maintain a tiny, tiny, unimportant open source package. It gets about 10K downloads a month. Assuming that each of those downloaders saved one minute of their time on average, and their time is worth $15/hr, I'm providing a service worth $2500/month. I'm starting to think, how could my next project provide the same value, and get paid for it?
- JJMcJ 5y agoHmm, 25 downloads at $100 per month would do it.
- moksly 5y agoThe alternative to what we have now is not going to be a healthy OSS community. The alternative is going to be big companies insourcing more of their libraries. The only reason why OSS has seen the up-pick it has is because major companies profit from it. Microsoft didn’t embrace open source because it had a change or morals, it embraced open source because it started making so much more money from enterprise orgs switching to Azure compared to selling us licenses for on-prem alternatives. Facebook and Google don’t share their massive front end-libraries and extensive tools because they are nice, they do so because it helps them dictate web-development and being able to on-board new hires who are already familiar with their tech. If anything, I think it’s more likely that we are going to see a big player pick up a NPM alternative and make sharing packages much harder. I think the fact that no one has done this, should tell you all about how little the enterprise industry worries about the status que. I don’t think it’s necessarily healthy, and I sympathise with OSS maintainers who don’t get paid for their work, but I don’t think it’s a massive issue either. The OSS world is still better than it ever was, and your tech stack isn’t actually in danger if you review that code you use.
- pas 5y agothe mindset is important. MS open sourced things because devs working there pushed for it. it's a good thing even if MS benefits more than others. it's not a zero sum game. the problem is on the other end, where the produced economic surplus is distributed to a very few.
- creamytaco 5y agoReviewing code is the elephant in the room. Filosotile -perhaps out of ignorance or disconnect- fails to mention that the vast majority of open source projects (log4j being a great recent example) are absolute shit. Nobody should be building anything on top, nevermind giving the maintainers more money. In-house development, software BOMs, rising of standards and multiple rounds of code review are the processes that the industry is shifting towards and for good reason.
- watwut 5y agoThe industry is nor moving towards multiple rounds of code review. Nor towards in house development nor away from using open source.
- jpeter 5y agoMANGA should pay them. They have enough money
- geerlingguy 5y agoNo thanks. Maintaining business relationships with $megacorp is one of the primary reasons OSS maintainers (maybe just speaking for myself, but I don't think so) do their OSS work, and don't develop proprietary software and market and sell it around a business venture. If you start writing up contracts or accepting direct payments with any strings attached at all, the dynamic is completely changed.
- WJW 5y agoNot to mention that the dynamic would completely shift in terms of community contributions. If I submit a patch to a free project where the maintainers make nothing, I wouldn't even think of asking for anything in return (even if it is a project used by bigcorps, such as Redis or GHC). If I know that the maintainers get paid a full salary for maintaining the software, it becomes a much weirder thing to send them bugfixes for free.
- kam 5y ago"Sending them bugfixes for free" is both a benefit and a burden to an open source project. It takes maintainer time and effort to review the fix, test, make releases, etc, and that's a thankless job. When a company pushes their patches upstream, they're gaining a benefit for themselves (avoiding maintaining a fork), and potentially benefiting any other users who might be affected by the bug or want the same feature. But they're also adding to a maintainer's workload, and that's often the scarcest resource in open source.
- WJW 5y agoFair enough, but I didn't mean sending in bugfixes because I need it for my employer, I meant sending in bugfixes (or features) to a project that I wanted to make because it bothered me. For example, some time ago I sent in a patch to use better data structures in an event loop library that I think is cool but otherwise don't use. Should OSS devs optimize for my (probably quite rare) use case? Probably not, but the feeling when making a patch for something that I like is still different when the maintainer runs it as a business compared to when they run it as a hobby. (This is what the whole discussion seems to be about btw. Some people like to program in their free time as a hobby and other people would REALLY like guarantees about the software that cannot be made without losing the essential hobby-ness of it)
- qnsi 5y agoCan someone help me find whos idea was it? Basically kill free open source. Make every "new open source" (NOS) program dual licensed, free for non commercial use and paid for conmercial use. He proposed companies paying 1% of revenue to license this software. But it would all go through a proxy company that would gather payment and send it to participating companies, I dont remember how it would be split. I think this is actually a way forward. I would feel better building on top of this kind of stack vs npm ecosystem
- rgrmrts 5y agoDoesn’t answer your question but something I’ve wondered about as well. I don’t maintain any open source software (yet?) but if I were to start a project I’d likely use a permissive license. I don’t want to start a philosophical flame war about licenses, but this idea makes sense to me. The details will likely take work to iron out, but why not have open source licenses with a clause for companies with over a certain amount of annual net profit. Does anyone have examples of this in practice? As far as I know, licensing models like Mongo or Elasticsearch are a bit more binary. I’d be fine letting individuals, small businesses, and startups use the software for free in perpetuity unless they hit some metric like “greater than $x in annual profit” or whatever. I guess a counterpoint to this might just be that companies that get to that scale would just develop the same thing in-house instead.
- slavik81 5y agoWhat you're describing is not an open source license. You seem to be looking for something akin to the Unreal Engine license, which Wikipedia describes as "source-available commercial software."
- rgrmrts 5y agoThanks for that term. I found the Commons Clause[0] that goes along with any existing permissive license. [0]: https://commonsclause.com/ https://commonsclause.com/
- ThrowawayR2 5y ago
- F6F6FA 5y agoI feel this is a problem of companies being cheapskates, not of OSS maintainers. So do not make it their problem. I do not make OSS for companies, but for enthusiasts, contributing to building cool stuff, students and researchers. Don't really want a commercialization of OSS maintainers. Does not seem in the spirit of OSS, but a convoluted way to contract a single dev to work on your stack. If you are this big company, ping your developer advocate, set aside a budget, and have them go through your dependancies and reward accordingly. What bothers me way more, is when companies take OSS and then do not adhere to the license. Not as in forgetting to attribute you, but publishing a patent based on your code and approaches. That's easy enough to kill your motivation if you are doing it for free in the first place. If money becomes an incentive for OSS maintainers, then they will start replying to the emails they constantly get, to buy their extension or use their CDN. Your company bet the house on a poor Polish CS student for logging or useragent parsing? Your, and only your, problem. OSS keeps on working.
- indymike 5y ago> I feel this is a problem of companies being cheapskates, not of OSS maintainers. So do not make it their problem. I do not make OSS for companies, but for enthusiasts, contributing to building cool stuff, students and researchers. I'm starting to do something different at my company. I'm finding the package maintainers for the non-commercial stuff we use in our product and making a donation. I'm also going to start asking the maintainers to invoice my company for support where that is possible to do.
- F6F6FA 5y agoIf this becomes a cultural thing, part of OSS, then more employees inside big companies will start to advocate for funding the OSS they rely on. Companies found to be profiting of OSS, while keeping a closed wall, complaining, but not contributing patches or funding, will lose market mind share, and a percentage of the best developers. Seems doable, but still hard without centralized control and PR.
- ttyprintk 5y agoWhat do you think of hiring maintainers to audit? Answer specific questions about usage and security, with some visibility into your codebase? We’ve talked this over and hit risks concerning access to code where we’d like an NDA that a consultant may dislike.
- wakeupcall 5y agoAs a maintainer of several OSS projects, I could work full time on them and have time for nothing else. Yet, I'm pretty sure that even if these projects would be 100x more popular, the donations I would receive wouldn't even pay my daily expenses. I refuse all donations/tips for three reasons: - as per above, your donation is generally insignificant. it's just overhead in tax accounting - people donate "with strings attached": AKA "here's $2, but I'd really love this feature" - receiving donations wouldn't be fair to any current or past contributors that made the projects what it is The last point is especially true in the OSS landscape. The most front-facing programs get the donations, but the low-level libraries and infrastructure that make them possible get nothing. Heck, I've seen forks with a few superficial tweaks receiving donations and reaping the benefits while the original projects is chugging along slowly at the hard-to-build infrastructure that nobody else wants to do. Bug bounty sites fall almost universally in the last category in my eyes.
- slooonz 5y ago> - receiving donations wouldn't be fair to any current or past contributors that made the projects what it is Hard disagree on that. Maintaining (bug triage, pull requests review, bug fixes…) is actually the hard work and the part that deserve the reward IMO. When I contribute to an open source software to fix a bug/add a feature, my reward is that the software I use has an annoying bug gone/the feature I want. I don’t need any reward. On the other hand, the thankless maintainer deserve it.
- DarylZero 5y agoJust fixing a bug isn't making the project what it is, though.
- etimberg 5y agoI've maintained a popular opensource project for the last 7 years. I finally relented and started a GitHub sponsors profile earlier this year. For a long time I had the same mentality about donations so when I set up my sponsors profile I made it super clear that I wasn't offering any perks for sponsorship. If someone chooses to donate, it's purely as a thanks for my work. Currently I make $6 a month so that covers a couple of coffees. In terms of fairness to past contributors, I put the sponsorship on my personal GitHub account and not on the repo for the project I maintain.
- heisenbit 5y agoGood maintenance requires skills and a steady hand but nobody is going to pay for it. New software is valued much more and thus is the resource allocation. If maintenance is done at all and not shifted to some lower cost organization or country. The Apple App Shop puts a premium on new over working a long time.
- andreineculau 5y ago> Professionalizing the role of maintainer My 2c are that the problem is there, not specifically to OSS. The whole industry is looking down on maintenance and maintainers. Keeping things working might not be a great career, but it's equally important as creating new stuff, and guess what: some people don't want to create but like to debug and maintain. A parallel might be drawn with the right to repair electronics. When we will get back the culture of repairing stuff, then we will value more the act of repairing. Because now, it's an art of repairing that very few afford.
- mbrodersen 5y agoIf course the industry is looking down on maintainers. They give away their work for $0 and then act all surprised and morally upset when people then value their work at $0. Facepalm galore. If you value your work, make people pay for it.
- nobodyandproud 5y agoFor businesses, “free, as in speech” is equivalent to “free, as in beer” because I as a company developer can build it and use it. Even better if it’s a non-viral copy-left license. Why pay for the cow when you get the milk for free? There’s no incentive for anyone to pay and this has become best practice. Anyone remember the uproar over CentOS being retired? There’s this unrealistic expectation that maintainers be paid without a real business model, but that’s what needs to be done. Become a business or being part of a business, and find a cost model that is both appealing to customers and self-sustainable. All which comes with non-engineering headaches, but there’s no avoiding it. What may help here—and the missing ingredient—-is the lack of a professional, trade organization. In fact, this would solve a number of pressing problems in our industry.
- neilwilson 5y agoThere is of course another way to do this. The state offers a guaranteed job and collects tax. Just as it does to maintain the roads. Toll roads became public roads . Earning six figures is a chore and frankly gets boring after a while. But if you had enough to keep the wolf from the door …
- baskethead 5y agoIf the US government had any sense of strategy, they would employ these maintainers en masse, not only to create good will but to make sure that other bad actors don’t get to them first.
- mbarbar 5y agoInteresting idea, similar to research funding I suppose. Do any governments do this, or offer grants for open source?
