Economics

The day the internet found out who was maintaining it

In 2014 a bug in OpenSSL revealed that software securing about one in six secure websites had a handful of maintainers and almost no donations. Here is what is true, what is folklore, and what your business still carries.

A dark card headed "The story behind - Heartbleed". In large amber type: "1 in 6", then in white: "of the world's secure websites." Below: "Looked after by a handful of people. One of them full time." Footer: OSS Malaysia, ossmalaysia.com.

On 7 April 2014, Neel Mehta at Google and a Finnish firm called Codenomicon separately reported the same mistake in software called OpenSSL. OpenSSL is what puts the padlock next to a web address: it keeps a customer's password private between their phone and your server.

The mistake was ordinary. A server would answer a routine "are you still there?" message, believing whatever that message claimed about how much text to send back. Send almost nothing, ask for 64 kilobytes, and you got 64 kilobytes of the server's memory: a password typed seconds earlier, a customer's session, sometimes the server's own master key.

No account needed, no password, no trace in the logs. That last part mattered commercially: no business could prove it had not happened to them.

Be careful what you take from that. No mass theft before disclosure was ever proven, and no confirmed mass exploitation was ever established. The known impact is that nobody could rule it out — and it was the impossibility of ruling it out that forced a global weekend of patching and password resets. That is the cost: labour and downtime, not a single dramatic loss.

The bug was not the story. The maintenance was.

The code was written on 31 December 2011 and shipped publicly on 14 March 2012. It sat in released software for just over two years, reviewed and unnoticed.

Five days after disclosure, Steve Marquess, co-founder and president of the OpenSSL Software Foundation, published a post about the money. His figure, repeated ever since: donations of about USD 2,000 a year, and one developer working full time.

That number is almost always told wrongly. USD 2,000 was donation income, not the budget. The foundation also earned consulting and certification revenue, reportedly never exceeding USD 1 million gross in a year. People were paid — through contracts they had to win themselves, which is time not spent on maintenance.

Told accurately it is worse. It measures not what OpenSSL cost to run, but what the world voluntarily paid for software half the secure web was sitting on.

What is folklore

"Two-thirds of the internet was vulnerable." Wrong. Two-thirds was the combined market share of the Apache and nginx web servers in Netcraft's April 2014 survey, not the share exposed. Netcraft's actual estimate was around half a million trusted secure servers, roughly 17.5% of SSL-enabled sites — one in six, and the only scale figure here with a named methodology.

"Two people maintained OpenSSL." Sources disagree: one full-time developer, two, four active core developers, fifteen project members by December 2014, depending on what is counted. "A handful, only one full time" is the most that is supportable.

Any direct quotation. We could not read Marquess's original 12 April 2014 post at source: the domain now serves a mismatched certificate, and we could not reach the archived copy from here — a limit of our own tooling, not a claim that the archive is gone. Its substance is confirmed by several outlets that did read it, so everything above is paraphrase and nothing is in quotation marks.

This is not an argument that open source is unsafe

Weeks before Heartbleed, on 21 February 2014, Apple patched CVE-2014-1266 — "goto fail". A single duplicated line skipped the final signature check in Apple's connection security, across macOS and iOS. That November, Microsoft patched a flaw in Windows Secure Channel undetected for roughly nineteen years.

Apple's budget. Microsoft's staff. Microsoft's own review found the second one, which is the point: nobody outside could have looked. Both kinds of software have shipped holes like this; what differs is who is allowed to find them. The real variable is whether anyone is paid to look.

Money arrived. The ratio did not change.

Seventeen days after disclosure, the Linux Foundation announced the Core Infrastructure Initiative: thirteen of the largest technology companies in the world, each pledging USD 100,000 a year for three years. The whole annual pool for critical internet infrastructure was smaller than one senior engineering team's payroll at any single funder. CII became the Open Source Security Foundation in 2020; Alpha-Omega followed in 2022 with USD 5 million from Microsoft and Google. All useful, none of it enough.

In December 2021, Log4Shell hit a component present in a large share of business software; the team responsible was 16 unpaid volunteers. In March 2024 a backdoor was found in xz-utils — bundled with essentially every Linux distribution, maintained by one person — after an attacker spent two and a half years winning commit rights. It was caught by accident, when a Microsoft engineer noticed logins running half a second slow.

The money did not reach the people. Tidelift's maintainer surveys put the share of unpaid maintainers at 60% in 2021, again in 2023, and again in 2024 — and found paid maintainers substantially more likely to follow critical security practices. Census II found in 2022 that 136 developers wrote over 80% of the code added to the fifty most-used packages. Reduced, not solved.

What this means for your business

You did not choose these parts and were never shown them. You bought a point-of-sale system, an accounting package, a booking site; inside each is a set of components your vendor assembled. Black Duck audited 965 commercial codebases during 2024 and reported in February 2025 that 97% contained open-source components, with 911 of them in the typical application.

Ask about Log4Shell first. Ask each vendor what they did during the Log4Shell weekend in December 2021. It costs nothing, anyone serious remembers it, no vendor can refuse it as proprietary, and the answer tells you more than a security questionnaire.

Then ask what you run. Ask for the list of third-party parts inside the product — the industry calls it a software bill of materials. You do not need to read it; you need to know they can produce one. Treat a blank look as a prompt to ask again rather than a verdict: plenty of small resellers cannot produce one even when they are diligent.

Buy support, not just licences. A defined response time turns "we hope someone fixes it" into someone's obligation — what the large companies started buying after 2014.

Put it in writing: who patches, how fast, and who tells you when something is found. A vendor who answers the Log4Shell question well and will not put any of it in the contract has told you something too.

We found no citable Malaysian cost figure for any of this, and no Malaysian advisory from April 2014 — so there is no ringgit number in this piece. Inventing one would make the rest worthless.

Sources

Researched and drafted with AI, reviewed and published by a human.