Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"I now have six amazing clients, and I’m making an amount of money equivalent to my Google total compensation package,[1] which proves the thesis that it’s possible to be a professional maintainer earning rates competitive with the adjacent market for senior software engineers."

His experience is totally unique. Please don't let this make you think you can quit your job and earn the same you did at your high paying FANG job. He's an outlier in the industry. I was a nobody when I left my job to work on open source full time. It was a year before I found a corporate sponsor and that was only because my friend worked there and he understood the value of what I was working on. Patreon was laughable in terms of what came back. Just be fully aware as you read this. With existing brand and following you can do what he did, without it you'll struggle immensely like I did.



> I’m sharing details about my progress to hopefully popularize the model, and eventually help other maintainers adopt it,

Hopefully this won't inspire people who don't meet the right conditions and whatever luck contributed to this existence proof.

I've known a lot of poor people trying to make it as independents in open source. I once sent a laptop to a homeless kernel hacker (and, earlier, sent them food), and had to find a laptop specifically to be small and discreet, because they feared being stabbed for anything flashy-looking. Another, who has done talks on their novel work at major hacker-as-in-HN conference, as well as other accomplishments, I had to tell them about Medicaid, because they couldn't afford to go to the doctor when they really needed to. One who accomplished something major that most HNers have used or heard of, was living in a trailer, and died. I've also known plenty of people in open source who had modest day jobs and were pretty stressed and depressed from money problems, and the cascading effects of that, despite being at least as tech-skilled as people making FAANG money.

If you happen to find yourself as the official maintainer of multiple open source components that are recognized as key by numerous enterprises (and cryptobro ventures) that are flush with cash, and you have ins at some of those, and you have a safety net warchest from years of FAANG, and enough reputation you could probably go back if the whole indie open source consultant thing didn't work out... sure, consider a consultancy like this post describes, as a lifestyle move.

Otherwise, it's like the movie star child of a Hollywood producer evangelizing this great career success formula they've found, prompting a bunch of aspiring actors to buy one-way Greyhound bus tickets from Kansas to LA, where most of them will be lucky if the worst that happens is they end up waiting tables.


I'm making about €30/month from Github sponsors. Of course I had to get a day job, so my open source time is limited compared to the previous decades. Though my company is fine for me contributing to some GNU projects or openssl.


I quit my job a couple years ago and secured several small retainers over a few weeks using my network. My employer at the time generously agreed to be my first client to smooth the transition.

Today I have am managing 8 active retainer clients, and regular 1-2 week audit contracts, while rarely working more than 40 hours a week. Virtually all code I write is open source, or on track to be so soon, and I only work with clients okay with that.

I am making triple my previous salary, and am actually onboarding new team members as a "tier 1" to help me meet demand without overworking myself.

I am a full stack security engineer with 20 years of experience, and most companies can't have access to senior security engineers without paying GAFAM money in the range of $600k+ total comp, which they just can't afford.

Instead I offer most companies start a retainer with my team and I for as little as 10 hours a month and we can be there when they need help with security architecture, important code reviews, risk assessments, conducting interviews, or just to help unblock people in general.

This model is a win for companies that can't yet afford experienced full time security hires in house, and it is a win for me who can be in control of my time and life with higher income, and only have to focus on the most interesting problems of many different companies with minimal exposure to internal politics.

I can't express how much happier I am. Best career choice I ever made. YMMV.


> most companies can't have access to senior security engineers without paying GAFAM money in the range of $600k+ total comp

It's difficult to believe that even in SV.



> His experience is totally unique. Please don't let this make you think you can quit your job and earn the same you did at your high paying FANG job. He's an outlier in the industry.

…and yet…

I run a self-funded SaaS business. I regularly pay (sponsor) developers of libraries that my software depends on. These are not large amounts, but they slowly grow over time. Additionally, there are some libraries (Semantic-UI for example) that are critical for me, but have been unmaintained for a while, and I'd gladly pay significantly more, on a regular basis, to have them maintained.

I am pretty sure I am not the only one. The money is there. The problem is in gathering critical mass: both for any single developer, to make a living, and for the entire movement, so that we shift from a culture of "FREE FREE EVERYTHING IS FREE" to a more responsible and sustainable "it's free, but if you depend on it, you better contribute money every month".


Quite frankly you're extremely unusual. As much as I sound cynical here, the only reason we use open source stuff in our production SaaS is because we don't have to raise a purchase order to get it or go through the whole onboarding process which is a pain in the ass. The money isn't even the issue; it's there and available but it's a bureaucratic shit show trying to give it to people. And the same is true everywhere I've worked for the last 20 years. Yes I know this is wrong.