- jbk 5y ago> Now is the perfect time for Open Source maintainers to become legible to the big companies that depend on them—and that want to get more out of them—and send them five-to-six figure invoices. Well, this is exactly what I've been doing around VideoLAN (VLC, x264) and FFmpeg for the last few years. In order to do that, I've created 2 official companies Videolabs and FFlabs (besides the non-profit orgs) and I've gone through all the hoops to get paid (PO, billing, invoices, registering to large companies is a lot of paperwork, tbh, but well..) and we try and bill small to large companies that depends on those projects. And FFmpeg and x264 are the core of the online video. So I did exactly what Filippo is saying we should do. But the result is really not impressive. Seriously, asking for money for support from those companies feels like we're pulling the nails, even if their full business depends on it. Getting 30-50k$ from those companies for support for one year can be very challenging, long or leading to nowhere at all. So, large SV companies and startup should also start agreeing to pay for open source, when it's the core of the tech.
- keyle 5y agoThat's interesting hey. Just imagine though, how does a company define what is "the core of the tech" and imagine the arguments in meetings between legal and engineering defining those terms. The way this industry has evolved is a complete dumpster fire, where the dudes that glue the pieces together are paid 10X the value the dudes that actually built the hard part!
- H8crilA 5y agoYou need a proper "asshole" in such organizations that will go and threaten complete lack of support if the bill isn't paid. Of course there is a lot more detail in such negotiations, but the fact is that he/she will be facing similar "assholes" from the side of the copros. The entire thing is essentially just a game of standard capitalism. You have to know how to play that game, though. FFmpeg should be able to pull multiple $M per year easily from all the major corporations that use it. For comparison, $1M is the total yearly cost of ~3 average engineers at FAANGs. And most, if not all of them, use FFmpeg quite seriously.
- jbk 5y ago
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- bogwog 5y agoEveryone does open source work for different reasons, and I'm not sure if more money is always enough of a motivator. I have a handful of projects that you couldn't pay me to provide commercial support for because I no longer have any interest in them. Working on boring projects for money is what full-time jobs are for (and most full-time eng jobs are much easier than maintaining a popular open source project). With that said, I could totally see how paid OSS work as the norm would be a catalyst to improving the status quo. It would certainly lead to more and better OSS projects. Even if the current OSS ecosystem doesn't like it, it will 100% lead to new projects and new devs pursuing the money. Maybe part of the solution is to form agencies which work with OSS devs to pursue contracts/sponsorships/donations from commercial users of their projects? The legal/business/sales part of the process is non-trivial. This makes me think of "content creators" on social media that make a ton of money producing free videos/streams. OSS devs are maybe like the B2B version of that? :P
- Jsharm 5y agoAre the salarys on levels.fyi accurate? Looking at Dublin salaries, they seem very high?
- fatcat500 5y agoIf there was a button on Github that donated small amounts of money to the maintainer(s) of a project, I would press it frequently for many libraries I depend on. For example, donating 25 or 50 cents every time I visit gofiber/fiber would be fine with me. However, there is no way to feasibly charge small quantities of money without the majority of it getting raked in processing fees. For example, Stripe charges 30 cents plus 2.9 percent (last I checked), meaning only ~20 cents would make it to the maintainer(s). The same issue exists with rewarding content creators. You either donate a non-trivial amount of money (often recurring) like $10 a month (which means you have to keep track of that expense, which is arguably an even greater disincentive for donating), or you don't donate at all.
- tbabej 5y agoYou can donate small amounts of money to any project with Github Sponsors custom one-time payments enabled [1]. Github pays all the processing fees and the maintainers get 100% of your donation. [1] https://github.blog/changelog/2021-04-06-custom-amounts-and-one-time-payments-rolling-out-to-github-sponsors/ https://github.blog/changelog/2021-04-06-custom-amounts-and-...
- seoaeu 5y agoYou could increase your donation estimate by 10x and it probably still wouldn't be worth the effort. On GitHub, starring a repository is free and yet log4j2 was only has about 1700 of them. Even if each of those was a donation, your suggested 25 or 50 cents translates to only about a single day of a market rate developer salary.
- rubyist5eva 5y agoIt's a double edge sword. They can you use your stuff AS-IS WITHOUT WARRANTY, but if something goes wrong it is AS-IS WITHOUT WARRANTY. We've gotten complacent that open source just exists and is maintained and it's sunshine and rainbows. We've been able to build amazing things on the backs of these maintainers, but you have to factor in that they don't owe you anything. So keep that in mind when you're just gonna install some random library from the public package repository because "not invented here" or something.
- kazinator 5y agoThis is completely wrongheaded. The people responsible for the logging library security are 100% the people who decided to integrate that piece, not some open source person who provides a patch and his three sponsors. The Log4j library has a LICENSE.txt with clauses "7. Disclaimer of Warranty." and "8. Limitation of Liability." The wake up call is that programmers should take responsibility for everything that they integrate, including all that they recursively integrate. If you put it in the image, it's your fault.
- philosopher1234 5y agoThere should be an umbrella company that takes ownership of a large number of major projects, charges a single licensing fee and grants access to all of them or none of them. It should remain free to amateurs and should be free or cheaper for small businesses.
- bawolff 5y agoCompanies barely spend money on their own internal security dept. It seems like it would be a hard sell to convince them to spend money on improving an external projects security posture. Maybe if it was core to their business, but investing to imorove the security posture of a logging library seems like a hard sell.
- ralph84 5y agoIt's a bit dubious that paying maintainers more will make them write more secure code. Certainly professional developers who write closed source have produced plenty of vulnerable code in exchange for their six-figure salaries. If you're really concerned whether a particular open source package is secure, it'd make more sense to pay a third party to audit it than the maintainer.
- trinovantes 5y agoEven if you dual license your software with AGPL/Commercial license, there's still companies that just plain ignore them. I was doing some scripting on my PDF bank statements and discovered they were generated using iText (AGPL version). Imagine a multinational bank blatantly violating copyright laws let alone expecting them to pay for open source.
- imglorp 5y agoI liked that analogy to paying a law firm. Most of these companies spend more on greenhouse services to keep plants in their offices than they spend supporting the F/LOSS stuff that they built their product around. That's how it should be viewed. The Faangs probably have on the order of 100m boxes running Linux etc. It would be totally reasonable to expect they would pay someone $1/year/box to help maintain all the F/LOSS in there.
- bluefox 5y agoMaybe businesses should pay a tax that goes into paying a respectable universal basic income. That would make it easier to develop and maintain such software, and it would make it easier for people doing other things besides software development (yes, they exist) to open up their artware without starving. Then there wouldn't be a need for the insane "professional" formalism described in this blog post.
- ozfive 5y agoThis assumes that large companies are willing to pay in the first place. In my experience most companies if they can get something half-developed for free. They will jump on it and think nothing further of the ramifications in the future however near or far that is. Any business that operates on that level deserves what is to come.
- rch 5y agoIt seems like Stripe Atlas could be adapted to help people formalize side projects, with invoices and subscriptions, while providing guardrails to keep from having to worry too much about the minutia of business, taxes, fees and so on.
- fleddr 5y agoApart from the discussion that nobody will pay, have you considered that companies aren't even remotely aware of what they use?
- Jupe 5y agoI don't know... I just don't see how OSS will ever be a real, sustainable business. The moment it does, someone else will simply subvert the paid-for software with a look-alike that does 90% of what the original does, but for free. In my view, this is the birth story of OSS. And I don't see any real market there. Even if you manage to find a "niche", like some sustainable software-as-a-service with subscription, there's nothing stopping someone else from undercutting you... all the way to "completely free". Moreover, isn't this what's happening to most software, everywhere? Cases-in-point: Compilers - when's the last time you actually paid for a programming language? I know for me: SAS C in the mid 1990's Databases - any new solution would likely use a free DB.. and why not? Digital audio workstations - "free" ones seem to come out monthly Graphic editors - 2D and 3D alike - the free varieties are getting better every year Developer IDEs - From console editors to full GUIs to online offerings; all free Even the business model of "hoping to make server software so good that everyone wants it" fails when hosting services just grab it, re-package with their own branding and profit.
- mbrodersen 5y agoYep. Open Source developers who give away their work for $0 are undermining their own value and the value of other peoples skills. Open Source should always come with a commercial license for companies.
- O_H_E 5y agoHey @mbrodersen, this is really not appreciated here on HN. This pasting of what is essentially the same reply on every top-level comment is borderline spam.
- mbrodersen 5y agoAre you a spokesperson for HN or a spokesperson for the HN community? If not then perhaps limit your comment to saying that you don't like it? That's fine. We all have our opinions. I (for example) personally don't like people who pretend to speak on behalf of other people when all they are doing is expressing their personal opinion.
- dalke 5y ago> Open Source maintainers graduating to sophisticated counterparties who send invoices for "support and sponsorship" on letterhead, and big companies developing procedures to assess, approve, and pay them as a matter of routine so that they can get what they need from the ecosystem. The first 1/2 already exists. It's the companies which need to change. I say this from experience. I'm self-employed, with my own company. For the first 15 years my plan was to provide commercial support for open source packages I worked on. I had an LLC, an accountant, I paid a designer for a logo, etc. I co-founded the Biopython project and offered commercial support for it, with a couple of other Biopython developers under NDA so we could work on commercial projects that used Biopython. Any interest? No. I started an open source package for high-performance molecular similarity search. This got some funding, mostly from personal contacts at companies which wanted new features. And people used it. In fact, at one conference a speaker gave a talk based in part on the results of my software. He commented correctly that it's very hard for a company to spend money on software they get for free. I commented, correctly IMO, that I offered support contracts, and support is easy to justify to management if they really cared. (Over the course of the conference, I learned what they liked best of "free software" was it is 1) available for no cost, and 2) doesn't come with string attached - they didn't want to care about upstream.) My story isn't unique. I'm not the only one to try the "sophisticated counterparty" route. LLCs are cheap. The real onus is on the big companies. And since that's not going to happen, I now offer proprietary licensing for my once FOSS-only software.
- mbrodersen 5y agoIf you offer your work with a price tag of $0 then people/companies will pay $0 for it. The nativity of open source developers thinking otherwise is jaw dropping. So yes I agree that commercial licensing is the way to go.
- dalke 5y agoYour view of the "nativity of open source developers" is itself naïve. To my understanding, most people who want to get paid a reasonable amount to develop FOSS go one of two routes. 1) Service-oriented, à la the Cygnus Solutions (now Red Hat) approach. FOSS developers get paid to fix bugs, add features, answer questions, and provide training. This has been my approach. 2) Employer cost savings. Work as an employee for a company which saves money by developing software, but where the employer is not interested in bringing it to market. See the section "Professionalizing the role of maintainer" of the linked-to essay for other examples of what a company might get through funding a FOSS project. ("security practices, like two-factor authentication and mandatory code review", etc.) None of this is "work with a price tag of $0", and the very essay we're talking about gives counter-examples to your interpretation. Furthermore, I tried selling FOSS software for a fee ($30K, not $0), and simple commercial licensing doesn't work either. Commercial proprietary licensing addressed certain economic problems that commercial FOSS licensing didn't resolve.
