after reading Ford Foundation document [0] i'll go beyond and purpose FOSS not only limit commercial use but also forking [1] as it seems we have an endless stream of libraries which do the same thing, scattering even more this "fragile" ecosystem which would benefit so much of big tech's evergreen
Being able to fork your own version is a desirable goal and by design. The original author can and will probably not want to take his project in all kind of imaginable directions.
I'm not sure it fits the free and/or libre software philosophy but I'm a big fan of releasing otherwise free and open source software as a paid version and with some exclusive QoL features in proprietary store fronts.
For example Krita. https://krita.org/en/download/ FOSS but you can buy it on Steam, Microsoft Store, Epic Store, and Apple Store. You get one exclusive feature, automatic updates, and you also support the developers (on the other hand Valve, MS, Epic, and Apple also gets a cut).
But if you read for example the Steam reviews everyone points out that it's free but buying on Steam is also a good and very straightforward way to support the devs + platform itself has such a pull ("buying games you never play") that people buy it just for the case of having it in their library
Filebot used to be open source. I bought it on the AppStore, it was a way to support development and I figured it would give me easier updates that would just happen in the background.
When Apple moved to ARM, the App Store version lagged behind. An ARM version was available, but not in the App Store. I assume this is because that ARM version was a separate download instead of being a universal app, and the x86 app would run on everything (for now).
The app is no longer open source, and is paid. To get the ARM version (due to my stubbornness in not wanting to install Rosetta), I had to pay again just to get the app through a different means of distribution.
Too many run-ins with silly issues like this can really sour a person on the “free app in a paid store” model.
That can happen regardless of which storefront you use to buy a free app. It's more of a developer-specific nitpick than a chronic problem with FOSS and freeware.
If you're happy to sponsor the app's development, then owning the App Store version should make you feel proud. The developer is still able to make a living thanks to you, and they're offering extended support if you're unwilling to use a fork of the free version. A good example of this is Dwarf Fortress, which I have bought on Steam 3 times now so that I could gift it to two of my friends. God willing, nothing will prevent me from buying a 4th and 5th copy when Christmas rolls around.
Yet by the active unique user numbers they have estimted sold at least ~168k copies and maybe upwards ~500k https://steamdb.info/app/280680/charts/ And that's Steam alone. I'd be really curious compared to this how many people click on the Donate button on the Krita homepage.
That's a lot of purchases imo for a project like this. I'm kind of ambivalent about the store cuts but they give a huge enough exposure to any game or software.
I think I have donated more for Inkscape, Gimp, Firefox, and Libre Office than I ever spent on proprietary software. I also tend to buy paid versions of open-source apps in app stores, where available. It's great when a piece of open-source software has an easy donation link / button.
That said, I tend to trust all closed-source software significantly less, even if it's given away for free. Especially is it's given away for free.
Without knowing how much you've paid for proprietary software, that could be a lot, or a little. If you're coming from a position where there is alternative FOSS software available to use, that's your bubble/sphere of experience. In other realms, say software for doing aerospace CAD, there is no FOSS available because it's just such a niche piece of software.
I mostly speak about more mundane software than CAD. I would say that the total sums involved are in the $100-$200 range, accumulated from multiple $5-$10 donations and purchases. I buy really, really little proprietary software %)
I feel like the main issue with projects switching between a permissive and less permissive license and back is that starting out as fully permissive in the first place was the main error.
If everybody would just agree to start their open source code as something like source-available or OpenRAIL -requiring companies with more than $5M in annual revenue to pay for the work - we wouldn't be in this situation.
They won't do this, because starting out as non-free doesn't get the same traction. Now that I think about it, it's basically a form of enshitification: draw people in with one deal, then after they're onboard, change it to something less favorable.
The usual pushback I get from FOSS zealots is that any time I mention things like money, popularity, increasing adoption etc. they just say none of that matters because it's "not a project goal."
In fact, often they don't even want money to be a thing at all, they think capitalism is inherently evil (cough innovation) and would prefer if everyone was just poor and lived in the woods or something.
Sorry... I like the world to be a little more interesting than that.
These are the currencies of the VC world, and many open source developers don't release their work for those reasons (myself included, limited though my contributions are). It seems strange to deride them as making the world uninteresting because of this.
Modern society has done a wonderful job proving that sentiment right. I can't blame them.
>would prefer if everyone was just poor and lived in the woods or something.
I'd prefer if everyone had proper control over the tools they used. Whether they choose to live in the woods to use such tools or use them to make society a worse place is the double edged of 'free' (as in freedom)
I completely understand those skeptical about perverse incentives from not making software 'free' (as in beer). It shouldn't be a surprise that adding monetary inventice changes the entire incentive structure.
I’m not sure who is worse, the people who want everyone to be poor and live in the woods, or the ones who want to monetize every human interaction until you need a microtransaction to unlock your front door.
The funny thing is that some of these "FOSS zealots" misunderstood the point of FOSS and believe that it is required to work for free, after the source has been released.
Most of the "FOSS zealots" should know that Stallman supported capitalism and the commercialization of free software in the form of paid support which this model has worked for many years and Stallman made his own money from speaking fees thanks to the GNU project.
The truth is, FOSS only works if someone else is paying.
> Now, finally, I have an idea. It's gonna take 5000 words to get there, though, so if you don't have that kind of time, skip to the part about registries.
This article is full of LLMisms, which is to be expected but maybe it wouldn't be 5000 words and wouldn't need this disclaimer if they wrote it themselves
The only llmism I sensed is the use of "load bearing". Im usually queasy after reading llm slop, and stop before the end. This didn't have that effect.
Maybe the llms are getting better, but either way, this article reads like a real hunan write the whole thing.
While I’m usually one to also get annoyed at uncurated slop, this doesn’t strike me in any way as LLM text, and likely something the author meant in earnest. I reads lot of LLM text. What part about it appeared generated to you?
From my perspective the piece was well structured, paced and thought through (and yes, a bit long)
I’d recommend looking through the 20+ years of Laurie’s writing in the archives. The LLMs may very well be mimicking him. I wouldn’t put LLM assisted writing past him, but I feel like this is being judged on topical similarity, and is not the standard kind of egregious incoherent slop that has little substance or lacks coherence. See for example:
> Now, the popular way to tell this story is "the system is breaking," and I don't think that's right, and the distinction matters. The system isn't breaking. It's stable, at a level of human cost we've collectively decided to put up with.
Reads like an LLM to me. "Load bearing" also used a few paragraphs down.
Isn't this similar to the anaconda model? (Except they keep the money instead of distributing it.)
Depending on how you count, in my research group we are like 10 and in my whoooole university we are like 60.000 employees. When they went from free to restriced for big organizations I just uninstaled it.
No, but "free as in speech" effectively precludes making money from sales of the software. As soon as you sell it to one person, that person can give it to others for less than he paid you (all the way down to free), so nobody has a reason to pay you any more. There's a reason FOSS survives on donations or service, rather than selling copies of the software.
The software still remains free, it's the registry that would become a paid service under such a model, that's what was proposed in the article. And even then, the registry would remain free for individuals, so it would merely be a price of convenience
I'm not reading an AI slop article, but there's nothing in either the Free Software Definition or the Open Source Definition restricting the selling of software. It does prevent you from restricting people from sharing that software once they've bought it, but you could always use a threshold pledge system to ensure you get enough money before releasing anything:
"We encourage people who redistribute free software to charge as much as they wish or can. ... So if you are redistributing copies of free software, you might as well charge a substantial fee and make some money. Redistributing free software is a good and legitimate activity; if you do it, you might as well make a profit from it. ... Distributing free software is an opportunity to raise funds for development. Don't waste it!" https://www.gnu.org/philosophy/selling.html
Indeed! While reading the original post, I was reminded of the old essays where RMS made it abundantly clear that charging for delivery media was absolutely ok - and if you wanted GNU updates, you should send in the stamps necessary to send them back to you.
Maintaining a popular registry is very hard work, hard enough that commercial entities would rather pay than having to do it themselves. It is literally SaaS. It could absolutely be monetized for the common good - although the gamification worry is real, and the governance would be really difficult to defend from sharks. But there might be clever ways to fix those issues.
The one thing you cannot fix is the cross-planet level playing field that registries provide. Today, a small African company can pull from a registry more or less in the same way as large US corporations. If you put a toll booth up, the toll will soon be too high for people in various parts of the world.
The reason I dislike this is because of the game it creates. Let's say we have someone who developed a small, well-used dependency (say: xz) but there is now incentive to be "in the dependency chain." xz is open, LLMs are really good at stealing/recreating; what stops someone from publishing rxz (maybe a rust port, maybe a gnu-r port, maybe it's "Really fast" xz, maybe it's just hoping for a typo in a registry.) This new dependency adds very little over the original xz and xz could have just used a simple PR.
On the other side of things, does accepting a PR from someone grant the author the ability to collect royalties for that software project? If so, how would you quantify that? LOC seems like a quick but really bad answer for what it is incentivizing.
For many, the entire point of "F" in "FOSS" is not getting tangled up in this kind of mess. I personally would never want to add "am I opening myself up to a lawsuit if I don't pay someone for their PR" to enter my calculus of accepting a PR. Especially if this is because I reject payment at all on a project.
Finally, if a company/employee submits code to FOSS under this model, do they now expect a return?
This new dependency adds very little over the original xz and xz could have just used a simple PR.
I kind of like the incentives created by this competition. This "what if someone takes your software, adds one feature, and sells it" argument has been made many times and I think the answer is that you, as the original maintainer, are in the best position to add features and if you squander that position you deserve to lose.
Seriously imagine the consequences of this "eat or be eaten" approach. What it incentivizes is not feature development per se, but fragmentation for the sake of it. This in turn leads to less attentation toward maintaining the shared base of the fragmented forks, as it has been superseded with features X and Y in different, probably incompatible forks.
how about making money from something else like hardware, to fund software (almost like IP is a fiction and people should be making money from tangible things rather than info)
I'm sure AI can also brainstorm more ideas for (F)OSS business models today
If you want people to pay you for your software, stop writing it for free. Conversely, if you write it for free, don't expect people to pay you for it. Otherwise you are no better than someone at an intersection with a bottle of Windex and a squeegee who, unsolicited, cleans a windshield and then demands the driver to pay for it.
The original authors of Free Software and open source were career academics and others who were paid to do other things, or were sponsored by scientific and DoD grants. I don't know how anyone got the nutty idea that you could make money on OSS itself. Practically every time someone has tried to make money on OSS it has failed, from Netscape on down.
Netscape basically died and was replaced by Firefox which doesn't/can't effectively charge users for the software so instead makes money by selling default search engine, etc.
Netscape existed as the internet was coming into existence. You used to have to buy a physical copy in the store to install it. People barely knew how to use their computers so the activation cost for bypassing their "pay wall" was high enough.
Netscape lost the ability to charge before it went open source. Among other things, Microsoft released internet explorer for free (part of embrace, extend, extinguish, afaik).
The open sourcing of Netscape 5.0 happened in early 1998, and AOL purchaed Netscape later that year. Firebird/Firefox came a few years later.
> You used to have to buy a physical copy in the store to install it.
That is not true. They also made it available to download over the internet free of charge. You were expected to buy a commercial license if you used it for business, though.
First, a self-correction: Netscape did not produce open source products until it open-sourced Mozilla. Netscape Navigator was freeware: free to download and run, but not open source. I shouldn't have mentioned them, but my point still stands.
Second, it depends on what you define as success and failure. Netscape made its pre-IPO shareholders money if they timed their stock sales right. But the stock didn't go up because the company was profitable. It went up along with every other dot-com stock until the 2000-2002 crash, based on hopes and dreams, not fundamentals. The company never turned anywhere near close to a profit.
To me, a successful company is one that makes a sustainable profit based on its business fundamentals, not one that makes its founders and early investors rich in an investment bubble.
Netscape was actually selling a licence, which became free for endusers and eventually the entire browser was free, as the company concentrated on its Enterprise Server as a source of revenue. Netscape becoming freely available for endusers is pretty much what made the Web a mass phenomenon.
Most people only measure success as something like being a B or Trillion dollar company, and thats part of the reason in a different way why nobody pays for FOSS.
I assume you mean "sell it before you open source it."
If you found one willing buyer while it was still closed source, odds are there are others. Why rob yourself of additional income? Open sourcing does happen from closed source, but usually that's long after the income stream has exhausted itself (see, e.g., https://github.com/microsoft/ms-dos).
There's nothing stopping you, true. But I think you will find that nobody is going to buy software for whatever thousands of dollars it took you to make it. So the limitation in this case is a practical one, not a legal or moral one.
That's kind of black and white thinking though. No one is going to pay a million dollars for QuickBooks, but a lot of people paid several hundreds. Just because no one pays you to develop a new QuickBooks (at least pre LLM), doesn't mean there's not a market there.
Isn't that the whole point of crowdfunding platforms like kickstarter?
Developer presents the idea and how much it costs. If enough people pitch in, then the idea is funded, the developer gets the money as a lump sum and can turn the idea into reality.
I can't possibly take this at face value since it's obvious that people (businesses) pay others many tens or hundreds of thousands and millions of dollars to build software for them. So, what do you really mean?
I'd argue the best possible model for goods that have no marginal costs (aka IP) is the "pay me to create it" model.
As in, let a creator decide how much they value creating the work. Then pay them that to create it - then release it free for everyone.
---
No ridiculous societal restraints that cost time and money to enforce (poorly) as IP law. Compensation is happening. Creating is encouraged.
Practical constraints make it unlikely we'll get much closer to this than Kickstarter (and equivalents) but it's a very honest model, that works with intellectual property by default.
I think Kickstarter and similar are a great model for creating open source software. It's more problematic for maintaining it. It could work for some features and bugs, but it doesn't scale down super well (maybe have campaigns for a packet of related features and bugs?), and more importantly it isn't great to have security fixes dependent on a successful funding campaign.
>Otherwise you are no better than someone at an intersection with a bottle of Windex and a squeegee who, unsolicited, cleans a windshield and then demands the driver to pay for it.
This seems like a pet-peeve that's slipped through, because
1) It's really not; the FOSS developers never forced anyone to use their software, even if they're asking for payment for a product that was originally "marketed" as "free",
and
2) With the damage to society done by the work of many of the people in the tech industry and "respectable" white collar work in general, they should hope to be as virtuous as the window washers. Service done, pay for service, they go away and don't bother you for a while? No subscription shenanigans? Don't have to give them my credit card number? No annoying marketing emails? Not intentionally designing their service to be addictive? Geez. Adobe, Google, Facebook, Amazon employees make them look like saints. People give themselves way too much of a pass just because they sit in an air-conditioned office all day.
One does wonder, if we'd gotten really used to the idea of paying for software, if advertising, and the resulting tracking that came from it, would have really taken off as much.
Not possible, under the current economic regime. People simply cannot pay for things anymore; the wage-to-productivity ratio has fallen so much that we can't afford the things that are being produced; they get rented to us instead.
People need more wallet-votes, relative to the total number of wallet-votes that are out there. That's the only way this changes.
The thing is; if your software wasn't offered for free, nobody would use it because someone else would offer their alternative for free.
Also, the most difficult problems which software solve are hidden problems. Sometimes critical, but hidden nonetheless. Nobody cares about system failure, at all, until it happens to them.
No matter how good your software is, you can't effectively market it as "reliable" because every single piece of software ever created in the world claims to be realiable even though almost none of them are! The label has lost all of its meaning and hence, cannot be communicated.
I disagree that a viable market exists. What set of arrangements exist there may be viable, for select few people, but it's not a market.
