Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exciting! We're a tiny company and have sponsored WireGuard two years in a row; you can see us on the WireGuard home page. Cloudflare is a gigantic company who just used the WireGuard design work to fork the project. Has Cloudflare given a cent to WireGuard? Why isn't their logo on the site?


And why should they? WireGuard is free† so it seems (to me) a bit futile trying to shame them on a niche site like HN and expect them to change their behavior and support the community that they draw from. Mind you, this problem is not limited to Wireguard/Cloudflare. The NTP servers, curl, libssl prior to Heartbleed, the list of important open source software in need of funding goes on. It's fighting also a basic refusal or desire to pay. When was the last time someone you know paid Redhat for CentOS or Canonical for Ubuntu on principal?

What/how can we do more to encourage corporate sponsorship (either time or money) of code that's critical to a company? There are various ways the community has tried to enable this, in different ways. Librapay and platforms like it try to make it easier (Think Patreon but less commercial). The Linux Foundation takes large corporate donations and distributes it out to a large number of projects they support. Stick a paypal email address or bitcoin address in the Readme.md as a "serverless" way to receive money.

However at the end of the day, that seems to not work. Curl is used in billions of devices but the majority of the work on it has been done by one person for 20 years.

Something is not working as we hoped.

†) specifically Open Source under the GPLv2 license ‡) https://www.linuxfoundation.org/projects/


> And why should they?

Because that's a sensible thing to do when someone's open source project is at the very core of your commercial product?

> When was the last time someone you know paid Redhat for CentOS or Canonical for Ubuntu on principal?

Netflix and Tarsnap have donated to FreeBSD Foundation multiple times[1], and Jan Koum has donated over $1 million after selling WhatsApp[2].

Also, look at how many companies are sponsoring LetsEncrypt[3] – including Akamai and Fastly – but not Cloudflare.

[1] https://www.freebsdfoundation.org/donors/

[2] https://www.freebsdnews.com/2016/12/02/jan-koum-founder-what...

[3] https://letsencrypt.org/sponsors/


Sensible isn’t really the right word here. It’s sensible to buy a support contract. It’s charitable and good PR to give them money.


> It’s sensible to buy a support contract. It’s charitable and good PR to give them money.

If the development of an open-source project significantly affects your commercial product, there is nothing charitable in supporting it: because you are the one who needs that project to survive.


Not really, it's open source. You could just start putting resources into it yourself. If you back up to a local copy, it's not like that source code is just going to disappear.


I don't know. That's certainly a way of looking at the world. To answer that question, I'd have to give you a deep reason why companies like ours and Trail of Bits and the VPN providers donated. I can't tell you any more than "it seemed like the right thing to do".


If I’m not mistaken, they’ve open sourced their “fork” (actually more of a rewrite than a fork).

https://github.com/cloudflare/boringtun/

Which is more valuable to the community? I don’t really think you can quantify it.


AFAIK They acted same with nginx.


s/home page/donations page/

https://www.wireguard.com/donations/


use wireguard instead if you want to be safer... not exciting at all unless you are invested in cloudflare




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: