Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It would probably be more sustainable if the companies that depend on 100s of FOSS OS'/libraries/applications/etc to generate billions of dollars in profit would contribute more significantly.


That's not how companies work.

Individuals have agency over discretionary spending, in other words you can wake up and decide to donate money, hire a OSS dev, and so on.

Because you personally have that agency, and because companies have lots of money, you project that agency onto companies.

But that's not how companies work.

People at companies have very little personal agency when it comes to spending money. Spending has to be approved, justified, and some value has to be received.

FOSS basically is (mostly) incompatible with this model. Some companies do pay staff to work on OSS but it's rare (and exclusively tech companies with a motivation.)

So while your statement is completely true, it's also not possible.

It's important to recognize that donations and corruption are indistinguishable, and company finances tend to be set up to avoid corruption.


> It's important to recognize that donations and corruption are indistinguishable, and company finances tend to be set up to avoid corruption.

Other than the humor in this sentence, I'm not sure why it would be limited to donations. They can hire devs to work on FOSS.

> People at companies have very little personal agency when it comes to spending money. Spending has to be approved, justified, and some value has to be received.

Approved by... people.


>> , I'm not sure why it would be limited to donations. They can hire devs to work on FOSS.

These FOSS we personally use. And FOSS we don't. Most of the FOSS we use already has plenty of paid devs. Think Linux, Firefox etc.

But what about small projects? How does that hiring conversation go? How do I explain my hiring request to my supervisor? Why am I spending 100k a year on a text editor? Why have I mandated we use my cousin's text editor and we're paying him to write it? When there hasn't been a significant update in 2 years? When we had to layoff staff to make mandated cost cutting?


> Why am I spending 100k a year on a text editor? Why have I mandated we use my cousin's text editor and we're paying him to write it? When there hasn't been a significant update in 2 years? When we had to layoff staff to make mandated cost cutting?

Wow. What absurdly unfair examples.


They serve to show why random OSS projects are indistinguishable from corruption.

In other words how do I choose which projects to support? How do I detect when said support is above board or when there are other factors?

You may take issue with the specific example but "hiring OSS devs", or worse making OSS donations, look exactly like this (if not as blatant.)

As a business owner How do I know these decisions are made in good faith? As a shareholder how much of this am I prepared to tolerate?

Those businesses making "billions in profit" have very high levels of accountability. Lots of people care deeply about that money.


> They serve to show why random OSS projects are indistinguishable from corruption. > In other words how do I choose which projects to support? How do I detect when said support is above board or when there are other factors?

Same argument can be applied to closed-source software. For example, how do you decide which vendor is your company going to select for their internal or external business. Why did you choose Cisco security solution over Fortinet or whatever other alternative there is? Is it corruption in terms of "I know this guy in Cisco" or is it "their solution is the most powerful"? Essentially, as you say, it is indistinguishable. I don't see how this is any different than to select some FOSS project to support if it generates your company/product a value.

Reason why companies aren't paying for FOSS is simply because they don't have to. And also there's no business on the other side to buy something back from you which is many times the case with B2B deals.


>> For example, how do you decide which vendor is your company going to select for their internal or external business.

Selecting software (commercial or OSS) is no problem. And OSS bring free is a plus in that column.

Paying for commercial software is easy. They give us an invoice, and we pay it. OSS has donated button on a web site. There is absolutely no motivation to click it, and indeed clicking it leads to all kinds of extra hassle and work.

OSS has no business model. That makes it hard for companies that are used to business.


> Reason why companies aren't paying for FOSS is simply because they don't have to.

Yup. All this other stuff is just noise: this is the real reason.

If I ran an open source project that businesses used, I could make something that looked exactly like an invoice for a piece of commercial software, but say it's optional to pay, and companies would -- completely correctly -- not pay it.


> How do I detect when said support is above board or when there are other factors?

> As a business owner How do I know these decisions are made in good faith? As a shareholder how much of this am I prepared to tolerate?

Hypotheticals that I'm not going to bother trying to answer, because that's going to depend on the business, the business owners, the projects they choose to support, and a myriad of other factors. Good luck getting some generic answer to such questions.

> In other words how do I choose which projects to support?

You're right. Impossible to decide, so let's not even try.

Or, like, do some research and have a discussion to determine which of the various FOSS your company uses that could do with some funding. Evaluate them individually. Decide on a monetary limit. Re-evaluate regularly. You know, normal business accountability things, right?


