But there's no reason that money can't go right back into basic infrastructure. For example, after the Heartbleed bug we learned that OpenSSL was receiving about $2k/year in donations. Surely there are obvious core open-source projects that could use reliable funding: https://arstechnica.com/information-technology/2014/04/tech-...