Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <87mrv4poxj.fsf@hope.eyrie.org>
Date: Sun, 02 Aug 2026 07:39:04 -0700
From: Russ Allbery <eagle@...ie.org>
To: Peter Gutmann <pgut001@...auckland.ac.nz>
Cc: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Some Changes to GNOME Security Tracking

Peter Gutmann <pgut001@...auckland.ac.nz> writes:
> Russ Allbery <eagle@...ie.org> writes:

>> One solution that anyone in open source software communities has heard
>> about for decades now is to turn open source software maintenance into
>> a job with a paycheck. Then it doesn't necessarily have to be fun

> It can still be fun, and in some cases more fun than pure open-source.
> Consider the difference between "we have a practical real-world problem
> that we need solved, there's real-world demand for it, we can describe
> it in detail, and we'll pay you to solve it" (commercial user) vs "i
> have some me-only feature that I want you to add to your code just for
> me and I'll whine endlessly on Github/Discord/whatever if you don't"
> (open-source).

Speaking as someone who has structured his entire career to be in the
first position that you describe, you're preaching to the choir on this. I
completely agree; part of the reason why I do less open source software
work in my free time these days is because I get paid to do it as part of
my day job and that comes with a much more satisfying and meaningful
problem stream to solve.

I'm not saying that open source software becoming paid work is bad. It's
great, I love it, I highly recommend it if you can arrange it.

My point is a little bit different than that. First, I'm a lot more able
(in terms of time and emotional energy) to do the annoying, obnoxious
tasks that make the software ecosystem more robust if I'm getting paid to
do them. And second, we don't know how to pay people for all of the open
source software that's out there today. We have tried a whole lot of
business models over the thirty-odd years that I've been following open
source and free software, and we've made some of them work for some
people. But we have never come up with a reasonable replacement for that
*vast* sea of hobby projects that fill in all the cracks and smooth over
all the sharp edges and provide all the irreplacable small tools for which
there is no large corporate benefactor.

Necessity is the mother of invention, so perhaps if we make volunteer
software maintenance sufficiently miserable that people start abandoning
the important small projects left and right, we will discover a way to pay
others to pick up that maintenance. I think I already see signs of that
happening in the Python ecosystem. It would be nice if we could do that in
a way that respects the existing volunteers and isn't hugely disruptive,
though, and that's the part that I don't feel like is happening.

(I am also somewhat cynical about what's going to happen to many of these
paid open source software models when the massive venture capital funding
stream for AI dries up, as it inevitably will like every other windfall
tech funding stream in the past has dried up, and the sector goes through
another massive contraction. I'm old enough to remember the dot.com
crash.)

> That's an extreme for illustrative purposes, but with commercial users
> you've got direction and focus while with open-source you've got a kind
> of free-for-all where people want this and hack in that unless you have
> a strong benevolent-dictator model or small group of maintainers who
> screen everything to keep the codebase stable and bells and whistles to
> a minimum.

Yes, I agree. There is real benefit to filtering work based on whether
people care enough about it to put actual resources into accomplishing it.

But there are also real problems with using money here because money is
not as fungible for open source developers as it might appear. There is a
*huge* threshold problem: The states of "I maintain some open source
software as volunteer work in my free time" and "I have stable employment
with a reliable salary as an open source developer" are separated by a
vast chasm of financial and resource complications. A lot of the positions
in between, in the middle of that chasm, are only livable for people who
are very comfortable with contracting, fund-raising, and unstable incomes.
For everyone else, there is often a hard ceiling on how much volunteer
work they can do, even if they're getting tips and other irregular
payments, because their full-time job has to take priority. And whenever
there's a hard ceiling, the parts of the job that suck are, quite
reasonably, not the parts that are going to get prioritized.

-- 
Russ Allbery (eagle@...ie.org)             <https://www.eyrie.org/~eagle/>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.