> You know, normal business accountability things, right?

No, not at all. A normal business accountability thing would involve not paying for something when you don't have to. Or, rather, not paying when paying doesn't grant additional value beyond what not paying gives you.

For the most part, a company that uses an open source project will not see any upside if they pay. Collectively, yes, it would be better to financially support the projects that companies depend on, but on an individual basis, a company logically sees no reason to pay.

And even if the worst happens, say the sole maintainer gets hit by a bus and dies... most companies will be content to wait and see, and deal with that problem if and when it happens, not before then.


> They can hire devs to work on FOSS.

And they do. Most big OSS projects have at least some of the maintainers and contributors be employees at a company where that OSS is used.


Of course it’s possible:

All of those reasons you listed are choices that people make — not laws of nature.


People make choices all the time. Choices that are overseen by management, and shareholders.

People can of course choose to spend their political capital, and discretionary budget on random OSS projects. Or they can choose to spend it on their project, their goals, the outcomes that make their walk in the company easier, the actions that will get them promoted and not fired.

These are choices people make, and frankly OSS funding delivers very very little bang for the buck. (On a buck by buck basis.)


Sure — my point was that we should discuss why this happens in terms of the real human dynamics. Either to conclude it’s not worth changing or to design a plan of how to change it.

But neither goal is aided by hyperbole, pretending that not paying OSS is gravity.


> frankly OSS funding delivers very very little bang for the buck

which is why companies generally don't pay anything for OSS. If the cost is zero, but the benefit is not zero, then the bang for buck is infinite!


> People at companies have very little personal agency when it comes to spending money. Spending has to be approved, justified, and some value has to be received.

seems to all hinge on the justification part, for which ppl that do it for the lulz don't really care


Absolutely, There’s hope in initiatives like https://osspledge.com/ & https://thanks.dev


Also https://polar.sh/, which lets users of the project "vote with their wallets" on which issues should be prioritized. You can see it in action in Starlette's GitHub issues, e.g. https://github.com/encode/starlette/issues/649


This would be nice, but since it hasn’t happened so far, hard to see why it would start happening.

No idea what the future will look like in general in 5, 10, or 20 years but I am reasonably confident that donations to OSS won’t be drastically more than they are now.


Terrible reason to believe something won't happen.


Fair enough, but having worked inside a lot of tech companies I think I also have a pretty good sense of why tech companies don’t monetarily contribute more: no incentive to do so and because OSS is often chosen specifically to avoid costs.

Hard to see why those things will stop being true.


I think it’s pretty easy:

Refer to any manager or executive at a tech company who uses open source to generate profits but doesn’t contribute as a “deadbeat” — so their choice becomes a source of social embarrassment.


If you think companies care about embarrassment I have a nice house in Bhopal to sell you.


I think most of the executives and managers do - yes.

That’s why I said to shame individuals, not faceless entities. And I think it’s fascinating that you didn’t reply to what I actually said.

Even as you tried to shame me (ie “if you actually believe that, you’re so dumb you’d buy something ridiculous!”) because you recognize that shaming is an effective tactic.


>I think most of the executives and managers do - yes.

To quote someone else who's worked with Big Corp:

>>Do not fall into the trap of anthropomorphizing management. Think of management the way you think of a lawn mower.You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower hates me' -- lawnmower doesn't give a shit about you, lawnmower can't hate you. Don't anthropomorphize the lawnmower. Don't fall into that trap about management.

>Even as you tried to shame me (ie “if you actually believe that, you’re so dumb you’d buy something ridiculous!”) because you recognize that shaming is an effective tactic.

I don't give a fuck what you think. I want to convince other people that you're wrong and we need better solutions for writing open source software because I enjoy doing it and I'd love to get paid for it. As far as I'm concerned you're a badly put together memetic lawnmower whose a danger to everyone around you - the end.


If you're going to quote then at least try to attribute.

Bryan Cantrill (quote@) https://youtu.be/-zRN7XLCRhc?t=2303

specifically about Larry Ellison (and Oracle), not about management in general.

Worth watching from: https://www.youtube.com/watch?v=-zRN7XLCRhc&t=33m as he starts by praising Sun management.


And I wonder who Sun got sold to and who organised the sale?


Yeah, I think it would take something like bankruptcy of a Fortune 500 company because a critical open source piece shut down.

And I'm not holding my breath that even that would sink in. People are amazingly talented at hearing only what they want to hear to justify doing it like they've always done it.


