Open source, closed wallets, big profits – nobody wins the OSS rock, paper, scissors game
- Reference: 1642411814
- News link: https://www.theregister.co.uk/2022/01/17/open_source_closed_wallets_big/
- Source link:
This is, of course, balderdash. It's not an open source problem, it's a software problem. All software needs resources to adapt as the working environment changes, resources the changed environment may not provide. Look how many out-of-support versions of Windows still limp on like superannuated footy players in the Sunday leagues.
According to StatCounter, as of December 2021, [3]one in seven PCs still runs Windows 7 . One in 200 is on XP. Try getting Microsoft to update either.
[4]
Why this is, is more complicated than just Microsoft's revenue model, although that's a part of it. The details aren't important. Paid-for software is not magically sustainable, any more than OSS is uniquely vulnerable. If anything, it's the other way around. If you really need it, you can pick up a dropped OSS ball and run with it. Try doing that with commercial abandonware. Yet nevertheless, there are plenty of OSS creators who'd like to be paid.
[5]
[6]
The question becomes not whether resources can be made available to keep OSS components up-to-date, secure and relevant as needed. Rather, it is how can the industry come to realise that if it wants long-term security of supply in software components, OSS is the better choice?
It's not that organisations don't like paying for things even when the benefits are nebulous. They have no problem spaffing millions in executive compensation, marketing departments, mergers and acquisitions and major strategic refocuses that go nowhere. It's only hard to get money spent on stuff actual workers actually need.
[7]
Ask Tatiana in devops whether she thinks it's a good idea to push some shekels towards the team who keep her favourite framework cooking, and "hell yeah" will be the printable version. Can she make that happen? Only out of her own pocket. She's not the one making millions out of that devops pipeline.
There are many schemes for collecting and dispensing enterprise donations to open source projects, but none is proving a generic solution. One component may be used by a thousand companies for one small but important task; one component, as with [8]Apache PLC4x , may have a natural market of a handful of places but with a potential value to them in the millions.
Some OSS teams do not and never will want monetary rewards; others grow [9]weary of seeing their work be exploited with no tangible reward. Even if it wants to, how can a company budget for everything on that spectrum, or what to donate to a clearing-house scheme?
[10]
How about licences that make software free to use below a certain level of resultant profitability? That works for big things run by single companies, but becomes a contract with financial commitments in a way that most OSS licences are not. As a dev or an architect, you may get blanket permission to use corporately approved permissive OSS licences. You won't where there's cash involved.
As so often, history has the answer – a mixture of deep and recent history, in this case. Let's start with the recent. It is not uncommon for organisations to adopt and publicise progressive policies on equality in the workplace or commitments to environmental or political stances, not just through a burst of otherwise undetectable ethics, but because they help recruitment and plonk a halo on the god-like being of the CEO. They cost money, but mostly from coffers that don't have to show a return on investment.
The deep history component is the tithe, then 10-per-cent levy popular with deities, priests and kings from Mesopotamia to the present day. These days, the compulsory tithes are dressed up as taxation (at more than 10 per cent, oddly enough), but voluntary tithes are still thick on the ground to fund churches, charities and other communitarian concerns that don't give you back anything specific.
In the case of churches, the deal might seem like they collect the lucre to provide God-centric services for soul disaster recovery, but whichever deity is involved, they don't get to spend it. Rather, you're buying into a community, to rules that give you support when you need it and provide a certain status. There's no need for either side to define either in too much detail. That sounds a good fit for corporate use of OSS.
[11]No defence for outdated defenders as consumer AV nears RIP
[12]Log4j and Omicron: Brothers in harm, mothers of invention
[13]Calendars have gone backwards since the Bronze Age. It's time to evolve
[14]Apple is happy to diss the desktop – it knows who's got the most to lose
Here's the deal. A universal code of conduct for organisations that use OSS, saying they are enlightened entities who recognise the good of OSS for one and all, and pledging a small percentage of turnover, proportionate and revisited, to OSS support. A single common clause for OSS licences that make them part of this. An industry organisation that publishes OSS usage stats to help facilitate payments – but, crucially, does not take a cut, for that way lies rentier corruption.
