Open Source Runs the Internet. So Why Are the People Who Built It Broke?
Let's start with a number that should make you stop scrolling: the estimated value of open-source software to the global economy is somewhere between $8 trillion and $9 trillion. That figure comes from a 2024 study out of Harvard Business School, and it represents the cost companies would face if they had to rebuild all the open-source tools they currently use for free.
Free. That's the operative word here.
Most of the developers who write, maintain, and debug the foundational code running underneath modern digital infrastructure are either unpaid or dramatically undercompensated for the value they create. And in 2024, after years of high-profile security incidents, maintainer burnouts, and corporate promises that never quite materialized, it's time to have an honest conversation about who's actually funding open source—and who's just freeloading.
The Infrastructure Nobody Sees
You've probably never heard of Log4j unless you work in tech. But in late 2021, a critical vulnerability in this small, largely volunteer-maintained Java logging library sent shockwaves through the entire software industry. Fortune 500 companies, government agencies, cloud platforms—all of them scrambled to patch a flaw in a piece of software maintained by a handful of unpaid contributors in their spare time.
Log4j wasn't an anomaly. It was a symptom.
The open-source ecosystem is full of critical libraries, tools, and frameworks maintained by one or two people who do it because they care—not because anyone's paying them. OpenSSL, curl, the Linux kernel subsystems that don't get the glamorous attention—these are the load-bearing walls of the digital world, and they're often held up by sheer volunteer stubbornness.
When those maintainers burn out, get sick, or simply decide they've given enough, the wall can crack. And the companies that built multi-billion-dollar products on top of that work? They're rarely the ones who patched the hole.
Corporate Open Source: Contribution or Colonization?
To be fair, not every big tech company is a pure free-rider. Google, Microsoft, Meta, and others employ engineers who contribute to major open-source projects. Linux kernel development, for instance, has significant corporate backing. The Android ecosystem, for all its complications, is built on open-source foundations that Google actively maintains.
But here's where it gets thorny: corporate contribution to open source is highly uneven, and it tends to flow toward projects that serve corporate interests. The trendy AI frameworks? Flush with resources. The unsexy but essential networking libraries? Good luck.
There's also the question of what "contribution" means in practice. Companies that open-source their own internal tools and then encourage the community to maintain and extend those tools are, in a very real sense, offloading labor costs onto volunteers. It's a clever arrangement if you're the company. Less so if you're the unpaid maintainer fielding bug reports at midnight.
Some critics have started using the term "open-source colonialism" to describe the pattern—taking the labor and creativity of a distributed community, building proprietary value on top of it, and returning comparatively little. It's a pointed framing, but it's hard to argue it's entirely wrong.
What Funding Models Actually Exist?
The ecosystem has developed a patchwork of funding approaches, none of them fully adequate.
GitHub Sponsors and Open Collective let individual developers and organizations donate directly to maintainers. It's grassroots and genuinely helpful for some creators, but the amounts are typically modest and wildly inconsistent. A project with 40 million downloads might be pulling in $200 a month in donations.
Foundations like the Apache Software Foundation, the Linux Foundation, and the Open Source Initiative provide organizational structure and some funding, primarily from corporate membership fees. The Linux Foundation, for instance, has a substantial budget and employs full-time kernel maintainers. But foundation membership has its own politics, and not every critical project lives under a well-funded umbrella.
Dual licensing is a model where software is offered free under an open license for non-commercial use and sold commercially to businesses. Companies like HashiCorp and Elastic have experimented with this—sometimes controversially, since it can blur the line between open and proprietary and alienate the community that built the project in the first place.
Sovereign Tech Fund, a German government initiative launched in 2022, is one of the more interesting recent experiments: direct public funding for open-source digital infrastructure, treated like the public good it actually is. The US has no equivalent, which says something uncomfortable about our national priorities.
The Case for Treating Open Source Like Infrastructure
Here's the argument that should resonate with anyone who's ever driven on a highway or drunk from a municipal water supply: some things are so foundational to public life that we fund them collectively, not because they generate profit, but because everyone depends on them.
Open-source software is infrastructure. The internet runs on it. Democracy increasingly depends on it—secure elections, accessible government services, independent journalism. Treating it as a voluntary hobby project maintained by enthusiasts is not a sustainable model. It's a slow-motion crisis we're choosing not to address.
Practical alternatives worth pushing for include expanded federal funding through programs like the NSF or CISA (which has started taking open-source security more seriously post-Log4j), mandatory open-source contribution requirements tied to government software contracts, and tax incentives for companies that contribute meaningfully to the projects they depend on.
None of these are radical ideas. They're just good infrastructure policy applied to a new kind of infrastructure.
What You Can Do Right Now
If you're a developer, a designer, or a creator who benefits from open-source tools—and you almost certainly do—consider making a recurring contribution through Open Collective or GitHub Sponsors to the projects you use most. Even $10 a month signals to maintainers that their work has real value.
If you work at a company that's built on open-source foundations, advocate internally for a formal open-source contribution policy. Many companies have them. Many more don't.
And if you care about digital rights and the future of shared creative and technical infrastructure, pay attention to the policy conversations happening at CISA, the White House Office of the National Cyber Director, and in Congress. The people who built the internet deserve better than a tip jar.