> because a critical open source piece shut down.

unless they're using some sort of hosted service for free, this cannot be critical. After all, software doens't rot, and they could continue to use the existing release until a (new) solution is found.

Look at how crowdstrike triggered outage didn't cause bankruptcy - that is more critical than most OSS would be.


It doesn't rot? I mean if it stops being maintained and the lack of updates makes it fatally insecure or something, it can become effectively obsolete.

Though I will note I'm agreeing that it's highly unlikely you can put a gun to the heads of corporations and get them to cough up, so I'm not sure what the point is here.


> stops being maintained and the lack of updates makes it fatally insecure or something

which doesn't happen instantly. For example, the end of life of the old java versions (1.5, 7 and 8 etc) - plenty of companies simply just paid a support fee and get support, while others paid to upgrade (or even change stack).

Most open source software, even with lack of updates, does not immediately start failing. The huge amount of time and leeway, even with security issues, is what prevents it from being critical, and prevents OSS from causing a bankruptcy.


> what prevents it from being critical

Well, there's plenty of mission-critical FOSS used by plenty of companies. But you are right in that it doesn't just fail one day, and companies have plenty of time and options for dealing with abandoned FOSS.

(Which is one of the major benefits of FOSS. It's more likely with proprietary software that it can just disappear one day, with little recourse for users.)


> For example, the end of life of the old java versions (1.5, 7 and 8 etc) - plenty of companies simply just paid a support fee and get support, while others paid to upgrade (or even change stack)

And plenty others simply keep using the old 1.8 version because there's no budget to upgrade and there's no budget to 'pay a support fee'. And there's no budget to 'change stack'. Because... there's no budget.

Convincing people you need to upgrade or switch to keep current is often a hard problem, and sometimes has to be done with "you'll get all these new features!". But often "hey, we need some money to upgrade system X" is met with "hrm... it's software! It doesn't rot!".


    > paid a support fee and get support
I cannot prove it, but I am convinced this is an important revenue stream for Redhat. They will patch an ancient Linux kernel forever if you pay them. I have worked at multiple companies where we were running ancient Linux kernels than received regular security updates, courtesy of our Redhat subscription!


And your point is?

Me: "I think you cannot get corporations to cough up without some ridiculous extreme event like a behemoth dying. And I'm not holding my breath that would really do it."

You: "Your extreme ridiculous scenario is extremely ridiculous and here's why..."

Rinse and repeat.


> if it stops being maintained and the lack of updates makes it fatally insecure or something, it can become effectively obsolete.

Sure, but that won't happen immediately when the maintainer abandons it. It might not happen at all. There's usually going to be plenty of time for a company to switch to an alternative, or even take on maintainership themselves.


That's only if they agree with your description. I really don't see that happening. I just see the simple, factual retort: "we're not deadbeats, and if you wanted us to pay, you should have sold it to us instead of giving it to us for free."

Which is absolutely correct!

As an open-source author and maintainer, I have no desire or motivation to call any of my users "deadbeats", especially when I license my software under terms that specifically do not require any kind of payment. That would be pretty hypocritical, as I've used lots of open source software (both personally and professionally) without paying for it.


Is there a website where one can see some open source contribution metrics? I found https://opensourceindex.io/ , but the absolute numbers do not tell much by themselves; of course the biggest companies contribute more[1].

[1] apart from Meta and Apple, they seem ridiculously low.


Why would you say that? I believe the GP is correct. Unless something drastically changes, why would we expect companies to start getting generous, spending money they don't have to? Especially in the context of donations! If we're talking about a licensing shift that requires companies to pay, then sure. But for donations? I doubt it.


Actually no, historical data is the best indicator of future probability.


They do. A huge chunk of open source software is maintained by companies.


Companies that depend on FOSS would contribute if the license did not explicitly tell them that they don't have to.

MPLv2/EUPL come to mind: they are compatible with proprietary products, but they make it mandatory to distribute changes/extensions of the library, not the whole product.

FOSS authors have a responsibility when they choose a permissive license.


> Companies that depend on FOSS would contribute if the license did not explicitly tell them that they don't have to.

No they won't. They'll only contribute if they're required to, or if doing so will be beneficial to them, and they'll do that regardless of whether the license says they have to or not.

When I've worked at companies that use FOSS, and have needed to modify those sources, I'll contribute back (regardless of license) if I think that change is likely to be accepted upstream, because I'd rather not have to maintain a fork. This would fall under "contribute if doing so will be beneficial to them".

