A look at the debate surrounding the economics of popular open source software like OpenSSL, as an ever-increasing workload on maintainers risks causing burnout
A look at the complicated business of funding open source software development. — It was just before midnight on New Years Eve …
Context & Ripple Effects
This Motherboard piece lands mid-arc in a running argument over who pays for the code everyone depends on. OpenSSL is the canonical case: critical internet infrastructure maintained largely by volunteers, with the New Years Eve framing underscoring that maintenance work follows no office hours.
The evidence has only hardened since. A survey of Open Collective projects found most earn below industry standards or poverty thresholds 80%+ of top-funded projects, a ~400-maintainer survey found nearly half unpaid 46% go unpaid, and the Log4j zero-day pushed the question of professionalizing the maintainer role onto the agenda.
First-order effects
- Maintainers of widely deployed projects like OpenSSL carry an expanding workload — review, patching, user demands — with little or no compensation, making burnout a direct operational risk for the projects themselves.
Second-order effects
- The funding gap pushes projects and companies toward monetization models, including the shift toward restrictive source-available licenses documented in the commercialization debate restrictive licenses for revenue.
- Downstream, every company shipping OpenSSL-adjacent stacks absorbs the risk: understaffed upstream means slower patches and more unbudgeted emergency work for corporate consumers of the code.
Third-order effects
- If the pattern holds, volunteer-maintained infrastructure becomes a recognized security liability rather than a cost saving — the XZ Utils backdoor crystallized exactly this concern volunteer culture as a security issue, strengthening the case for treating maintainership as paid, professional work.
The trend: Critical open source infrastructure is drifting from volunteer labor toward professionalized, explicitly funded maintenance as burnout and security incidents expose the cost of the free model.