Why Open Source Matters for Institutional Adoption | Hart Montgomery (LFDT) at ETHConf
Sun, Aug 2, 2026, 12:00 AM
In this talk, Hart Montgomery from the LFDT (Linux Foundation Decentralized Trust) explains why open source matters for institutional adoption, sharing lessons from the Linux Foundation. He covers open source background, table-stakes items institutions expect (software licensing, IP protections, and security best practices), and open governance. He pushes back on the perception, common in the blockchain community, that open source is purely a cypherpunk ideal championed by Vitalik and the Ethereum Foundation. In reality open source is everywhere: even in a typical closed-source enterprise codebase, around 90% of a modern application is open source, assembled as an open source hamburger of frameworks, custom glue code, and libraries. He describes the virtuous flywheel where open source projects power commercial products whose profits flow back into the projects, amplified when a real community forms (illustrated by Kubernetes, where Google's share of contributions shrank proportionally even as its absolute contributions grew). The Linux Foundation exists to solve collaboration when multiple parties want shared code but trust no single owner, and it hosts many Ethereum projects including Besu (around 15 to 20% of mainnet). Hart walks through the table stakes. On licensing, he covers three types: BSL (source-available, not truly open source, like Arbitrum Nitro), copyleft (requires derivative works be made public, principled but commercially hard since companies fear forced disclosure), and permissive (do-what-you-want, easiest for adoption), recommending Apache 2 for its explicit patent grants and warning about dependency pitfalls like LGPL. On IP protections, he explains contributors may add code with patent restrictions, which is why the Linux Foundation created the Developer Certificate of Origin (DCO), and urges every project to use a DCO or CLA. On security, he highlights vulnerability disclosure, software bills of materials (SBOMs) to track dependencies (citing a Black Duck audit where 81% of codebases had high-risk or critical vulnerabilities), and artifact signing via tools like Sigstore against impersonation, plus AI contributor policies and OpenSSF resources like the scorecard for verifiability. He closes on governance, distinguishing open source (code), open development (building in the open), and open governance (transparent roles and roadmap), ranging from a code dump to open product to benevolent dictatorship to true open governance (a do-ocracy where those who do decide). He argues institutions are far more likely to adopt openly governed projects since it avoids vendor lock-in and signals long-term health. 00:00 Introduction 00:34 What the Talk Will Cover 00:58 Why Open Source Is Not Just Cypherpunk 01:30 The Open Source Hamburger 01:54 The Value of Open Source to Enterprises 02:20 The Virtuous Flywheel of Open Source 02:46 The Kubernetes Community Example 03:19 Why the Linux Foundation Exists 03:39 The Breadth of the Linux Foundation 04:38 The Ethereum Projects at the LF 05:06 Why Institutions Trust Open Source 05:27 Defining Open Source Software 05:48 The Three Types of Licenses 06:11 BSL: Source Available, Not Open Source 06:37 Copyleft Licenses and Their Caveats 07:31 Permissive Licenses and Apache 2 08:19 Common Licensing Pitfalls 09:08 Other Legal and IP Protections 09:33 The Risk of Patent Lawsuits 09:58 The Developer Certificate of Origin 10:50 Moving On to Security 11:10 The Open Source Security Foundation 11:40 Making Bug Reporting Easy 12:32 The Software Supply Chain Problem 12:53 Why 81% of Codebases Have Vulnerabilities 13:30 Software Bills of Materials 13:58 Minimizing Dependencies 14:17 Signing and Authenticating Artifacts 14:37 AI and Security 15:34 Why Verifiability Matters 15:57 Talking About Governance 16:27 Open Source vs Development vs Governance 17:12 Four Categories of Governance 17:44 From Benevolent Dictatorship to Open Governance 18:32 Why Open Governance Wins Adoption 19:15 Closing _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ *ETHConf 2026* ETHConf is a 3 day event for founders, industry leaders, and builders who are excited about the possibilities of building on top of Ethereum. Connect with 2,000+ top innovators in crypto, finance, technology, and policy at our inaugural three-day event packed with showcases, demos, partnerships, and conversations shaping the future of the global economy. _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ ✅ *Follow ETHConf* X: https://x.com/ethconf Website: https://ethconf.com _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 🎟️ Get your early bird tickets for ETHConf 2027: https://ethconf.com/2027#tickets 🎤 View the full ETHConf 2026 Speaker Schedule: https://ethconf.com/schedule _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
Speakers
Hart Montgomery is the CTO of Linux Foundation Decentralized Trust and serves as the ED of the Post-Quantum Cryptography Alliance. Hart previously worked in blockchain and cryptography research at Fujitsu where he helped lead Fujitsu’s efforts in Hyperledger. Prior to Fujitsu, Hart received a Ph.D. in cryptography at Stanford. Hart has numerous academic publications and patents in cryptography and blockchain and brings a wealth of experience in these areas to the LF.