- DarylZero 5y agoThe real solution is to throw out all the crap at the top of the stack, get down to simpler and simpler code that can be maintained by the people autonomously without corporate involvement. E.g., Gemini.
- KingMachiavelli 5y agoIt would certainly help if the IRS did something to encourage open source. You can donate a work of art to a museum for a deduction but you can't donate 20 hours of labor. The IRS is deliberately becoming more strict [1] so many current non-profit software foundations e.g. Apache are actually the exception to the rule.
- WesolyKubeczek 5y agoThere's a whole old elephant in the room, but we're not really talking about it because it's an elephant everyone loves to hate. And yet. This is a model that MPAA and RIAA use. And their equivalents in countries that have functional copyright legislation. Most first world countries have one. Don't get me wrong, they are mostly rent-seeking racketeers, but if you try to weasel out of paying for stuff you're using for your own profit, you're bound to get one. Either some law pertaining to maintenance of "digital commonwealth" or some other nice name is passed in enough countries so other countries have to follow suit if they want to be in good company, and organizations with teeth, one per country, are set up to make sure the "digital commonwealth" tax is collected from everyone, big and small. They will even distribute money among creators, by usage or something. Microsoft would probably love to be such an arbiter. They have Github. They have all the stats. They know if your company had been naughty or nice, how many times they downloaded your stuff, and how many times their employees were demanding shit in issues. It's child's game to join the party, just have an account with them. Or we just piggyback on the existing copyright legislation and give RIAA and their likes more power and custody of making sure OSS maintainers don't starve. They will surely protect their interest with eagerness, who wouldn't like more profit? Of course, companies will try to fight tooth and claw. They will tell you all sorts of doomsday scenarios, how the poor megacorporations won't be able to afford it, how they will have to raise your subscription fees. Gee, haven't we seen those crocodile tears when free roaming in EU was going to be established? We also know how it ended: they all sucked it up, complied, maybe their profits took... well... not a hit, but a nudge maybe. Companies who have to buy music know how to pay the music tax to copyright racketeers. They will get used to that. They will also be happy to pay just one entity and be done with it. And if you dare start a company using F/OSS, you're in for the largest financial hit. The little man always suffers the most in such schemes.
- ItsBob 5y agoDoes this not mean it's time for a new open source license? Perhaps one that stipulates all the freedom current ones have up to a point? I am not a lawyer and know little about open source but is it possible to create a new license that allows free use up to a certain revenue level?
- johnny22 5y agosure, and I think I've even seen one. The problem is, your software won't be included in any distribution repositories anymore because it is no longer Free Software under whatever definition they use (likely based on Stallman's "Four Freedoms") Some similar things have happened to mysql (to mariadb) and mongodb (to whatever the fork is called). Dual licensing it like MySQL did is one way to approach it, but plenty of people were happy enough with what it did that they didn't pay for it.
- jokethrowaway 5y agoThis is happening because we created a culture that glorify an ideal, Free Software, over practical concerns. OSS is communism applied to software: it doesn't make sense and it doesn't work. After a few generations of idealistic people who sacrificed themselves and worked for free to give us foundations, most of OSS nowadays is just: - Advertising to let engineers know that company X is cool and you should go work for them - Ways to keep your staff motivated (who doesn't want to become a OSS rockstar?) - Advertising to sell an actual business I'd rather live in a world where companies are building and maintaining software and reselling it to other companies. Unfortunately we made it sound uncool, somehow. Pay your invoice, get your token and npm install @user-agent-experts/ua-parser I'm not necessarily against open source and I certainly benefit and contribute to it; OSS also has the benefit that more people can spot bugs and end users can fix your shit when it's broken. Still, I would never maintain something that allows companies to use it for free. It doesn't make any sense, no matter how much code the companies are publishing.
- pbiggar 5y agoHere's something I wrote in 2018 that could basically be the exact same thing written today: https://medium.com/@paulbiggar/how-to-fund-open-source-8790e42e10fe https://medium.com/@paulbiggar/how-to-fund-open-source-8790e...
- dkjaudyeqooe 5y agoWhy not start a foundation, or even a business where companies and individuals can voluntarily pay for open source software, like an online store? Different projects have different prices, but you can pay more. The money is forwarded to project maintainers was wages, but a "tax" is applied so that some money is redirected to small but growing projects. Projects that see sufficient income would be certified as having certain level of guaranteed support, based on the fact that they essentially have a staff to maintain the project. The entity would ensure and manage this. Some of the money would be used to fund this process.
- WesolyKubeczek 5y agoYou used the word “voluntarily” here, and it’s going to be the singular reason it won’t work. Corporations ever do anything voluntarily if the alternative is tangibly worse, evidently more expensive, or existentially threatening, especially in short to middle term.
- mbrodersen 5y agoNobody pays for anything they don’t have to pay for. Surely that shouldn’t be a surprise to anybody living in the real world?
- ChrisMarshallNY 5y agoOne thing that I constantly think, when reading about these Jurassic-scale disasters, is "where are the wise, conservative stewards?" I've been appalled at the way that older, more experienced developers are treated, and am not surprised at this. There's a really good chance that many of these bugs were introduced by developers that are now older, and more cautious. In some cases, these may be the harsh lessons that caused these developers to become more conservative, these days. A conservative (not political "conservative," practical "conservative") approach is generally best, when maintaining infrastructure. Be careful, test well, don't "push the envelope" too much, and, for God's Sake, don't add new stuff, until you have the old stuff completely tested, documented, and supported. New stuff can be added via forks, and introduced via carefully-vetted PRs. I keep thinking of the Linux core kernel project as an example of how to do it right, but I am not very involved in that ecosystem, so it may be a case of "the grass is greener on the other side of the fence." I can tell you that I take each of the tools I make, very seriously. A quick shufti at any of them will tell you that. No one really uses them, but that's fine with me. I write them for myself.
