Part 3 of 8. Part 2 set out what dependency costs you.

What this post covers

  • The years when open source was fought.
  • Why the fight stopped.
  • Who keeps the software going today.
  • What happened when the makers tried to charge.
  • What happens to companies after they are bought.
  • What it means for you.

The years when open source was fought

Open source is software whose code anyone can read, use and change.

It is ordinary now. For about 15 years it was treated as a threat.

In October 1998 an internal Microsoft memo leaked. Eric Raymond published it with notes, and it became known as the Halloween documents.

The memo was honest about the quality of open source. It called the way thousands of people work together on it remarkable.

Then it set out what to do about it. One line explains a great deal:

By extending these protocols and developing new protocols, we can deny OSS projects entry into the market.

A protocol is an agreed way for 2 systems to talk to each other.

So the plan was not to build a better product. The plan was to change the joins between products, so a competitor could not be dropped in.

Several other steps followed over the next 10 years.

In 2003 a company called SCO claimed Linux contained code it owned. The case dragged on for years and SCO did not win. While it ran, plenty of organisations were unsure whether Linux was safe to take on.

Microsoft also signed patent agreements with mobile phone makers. For several years it took a payment on every handset sold running Android, an operating system it had not written.

In 2008 Microsoft’s document formats were approved as an international standard. Several national standards bodies objected to how that was handled.

Europe pushed back on some of it. The European Commission fined Microsoft €497 million in 2004 over information competitors needed to work with its products.

It fined the company €561 million again in 2013, because an agreed remedy had not been put in place.

That second fine is worth a moment. The problem was not a new one. The agreed fix simply had not been done.

Why the fight stopped

It stopped around 2014, because it had not worked.

Linux had become the software most servers run on. It also runs most cloud services and most mobile phones.

You cannot take something out through the courts once everything is built on top of it.

So the approach turned right round.

Microsoft joined the Linux Foundation. It released some of its own tools as open source. In 2018 it bought GitHub, the site where much of the world’s open source gets written.

Amazon and Google built very large businesses on open source, and all 3 companies now put a great deal of work back into it.

That work is real, and the software is better for it. It would be daft to pretend otherwise.

But 1 thing did not change.

The companies that once tried to slow open source down are now among its biggest funders. They are also still the biggest companies in the market.

Open source won the technical argument. It did not change who holds the strongest hand.

Who keeps the software going today

Here is the bit that surprises folk outside software.

A great deal of widely used open source is kept going by very small teams. Some of it by 1 person, in their own time, for nowt.

Those same pieces then sit inside products sold by very large companies.

In December 2021 a fault turned up in Log4j, a small tool Java programs use to record what they are doing.

The fault let attackers run their own code on affected systems. It hit an enormous number of organisations at once. The UK National Cyber Security Centre put out guidance on it.

The tool was maintained by a small group of volunteers.

The lesson is not that open source is risky. Most of it is very good, and open to inspection in a way closed software never is.

The lesson is about paying for things. Shared work that many businesses lean on needs funding, and often does not get it.

This one is fixable, and some organisations do fix it. Paying a maintainer, or funding a foundation, is usually a very small cost next to what the software saves you.

What happened when the makers tried to charge

Some companies build open source and sell a paid service round it. That worked well enough for a long while.

It got harder when cloud providers started offering the same software as a service of their own.

The provider took the revenue. The company that wrote the software did not.

Several of them responded by changing their licence, so others could not offer their software as a competing service.

  • MongoDB changed its licence in 2018.
  • Elastic followed in 2021.
  • HashiCorp changed in 2023.
  • Redis changed in 2024.

The Open Source Initiative sets the accepted definition of open source. It ruled that 1 of these new licences did not meet it.

Plenty of Linux distributions then dropped the affected software.

The wider community took copies of the last open versions and carried them on separately. A copy like that is called a fork.

  • OpenSearch carries on the earlier Elasticsearch code.
  • OpenTofu carries on the earlier Terraform code.
  • Valkey carries on the earlier Redis code.

Elastic and Redis have both since gone back to open licences.

It is worth looking at how that ended, because nobody involved got what they were after.

A company built useful software. A bigger company made more from it than the maker did. The maker restricted the licence to survive. The community objected, rightly, that this was no longer open source. A fork appeared, often backed by the bigger companies.

At the end of it the software is still free to use. The forks are mostly steered by the biggest players. The business that paid for the original work is weaker than when it set off.

What happens to companies after they are bought

The second way value leaves a business has nowt to do with software licences.

It is about how a company gets bought.

Here is the pattern, plainly.

A buyer borrows most of the purchase price. The loan is then secured against the company being bought. So the company ends up carrying the debt used to buy it.

The buyer may then sell the company’s buildings and rent them back. The money raised can be paid out to the new owners. The company now pays rent on premises it used to own.

Costs that do not show up this year get cut. That usually means maintenance, staff numbers, research and product development.

Then the company is sold on.

The Bank of England has looked at the financial stability side of this. Its review of private equity notes that heavy borrowing on buyouts makes those companies more likely to default, and leaves their lenders exposed to losses. It has kept watching the sector since.

Not every buyout works this way, and plenty of owners invest rather than strip. This is a pattern to recognise, not a description of all buyers.

But where it does happen, the outcome is the same every time.

The business was usually working fine. What did not work was the business plus the debt taken on to buy it.

The same business before and after a buyout funded by borrowingBeforeAfterThe workSame staff, same customersOwns its buildingsNo debt from being boughtFunds maintenanceFunds researchRent paid: noneThe workSame staff, same customersRents the same buildingsCarries the loan used to buy itMaintenance reducedResearch reducedRent paid: every monthbought withborrowed moneyThe business still does the same work for the same customers.What changed is what it owns, and what it now has to pay out.
The same business, before and after. The work and the customers stay put. The buildings and the borrowing change hands, and the running costs go up.

The same pattern in software

This reached software some years back.

The asset being worked is not a building. It is the customers who cannot easily leave.

A mature product with long-standing customers can be repriced. Those customers cannot move quickly, and as such most of them pay.

At the same time, spending on engineering can be cut. That takes years to show, and by then the sale has gone through.

Part 2 covered what this looked like for VMware customers.

There is a version funded by investors rather than debt, too. It has been described often enough to earn a name: enshittification, a word used by the Canadian writer Cory Doctorow from 2022.

It runs in 3 stages.

  1. The service is sold below what it costs to run, paid for by investors. It is cheap and good, so people move to it.
  2. Once people cannot easily leave, it is changed to suit the paying business customers instead.
  3. Once both sides are committed, terms change again to raise profit.

Stage 1 is the one that matters for this series.

A company selling below cost for years is not winning because it is better. It is being funded to take the market.

Smaller businesses that have to cover their own costs cannot match that price. Plenty shut.

When prices later climb to something sustainable, the choice that used to exist has often gone.

What it means for you

Two practical things come out of this, and both are easy enough to do.

Check how many people keep your dependencies going.

Look at the tools your systems could not run without. Find out how many people actively maintain each one.

If the answer is 1 or 2, that is worth knowing. You might want to fund that work, keep your own copy of the source, or plan what you would do if it stopped.

Watch who owns your suppliers.

Your terms follow the owner, not the product. A change of ownership can shift your renewal more than any change in the software.

When you sign, check what you keep if you stop paying. Check whether you can still run what you have already installed, and whether you still get security updates.

Neither takes long. Both are far easier before a renewal than during one.

Part 4 looks at what courts and regulators have already decided.


First published: 2026-08-25. Last updated: 2026-08-25.