Before "software" was a product (1950s–1970s)¶
In the early days nobody thought of software as something to sell. Hardware was the product; software was what you needed to make it useful, and it shipped with source.
- 1955 – SHARE. Users of IBM's 701 and 704 mainframes formed SHARE to swap code, libraries, and fixes. It was effectively a user-run code-sharing collective decades before the internet.
- 1961 – DECUS, the DEC user society, did the same for DEC machines.
- Academic culture at MIT, Stanford, Berkeley, and Bell Labs treated code like research: you published it, others built on it, and you got credit.
- 1969 – Unix is written at Bell Labs by Ken Thompson and Dennis Ritchie. Because of a 1956 antitrust consent decree, AT&T was barred from entering the computer business, so it licensed Unix (with source) to universities for a nominal fee. A generation of students learned operating systems by reading Unix source.
- 1977 – BSD. UC Berkeley begins distributing its own Unix additions as the Berkeley Software Distribution, eventually adding the TCP/IP stack that the internet runs on.
The culture that grew out of this was later documented by Steven Levy in Hackers: Heroes of the Computer Revolution (1984) as the hacker ethic: access to computers should be unlimited, all information should be free, mistrust authority, and judge people by what they build rather than by credentials.
The enclosure (late 1970s–early 1980s)¶
Then software became a business.
- In 1976, Bill Gates published his Open Letter to Hobbyists, accusing hobbyists who copied Altair BASIC of theft. It's an early, clear statement of the proprietary model.
- Copyright law in the US was extended to cover software (1980 amendment), making closed binaries legally enforceable.
- The 1984 breakup of AT&T freed it to commercialize Unix. Licensing fees rose sharply and source access disappeared. The thing a generation had learned from was now a trade secret.
- Vendors began shipping binaries only, requiring non-disclosure agreements, and forbidding sharing.
Stallman and GNU: the counter-revolution (1983–1991)¶
Richard Stallman was a programmer at the MIT AI Lab, one of the last strongholds of the old sharing culture. The (now famous) trigger story: the lab's new Xerox laser printer jammed constantly. On the previous printer, Stallman had modified the driver to notify users of jams. Xerox refused to provide source for the new one. A researcher at Carnegie Mellon had it but had signed an NDA and refused to share. Stallman took that refusal personally — a colleague choosing a contract over cooperation.
As the AI Lab's hackers were hired away into proprietary companies, Stallman decided to build an entire free operating system so nobody would ever have to sign that NDA.
- 27 September 1983 – Stallman announces the GNU Project ("GNU's Not Unix") on Usenet.
- 1985 – The GNU Manifesto is published, and the Free Software Foundation is founded.
- Over the following years GNU produces GCC, GNU Emacs, glibc, bash, coreutils, make, gdb — most of the userland every Linux system still depends on.
- 1989 – GPL v1. The GNU General Public License introduces copyleft.
What GNU didn't finish was a working kernel. Its planned kernel, the Hurd, was (and remains) unfinished.
Copyleft: the legal hack¶
Copyleft is the single most rebellious idea in the history of software licensing, and it's worth understanding why.
Copyright gives the author exclusive control over copying and distribution. Proprietary vendors use that power to restrict users. Stallman used the same legal power to do the opposite: the GPL grants everyone the freedoms to use, modify, and share — on the condition that anyone who distributes the software (or a derivative) must pass those same freedoms on, with source.
It turns copyright against itself. You can't take GPL code, improve it, and lock the improvements up. The freedom is "sticky." Critics called it "viral"; supporters call it reciprocity.
Linux and the BSDs (1991–1995)¶
- 25 August 1991 – A 21-year-old Finnish student, Linus Torvalds, posts to
comp.os.minixthat he's doing a free operating system, "just a hobby, won't be big and professional like gnu." - 1992 – Linux is relicensed under the GPL v2 (with version 0.12). Combined with the GNU userland, there is finally a complete free operating system. (This is why the FSF insists on "GNU/Linux.")
- 1992–1994 – Unix System Laboratories sues BSDi and UC Berkeley over BSD code. The lawsuit froze BSD adoption at exactly the moment Linux was taking off — one of the big "what ifs" of computing history. It settled in 1994, and 4.4BSD-Lite was released free of AT&T code, leading to FreeBSD, NetBSD, and OpenBSD.
- 1993 – Slackware and Debian (Ian Murdock) are released. Debian's social contract and its Free Software Guidelines later become the basis of the Open Source Definition.
- 1994–1995 – Red Hat is founded; the Apache HTTP Server emerges from patches to NCSA httpd ("a patchy server") and goes on to dominate the web.
"Open source" is coined (1997–1999)¶
By the late 90s the free software community had a marketing problem: businesses heard "free" as "worthless" or "anti-business," and Stallman's ethical framing made executives nervous.
- 1997 – Eric S. Raymond presents The Cathedral and the Bazaar, contrasting closed, planned development (cathedral) with Linux's chaotic, public, release-early-release-often model (bazaar). Its most quoted line, "Linus's Law": given enough eyeballs, all bugs are shallow.
- 22 January 1998 – Netscape, losing the browser war to Microsoft, announces it will release the source of Netscape Communicator. The code ships on 31 March 1998, becoming the Mozilla project (and eventually Firefox, 2004).
- 3 February 1998 – At a strategy meeting reacting to Netscape's announcement, Christine Peterson proposes the term "open source."
- Late February 1998 – Raymond and Bruce Perens found the Open Source Initiative (OSI).
- 1999 – The Apache Software Foundation is formed. Red Hat's IPO (August) and VA Linux's (December, one of the largest first-day gains in history) show Wall Street that open source can be a business.
This is the moment the movement split into two camps that still argue today: free software (ethics) and open source (practicality).
The empire strikes back (1998–2007)¶
- October 1998 – The Halloween Documents. Leaked internal Microsoft memos assessed open source as a serious threat and discussed strategies to counter it, including "de-commoditizing" protocols. Raymond published and annotated them.
- 2001 – Steve Ballmer calls Linux "a cancer that attaches itself in an intellectual property sense to everything it touches" — a direct attack on copyleft. Microsoft's "Shared Source" initiative tries to offer source visibility without open source freedoms.
- 2003 – SCO v. IBM. SCO claims Linux contains stolen Unix code and sues IBM for billions, threatening Linux users with licensing demands. The case dragged on for years; SCO went bankrupt and its claims largely collapsed, notably after a court ruled that Novell, not SCO, owned the Unix copyrights.
- 2005 – Git. The kernel had been using the proprietary BitKeeper for source control. When its free license was revoked in a dispute, Torvalds wrote Git in about two weeks. The tool that every developer now uses was itself a product of an open source fight over proprietary dependencies.
- 2007 – GPL v3. Responds to "Tivoization" (devices like TiVo ran GPL software but used hardware signing to block users from running modified versions) and to software patents. Linus Torvalds famously declined to move the kernel to GPLv3; it remains GPLv2-only.
- 2007 – The Linux Foundation is formed.
Open source wins (2008–2019)¶
- 2008 – GitHub launches and makes forking and pull requests social and frictionless. Android ships, putting the Linux kernel in billions of pockets.
- 2011 – GitLab begins as an open source project by Dmitriy Zaporozhets.
- 2014 – Satya Nadella declares "Microsoft ♥ Linux." .NET Core goes open source. Google open-sources Kubernetes; the CNCF forms around it in 2015.
- 2014 – Heartbleed. A bug in OpenSSL exposed how critical infrastructure was maintained by a tiny, underfunded team. The Linux Foundation's Core Infrastructure Initiative was created in response (later folded into the OpenSSF, 2020).
- 2016 – left-pad. A developer unpublished an 11-line npm package after a naming dispute and broke builds across the JavaScript ecosystem, showing how fragile dependency trees had become.
- 2018 – Microsoft acquires GitHub for US$7.5 billion.
- 2019 – IBM completes its US$34 billion acquisition of Red Hat.
By the end of the 2010s, open source wasn't the rebel anymore — it was the default foundation of nearly every commercial software stack, cloud, and phone. Which created a new set of problems.
The modern era: license wars, security, and sustainability (2018–present)¶
The cloud problem and the "source-available" turn. Companies built businesses on open source projects, then watched cloud providers offer those projects as managed services without contributing back. Several vendors responded by relicensing away from open source:
| Year | Project | Change | Community response |
|---|---|---|---|
| 2018 | MongoDB | AGPL → SSPL (not OSI-approved) | Debian, Fedora drop it |
| 2021 | Elasticsearch / Kibana | Apache 2.0 → SSPL / Elastic License | AWS forks OpenSearch |
| 2023 | Terraform (HashiCorp) | MPL 2.0 → Business Source License | Community forks OpenTofu under the Linux Foundation |
| 2024 | Redis | BSD → RSAL / SSPL | Linux Foundation forks Valkey |
Some of these partially reversed course: Elastic added AGPL as a licensing option in 2024, and Redis added AGPL with Redis 8 in 2025. The forks, however, remained.
Related upheavals: Red Hat ended CentOS Linux as a RHEL rebuild in favour of CentOS Stream (announced December 2020), spawning Rocky Linux and AlmaLinux, and in 2023 restricted public access to RHEL sources, reigniting arguments about the spirit vs. letter of the GPL.
Supply chain security.
- December 2021 – Log4Shell (CVE-2021-44228) in Apache Log4j, maintained by volunteers, sent the entire industry into emergency patching.
- March 2024 – The xz backdoor (CVE-2024-3094). An attacker spent roughly two years building trust as a contributor to xz-utils, pressured the burned-out solo maintainer (in part via sock-puppet accounts complaining about slow progress), gained co-maintainer access, and slipped a backdoor targeting OpenSSH into release tarballs. It was caught almost by accident by Andres Freund, who noticed SSH logins were taking about half a second too long. It is the defining case study of maintainer burnout as an attack surface.
- 2022 – Protestware. Maintainers deliberately sabotaged their own packages (colors.js/faker.js over unpaid corporate use; node-ipc over the invasion of Ukraine), raising hard questions about trust.
Regulation and AI. The OSI published the Open Source AI Definition 1.0 in October 2024, sparking debate about whether "open weights" models are truly open without training data. The EU Cyber Resilience Act introduced security obligations for software sold in the EU, with carve-outs for non-commercial open source and a new "open source steward" role for foundations.