A market implies that people are allowed to compete on price. If a participant can only compete after receiving investment from certain VCs (and otherwise can't participate, at any price point), then it's not a market.
Also I'm not claiming anything about the past. I'm just saying today, there's no market.
The label has not lost its meaning. Everybody knows what it means and wants it, just almost everybody “selling it” is claiming it without regard for the truth of their claim for their own financial gain. In polite society that is called lying and fraud.
People accept a surprising amount of unreliability.
For example, I've been using SharePoint to modify excel files at scale.
We kept running into issues with cache that we would write to a file, the service would respond with success, but then when we read the file, it shows the old cached value, not the new one we just WROTE! And there was no reliable way to check when the newly written value had been completely flushed using that API.
Microsoft will call this 'optimized'. They'll say that caching is good; it's a feature, not a bug!
But really, it's unreliable! It's not doing the job it claims to do.
Open source is not about your ability to charge for the software. It is about the ability of the users of your software to modify it.
"Open-source software has its roots in the culture of source code sharing that dates back to the origins of computing in the 1950s. The term was formalized in 1998 with the founding of the Open Source Initiative, succeeding the free software movement initiated in the 1980s, with the intention of overcoming the ambiguity of the word "free" — meaning both freedom and gratis — to better appeal to the business world."
I think a small issue with foss and monetization is that you can accept money for said software hell even release it with expectations that you have to pay for it, but you can't insert a clause in the license that stipulates that the foss rights only applies to paying or paid customers.
Thus there is no legal protection you really got if you go foss as a developer when it comes to ensuring fair compensation.
There is plenty of legal protection: copyright law so far held up pretty well. With the AI laundromat in play it's a completely different story though.
Ok, but this kind of seems like semantic quibbling.
At least since I've been programming (early 2000s), open source has been almost entirely free as in beer. Whatever the original origins of the movement, as it actually exists today and has for a long time, both definitions of free are integral parts of the concept.
The parent's point is that if you are looking to make some money, putting a bunch of code on github with an open source license and helpful readme is extremely unlikely to move you towards that goal. It happens every once in a while, but don't count on it.
Indeed. It's either AGPLv3 or all rights reserved, and I'm increasingly in the proprietary camp.
There are two free software business models:
1. Choosing the most copyleft, most business hostile license imaginable (AGPLv3) and charging for permission to violate it.
2. Relying on crowd funded patronage via platforms like Patreon, GitHub Sponsors, Kickstarter.
AI's ability to rewrite entire codebases is quickly killing 1, and even the biggest projects which are most successful at 2 don't make enough to cover even a single full time developer's salary.
All of my new projects will be private by default from now on.
> AI's ability to rewrite entire codebases is quickly killing 1
People say things like this, but can you name an instance of this actually happening? What non-trivial existing free software has been displaced in popular use by a vibe-coded alternative?
Anthropic rewrote the MIT licensed Bun. The capability has clearly been demonstrated. As far as I'm concerned, the writing is on the wall.
And it's not just free software either. AI can quickly reverse engineer compiled software too. It's almost scary how it made short work of all the firmwares running on my laptop. Even the days of compiled proprietary software are numbered since AI can trivially make free software out of them.
We live in interesting times. The very act of publishing software at all is now questionable.
That is a first party mechanical rewrite from one language to another. And I'm sure a significant part of the motivation was as a publicity stunt to increase demand for Anthropic's products. If anthropic hadn't acquired bun and had instead "vibe coded" their own replacement, do you think that would have become more popular than bun?
Disassembling a binary to tell you what it does is neat, but it doesn't give you anything new against free software whose source code was public to begin with.
Whereas if you ask it to generate a new large complex piece of software, the amount of human labor required to guide it into producing something that isn't hot garbage and then continue to maintain it indefinitely generally compares unfavorably with the amount it costs to buy a support contract for the existing thing.
There is a pretty reliable way to do this. Which is to distribute the code under two licenses, where one of them is the AGPL and the other is a paid license.
AGPL allows you to satisfy the free software people (and the free-as-in-beer people) and correspondingly win market share and get code contributions etc., but it also scares a lot of large corporations (whether or not it should). And if their in-house bureaucrats won't let them license code under the AGPL but they still want to use it then it leaves them to pay you for the other license. Meanwhile the bureaucratic corporations are the ones with the resources to pay you anyway.
Please don't believe that this strategy is "reliable" in any way to get paid, if you or your company need that money for survival. FOSS and especially (A)GPL is just about forcing the balance to put more power in end user's hands, nothing else. A Proprietary+AGPL license combo might get you some cash from business wanting to change the code, but it will still allow any Amazon out there to host your code for free as part of their service catalog, while you are left to go out of business.
> it will still allow any Amazon out there to host your code for free as part of their service catalog, while you are left to go out of business.
Most other licenses allow them to do that without even contributing back improvements, since they're running the software but not distributing it.
Moreover, what is your business supposed to be? When you're selling support contracts or getting paid to make specific improvements to the code, what difference does it even make that some customers are running the software on AWS rather than their own local hardware?
I am annoyed by people who do bait and switch, like „we are open and promise free forever” - just after they build community or they manage to get some VC to talk with suddenly they start charging for project taking in all work contributors also created with it.
On the other hand there is bunch of cool projects that started like that and even if they bait switched it is hard to be angry at them.