Business idea: If there was a single corporate intermediatory who would handle all this sitting somewhere we could create a supply agreement with and funnel the cash through to the right people we could probably deal with it. We currently do this via AWS marketplace regularly so we don't have to deal with the paperwork.


I feel like there is a business waiting to bloom here. Imagine a stripe like company that says “we are the unified B2B transaction company” who takes both sellers of software and buying enterprises as customers and create a easy to use purchase system where a software dev in the US could sell to a company in New Zealand without worrying about 1. Currency conversion 2. Local tax collection 3. Invoicing 4. Any other local formalities

That is totally worth day 10% of the value of the product!


>That is totally worth day 10% of the value of the product!

It won't work: this company will eventually crank up their fees to 30+% of the value.


These companies exist, at least domestically in varying regions of the world.

A lot of software/B2B sales are procured through a channel whose primary purpose is an existing business relationship with the company you're trying to sell to.

They take a % as a transaction fee. Anywhere from 10-30%, depending.


Ah, procurement.

They exist. They suck, they all suck... and I say this as a vendor "procured" by these companies.

It's a necessary evil, one that's ripe for disruption.


I think it's a logical next step for companies like Crossbeam[1]. You have a network of partners, some of which are fulfillment partners. They can be the middlemen to expand your network and take a piece.

1: https://crossbeam.com


Sounds like Open Collective.


> Business idea: If there was a single corporate intermediatory who...

Isn't that what tidelift [1] is doing?

[1] https://tidelift.com


I get your point. I'm not too keen on administrative overhead, either.

> Business idea: If there was a single corporate intermediatory who would handle all this sitting somewhere we could create a supply agreement with and funnel the cash through to the right people we could probably deal with it.

Isn't that exactly what Github does through its Sponsors program? I think I only handle two endpoints these days: Github Sponsors and Clojurists Together. Github works very well, and they will even fold/consolidate new sponsorships into your existing invoices as you add them over time.

I don't think "overhead" is a valid excuse anymore.


> the only reason we use open source stuff in our production SaaS is because we don't have to raise a purchase order to get it

I'm sure it's not the only reason to choose open-source tech.

At least with open-source projects you can read, patch, clone or fork the source


I don't think current platforms make it easy for developers to make money from their software. Especially libraries. There's a total unwillingness to pay for support because it's easier to just open a GitHub issue and complain. I think you're a rare case and that really means developers can't make a living off stuff like this. The few exceptions are something like sqlite maybe. Other stuff ends up needing to be heavily VC funded or backed by corporate sponsorships.

If GitHub actually helped developers make money this would be a different story. Sponsorships are a tipjar, it's not a sustainable path, it's not a form of employment. Grants, same thing, waste of time. We need the ability for developers to put a Pay but on their repositories. This is not about optional sponsorship. This is about paying to download the code, paying for use after a certain point. This is about putting a real number on the value of software. It only works when you define the economic model. If each Dev has yo setup their own website, integrate payments, do sales, etc its a struggle. GitHub is a big enough distribution channel where they could actually streamline this, App Store style. I know they have a marketplace but realistically who's using it?


> If GitHub actually helped developers make money this would be a different story. Sponsorships are a tipjar, it's not a sustainable path, it's not a form of employment.

I really don't understand. GitHub does help developers make money. Sponsorships are subscriptions, not one-time tips. If you can get 20 companies to pitch in with, say, $250/month, you begin to look at a sustainable living. From a company point of view, paying, say, $1000/month for four most-used pieces of software that the company depends on, is still many times less expensive than hiring even a single full-time developer.

I feel like rather than trying to change the mindset ("everything must be FREE FREE FREE"), we are trying very hard to find reasons not to use a perfectly good existing solution.


With GitHub, sponsorships are either one-off payments or regular subscriptions. FWIW I've only ever been paid once through GitHub sponsors and that was a one-off payment. This payment ($500) was actually from GitHub itself because they use the software I work on.


It's the issue with the concept of sponsorship. It's still associated with optional donation rather than payment for a service or tool you need. That mindset shift is huge. Until someone does it we'll continue in the way we're going.


The number one rule of transitioning to contractor is _do not start from zero_. This can't be stressed strongly enough!! The amount of time and energy it takes to get the ball rolling in that space before momentum kicks in is enormous. Hoping to rely on the goodwill of the anonymous masses, and not leaning _extremely_ hard on your existing direct network is absolutely a failure waiting to happen in 99.9% of cases. If you are working full time, and plan to transition, you absolutely should be moonlighting it first and/or have hard contracts in place with your first 'medium/long-term' client already (i.e. not a one-off engagement).


