2022-01-22

Pay the maintainers of FOSS - Your business relies on it

Pay per use.

Ever wondered why large software corporations - including, but not limited to - Apple, Cisco, Microsoft, and Oracle, are able to develop licensing schemes so intricate that it requires tons of people to understand, but doesn't seem to be able to create a comparatively simpler model of paying the maintainers of the Open Source Software that their products and businesses rely on?
 

 
 
Yeah Yeah, I know it isn't that simple, some of those corporations have people employed that work on Open Source projects as well, but the point still stands.

Just today @bagder of Curl fame posted this:

 

The business model of the large cloud providers is to sell services (mainly) based on Open Source Software providing great services (most of the time) to their customers. Their shrink wrapped software is based on or contain FOSS components - Windows 10/11 contains curl as well as OpenSSH. Many others including Aruba, BMC, Broadcom, Cisco, Citrix, and VMWare use Log4j. (See also https://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.md).

The harsh truth is that the corporations that relied on Log4j never paid a dime to the maintainers, while being so bad at CI/CD that they couldn't even tell us what versions they used where, nor how it was configured out of the(ir) box.  

 

 

Worst of all, over the course of handling the Log4Shell incident, I heard people blame Open Source for this situation. Please, this is beyond stupid.

This needs to stop, and we must hold all companies responsible for  the  current state of affairs. I do not have the legal, nor financial, insight into whether or not it would be possible to demand that when you pay e.g. Microsoft for Windows, that a buck or two of that cost had to be forwarded to the maintainers of Curl (and others) but we need to "nudge" those corporations to do that to a greater extent.

Back to the intricate licensing models; Why not "just" add a clause, stating that every time you sell a product or use license containing/using e.g. Curl, a small percentage of that had to go to the maintainers. It wouldn't make the license less understandable (That's impossible for most of them anyway), ensuring that the maintainers get something for their efforts and can continue to maintain their project; to the benefit of everyone using it/relying on it!

And... Please do remember to pay for the FOSS used when building software and solutions inside your organization, if it's worth deploying, it's worth paying for.

 

Let me just end by saying that way waaaaaaaay smarter people have pondered this question, so please investigate this topic further yourself.



No comments: