# Why Open Source Matters for Institutional Adoption | Hart Montgomery (LFDT) at ETHConf

- Speakers: [Hart Montgomery](https://streameth.org/speakers/hart-montgomery)
- Channel: [ETHGlobal](https://streameth.org/ethglobal)
- Date: 2026-07-09
- Duration: 19:24
- Topics: LFDT, Hart Montgomery, Linux Foundation, ETHConf, open source, institutional adoption, software licensing, Apache 2, permissive license, copyleft, BSL, IP protections, DCO, CLA, patents, security, SBOM, software bill of materials, vulnerability disclosure, supply chain, Sigstore, OpenSSF, scorecard, open governance, do-ocracy, vendor lock-in, Kubernetes, Besu, Ethereum, EVM, dependencies, Black Duck, AI contributor policy, decentralization, community, blockchain, enterprise
- Watch: https://streameth.org/watch/yt-dj_YiBMC0E0
- YouTube: https://www.youtube.com/watch?v=dj_YiBMC0E0

## Description

In this talk, Hart Montgomery from the LFDT (Linux Foundation Decentralized Trust) explains why open source matters for institutional adoption, sharing lessons from the Linux Foundation. He covers open source background, table-stakes items institutions expect (software licensing, IP protections, and security best practices), and open governance. He pushes back on the perception, common in the blockchain community, that open source is purely a cypherpunk ideal championed by Vitalik and the Ethereum Foundation. In reality open source is everywhere: even in a typical closed-source enterprise codebase, around 90% of a modern application is open source, assembled as an open source hamburger of frameworks, custom glue code, and libraries. He describes the virtuous flywheel where open source projects power commercial products whose profits flow back into the projects, amplified when a real community forms (illustrated by Kubernetes, where Google's share of contributions shrank proportionally even as its absolute contributions grew). The Linux Foundation exists to solve collaboration when multiple parties want shared code but trust no single owner, and it hosts many Ethereum projects including Besu (around 15 to 20% of mainnet).

Hart walks through the table stakes. On licensing, he covers three types: BSL (source-available, not truly open source, like Arbitrum Nitro), copyleft (requires derivative works be made public, principled but commercially hard since companies fear forced disclosure), and permissive (do-what-you-want, easiest for adoption), recommending Apache 2 for its explicit patent grants and warning about dependency pitfalls like LGPL. On IP protections, he explains contributors may add code with patent restrictions, which is why the Linux Foundation created the Developer Certificate of Origin (DCO), and urges every project to use a DCO or CLA. On security, he highlights vulnerability disclosure, software bills of materials (SBOMs) to track dependencies (citing a Black Duck audit where 81% of codebases had high-risk or critical vulnerabilities), and artifact signing via tools like Sigstore against impersonation, plus AI contributor policies and OpenSSF resources like the scorecard for verifiability. He closes on governance, distinguishing open source (code), open development (building in the open), and open governance (transparent roles and roadmap), ranging from a code dump to open product to benevolent dictatorship to true open governance (a do-ocracy where those who do decide). He argues institutions are far more likely to adopt openly governed projects since it avoids vendor lock-in and signals long-term health.

00:00 Introduction
00:34 What the Talk Will Cover
00:58 Why Open Source Is Not Just Cypherpunk
01:30 The Open Source Hamburger
01:54 The Value of Open Source to Enterprises
02:20 The Virtuous Flywheel of Open Source
02:46 The Kubernetes Community Example
03:19 Why the Linux Foundation Exists
03:39 The Breadth of the Linux Foundation
04:38 The Ethereum Projects at the LF
05:06 Why Institutions Trust Open Source
05:27 Defining Open Source Software
05:48 The Three Types of Licenses
06:11 BSL: Source Available, Not Open Source
06:37 Copyleft Licenses and Their Caveats
07:31 Permissive Licenses and Apache 2
08:19 Common Licensing Pitfalls
09:08 Other Legal and IP Protections
09:33 The Risk of Patent Lawsuits
09:58 The Developer Certificate of Origin
10:50 Moving On to Security
11:10 The Open Source Security Foundation
11:40 Making Bug Reporting Easy
12:32 The Software Supply Chain Problem
12:53 Why 81% of Codebases Have Vulnerabilities
13:30 Software Bills of Materials
13:58 Minimizing Dependencies
14:17 Signing and Authenticating Artifacts
14:37 AI and Security
15:34 Why Verifiability Matters
15:57 Talking About Governance
16:27 Open Source vs Development vs Governance
17:12 Four Categories of Governance
17:44 From Benevolent Dictatorship to Open Governance
18:32 Why Open Governance Wins Adoption
19:15 Closing

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

*ETHConf 2026*
ETHConf is a 3 day event for founders, industry leaders, and builders who are excited about the possibilities of building on top of Ethereum.

Connect with 2,000+ top innovators in crypto, finance, technology, and policy at our inaugural three-day event packed with showcases, demos, partnerships, and conversations shaping the future of the global economy.

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

✅ *Follow ETHConf*
X: https://x.com/ethconf
Website: https://ethconf.com

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

🎟️ Get your early bird tickets for ETHConf 2027: https://ethconf.com/2027#tickets
🎤 View the full ETHConf 2026 Speaker Schedule: https://ethconf.com/schedule

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