At any rate, no FOSS license (that I'm aware of, or is in wide use) requires users to contribute. At most, they require that changes be made available. There's nothing that says the changes need to be submitted (or accepted) upstream. Often getting a change into a state where it would be accepted upstream is a significant amount of work beyond what the company has already done for their own purposes, so they don't bother.


> No they won't. They'll only contribute if they're required to

Did you actually read my comment before you answered? Because I said that copyleft licenses "make it mandatory to distribute changes/extensions", which means that companies are required to contribute if the license is reciprocal.

> At any rate, no FOSS license (that I'm aware of, or is in wide use) requires users to contribute. At most, they require that changes be made available.

Making changes available is a form of contribution. If you work on a proof of concept for a month and at the end your company decides not to use it in a product (thanks to the learning from your work), do you say that you did not contribute, so you should not be paid?

Feels like you're being pedantic just for the sake of the argument.


There is a method to have companies fund public infrastructure work: taxation.


That's certainly an interesting idea, but I think some commenters' heads would explode if we tried talking about that. :P


That support would inevitably come with strings attached. Which most open source maintainers fervently avoid.


Permissive licenses come with strings attached (that most companies ignore): attribution.

With copyleft licenses, nothing say that you have to get your changes upstream: you just have to distribute them to the users. It's not a whole lot more complicated than attribution: set up a repo and put your fork there publicly.


Attribution has its own issues too, like when curl developers faced Toyota owners who were grasping at straws because the curl attribution featured prominently in the car's malfunctioning entertainment system.


[flagged]


I am not here to shill for Google, but they publish a staggering amount of liberally licenced software. We can much less of that about Microsoft, Apple, and (my personal most dreaded for open source) Amazon.

Also, I stand by my previous comments from other similar discussions: Almost all big corps use Redhat. They are indirectly funding open source. Redhat probably employs more programmers that contribute to a base Linux install than any other company on the planet. (Yeah, I know they were bought by IBM, which gets no love around here.)


> you're not a good person, you don't fool me. Fund open source, it would support young people who were just like you were

Or maybe he knows he's not a good person and has no intention of multiplying people who are just like he was, because he knows people as himself are bad and the world is better without them.


Killing other people because you’re a bad person makes you a worse person.

If he’s doing that, we should stop him as a danger to others - no different than any other criminal.


> It's probably too much to ask corporations to dump money into it as it would not be a legitimate business expense.

Um, excuse me?

Ok, let's suppose you've got a product that depends on open source project X. For simplicity let's say it's a direct dependency, though I think everything here applies to indirect ones as well.

Let's consider the options.

Option 1: never pay a dime for it. This works in so far as someone else picks up the bill. So really there are two sub-cases:

Option 1(a): the project is successful enough that it's self-sustaining. What this really means is that someone else (or multiple someone elses) picked up the bill. Congrats, you lucked out.

Option 1(b): the project is insufficiently funded and either dies or has a major security breach. Now you end up paying either for the security breach fallout and/or to replace the component, possibly on short notice, with something else. Or you maintain it yourself and start paying that cost, again possibly on short notice.

Is that really worth it? Do you think so? I'm betting all those costs are higher than it would have cost to maintain it in the first place. Because anything you do in an emergency is more expensive, and you're paying the cost of losing all the context in the development of the project itself (if someone leaves before you start maintaining it).

Option 2: pay for the software in the first place, making the cost predictable and avoiding a low-probability high-impact failure mode. Honestly, given all the risk management companies do, this seems worth it to me. At least if the dependency is critical enough.

Obviously you won't do this with any random open source project. But that's sort of the point: companies are making economic decisions all the time about what they really care about. If they aren't paying, that means they're happy with the inverse lottery[1] of the failed open source project model.

[1]: An inverse lottery is one where most of the time you get nothing, but rarely you lose big.


There are other options.

Option 2: Fork the code and do whatever they want with it.

Option 3: Directly employ open source project maintainers instead of donating to the project. They can exert at least some control over project direction that way.

Most enterprises don't even have a budget line item for open source project donations.


> Most enterprises don't even have a budget line item for open source project donations.

But it's common that they have employees who are assigned to working on the open source project. That's an item in the budget, it just isn't labeled "open source project donations".


Let's not forget Option 4: remove the dependency and migrate to another one still alive




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: