How Steve Marquess and Stephen Henson became the overworked, underpaid stewards of OpenSSL, which is finally staffing up post-Heartbleed
The Internet Is Being Protected By Two Guys Named Steve — The Heartbleed bug put the spotlight on OpenSSL, the security toolkit used …
Context & Ripple Effects
Heartbleed surfaced on April 7 as a zero-day in OpenSSL, and by April 8 researchers confirmed it let anyone read the memory of systems protected by vulnerable builds — turning a quietly maintained library into the internet's most scrutinized codebase overnight. On April 13, the OpenSSL Software Foundation's president publicly asked companies and governments to fund a team of six or more full-time workers (the foundation's own funding plea), admitting the project ran on a shoestring.
This BuzzFeed profile lands mid-fallout: it names Steve Marquess and Stephen Henson as the two men effectively carrying the toolkit, and reports the project is finally hiring in response. The competitive backdrop sharpened on April 22, when the creator of the LibreSSL fork declared the OpenSSL codebase beyond repair — making the staffing question not just charitable but existential.
First-order effects
- Marquess and Henson get relief from sole stewardship as new hires come aboard, directly answering the foundation's stated need for six-plus full-time workers.
- Every company shipping OpenSSL-backed products faces immediate pressure to become a paying sponsor rather than a free rider on two understaffed maintainers.
Second-order effects
- The LibreSSL fork becomes a live alternative for vendors deciding whether to fund upstream OpenSSL or defect, forcing the foundation to justify its codebase against a rival built from the same tree.
- Other widely used, underfunded security libraries now face the same donor scrutiny OpenSSL did, as CTOs audit which critical dependencies rest on one or two unpaid people.
Third-order effects
- If corporate and government money actually materializes, the pattern points toward critical internet infrastructure shifting from hobbyist maintainership to professionally funded teams — with the Heartbleed episode as the case every funder cites.
- The fork dynamic suggests fragmentation risk for foundational libraries: when upstream moves too slowly, well-resourced projects split the codebase rather than wait, reshaping how security tooling is governed.
The trend: Heartbleed is accelerating critical open-source security software from informal, underpaid maintainership toward corporate- and government-funded professional teams — with forks waiting for any project that fails to make the transition.