>Then drop it and let someone else maintain it.
I want to reply to this person: then fork the last open source version and maintain that. That's the whole point really. Besides he apparently made the change two years ago and people only start noticing now, it's pretty clear that there's not a vibrant community of contributors ready to take the project over.
It's not entirely fair in this case because of the certificate needed to sign the kernel module but if it's really that difficult to get a certificate from Apple as an open source project that seems more like a problem with Apple than with osxfuse's maintainer. Besides what can he reasonably do? Just give the certificate to whoever asks for it? That's going to get it revoked by Apple in approximately 4 femtoseconds.
Companies benefiting from the work of opensource projects and not giving anything back is genuinely a big problem IMO. It's not illegal of course, but it is unethical in my opinion. Look at the state of OpenSSL, one of the most (if not the most) popular crypto library out there, who has to beg for scraps in order to fund the project. And when there's a critical vulnerability like heartbleed, who gets mocked online? The poor guy or gal who authored the commit, not the countless multi-billion dollar corporations who deployed their code for free without paying for a thorough audit or contributing anything back.