- qwerki 5y agoIt's great to see more discussion in this space. The way I see it: 1) It's really difficult to donate to Open Source; 2) Companies don't get enough value in exchange for donating – They are businesses and think in dollars & cents; 3) and, Devs much prefer to write code rather than chasing companies for donations & sponsorships. As a result of these dynamics, OSS is very mispriced at the moment. Unfortunately that is going to impact quality and we shouldn't be surprised by the Log4j bug.
- zajio1am 5y agoFor BIRD Internet Routing Deamon, we solved financing issue by offering support contracts ( https://bird.network.cz/?support https://bird.network.cz/?support ). If you develop free software that is mission-critical for some companies, then it makes sense for such companies to pay for support both to get developed features they need and to ensure there is someone to help them if something unexpected happens. Even in cases where no real support is needed and the contract is de-facto sponsoring, i guess for many corporations it may be more acceptable to bill it as support.
- davidgerard 5y agoThis essay looks like the business model for free software since Cygnus, thirty years ago - and yet, here we are. I have asked if he has a version that addresses the history of these ideas, and how they've worked out - because the history is a very long one. I would suggest moving away from permissive licenses, which are "just take my stuff." Companies don't even throw in their alterations. Stallman was 100% right about the importance of software freedom, and strong copyleft. AGPL more of the things. AGPL your latest Rust libraries.
- titoCA321 5y agoCompanies do submit alterations. Whether or not it's adopted into the streams is a different matter. Some don't submit but many do. The real problem isn't contributing to open source. Companies have teams of developers that contribute packages to open source projects as part of their portfolio of duties with the company. The problem is no one wants to work on the day-to-day issues that need maintaining to keep the project afloat. Sure companies will pay to incorporate this feature and that feature and the community will submit this bug-fix on this new widget, but day-to-day maintenance to keep the code base alive is left to bit-rot. It's like the newspaper website for your local town. There are links to and from older stories that lead to broken webpages, but no one wants to update the links yet new content is posted on the newspaper's site each day.
- iso1631 5y agoI have problems raising a PO for $10, it's a massive hassle to go through to explain to people nowhere near my department how it works Spinning up an AWS instance costing $10 a month is trivial because the buisness has decided to empower employees with unlimited funds to spend on it. So how can I spin up a $10 a month "instance" which goes to say ffmpeg developers, or apache developers, or openjdk developers, or whatever, with only a small overhead going to AWS and the majority of that money going to the people my business relies on.
- seoaeu 5y agoOne of the core points in the original article is that the invoices should be for 5 or 6 figures. $10/month = $120/year quite simply isn't worth the effort to collect
- alecthomas 5y agoI maintain a lot of open source projects, but IMO this is not the right approach. I think the [anecdote from @jbk](https://news.ycombinator.com/item?id=29524103 https://news.ycombinator.com/item?id=29524103) about ffmpeg illustrates that. I also don't think the problem it solves gives the greatest benefit for the amount of work required. I think making it easier for companies to pay open source contributors is the right approach. For any company that builds software, finding and paying the open source projects they use is a massive amount of work and there's nothing that helps with that. If there was much less friction to paying maintainers, more companies would do it. I would love to see a tool that, given a pool of money, will collect dependencies from projects in any language (extensible), find the authors (git commit history, etc.), find where they accept contributions (extensible), and pay them, based on both computed and hand crafted weights.
- fri_sch 5y ago> I think making it easier for companies to pay open source contributors is the right approach. Making it easier and making it a common habit. Companies need to realize, that paying maintainers/contributors pays off for them. > I would love to see a tool that, given a pool of money, will collect dependencies from projects in any language (extensible), find the authors (git commit history, etc.), find where they accept contributions (extensible), and pay them, based on both computed and hand crafted weights. Looking at https://flossbank.com/ https://flossbank.com/, this seems like just what you describe. I don't know how it works exactly, though.
- alecthomas 5y ago> Making it easier and making it a common habit. Companies need to realize, that paying maintainers/contributors pays off for them. Definitely agreed. > Looking at https://flossbank.com/ https://flossbank.com/, this seems like just what you describe. I don't know how it works exactly, though. That looks ... related, but I _detest_ that it relies on injecting ads into package managers. It's also not extensible. I think an open source tool would be preferable so that incentives don't get skewed by for-profit motives. I would also prefer if the payments didn't go through a single company. Paying developers through GitHub Sponsors, Patreon, Flattr, or whatever their preferred mechanism is.
- travisgriggs 5y agoWhat always strikes me about the XKCD picture is that there are so many problems before we get to the punchline. The picture paints a picture of complexity through layering and centralized liability through the one lone leg. Even if that one leg were well staffed and funded, it is still a centralized liability. There are any number of problems that occur when you have a single spot liability, beyond just “we’re depending on a few people’s goodwill.” I wish we lived in a world where when we see that picture we stress less about the paucity of volunteer developers and instead observe, there should be more legs right there, redundancy would be good. Interoperability would be good. I wish we lived in a world where when we saw that complexity we said “it’s nice to reuse, but simplicity of algorithm and design should still trump quick select complexity.” The file formats, protocols, design patterns, languages, that should get people excited on HN are the ones where you can learn/implement/understand it in a day. Not the ones where we build artificial mountains of complexity and then celebrate those that put in the time to become gurus sitting atop of the arbitrary mountains we’ve built.
- quicklime 5y agoI built and maintain a small open source tool. It's a very niche tool that is useful for some big enterprises, but not really useful anywhere else. When I built it, it was great to learn about some interesting new tech, and scratch a personal itch. But by far the biggest reason I keep maintaining it is the community. Every once in a while (maybe once a month or so) someone randomly comes up to me (in person, or in a chat) and says thanks, and tells me about how this tool saves them a huge amount of time and makes their life so much easier. Would I want to be paid by a company, in exchange for providing features and support to them? Fuck no. That would kill any joy I had in doing this. Why would I want to ruin the fun by having to adhere to a timeline set by some corporate project manager? If a company wants to help, what I'd much prefer is that they help out with the boring stuff. Pay someone smart to triage bugs for me, provide first-line support, write user docs, all that stuff so I can focus on the fun parts.
- bfung 5y agoAnyone know of examples in the US for OSS backed by a non-profit specifically setup for OSS maintenance? It then takes the profit motive out of the equation, mostly
- urthor 5y agoI do wonder if we need a new type of copyleft license free and open source license that permits only free noncommercial use. Commercial use should bring with it a much difference set of obligations than non-commercial use.
- kello 5y agoSide note but not captioning the xkcd graphic and modifying it is a bit sleazy. Yes, it is mentioned in the following paragraph but a caption would be better.
- tbonesteaks 5y agoI think think the size and niche of the open source project matters too. Just because you wrote a logging library or a parser of something that lots of people decided to use doesn’t really seem like a reason for companies to sponsor or pay for support. It’s a very small dependency. But, if it’s a database or a voice server or a web server even, those seem like something that can’t easily be replaced, so companies probably sponsor or pay for support more often. Am I wrong in thinking down this avenue?
- strenholme 5y agoOh, yes, open source economics. Everyone wants to use open source, no one wants to pay for it, a large number of entitled people get angry when you don’t provide support or implement their feature request for free...I’m sure anyone here who has done an open source project notable enough to make the Wikipedia has seen all of this. To keep my sanity, I had to enforce strong boundaries: No, you are not a customer until you start paying me like a customer (lots of entitled users think they can have the same relationship with an open source developer as they do as a customer of a company). No, telling me how you’re an important person or part of an important organization doesn’t change my tune, unless you’re willing to show me the money. No, you do not have a better idea which features would make my open source project more popular than I do. No, I will not support you for free via email; if you want support, you either pay me or we do it on the public mailing list. No, that’s not a security bug; that’s a feature request, and, no, I will not implement it just because you want me to. Because I have done all of this, I am able to continue to maintain my open source project today, because the boundaries I have set up are basic self-care: Trying to please every random entitled Internet user leads only to burn out and abandoned open source projects.
- mbrodersen 5y agoYou provide your work with a price tag of $0. So people/companies pay $0. What’s so hard to understand about that? You give away BMW’s for $0 and the same thing will happen. You are signaling that your work is worth nothing. So people then expect you to do more work for nothing. Yes of course! You yourself value your work at $0! And the world then agrees. Don’t be naive and expect otherwise.
- strenholme 5y agoJust because a blob of code is free doesn’t mean the support is free, and it has been this way for a very long time. Have you ever seen how much an email-only 1-year support contract from ISC costs (clue: Five figures)? In the real world, free but pay for support is a reasonable expectation. RedHat has been doing it since 1993. Even with end user software, freemium has been a thing for quite a while. I see from your posting history that you’re pushing variations of this “they didn’t pay for this, so your time and effort is worthless” notion. I can’t be sure you’re not trolling; I will assume good faith and think you actually believe this ridiculous argument. Frankly, to pretend that free code with for pay support doesn’t exist comes off as entitled to me. Let me explain to you how classic open source works. The idea behind open source is this: The relationship between users and developers is different with an open source project. In return for getting code for free, instead of having the relationship a customer of proprietary software has, where the only way to implement a feature is to ask the original developer to implement it, we instead have a relationship where you can get any feature (or bugfix) you want, by simply providing a patch or pull request. The code is free, but the support is not free. Linux is a classic case of this: Sure, you can get the kernel for free. Sure, you can download a distribution for free. But, as soon as you ask for support, the company tells you they will change you so much $$$ per networked computer to get service and support. It works really great when a lot of developers and companies contribute patches and bug fixes for free, in exchange for getting the software for free. It works not so great when entitled users think they have a customer to company relationship with open source software. Hence, the hard boundaries, and the resetting of expectations. I used to have a “I don’t support my open source project for free in private email any more, and if you reply to this demanding support, I will make this email exchange public on the mailing list” canned reply. I only had to make the exchange public once over a decade ago; most people got the message. I even occasionally had someone throw me a few bucks. My project? I still maintain it, because my boundaries keep me sane. I’ve only have had one rude entitled user whose bug report I had to delete from GitHub in the last decade; since then I just lock the conversation after giving them the “no, I don’t support that” spiel.
- noway421 5y agoThis can work, if there's a sales team attached to the company that actually goes out and sells the idea of paying money to the open source project. For a maintainer to do an SDR and a salesperson job is just not sustainable - they are not good at it and it will take them a lot of time that they can spend writing code. Instead, you could set up a structure where open source authors set up an LLC, and then get a salesperson hired on a revenue-based retainer. The salesperson then actually goes out and talks about "supply chain attacks" and "open source sustainability" to the target companies and tries to close deals with them. Maybe they can even work on stuff like "vendor approval assessment" and other paperwork. Maybe the salesperson hires more people that actually do the paperwork and sales development, and the salesperson themselves only does the closing. That way, the maintainer continues to write code and now it's a salesperson who actually brings in the revenue. You can even set up a marketplace startup which caters to this whole workflow. 2 user types: open source authors and salespeople. Open source authors can create an LLC with a click (integrate with Stripe Atlas?), then they go into 'Call-for-salesperson' directory, put out a listing saying we're so-and-so open source project with 10k stars on GitHub, come represent us. Then on the supply side, a salesperson sees the listing, writes up a proposal which might include a percentage fee they'll receive from the sales (say 25%). After receiving a few offers, open source author can choose who to go with. Maybe if it doesn't quite work out with this salesperson, they go back and re-list. Just a quick idea on how this can be solved with a marketplace model. Everyone in this structure is happy: open source authors get money, salespeople get their percentage fee, corporations get sustainable open source projects.
- akagusu 5y agoAll this crap is not maintainers fault. Companies do not want to pay, this is the reason they use FOSS code in the first place. Do you want to force every single company that rely on FOSS to pay? Change your license. Stop using permissive licenses like MIT or BSD and license your project with GPL. Companies will have 3 choices: use your GPL licensed code and make their software GPL too, which they don't want to; pay you in a dual license scheme, so they can keep their code proprietary; develop themselves every piece of code they need. They don't want the first option, so they will pay you or they will pay an employee. In both cases, they will pay.
- baud147258 5y agoor maybe they will stay on an older version, which would be covered by the permissive license or just switch to another software
- CryptoPunk 5y agoMaintainers should start issuing NFTs and offering them to parties that want to support their work, and companies should create digital showcases displaying which NFTs they've purchased. The showcase can be a simple OpenSea widget showing the NFTs owned by a particular address.
- overready 5y agoWhy not start with the project being non-open-source and have a bounty to make it open source?
- autarch 5y agoI'm the creator (often with others) and maintainer of some very popular Perl distributions that are used either by many other libraries, many applications, or both. The most notable are probably DateTime (https://metacpan.org/dist/DateTime https://metacpan.org/dist/DateTime), Log-Dispatch (https://metacpan.org/dist/Log-Dispatch https://metacpan.org/dist/Log-Dispatch), and Exception-Class (https://metacpan.org/dist/Exception-Class https://metacpan.org/dist/Exception-Class), among many others. The first release of DateTime was in 2003. In 2008, I added a "DONATIONS" section to the docs, and around that time I started adding it to everything I released. It was basically just a link to web page with a PayPal button it, so not very professional. Over the years since I started doing this, I'd estimate I've gotten somewhere between $1,000 and $5,000 (PayPal doesn't offer historical data far enough back to know for sure). On the one hand, that's a lot of "free" money. OTOH, this is software that has been used by absolutely massive companies, including Amazon (which I know for a fact used a lot of Perl in the early days, including things I worked on). So even $5,000 is an incredibly small fraction of the value this software generated. Almost all of these donations were $100 or less and seemed to come from individuals. I can only recall one instance where someone asked for an invoice first, after which their company donated $500 (or maybe 500 euros), which was nice. So this is just another data point. And then I realized that this link has been broken since some time in 2018. Doh! I'm fixing it and adding a "email me for an invoice" bit as well. It can't hurt.
- jayp1418 5y agoCheck this it might help https://artlessdevices.com/ https://artlessdevices.com/
- pabs3 5y agoSome resources on how to get paid for open source work: https://github.com/fossjobs/fossjobs/wiki/resources https://github.com/fossjobs/fossjobs/wiki/resources
- AtlasBarfed 5y agoDo businesses pay for roads? This isn't a problem of shaming businesses. This is a government and multi-government concern. It's a national security issue. There should be BILLIONS of dollars of funding coming from all portions of governments: the military, universities, regulatory agencies, research agencies, any and all departments using IT systems. Corporations don't even need to fund it. They just need to have the government fund it.
- eyelidlessness 5y agoThere are a lot of replies and I can’t go through them all. But I think now is as good a time as any to start thinking about a free-as-in-speech-but-NOT-free-as-in-beer license. Free for open source works really well for hosted pricing. I don’t know what legal barriers there are, but a free for open source/explicitly paid license for corporate use model would probably help alleviate a lot of this. Edit: and of course such a license could waive fees for contribution, stewardship, good faith involvement that keeps the project healthy.
- throwaway47292 5y agoI can make an argument that money will make it even worse, as people will full-time make even more useless features that just increase the attack surface. This particular class of problems (same as the sqlite fts tokenizer exploit and most of openssl exploits, even lots of the sendmail exploits) are just obscure unused features. It happens even in CPUs themselves. (e.g. https://www.youtube.com/watch?v=lR0nh-TdpVg https://www.youtube.com/watch?v=lR0nh-TdpVg) Removing code is twice harder than adding code, why do you think paid maintainers would improve anything? Just look at the code written in FAANG or any enterprise, and those maintainers are very well paid, imagine this code being public, we will have 1 new exploit per day per company... and that is assuming non malicious developers that can be shipping trojan code https://lwn.net/Articles/874951/ https://lwn.net/Articles/874951/ (it is also hard to assume all millions of developers are non malicious, even if we assume 1 in 100000, things look really bad) Less code is the one solution. Regardless if open source or enterprise code. We are stuck, and change is needed, but money is not a solution, and might even be the cause of the problem. (incentive to write more code)
- charsi 5y agoHere is an idea. Make your code royalty free for up to 364 days a year. "MIT-364" is a catchy name right ? Any company that cannot afford to go without your software for 24hrs per year should pay full whack for a commercial license.
- renuac 5y ago1705025: snapuserd: Remove assertions from daemon | https://android-review.googlesource.com/c/platform/system/core/+/1705025 https://android-review.googlesource.com/c/platform/system/co...