The money – which needn't be much, OSS is very efficient – comes out of marketing. There's a simple legal framework for the book-keeping, and all sides accept it's voluntary and unenforceable. The code of conduct can include things like asking Tatiana for usage stats, and the whole thing runs on ego, openness and good will.
An impossible basis to do anything? Try telling that to the open source community. It's amazing what you can do when you feel the love. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2022/01/13/opensource_apacheplc4x_payment/
[2] https://www.theverge.com/2022/1/13/22882176/google-government-action-protect-open-source-software-funding-security
[3] https://gs.statcounter.com/os-version-market-share/windows/desktop/worldwide
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YeVMWR0VxoQN17spTtYQOAAAABU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeVMWR0VxoQN17spTtYQOAAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeVMWR0VxoQN17spTtYQOAAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeVMWR0VxoQN17spTtYQOAAAABU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/01/13/opensource_apacheplc4x_payment/
[9] https://www.theregister.com/2022/01/10/npm_fakerjs_colorsjs/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeVMWR0VxoQN17spTtYQOAAAABU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2022/01/10/opinion_column_consumer_av/
[12] https://www.theregister.com/2021/12/20/log4j_and_omicron_opinion_column/
[13] https://www.theregister.com/2021/11/08/calendar_backwards/
[14] https://www.theregister.com/2021/05/24/desktop_os/
[15] https://whitepapers.theregister.com/
re: This is, of course, balderdash.
Yes. Yes, it is.
Hoping everyone will start to play together nicely is not a plan.
Re: re: This is, of course, balderdash.
See: Cats, herding.
Tragedy of the commons
And how does this prevent the above? Bad users will make a relative competetive advantage by not contributing with no loss to themselves. There is a reason why taxation is compulsory and also why most of accountants spend significant time understanding and using the most "efficient prayers" to the system. Some small subset of creators find their products make more and more demands on their time and are used excessively, beyond their expectations. Most don't. The religious model given is in many ways apt; few gods are bothered by the prayers of many.
And I have yet to notice as stringent expectations placed on gods as maintainers of FOS software. In fact it is close to the opposite - when things go wrong we call it "an act of God". When software goes wrong it can be and has been called any damn thing whatever but there is an expectation of responsibility and FIX IT NOW.
It seems the Internet still hasn't got the hang of payment for content (whether it's an essay or code, it's all the same thing), which suits the big corps very well thank you so why would they want anything to change or come up with a payment system?
Unless you count the Brave wallet and tip jar, which is crypto-currency and therefore planet burning, so that's not a solution either.
The decision to use a certain Open Source component is usually up to individual developers who usually don't have budget authority. They just do it. If there was some kind of contract with payments involved, things would slow down to a crawl: That would require an aqucisition process that might not even be suitable for most projects (a Patreon account doesn't fit).
Governments
Government departments are becoming increasing users of OSS, and the more enlightened senior civil servants are even becoming vaguely aware of the fact.
But often, they have arcane rulebooks which forbid them from helping to develop or fix a given product, or even OSS in general, for some absurdly obsolete reason (Insistence that everything their staff write during working hours must be Crown copyright, for example).
Yet all around the world, governments spend billions on developing and supporting vital infrastructure, while their taxpayer-funded research institutions frequently help out private enterprise in their side of the development.
A little realism and engagement, pushed down from our political and Departmental leaders, could go a very long way in making OSS deliver on Departmental needs - which include such goodly things as long-term stability and support.
We have seen it on rare occasions, such as when the American NSA released SE Linux. But it needs to become the norm, not the exception.
Re: Governments
It's not just Governments. If money and contracts get involved, things get complicated everywhere. This adds so much friction, that it suddenly might not be worth it.
In public organizations that would usually trigger requirements to issue an open tender. These requirements are there for a good reason, but they don't fit the open source model.
Re: Governments
And herein lies the ultimate problem with financing OSS.
Hell, even if govt 'solved' the problem by requiring fully supported software stacks, you'd end up with more or less the same arguments of unfairness or horribly-structured dependencies.
Look what has happened with broadcast music - most songs ended up around 3 minutes long 'cos that's what the station was prepared to play. Streaming services (spotify etc) pay for music on a different basis and so - magically - artists have changed their offering to maximise revenue and so tend towards having many more shorter tracks. Leftpad would only be the start...
If you're a OSS dev, do you try to make it possible to get paid?
(AC to protect identity)
The large company (multi £billion turnover) I work for has a whole department which approves / signs-off on architecture and, particularly, the s/w choices made therein. No project can go ahead without this architecture being approved and rubber-stamped. On the face of it, this is to try to ensure consistency and promote re-use (etc etc). All of the software we write is for consumption by external clients (other than the obvious internal tooling etc)
In reality, this entire department is staffed by lawyers and procurement people. There are, as the article says, carte-blanche approvals for certain types of licence (Apache, MIT) but anything with a copyleft can be a bit of a problem to get approved ([L]GPL especially).
This department is 100% concerned with "If our client sues us, do we have somebody to counter-sue or deflect to?" and "if we use
These guys (and I interact with them all the time) would much rather pay for software than use open-source - because paying for it comes with certain contractual obligations which can be enforced with the help of m'learned friends. They frequently lament that even if they wanted to pay for a vital piece of software, how do they cut a cheque to developer_and_his_dog@github when there is no commercial entity to deal with? There's no way of being able to expense any donations that I might want to make, and no way for the company to do it.
Apache have, for many years, something vaguely resembling the skeleton of a model that could work. Incubating projects vs top-level projects. Perhaps if there was clever lawyers at ASF who could craft a licence which required payment when >£threshold is reached for a top-level project and the ASF can disperse the payments - because the ASF are easy to deal with commercially. I use 'ASF' as an example, it doesn't have to specifically be them. The YouTube model (I know, I know) might also have similar inspiration: you're only allowed to "monetize" videos when
Companies won't volunteer, but that doesn't automatically mean that all of them will try to avoid payment - legal and risk and procurement people in these companies actually want commercial paid agreements in place but there's no way of doing it
Until OSS devs and maintainers have, or are part of, some commercial structure which the byzantine procurement of megacorps can deal with - i.e. is able to handle how these megacorps *buy* - then this situation is not going to change any time soon.
TL;DR if you want to get paid for the OSS you develop and maintain, then you have to be able to 'engage commercially with the people who pay you, backed by a licence where there's sufficient compulsion for them to pay you.
Sounds very much like the music industry
The proposal sounds similar to how the music collects and distributes royalties. This works better in some countries than others.
However, the biggest problem is reconciling the open source approach with product liability when the two are, in a sense diametrically opposed.
Re: Sounds very much like the music industry
It'd be even more broken than mandatory music royalties. After Linux sucks up 90% of the revenues (on the grounds everyone and everything uses it), the Apache foundation, Red Hat and 2-3 others take 90% of what's left. After that the people distributing will say "It's not cost effective to try and recompense everybody else" (and be entirely correct, because transaction costs will be higher than the payments) and nobody will get anything anyway.
Then Governments will step in, make it compulsory, and you'll end up having to pay some profit making royalty distribution service money to use your own software and get nothing back.
Not a bad idea, but
Here's what is likely to happen :
1) OSS coders who want to get paid will get fed up not being paid anything, and will simply stop updating their code
2) Companies using said code will start fretting about outdated code, or will wait until everything breaks to wail about how they didn't see that coming and OSS is not reliable
3) Somebody will step in and say "for a price, I can update this", and they will require a licensing deal, which companies will gladly fork over
4) Situation normalizes to "free" OSS code, not paid for ever, and "commercial" OSS code, which requires a license and gets updates, but can be forked and any approved coder can contribute (how that happens needs to be determined)
I don't believe in unicorns and I doubt very much that companies are going to wake up to anything until it slaps them in the face - especially when it means spending money that does not go towards CEO/board bonuses.