> Otherwise you are no better than someone at an intersection with a bottle of Windex and a squeegee who, unsolicited, cleans a windshield and then demands the driver to pay for it.
I am struggling to see how this analogy is relevant. It seems more like a knee jerk to the use of "force" in the headline. TFA seems to be talking about a potential way to _generate revenue_ through side channels that are deemed valuable by the users. This is clearly different from "demand the user to pay for it" as the analogy would imply.
Open source contributors don't come unsolicited to "clean the users' windshields". They just write stuff that they find useful and the inherent value of that work attracts other developers as much as users. And then the whole thing grows too large to maintain without serious money.
If the language were centered around donations (charitable gifts) instead of revenue and the implicit expectations that go with it, then I might take a different view.
> If you want people to pay you for your software, stop writing it for free. Conversely, if you write it for free, don't expect people to pay you for it. Otherwise you are no better than someone at an intersection with a bottle of Windex and a squeegee who, unsolicited, cleans a windshield and then demands the driver to pay for it.
There are two ways to think about this whole situation, two mindsets. One way is something similar to your argumentation: "if you create a software under a free license, is it ok to expect people to pay for it?". The other way of thinking is a chess player mindset: "here are my goals - what move should I do to achieve these goals?". And we should at least understand and aknowledge this difference. Laurie Voss (the author of the post) uses this second way of thinking, you are using the first one, so it will be hard for both of you to come to any agreement.
> The evolutionarily stable strategy for a piece of software is "anybody may use this for anything, including commercially, for free." That's MIT, BSD, Apache, the licenses that ask for nothing. Every project that has tried to be a slightly less generous dove has lost to a project that stayed a full dove
Linux (GPLv2) seems like an obvious counterexample?
Arguably that happened because Linux was, in fact, the most generous option: the BSDs effectively refused to get contributors beyond their very small groups, and refused to incorporate patches to support "bad" hardware or nonfree blobs - meanwhile, Linux was built around modules that could contain anything regardless of license, and happily accepted new patches and unknown maintainers. You still see it today: Linux literally built its own distributed VCS (git), while some BSDs are still on the hyper-centralized CVS.
If there isn't an even more generous option is simply because building a mainstream OS is incredibly hard.
The legal permissiveness described is critical for most software because it enables business adoption. But for a kernel, which sits at the intersection of hardware and software, "free as in beer" is not enough, there is another critical factor: how easy it is to make it work with proprietary hardware. A free kernel that won't work with my custom chip and whose maintainers won't accept the necessary patches to fix this state of things, is just useless to my business.
Other than charity and donations, the only two ways of getting paid for developing FOSS are: 1) support contracts and 2) crowdfunding the next release.
Digital goods live in a post-scarsity situation. Applying the same business model as real life products is crazy and it's the reason why we have Adobe&Co.
I'm not convinced a problem is actually here. I certainly wouldn't believe LLMs, an optional tool, make any part of this fundamentally worse. Maybe superficially for people who can't adapt.
Hard pass, thanks. Just, don't expect to get paid for maintaining open source projects.
It's easy. Everyone knows the deal going in, and if somehow you missed that you're not going to get paid for this and you want out at any time -- you just stop.
If you made something of value someone else who cares enough will pick it up. Or it can languish and the earth will keep spinning. It's fine.
> Ruby Central, whose dependence on one big sponsor then produced the 2025 takeover
Ruby Central had two major sponsors at the time: Alpha Omega and Shopify. Also the events had much more to do with interpersonal conflicts than sponsors.
The named people we lost from the report: Sam was already way out the door. Andre was most of the way. Ellen wasn't doing that operational work. Deivid was only working on bundler and not the registry. Josef is the main operational loss, he removed himself. I'm unsure of which attack exactly Is being referenced, but Colby was promoted to full time (was planned before, just waiting on paperwork).
Other prior maintainers and security researchers did NOT leave. Maciej Mensfeld Was especially crucial. Jenny Shen. To name a few. These people are “the maintainers” too. We’ve (I’m a volunteer, came on in October 2025) brought on a number of in-kind engineers as well (companies donating engineer hours via letting employees work on company time).
I reached out to everyone unnamed that lost GitHub access. Of them, one asked for admin back (granted). None were active in operations.
Seldo’s overall point: about the fragility of all of this still stands. But I also believe the details and the nuance matter. I reached out to Laurie on bsky when this was first published but didn’t hear back.
Cannot edit to add: I left off Martin accidentally. Not intentionally. I don't actually know how involved he was with operations recently (he was a former acting OSS director for a short period a long while ago).
One of the easiest ways to get paid for something is to to offer commercial support once something shifts to 'end of life' for community support. Can't get off of an old busted version - write a check for continued support! This sort of thing is reasonably easy to get through the accounting process.
Leaving a tip, paying for something free, trying to send money to a group that our infrastructure absolutely relies on - stupid hard. Commercial support, on the other hand, is very understandable to the bean counters.
Great proposal Laurie! It'd be great if YC would set up an Open Source endowment also, with say 0.5% of their companies' stock (voluntarily) endowed to open source software.