With six clients one could think, ok it's not so expensive for them, but still sums up nicely for the developer.

Still I think the situation is highly exceptional. Which employer/client would be happy with someone working for them only 1 day a week? And think about the adminstrative overhead for a single person to deal with 6 contracts all the time. With some clients the paperwork can be significant.


The context switching is substantial with 6 clients, even if it's the same tech. As for 1 day per week: a very senior person can give good advice or point to the right direction. The company I work for isn't a tech company, but we do hire people to provide specialist knowledge and it doesn't require full time position to do so.


The “thesis” he speaks about only needs one example to hold, and he is it. So, not much of a “thesis” but a data point.

It is possible to survive a shark attack. Well, yes, but do not count on my to try.


> He's an outlier in the industry.

...even more than that. He's an outlier in the industry and has chosen an industry with access to pyramid scheme money.

Neither the investment bubble surrounding FAANG, nor the job market bubble surrounding the talent pool that FAANG recruits from (namely SE talent that happens to be localized in the Bay Area) were sustainable.

Now that the market seems to finally be correcting away from that unsustainable local equilibrium, he's hopping right into the next one by becoming an open source crypto bro.

> "proves the thesis that it’s possible to be a professional maintainer earning rates competitive with the adjacent market for senior software engineers."

"Prove" is a strong word but "possible" weakens the statement.

"It's possible to earn 95th-percentile compensation." True, by definition, for 5% of all people. Nothing to see here. "There's more than one way of getting there." True. "Honest pay for honest work will get you there." Probably not. "Just seek out the bubbles and jump right in is a reproducible way of getting there." Probably not, you'd have to get the timing right, and that's mostly luck.


For anyone reading this, don't be misled by "open source crypto bro." into thinking the author is a web3 "crypto" developer, he is the maintainer of the go crypto library. Also what do you mean by 'Bro'?, it sounds demeaning. I have met filippo and he is far from being how you're insinuating him to be.


Yes, this guy is doing proper crypto, and the "pyramid scheme money" comment is uncalled for and incorrect.


As are geologists who do “proper geology” research that aids the identification of underground oil wells. Yet it’s still relevant to point out where their funding comes from when it’s an oil company.


Pointing out, maybe. But calling OP an "open source crypto bro" and saying he earn "pyramid scheme money" is too much.

Effectively what should be pointed out is "this guy makes some extremely fundamental crypto libraries that are used by millions of projects out there, including cryptocurrencies". But that's hardly relevant.


Does it matter if "the guy is doing proper crypto" if he is getting paid by "pyramid scheme money"? Arguably it is worse since his presence is ostensibly legitimizing the "pyramid schemes". It feels like the techie version of celebrity endorsement


I just use the term "crypto bro" broadly to refer to anyone who benefits, directly or indirectly, from cryptocurrencies, NFTs, and things like that. I do consciously choose a term that expresses the fact that I have a negative attitude towards those things as I believe that they're not "honest money".

Taking Google-money means taking money that's earned through surveillance capitalism and anticompetitive tactics deployed by a monopolist that erode our free markets. Taking crypto-money means taking money earned through "greater fool theory" of valuations of investable assets.

People, on the whole, are never all-good or all-bad. When I see somebody showing off their good sides, I instinctively start looking for the bad. When I see somebody owning up to their bad side, I instinctively start looking for the good.

The good in this person is that he does open source. But that doesn't make him an angel. The bad in this person is that he's a top earner in part because he takes money that causes bad things to happen in the economy. As to his personality, I simply have no information on that and have never met him.


> I just use the term "crypto bro" broadly to refer to anyone who benefits, directly or indirectly, from cryptocurrencies, NFTs, and things like that

Which he does not do. He develops cryptographic libraries (used to encrypt files, network connections and the like). Nothing to do with cryptocurrency at all, save some cryptocurrencies might use the library he writes, but most of the use will be for TLS connections, file encryption etc.


The article mentions "Filecoin", whatever that is.


It mentions it as one of the well-known outputs of a company he consults for. I am confident that he is not working on a cryptocurrency at all.

If your definition of "crypto bro" is so broad to include "receives money from any person or company that has ever incidentally done anything with cryptocurrency" you've basically painted the entire industry that way.

Just because it mentions "Filecoin, whatever that is" doesn't imply that he's working in cryptocurrency.

I use "crypto bro" to describe people who actively work/invest in cryptocurrency directly and/or evangelize it. This usage does not intersect with Filippo at all.


> any person or company that has ever incidentally done anything with cryptocurrency

But Filecoin IS a cryptocurrency. It's not merely "incidental".


Of course it is. Cryptography libraries can be used for lots of things. If one of his clients uses them for cryptocurrency, it is incidental.


Look again at the logos prominently displayed in the blog post. There's nothing incidental here and you don't get to make that kind of money otherwise...


That still doesn't make him a "crypto bro", any more than those companies using cloud providers makes the cloud providers cryptocurrency specific. They require stuff that's pretty universally applicable.

Or change my mind and show me which of his projects is cryptocurrency-specific.


> to refer to anyone who benefits, directly or indirectly, from cryptocurrencies, NFTs, and things like that

You don't?

There's a massive difference between "hey this signature scheme is safe, trust me I'm a cryptographer, all my colleagues agree" and "hey this signature scheme is safe because if anyone can break it they can steal over $1,000,000,000 USD anonymously"


> I do consciously choose a term that expresses the fact that I have a negative attitude towards those things as I believe that they're not "honest money".

The fact that "bro" is a derogatory term for you is also not great.


>When I see somebody showing off their good sides, I instinctively start looking for the bad.

Fair enough, no reason to denounce him as "crypto bro", though, because you know full well what it insinuates.

Also:

>Google-money [...] surveillance capitalism

The email domain from your profile points to 180.136.102.34.bc.googleusercontent.com ...

Just saying, you know.


> has chosen an industry with access to pyramid scheme money.

Seems you can confusing cryptography with cryptocurrency, this guys is a cryptographer, that's a proper expert level security guy, nothing to do with pyramid scheme money.


I’m pretty sure that’s fully accurate. Filippo mentioned one of his backers is the Interchain Foundation [1], and several others of his backers are at the very least cryptocurrency/web3 adjacent. Note, the GP didn’t say that Filippo is working directly on cryptocurrency - but that the funding is likely (at least in part) coming from cryptocurrency profits.

1. https://interchain.io/


Cryptocurrency is one way of applying cryptography, and the article mentions "Filecoin", whatever that is.

Even aside from cryptocurrency, blockchain, NFTs and that kind of stuff, there's a lot to question when it comes to the ethics of the computer security industry. A lot of it is snake oil, like Firewalls that basically whitelist everything so as not to become annoying. A lot of it is a racket (e.g. you can't get insurance for your company if it doesn't have antivirus software). VPNs basically make money by helping people break the law by circumventing geoblocking. I could go on, but I won't.


Break the law? What are these countries that have instituted geoblocking into their laws?


I read that comment as referring to the Bay Area startup bubble.

I myself don't refer to anything that isn't paying new customers with old customers money as a pyramid or Ponzi scheme, because I think that trivializes actual pyramid schemes.

But a lot of people do, apparently, and it's completely understandable that a self perpetuating scheme where startups losing money at their core business at a varying rate are constantly sold at higher and higher valuations to see who holds the last hand, is regarded with the same skepticism.


By "pyramid scheme" I meant crypto, not Bay-area startups.

> I myself don't refer to anything that isn't paying new customers with old customers money as a pyramid or Ponzi scheme

In Wikipedia's definition, that aspect doesn't seem to be strictly necessary [1]. They define it as "a business model that recruits members via a promise of payments or services for enrolling others into the scheme".

In my mind it also plays a bit of a role whether you're doing that with retail investors vs. high-net-worth or institutional players. A retail investor generally can't invest in startups, but might invest in crypto if their neighbor recently bought some and then talked them into it.

[1] https://en.wikipedia.org/wiki/Pyramid_scheme


A person doesn't get any direct reward for convincing their neighbour to buy crypto, though. Compare to a multi-level marketing scheme where the person would directly sell to the neighbour.


> "Prove" is a strong word but "possible" weakens the statement.

Prove is the technically correct word here, in the sense of mathematical proofs: the existence of an example proves that it's not impossible.


Yes, it's absolutely mathematically correct, while being entirely uninteresting when taken in its strict mathematical meaning.

When a motivational speaker says something like "Billionaire X proves that it's possible to be a billionaire" that's mathematically correct, yet totally uninteresting. What people go there to hear about is methods for reproducibly becoming a billionaire or even just slightly increasing your odds of becoming a billionaire, and this article is just as lacking in that department as most motivational speeches.

Don't get me wrong. I think open source is a good thing. It seems like the author is working hard, doing good work, sharing it, and making a solid livelihood may be well-deserved for him. There's just nothing here that suggests a reproducible method.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: