Slashdot Mirror


OpenBSD Project in Financial Danger

DieNadel writes "In an entry to the OpenBSD Journal, Marco, from the OpenBSD project, warns about the somewhat disturbing financial situation in which they are now. The OpenBSD team is the one that also develops the OpenSSH suite, used nowadays almost everywhere. From the entry: 'What I want to point out what a lot of people don't seem to realize is that OpenSSH development is paid from the same pool of money as OpenBSD. OpenSSH is in use by millions around the world however the revenue stream just simply isn't there. This is where other projects could help. Without naming entities or projects by name there are others out there that are sitting on some cash. It would be wonderful if these entities could share some of the wealth to keep us going.'"

13 of 610 comments (clear)

  1. Seperate the openBSD & openSSH projects? by tpgp · · Score: 4, Insightful

    I know some large companies (cough*apple*microsoft*redhat*cough*) can certainly afford to support openSSH, and need the project to continue running.

    These companies however would not want to give to an operating system project that competes with them.

    Maybe the openBSD & openSSH projects should seperate?

    --
    My pics.
    1. Re:Seperate the openBSD & openSSH projects? by zerocool^ · · Score: 4, Insightful


      Maybe the openBSD & openSSH projects should seperate?

      This is exactly the first thing I thought when I read this story. It sounds like the developers are yelling: "OH NOES, OPENSSH IS DYING, WE NEED MONEY!!!!11", and then honest people, who want to support openssh, ask "How can I support OpenSSH?". The answer given is "Give money to OpenBSD."

      To me, that's unacceptable. It's classic bait-and-switch. I use OpenSSH every day of my life and if you count scripts and cronjobs, probably every hour of my life. But I could give a shit about OpenBSD. So, while I'd be willing to help OpenSSH out, I want to know that my money is being spent on OpenSSH. I don't want the overhead going to OpenBSD. There, I admit it - I expect something in return for the money I donate - it's my money so sue me.

      You want to get support for OpenSSH? Fork off the legal entity and make an OpenSSH foundation which can accept donations directly. We're not going to solve your OpenBSD problems for you, though.

      ~Will

      --
      sig?
    2. Re:Seperate the openBSD & openSSH projects? by peacefinder · · Score: 4, Insightful

      "I like my tax money to fill potholes in the street outside my house, but not the ones in front of your house. Screw taxes, I'm not paying!"

      Same argument, only taxes aren't voluntary. This is.

      (Don't forget that the money you might give only to the OpenSSH project would go towards ensuring it works on about a dozen hardware platforms. I suppose you'd prefer that such money go only to OpenSSH/i386, because that's all you think you use?)

      --
      With reasonable men I will reason; with humane men I will plead; but to tyrants I will give no quarter. -- William Lloyd
    3. Re:Seperate the openBSD & openSSH projects? by Alioth · · Score: 4, Insightful

      Do you use the X Window System (i.e. any Unix desktop?)
      In which case, OpenBSD is helping you. OpenBSD's new safer malloc()/free() implementation found security bugs in x.org recently.

      Same goes for most things that end up as part of OpenBSD - the stricter environment of OpenBSD shakes out bugs and the entire community benefits, not just OpenBSD users.

      OpenBSD benefits far more than its immediate userbase.

  2. Re:Sad by danielk1982 · · Score: 5, Insightful

    Hopefully someone can pick up the slack and donate to this great project.

    You?

  3. Open Source Funding... by Anonymous Coward · · Score: 5, Insightful

    What you said may sound troll-ish to some, but it just goes to show how little support there is for open source projects - especially money wise. Everyone here seems to think everything should be F/OSS, and that you should live off support contracts and such. But in reality, 99.9% of the time, it just doesn't work out (and I don't know many coders who want to do a living off answering the phone instead of coding).

    There are some great and very useful OSS projects, but I don't make a living that way. My money comes off closed source/proprietary software - on the hugely popular closed platform. It's already hard enough making a living this way, I can't imagine how "easier" it would be if I gave the app away with the source code and let people fork it. I have enough money now to retire at 30, put my kids thru university, etc. Had I gone the open source way, I don't think this would be true.

    It's just like websites and newspapers lately. Besides some advertizing (that we block in any way we can like using AdBlock), there just isn't much of a revenue stream. Nobody's really figured it out yet... Yet there are so many bright folks who've been scratching their heads for a while. This could be the 2nd "dotcom" crash - money has to come from somewhere to fund all this.

  4. the flip side to all this by corbettw · · Score: 4, Insightful

    No one's made this observation yet, so I figure I should: the flip side to OpenBSD not having enough money to maintain operations means that the software they make, especially OpenSSH, is in danger of being no longer supported. Yes, yes, I know, it's free software, so someone else can pick up the pieces after Theo is forced to take his toys and go home. But the reality is that no business in the world should trust software who's creator is about to implode.

    What happens in six months when OpenSSH is no longer actively supported by the team that created it and a new exploit is discovered/released? What responsible IT manager is going to let his employer get into the potential problem in the first place?

    I say, rather than begging for donations, the OpenBSD team needs to get their act together and find a way to keep the lights on, or they're going to see fewer and fewer people trusting the use of their software in large corporate environments. If that means the leader of the team needs to keep his mouth shut about his anti-war views when he's depending on a grant from the US Defense Department to keep his operation going, then that's what he needs to do. Being an adult means doing things you don't neccessarily want to do, like eating your peas and broccoli.

    --
    God invented whiskey so the Irish would not rule the world.
  5. Re:Sorry, wrong answer by Bogtha · · Score: 4, Insightful

    It sounds like they're basically asking other F/OSS projects to fork over cash because OpenBSD can't raise money.

    What are you talking about? Let's look at that quote in full:

    OpenSSH is in use by millions around the world however the revenue stream just simply isn't there. This is where other projects could help. Without naming entities or projects by name there are others out there that are sitting on some cash. It would be wonderful if these entities could share some of the wealth to keep us going.

    It seems to me that he's talking about businesses such as RedHat, who include OpenSSH in their products, not random open-source projects.

    If you are going to have an OpenBSD organization, then that means that part of your job is raising funds to keep yourself a going concern.

    And if you were keener on reading the article than flaming, you would see that they had a working revenue stream in the form of selling CDs, but that people were moving away from it in preference to obtaining it for free.

    The demand isn't any less, they aren't losing any users, they are just having to deal with people less willing to spend money when they can get something for free. It seems very reasonable to hint - without naming names - that the businesses who base their products on OpenBSD's work should contribute a bit. It's in their own best interests even.

    --
    Bogtha Bogtha Bogtha
  6. Their biggest problem... by chill · · Score: 5, Insightful

    ...is that there is no corporate entity at all. You make checks out to "Theo de Raadt", which *isn't* going to happen from any really large company with deep pockets. There is zero tracability and zero accountability.

    When the U.S. DoD was funding them, the disbursements were handled thru a University or some such.

    They need to grow up as an organization. Find a sympathetic accountant to donate his time/effort to establish a tax-free (and tax deductable) non-profit in Canada and an arm in the U.S. Hell, maybe one in the EU and one down under as well.

    This will make them infinitely more appealing to corporations who have deep pockets and MAJOR qualms about writing big checks out to individuals.

      -Charles

    --
    Learning HOW to think is more important than learning WHAT to think.
  7. Re:Nice of Maddog -- but this is one for Google by Triumph+The+Insult+C · · Score: 5, Insightful

    you are wrong

    what openbsd needs, and what the article is highlighting, are the big companies who use openssh to kick in a few bucks

    cisco uses it in their kit. soes does hp. ibm is another. do you think that between the three, they can't come up with say, $75k/year?

    ~a year ago, a friend of mine consulted at a company that was reworking their entire network. they ended up spending well over $30k on kit. they chose cisco *because* they had ssh (openssh btw) on their kit at the time. the other vendors they had did not

    --
    vodka, straight up, thank you!
  8. flush master by epine · · Score: 4, Insightful


    If eighty cents of every dollar I spend supporting OpenSSH gets flushed down the OpenBSD toilet, is that a good use of my contribution?

    The cluelessness of this post defies belief.

    I want to support this OpenFoil airplane wing because it supports me. However, if eighty cents of every dollar I spend supporting OpenFoil is vented through the OpenBlow high-test wind tunnel, is that a good use of my contributions?

    NX protection, Pro-police, and priv-sep are all products of the two efforts coordinated together. Almost every dime OpenBSD spends is spent in the pursuit of enhancing security, and it's to imagine that those results are not immediately folded back into OpenSSH. Unlike FreeBSD, OpenBSD spends shockingly little on the OS itself. They aren't busy inventing disk geometry managers or porting to 150 different platforms.

    90% of human stupidity originates in the capacity of the human mind to engage in intellectual shell games. Here is this dollar: let's split it up in to the 80 cents wasted on OpenBSD and the 20 cents invested in OpenSSH.

    Or, my brother is dying of Leukemia. I want to donate blood because blood keeps him alive. Is that a good investment if 80% of the blood I donate is flushed down the toilet to replace blood lost during bone marrow transplants?

    Almost too dumb to live, really.

  9. Re:How you can help by Billly+Gates · · Score: 4, Insightful

    Right on

    Just say no to TCP/IP, BSD UNIX, WWW, the Internet, FTP, and many algorithms used for smp systems and servers.

    If it were not for uncle sam you would be paying $50 a month for AOL or CompUserve on a dialup modem with no interent nor innovation.

    The government is not that evil in doing things like setting standards and funding research that private industry can't do because of their need to generate profits.

    I have no problem with academia sponsoring OpenBSD because it will help everyone including business and personal use. OpenSSH is the result of free software and so is the web and apache.

    Its not that evil folks and the government is not always bad. Sometimes its needed because the industry can't help itself.

  10. Re:Do what you can. by LinuxGeek · · Score: 4, Insightful

    If he was at a conference, then he probably had his travel expenses paid by the organization. Very common.

    Also, I just sent a donation to OpenBSD via paypal. Even if I don't think of Theo as the greatest guy in the OSS world, the project is very important to keep alive, and not just for the OpenSSH portion. The OpenBSD group has made a public plea for support and I'm dissapointed to see something along the lines of "needing money, huh, hehehehe then just suffer bitches..." from many posts here.

    I'm sure that talented people with a little spare time will read those kinds of posts and be glad to spend a year or two writing something cool and useful for you. With these attitudes, they may get what they are really begging for; a computer running microsoft software because developers got tired of people not stopping at mere indifference towards the projects, but happily extending into ridicule. What a grateful bunch we must seem to be.

    --

    Kindness is the language which the deaf can hear and the blind can see. - Mark Twain