I think it's a great idea and I hope someone inside the teams of popular registries sees this and they actually give it a go. I imagine the shitstorm of reactions that it's gonna cause from people who aren't even included in the "required to pay" group and I wish the registry maintainers strength to get through this
168 comments
[ 0.14 ms ] story [ 195 ms ] thread[0] https://www.fordfoundation.org/learning/library/research-rep... [1] https://happort.org/constraining_freedom
For example Krita. https://krita.org/en/download/ FOSS but you can buy it on Steam, Microsoft Store, Epic Store, and Apple Store. You get one exclusive feature, automatic updates, and you also support the developers (on the other hand Valve, MS, Epic, and Apple also gets a cut).
But if you read for example the Steam reviews everyone points out that it's free but buying on Steam is also a good and very straightforward way to support the devs + platform itself has such a pull ("buying games you never play") that people buy it just for the case of having it in their library
https://store.steampowered.com/app/280680/Krita
When Apple moved to ARM, the App Store version lagged behind. An ARM version was available, but not in the App Store. I assume this is because that ARM version was a separate download instead of being a universal app, and the x86 app would run on everything (for now).
The app is no longer open source, and is paid. To get the ARM version (due to my stubbornness in not wanting to install Rosetta), I had to pay again just to get the app through a different means of distribution.
Too many run-ins with silly issues like this can really sour a person on the “free app in a paid store” model.
If you're happy to sponsor the app's development, then owning the App Store version should make you feel proud. The developer is still able to make a living thanks to you, and they're offering extended support if you're unwilling to use a fork of the free version. A good example of this is Dwarf Fortress, which I have bought on Steam 3 times now so that I could gift it to two of my friends. God willing, nothing will prevent me from buying a 4th and 5th copy when Christmas rolls around.
That's a lot of purchases imo for a project like this. I'm kind of ambivalent about the store cuts but they give a huge enough exposure to any game or software.
https://github.com/utmapp/UTM
Affordable binaries and SASS are fine options that I’d like to see
I understand it didn't work, but I think there is a way to get it to work (good enough).
That said, I tend to trust all closed-source software significantly less, even if it's given away for free. Especially is it's given away for free.
If everybody would just agree to start their open source code as something like source-available or OpenRAIL -requiring companies with more than $5M in annual revenue to pay for the work - we wouldn't be in this situation.
https://fair.io/
In fact, often they don't even want money to be a thing at all, they think capitalism is inherently evil (cough innovation) and would prefer if everyone was just poor and lived in the woods or something.
Sorry... I like the world to be a little more interesting than that.
These are the currencies of the VC world, and many open source developers don't release their work for those reasons (myself included, limited though my contributions are). It seems strange to deride them as making the world uninteresting because of this.
Modern society has done a wonderful job proving that sentiment right. I can't blame them.
>would prefer if everyone was just poor and lived in the woods or something.
I'd prefer if everyone had proper control over the tools they used. Whether they choose to live in the woods to use such tools or use them to make society a worse place is the double edged of 'free' (as in freedom)
I completely understand those skeptical about perverse incentives from not making software 'free' (as in beer). It shouldn't be a surprise that adding monetary inventice changes the entire incentive structure.
Maybe there’s a balance to be struck.
Most of the "FOSS zealots" should know that Stallman supported capitalism and the commercialization of free software in the form of paid support which this model has worked for many years and Stallman made his own money from speaking fees thanks to the GNU project.
The truth is, FOSS only works if someone else is paying.
This article is full of LLMisms, which is to be expected but maybe it wouldn't be 5000 words and wouldn't need this disclaimer if they wrote it themselves
Maybe the llms are getting better, but either way, this article reads like a real hunan write the whole thing.
It's not only not 'worse than the LLM prose', it's a community service!
"and I don't think that's right, and the distinction matters" Yeah right. lol
From my perspective the piece was well structured, paced and thought through (and yes, a bit long)
https://developer.nvidia.com/blog/introducing-cuda-rust-two-...
Reads like an LLM to me. "Load bearing" also used a few paragraphs down.
Depending on how you count, in my research group we are like 10 and in my whoooole university we are like 60.000 employees. When they went from free to restriced for big organizations I just uninstaled it.
If pypi started charging too, you'd have nowhere else to go.
I'm not reading an AI slop article, but there's nothing in either the Free Software Definition or the Open Source Definition restricting the selling of software. It does prevent you from restricting people from sharing that software once they've bought it, but you could always use a threshold pledge system to ensure you get enough money before releasing anything:
https://en.wikipedia.org/wiki/Threshold_pledge_system
As I understand it, if you have the first, the second follows from it. So it's effectively the same.
Maintaining a popular registry is very hard work, hard enough that commercial entities would rather pay than having to do it themselves. It is literally SaaS. It could absolutely be monetized for the common good - although the gamification worry is real, and the governance would be really difficult to defend from sharks. But there might be clever ways to fix those issues.
The one thing you cannot fix is the cross-planet level playing field that registries provide. Today, a small African company can pull from a registry more or less in the same way as large US corporations. If you put a toll booth up, the toll will soon be too high for people in various parts of the world.
On the other side of things, does accepting a PR from someone grant the author the ability to collect royalties for that software project? If so, how would you quantify that? LOC seems like a quick but really bad answer for what it is incentivizing.
For many, the entire point of "F" in "FOSS" is not getting tangled up in this kind of mess. I personally would never want to add "am I opening myself up to a lawsuit if I don't pay someone for their PR" to enter my calculus of accepting a PR. Especially if this is because I reject payment at all on a project.
Finally, if a company/employee submits code to FOSS under this model, do they now expect a return?
I kind of like the incentives created by this competition. This "what if someone takes your software, adds one feature, and sells it" argument has been made many times and I think the answer is that you, as the original maintainer, are in the best position to add features and if you squander that position you deserve to lose.
I'm sure AI can also brainstorm more ideas for (F)OSS business models today
The original authors of Free Software and open source were career academics and others who were paid to do other things, or were sponsored by scientific and DoD grants. I don't know how anyone got the nutty idea that you could make money on OSS itself. Practically every time someone has tried to make money on OSS it has failed, from Netscape on down.
Netscape existed as the internet was coming into existence. You used to have to buy a physical copy in the store to install it. People barely knew how to use their computers so the activation cost for bypassing their "pay wall" was high enough.
The open sourcing of Netscape 5.0 happened in early 1998, and AOL purchaed Netscape later that year. Firebird/Firefox came a few years later.
That is not true. They also made it available to download over the internet free of charge. You were expected to buy a commercial license if you used it for business, though.
Second, it depends on what you define as success and failure. Netscape made its pre-IPO shareholders money if they timed their stock sales right. But the stock didn't go up because the company was profitable. It went up along with every other dot-com stock until the 2000-2002 crash, based on hopes and dreams, not fundamentals. The company never turned anywhere near close to a profit.
To me, a successful company is one that makes a sustainable profit based on its business fundamentals, not one that makes its founders and early investors rich in an investment bubble.
If you found one willing buyer while it was still closed source, odds are there are others. Why rob yourself of additional income? Open sourcing does happen from closed source, but usually that's long after the income stream has exhausted itself (see, e.g., https://github.com/microsoft/ms-dos).
Developer presents the idea and how much it costs. If enough people pitch in, then the idea is funded, the developer gets the money as a lump sum and can turn the idea into reality.
Why did this model fail?
I'd argue the best possible model for goods that have no marginal costs (aka IP) is the "pay me to create it" model.
As in, let a creator decide how much they value creating the work. Then pay them that to create it - then release it free for everyone.
---
No ridiculous societal restraints that cost time and money to enforce (poorly) as IP law. Compensation is happening. Creating is encouraged.
Practical constraints make it unlikely we'll get much closer to this than Kickstarter (and equivalents) but it's a very honest model, that works with intellectual property by default.
This seems like a pet-peeve that's slipped through, because
1) It's really not; the FOSS developers never forced anyone to use their software, even if they're asking for payment for a product that was originally "marketed" as "free",
and
2) With the damage to society done by the work of many of the people in the tech industry and "respectable" white collar work in general, they should hope to be as virtuous as the window washers. Service done, pay for service, they go away and don't bother you for a while? No subscription shenanigans? Don't have to give them my credit card number? No annoying marketing emails? Not intentionally designing their service to be addictive? Geez. Adobe, Google, Facebook, Amazon employees make them look like saints. People give themselves way too much of a pass just because they sit in an air-conditioned office all day.
People need more wallet-votes, relative to the total number of wallet-votes that are out there. That's the only way this changes.
Also, the most difficult problems which software solve are hidden problems. Sometimes critical, but hidden nonetheless. Nobody cares about system failure, at all, until it happens to them.
No matter how good your software is, you can't effectively market it as "reliable" because every single piece of software ever created in the world claims to be realiable even though almost none of them are! The label has lost all of its meaning and hence, cannot be communicated.
That suggests there's never been a viable market for commercial software at all, which is obviously wrong.
A market implies that people are allowed to compete on price. If a participant can only compete after receiving investment from certain VCs (and otherwise can't participate, at any price point), then it's not a market.
Also I'm not claiming anything about the past. I'm just saying today, there's no market.
That's a pretty narrow definition. Markets can also compete on features.
Microsoft will call this 'optimized'. They'll say that caching is good; it's a feature, not a bug!
But really, it's unreliable! It's not doing the job it claims to do.
Open source is not about your ability to charge for the software. It is about the ability of the users of your software to modify it.
"Open-source software has its roots in the culture of source code sharing that dates back to the origins of computing in the 1950s. The term was formalized in 1998 with the founding of the Open Source Initiative, succeeding the free software movement initiated in the 1980s, with the intention of overcoming the ambiguity of the word "free" — meaning both freedom and gratis — to better appeal to the business world."
https://en.wikipedia.org/wiki/Open_source
You seem to be caught up in the 'free' part of 'free software'. It does not mean 'gratis software'.
https://en.wikipedia.org/wiki/Free_software
Thus there is no legal protection you really got if you go foss as a developer when it comes to ensuring fair compensation.
I understand the distinction but have literally never encountered it in practice.
Also very few software can be sold only on having support, regular users don't care about support.
It’s about the definition of ownership. What does it mean to own a program?
When you distribute the program, you must also distribute the code for it. That’s open source.
At least since I've been programming (early 2000s), open source has been almost entirely free as in beer. Whatever the original origins of the movement, as it actually exists today and has for a long time, both definitions of free are integral parts of the concept.
The parent's point is that if you are looking to make some money, putting a bunch of code on github with an open source license and helpful readme is extremely unlikely to move you towards that goal. It happens every once in a while, but don't count on it.
There are two free software business models:
1. Choosing the most copyleft, most business hostile license imaginable (AGPLv3) and charging for permission to violate it.
2. Relying on crowd funded patronage via platforms like Patreon, GitHub Sponsors, Kickstarter.
AI's ability to rewrite entire codebases is quickly killing 1, and even the biggest projects which are most successful at 2 don't make enough to cover even a single full time developer's salary.
All of my new projects will be private by default from now on.
People say things like this, but can you name an instance of this actually happening? What non-trivial existing free software has been displaced in popular use by a vibe-coded alternative?
And it's not just free software either. AI can quickly reverse engineer compiled software too. It's almost scary how it made short work of all the firmwares running on my laptop. Even the days of compiled proprietary software are numbered since AI can trivially make free software out of them.
We live in interesting times. The very act of publishing software at all is now questionable.
Whereas if you ask it to generate a new large complex piece of software, the amount of human labor required to guide it into producing something that isn't hot garbage and then continue to maintain it indefinitely generally compares unfavorably with the amount it costs to buy a support contract for the existing thing.
AGPL allows you to satisfy the free software people (and the free-as-in-beer people) and correspondingly win market share and get code contributions etc., but it also scares a lot of large corporations (whether or not it should). And if their in-house bureaucrats won't let them license code under the AGPL but they still want to use it then it leaves them to pay you for the other license. Meanwhile the bureaucratic corporations are the ones with the resources to pay you anyway.
Most other licenses allow them to do that without even contributing back improvements, since they're running the software but not distributing it.
Moreover, what is your business supposed to be? When you're selling support contracts or getting paid to make specific improvements to the code, what difference does it even make that some customers are running the software on AWS rather than their own local hardware?
I am annoyed by people who do bait and switch, like „we are open and promise free forever” - just after they build community or they manage to get some VC to talk with suddenly they start charging for project taking in all work contributors also created with it.
On the other hand there is bunch of cool projects that started like that and even if they bait switched it is hard to be angry at them.
I am struggling to see how this analogy is relevant. It seems more like a knee jerk to the use of "force" in the headline. TFA seems to be talking about a potential way to _generate revenue_ through side channels that are deemed valuable by the users. This is clearly different from "demand the user to pay for it" as the analogy would imply.
Open source contributors don't come unsolicited to "clean the users' windshields". They just write stuff that they find useful and the inherent value of that work attracts other developers as much as users. And then the whole thing grows too large to maintain without serious money.
There are two ways to think about this whole situation, two mindsets. One way is something similar to your argumentation: "if you create a software under a free license, is it ok to expect people to pay for it?". The other way of thinking is a chess player mindset: "here are my goals - what move should I do to achieve these goals?". And we should at least understand and aknowledge this difference. Laurie Voss (the author of the post) uses this second way of thinking, you are using the first one, so it will be hard for both of you to come to any agreement.
Linux (GPLv2) seems like an obvious counterexample?
If there isn't an even more generous option is simply because building a mainstream OS is incredibly hard.
The legal permissiveness described is critical for most software because it enables business adoption. But for a kernel, which sits at the intersection of hardware and software, "free as in beer" is not enough, there is another critical factor: how easy it is to make it work with proprietary hardware. A free kernel that won't work with my custom chip and whose maintainers won't accept the necessary patches to fix this state of things, is just useless to my business.
If the corporates want to use it, they can make a licensing agreement and put money into a trust of all who support it.
They don't want to pay? Too fucking bad.
Digital goods live in a post-scarsity situation. Applying the same business model as real life products is crazy and it's the reason why we have Adobe&Co.
It's easy. Everyone knows the deal going in, and if somehow you missed that you're not going to get paid for this and you want out at any time -- you just stop.
If you made something of value someone else who cares enough will pick it up. Or it can languish and the earth will keep spinning. It's fine.
https://brynet.ca/wallofpizza.html
> Ruby Central, whose dependence on one big sponsor then produced the 2025 takeover
Ruby Central had two major sponsors at the time: Alpha Omega and Shopify. Also the events had much more to do with interpersonal conflicts than sponsors.
My report: https://rubycentral.org/news/rubygems-fracture-incident-repo...
That is the GitHub only portion, but the AWS root happened immediately after/during and has its own timeline https://rubycentral.org/news/rubygems-org-aws-root-access-ev...
> a depleted team
The named people we lost from the report: Sam was already way out the door. Andre was most of the way. Ellen wasn't doing that operational work. Deivid was only working on bundler and not the registry. Josef is the main operational loss, he removed himself. I'm unsure of which attack exactly Is being referenced, but Colby was promoted to full time (was planned before, just waiting on paperwork).
Other prior maintainers and security researchers did NOT leave. Maciej Mensfeld Was especially crucial. Jenny Shen. To name a few. These people are “the maintainers” too. We’ve (I’m a volunteer, came on in October 2025) brought on a number of in-kind engineers as well (companies donating engineer hours via letting employees work on company time).
I reached out to everyone unnamed that lost GitHub access. Of them, one asked for admin back (granted). None were active in operations.
Seldo’s overall point: about the fragility of all of this still stands. But I also believe the details and the nuance matter. I reached out to Laurie on bsky when this was first published but didn’t hear back.
Leaving a tip, paying for something free, trying to send money to a group that our infrastructure absolutely relies on - stupid hard. Commercial support, on the other hand, is very understandable to the bean counters.