Red Hat Goes Public, IBM Goes All In

Red Hat Goes Public, IBM Goes All In


Late 2000. I was at Telecom XTRA, running a team in a world built on Windows and Solaris. Linux existed in pockets at XTRA, running a handful of things the enterprise stack could not quite manage, but it was peripheral. The serious infrastructure was proprietary.

Then IBM CEO Lou Gerstner walked to a podium in New York and announced that IBM had already invested approximately one billion US dollars in Linux, with more committed for 2001.

I found the news and walked into my manager's office. "Sooner or later," I told him, "I'm going to leave XTRA and dedicate myself to Linux." He laughed. It was not a cruel laugh. He looked at me, and said "stick to your guns."

He meant it as caution. I heard it as validation. IBM had just told the world what I had already known for years.


What Wall Street Said First

A year before Gerstner's announcement, something equally significant had happened 9,000 kilometres away.

On 11 August 1999, Red Hat Inc. began trading on NASDAQ under the ticker RHAT. The opening ask was $14. By the close of day one, shares had reached approximately $52: a 271 percent gain, among the largest first-day jumps in Wall Street history to that point [1]. The company had been incorporated since 1993, had been distributing Linux on CD since 1994, and had introduced the Red Hat Package Manager in 1995. Its primary asset was a software product anyone could download for free.

The market valued it at approximately USD 3.5 billion anyway [1].

What the IPO proved was not that free software was valuable in spite of being free. It proved the opposite: the services around free software were worth paying for precisely because the underlying platform was shared. Red Hat sold support, certification, documentation, and professional stability. It sold the promise that a Global 2000 enterprise could pick up the phone and reach someone accountable when the system went down.

None of that required owning the code. It required knowing the code better than anyone else.

I was at ICONZ when the IPO happened, running production infrastructure that was largely Red Hat, with Debian carrying the Web NZ server. The TARDIS self-service portal was already live by then: Apache, MySQL, and PHP sitting on top of a kernel we had chosen because it worked, not because anyone had told us it was safe to choose. The IPO did not change what we were doing. It changed who felt comfortable asking about it.

By mid-2000, I had moved to Telecom XTRA. The environment was different: Windows and Solaris ran the serious infrastructure, Linux in the margins.


What IBM Said Next

The announcement I remember is Gerstner's, from December 2000. IBM had committed approximately one billion US dollars to Linux development, services, and hardware integration [2]. The investment was not philanthropic. IBM's strategic logic was specific: commoditise the operating system layer, then sell hardware, middleware, database, and services on top of it.

System z mainframes running Linux. WebSphere on Linux. DB2 on Linux. IBM Services helping enterprises migrate.

The move was significant for a reason that had nothing to do with technology. The technology was already proven. What IBM provided was institutional cover. A CIO who had been watching Linux quietly for three years could now point to a billion-dollar IBM commitment and explain to their board why they were considering it. IBM's money did not improve the kernel. It improved the conversation about the kernel.

By the following year, IBM VP Bill Zeitler said publicly at LinuxWorld that the company had already recouped most of its investment [2]. IBM's Linux-related revenue reached approximately USD 2 billion annually within two years [3]. The return-on-investment case was not theoretical. It was reported in the trade press.

The mainframe port deserves a paragraph. IBM integrated Linux into its zSeries hardware through 2000 and 2001. Mainframes had been the definition of proprietary enterprise computing since the 1960s. Putting Linux on one was not a technical gesture. It was IBM telling the Global 2000 market that open-source infrastructure belonged in the most demanding, most accountability-driven computing environments on the planet. If it ran on zSeries, it ran everywhere you needed it.


The Enterprise Template

In March 2002, Red Hat launched Red Hat Enterprise Linux 2.1, codenamed Pensacola and based on Red Hat Linux 7.2 [4]. This was the first dedicated enterprise distribution from Red Hat: a separate product, a subscription model, a contractual relationship between a vendor and an enterprise customer that looked nothing like a software licence and everything like a service agreement.

The split between Red Hat Linux (free, community) and RHEL (subscription, enterprise) became the template. SUSE followed it. Oracle Linux followed it. Amazon Linux eventually followed it. For 23 years, the dual-track model held: free upstream, paid-for enterprise tier, no one locked out of the underlying code.

I encountered RHEL formally for the first time working with IBM on the Air New Zealand online ticketing platform, in 2002 or early 2003. RHEL on the server side, IBM middleware above it, enterprise SLAs wrapped around the whole thing. The kernel we had been compiling from source at ICONZ five years earlier was now in a commercially supported, contractually warranted deployment serving one of New Zealand's largest transport operators. The distance between those two moments is the distance IBM's investment bought.


Why the Economics Held for 27 Years

The reason the Red Hat model worked was not sentiment. It was not the idealism of the free software movement, though that idealism built the thing. It was an economic argument about vulnerability discovery.

Open source meant millions of eyes on the code. Developers, security researchers, academics, government agencies, competing vendors: all of them could read it, all of them had incentive to find the problems, and all of them could contribute the fixes. The cost of discovering a vulnerability in open-source code was distributed across the entire community. No single organisation bore the full burden of finding everything. The adversary had to find the flaw first; the collective had to find it first back.

Red Hat's IPO validated the commercial model. IBM's commitment validated the enterprise deployment. But the underlying economics, collective scrutiny distributing the discovery cost, is what made both investments rational.

For 27 years, that calculation held.


What NHS England Did on 29 April

On 29 April 2026, NHS England issued Software Development Lifecycle directive SDLC-8. Every public source code repository was to convert to private by 11 May 2026. Exemptions required Engineering Board approval by 6 May, a deadline that had already passed by the time this article was written [5]. The directive guidance cited the Anthropic Mythos model by name.

Two weeks earlier, on 14 April, Cal.com, a commercial open-source scheduling platform, had made the same pivot, closing its core platform source code [6].

Neither the UK AI Safety Institute nor NCSC UK has endorsed SDLC-8 [5]. The policy contradicts the UK Technology Code of Practice, which mandates that publicly-funded code should be open by default. Former NHSX open-source lead Terence Eden and other analysts have noted the structural problem in SDLC-8's logic: closed code offers no protection against AI tools that scan compiled binaries, and previously-public code has already been ingested into training corpora [7]. Closing the repository does not undo the ingestion.

But dismissing SDLC-8 as technically confused misses what it is telling us.

Three days before the directive was issued, security firm Theori disclosed CVE-2026-31431, a nine-year-old logic flaw in the Linux kernel's algif_aead cryptographic module [8]. Theori's Xint Code AI tool had found it in approximately one hour of scan time, a single operator prompt, with a 732-byte Python exploit. CISA added it to the Known Exploited Vulnerabilities catalogue on 4 May [9]. The flaw had been present in every Linux distribution since 2017. The community did not find it first.

What changed was not the quality of the open-source code. What changed was the cost of finding vulnerabilities in it. For 27 years, that cost favoured collective scrutiny. A well-resourced adversary could spend millions to find a flaw that millions of eyes had not yet found. An AI tool can now find the same class of flaw in an hour for the cost of a query.

Anthropic released Project Glasswing alongside the Mythos Preview: USD 4 million in direct donations to the OpenSSF and Apache Software Foundation, plus USD 100 million in usage credits to defensive open-source contributors [10]. The investment is real. The asymmetry is also real: four million dollars against more than 30 million lines of Linux kernel code and approximately 350 Apache projects. Glasswing is a signal of intent, not a solved problem.

Red Hat proved that the open layer wins. IBM ratified it. The question NHS England's SDLC-8 opens, not wisely but genuinely, is whether the open layer's winning condition has changed, and what the right response looks like if it has.

Closing the repositories is not the answer. Treating the discovery-cost shift as though it is temporary or addressable by privacy controls does not address the underlying economics. But that does not mean there is no problem to address. The conversation IBM started in December 2000, about who is accountable when production systems rely on shared infrastructure, is the same conversation we are now having about shared infrastructure that AI tools can scan in an hour.

It was a good conversation in 2000. It is still a good conversation now.


If you were sitting in the procurement meeting at ICONZ in 2001, listening to IBM's billion-dollar Linux commitment, what would you tell a board today that asked you whether your open-source dependencies are an asset or a liability, and what would you ask them in return?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


About the Author: Andreas Hamberger is a New Zealand-based enterprise architect and technology strategist. Over 30 years, he has moved from compiling kernels on a 486 to leading cloud, cyber, and AI transformation programmes across government, banking, transport, and aviation. He founded Yoper Linux, served as a technology specialist for Novell during the Linux Wars, and is the author of "Generative AI: Skynet or Heaven" and "Space Mafia." He can be reached at linux@linux.co.nz.

A Concise History of Linux chronicles the operating system that changed the world and the lessons it holds for the AI era.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] Wikipedia / Sonar Source. "Red Hat IPO, August 1999." Trading commenced 11 August 1999; opening price $14; close approximately $52; 271 percent first-day gain; market capitalisation approximately USD 3.5 billion. https://www.sonarsource.com/blog/the-red-hat-ipo-experiment-to-pay-maintainers-25-years-later/

[2] HPCwire / CNET archive. "IBM Linux Investment Nearly Recouped." February 2002. VP Bill Zeitler statement at LinuxWorld. IBM $1B commitment announced December 2000. https://www.hpcwire.com/2002/02/01/ibm-linux-investment-nearly-recouped/

[3] IDC via Opensource.com. "IBM's ROI from Investment in Linux." 2013 article citing 2003 IDC data. USD 2 billion annual Linux-related revenue by 2003. Source chain: IDC report not directly accessible; figure widely cited in trade press. https://opensource.com/business/13/10/ibm-roi-investment-linux

[4] Red Hat Inc. "Red Hat Enterprise Linux 2.1 Launch." March 2002. Codename Pensacola; based on Red Hat Linux 7.2; first dedicated enterprise distribution with subscription model.

[5] The Register / Digital Health News. "NHS England SDLC-8 Directive." 5-7 May 2026. Directive issued 29 April 2026; repositories to private by 11 May 2026; Engineering Board exemption deadline 6 May 2026; UK AI Safety Institute and NCSC UK have not endorsed.

[6] Cal.com. "Cal.com closes core platform source code." 14 April 2026. Announcement via company blog and press reports.

[7] Eden, Terence. "NHSX Open Source: Why Closing Repositories Does Not Protect Against AI Training Ingestion." shkspr.mobi. May 2026. Primary blog source; former NHSX open-source lead.

[8] Theori. "CVE-2026-31431: CopyFail, Linux algif_aead Logic Flaw." Theori Xint Code AI disclosure. Flaw present since 2017; discovered via AI tool in approximately one hour; 732-byte Python exploit. https://xint.io/blog/copy-fail-linux-distributions

[9] CISA. "Known Exploited Vulnerabilities Catalogue: CVE-2026-31431 Added 4 May 2026." Federal agency deadline: 15 May 2026.

[10] Anthropic. "Project Glasswing: Defensive Open-Source Investment." USD 4 million direct donations to OpenSSF and Apache Software Foundation; USD 100 million in API usage credits to defensive open-source contributors.

Previous
Previous

Rust in the Kernel: The Thirty-Year Language War

Next
Next

Stability Is the Feature: What Linux 7.0 Is Actually Optimising For