HN user

bkuhn

202 karma
Posts1
Comments45
View on HN

In case folks here were curious, we at the Software Freedom Conservancy have asked the Plaintiffs to endorse the Principles of Community-Oriented GPL enforcement: https://sfconservancy.org/news/2022/nov/04/class-action-laws...

… & of course we again ask Microsoft's GitHub to start respecting FOSS licenses, cooperate with the community, & retract their incorrect claim that their behavior is “fair use”.

A few more links to our work on this issue:

https://sfconservancy.org/blog/2022/feb/03/github-copilot-co... https://sfconservancy.org/news/2022/feb/23/committee-ai-assi...

It seems to me that almost everything that needs to be said about the SS Public License has already been said. I have even posted twice about it (and related issues) myself a few times: https://sfconservancy.org/blog/2018/oct/16/mongodb-copyleft-... https://sfconservancy.org/blog/2020/jan/06/copyleft-equality...

The only thing I haven't seen said succinctly, although it's been hinted at by many, is this:

There is no one on the planet yet who has agreed that they will run a project under the SS Public License and be themselves bound by the SS Public License.

That really says it all. Whatever your view about copyleft licenses generally: legitimate and well-intentioned copyleft licenses (e.g., CC-BY-SA, GPL, and Affero GPL) have many projects that use the license in an inbound=outbound contributor licensing fashion. All (two of the) SS Public License uses have a strict CLA that give the publishing entity non-SS-Public-Licensed rights to the contributions. We shouldn't take anyone seriously who promulgates a license but won't use it themselves in an inbound=outbound way. Period. I suggest we all try to not give further interest to this clearly risible licensing proposals from MongoDB and Elastic.

If there's energy to focus here, I'd say it's toward figuring out how to handle good governance of forks of these two projects. I hope folks can maintain the discipline to discern and bifricate these two very different issues.

As the author, I can confirm I'm fully aware of the etymology of “A Modest Proposal” — my undergraduate degree included the Honors program in the Humanities and there are many professors who would be aghast if I'd forgotten.

I chose the title because the proposal should be not a big deal — especially given that these companies already demand that copyleft projects grant these 30 days — however, it's ultimately an untenable proposal. Just like the original Modest Proposal, it's made to a ruling class who don't realize their policies are completely unreasonable.

Your life or death scenario is an edge case with its own special complexities which should not be lumped in with discussions of the vastly voluntary choices we can make.

Karen's and my 2019 FOSDEM keynote (and accompanying podcasts) discuss her struggles with the medical device industry and how those struggles relate to the larger set of choices related to technology that we make. This isn't an issue that lends itself well to short-form discussion. The issues are quite complex:

https://archive.fosdem.org/2019/schedule/event/full_software...

https://archive.fosdem.org/2019/interviews/bradley-m-kuhn-ka...

http://faif.us/cast/2019/jan/13/0x60/

http://faif.us/cast/2019/feb/19/0x61/

http://faif.us/cast/2019/mar/12/0x62/

http://faif.us/cast/2019/mar/20/0x63/

I realize sarcasm is the "way of expressing things on HN", and I did some of it myself in a post upthread, but to get serious on norgie's point for a moment: I picked this specific issue to speak out on for two reasons: (a) as a regular traveler [0] and speaker at FOSS events, this was a great opportunity to draw attention to the problems with airlines, as all of us use them to attend these events and my blog is well read among FOSS folks and (b) as someone who is a frequent traveler, and recognized by Delta as a "good customer", I have a louder voice then most in this debate.

There are indeed a lot of issues that we should be speaking up on, and it can be exhausting to speak up on all of them. I try to target moments when my voice can get a bit more attention than usual for some reason and pounce on the opportunity to make a difference. I think it's a good approach.

(Again, I'm the poster of the ebb.org blog post that was the original article linked to in this thread; as others have mentioned, this article was changed to be about the Washington Post news story that inspired my blog post).

[0] and yes, the fossil fuel impact of that does bother me and I've spoken about that too at FOSS conferences)

I go to great lengths to buy clothes not made in sweatshops, actually. I admit I have some clothes probably made in sweatshops that I go second-hand. BTW, I've often been the only one at FOSS conferences raising the issue that t-shirts given out and/or sold were made by sweatshop labor.

Yes, the X200 I'm typing this on was probably made in a sweatshop, as was the Nexus One I still use as a mobile device. But, I use every piece of hardware I have until it breaks in an unfixable way, and I also only buy used hardware. I've purchased a newly made electronic device since the late 1990s.

As I mentioned in the original post, I've only worked for charities dedicated to causes I support. I'm curious to know which causes you spend your time getting "bent out of shape" to work on. Perhaps making up facts about authors of posts that get HN coverage is your cause? Is that your day job, or just a hobby cause? :)

Oh, and as for commuting, I work from home, which means I don't drive home from work any day. The last day I "drove home from work" was circa early 1997. Did you happen to research and were speaking about the commuting I did in the 1990s?

I wonder how the rest of HN readers cash in on this "guarantee" you gave them about the facts of my life which I can easily disprove you were wrong about.

I posted my response on a blog post at: https://sfconservancy.org/blog/2018/oct/16/mongodb-copyleft-...

TL;DR: while vmbrasseur of OSI does say "what's done is done" in comments here, I think the OSI shouldn't accept the proposal as submitted, and should demand that licenses submitted them to have gone through a prior public drafting process. This is particularly important for licenses whose stated goal is to make fundamental changes to how copyleft works. GPLv3 and (even better) copyleft-next made this the standard of how new license drafts are done, and we should follow that standard.

Hey, Tim, I've talked a number of times with GitHub about the issue of lack of nuance in their license monikers on GitHub. I haven't gotten very far, but this change will cause me of course to raise it again.

As others have commented, kragen is jumping to excitement a bit too quick. GitHub's license data is not curated, and I'm quite sure determining a license of software is an undecidable problem; it just requires human judgment, and many self-report their own license incorrectly to GitHub.

GitHub has a lot of problems to solve before the license data they are presenting can be trusted. Even many very common programs have licenses that can't even be described with an SPDX moniker, so the "badge method" just isn't going to work.

What is copyleft? 10 years ago

Those who wish to learn more about copyleft after reading Ben's article may also want to look at the copyleft guide https://copyleft.org/guide for more information.

Ben is a contributor to the copyleft guide, so we'll likely merge in his article into the Guide.

It seems that most commenting in this thread don't have not actually followed the complex political debate going on in the world of automotive industry adoption of FLOSS.

Specifically, the automotive industry has made a series of arguments that proprietary software is ultimately safer than FLOSS, and all their goals are to lock-down FLOSS in various ways to prevent the nefarious from "hacking" the vehicle.

The vehicles are all still hackable, and many have been modified by people for both reasonable and nefarious purposes. The FLOSS situation won't change anything, and there aren't even any examples yet of hacks where FLOSS made the situation worse. It's an assumption they make without full information because of their inherent pro-proprietary bias.

You're conflating a lot of different issues. Anyway, the example you started with would likely work similarly in the USA. You'd have to provide a lot more detail to actually show the the difference that it seems you're trying to show.

There are strong rules of evidences in common law systems as well, and the Court expects the parties to introduce evidence; I don't know of any Court that goes seeking evidence that wasn't provided.

In the USA, we talk of jury's as "fact fiinders", but their job is to only consider the evidence before them (possibly conflicting, as it comes adversarially from both sides), and find what's true. But no one in this process other than the parties in civil litigation bring evidence forward.

So, the specific distinction you're trying to make isn't really a distinction between the two systems. I agree with you that there are huge differences in various ways.

My guess at what you're trying to point out is that there is no discovery process in Germany and elsewhere, which is certainly true and is relevant to this discussion, and makes the evidentiary systems very different in practice.

Interestingly, Richard Fontana just told me today a piece of history I didn't know: the USA didn't have discovery in civil cases until the early 20th century, apparently.

The biggest impact individual developers can make on all the points I raised is to keep their own copyrights on copylefted works and do not sign an employment contract unless it explicitly allows you do to that.

Developers have more leverage in employment negotiation than they realize. Right now, most copylefted codebases that have historically had mostly individuals holding the copyrights are drifting to having companies mostly hold the copyrights. We have to stop this trend.

If individual developers hold copyrights, they make their own decisions about enforcing, and companies who oppose enforcement have less leverage.

I always find it frustrating when people pontificate about how the GPL should work who have never done the hard work to enforce it (BTW, I'm always looking for volunteers who want to help in the really really boring work of enforcing the GPL, but I rarely get any takers once I start describing what the work entails).

I've done and/or led more GPL enforcement than anyone on the planet, for more than a dozen different copylefted projects, and I've done it as a volunteer, as an employee of both FSF and Conservancy, and for GPLv2-only, GPLv3-or-later, and LGPLv2.1 works.

While I love, as a purely intellectual exercise over a nice meal, to talk theory with people who only have a theoretical understanding, real world experience with the licenses is the center of drafting good copyleft licenses. The GPL might as well be the ISC license if its clauses are never enforced, so enforcement is really the litmus test on how the license is working and what changes are needed. If the author or anyone else would like to get involved with "field research" and help in Conservancy's enforcement efforts for Linux, Samba, BusyBox and other projects, I'm easily contactable.

Anyway, I think what Christopher Price and others in this thread are really looking for is the copyleft-next project. It's Richard Fontana's project that's attempting to redo copyleft licensing from first principles and from (initially) a theoretical basis. I'm a fan of the project as I do think a "redrafting from ground up done in a community fashion" is a good idea to try in parallel to the existing functioning copylefts like GPL.

But saying "GPL is broken, therefore we need a GPLv4" is not terribly helpful. GPL is on the verge of collapse not for most of the reasons pundits say it is, but because (a) it's widely violated, (b) few people are willing to enforce, (c) some of those who enforce won't follow community Principles when they do, and (d) there is heavy political opposition from wealthy corporations and trade-associations against those who do enforce, even when they commit to follow published community Principles.

IMO, those are the biggest problems GPL has now, and I work every week to seek to solve those.

Sure, having been involved with copyleft policy since the early 1990s, I keep a private bug list of GPLv3 (i.e., things I'd like to see in GPLv4). But, it's far from my top priority, and it shouldn't be the community's top priority, IMO, either.

Scripts doesn't necessarily mean software scripts; it could be a script as in a script for a play. If the BMW engineers memorized their lines and know how to do them, they have to write out those lines as a requirement of the GPL. The GPL requires "oral tradition" build scripts to be passed along as well.

As someone who has enforced the GPL for a few decades, I have to note the GPL compliance process isn't done here yet. Someone actually has to verify that the "scripts used to control compilation and installation of the executable"(s) actually work. Is anyone working on that?

Please send a copy of the manual and specific details of what you tried to receive source code from DirecTV to <compliance@sfconservancy.org>.

Note that GPL doesn't require "putting the source online" necessarily, but they are required to make a valid offer for source code to you and fulfill that offer when exercised. We'll need to investigate whether or not they've properly done that before anyone should claim that DirecTV has violated GPL.

(BTW, I'm Bradley M. Kuhn, who, through my role at Conservancy, started the GPL Compliance Project for Linux Developers: https://sfconservancy.org/linux-compliance/

It is sad to see how often forks go downhill

As can be seen in my blog post and various talks in the subject, the Kallithea community faced two choices: a fork of only the GPLv3'd components, or a lengthy GPL enforcement battle with Rhodecode, who violated the GPL by changing to a non-Free-Software license for code that combined GPL'd software that wasn't copyrighted by Rhodecode.

If Rhodecode would go back to a pure GPLv3 model for its software and develop the software in pubic again, I think the fork could be easily resolved and we could all work together again. Thus, only one simple act of yours would resolve the fork entirely, sebastiank123, will you take that act?

Meanwhile, I'm sure the Free Software user community can make the easy and obvious choice between a community-run, developed-in-public Free Software project that complies with GPLv3 and a for-profit-corporate run, developed-in-private, semi-Open-Source project that has a history of GPLv3 compliance problems.

It's odd you keep saying "all open source lawyers" agree with you, because I can't figure out who you could possibly mean. Like, which specific human being do you believe agrees with you? I've studied copyleft almost daily for two decades, and I'm aware of the position of nearly anyone who has ever called themselves an "open source lawyer" in the world, so one would think I'd know who you are talking about since I "know them all" and I can't figure out who I could ask that would give me the same argument as you give.

The only lawyers I find who agree with your position (and, BTW, they agree with it for completely different reasons than you state, and I suspect they wouldn't agree with your reading of v2 Section 6) are a few lawyers in Germany.

I thus find myself in the odd situation of having to defend your trolling a bit, because Till Jaeger, Christoph's lawyer in the VMware case, has indeed stated publicly that he believes you can regain a license under GPLv2 by coming into compliance and redownloading in Germany. However, this is likely specific to Germany because no other legal expert I've ever met who has studied this issue has argued it works anywhere else in the world.

This point is therefore salient insofar as this thread is discussing a copyright case in Germany. But, as I wrote in the copyleft.org footnote I referred to earlier, the issue is just an esoteric legal detail except in the case of proprietary relicensing business models. Community-oriented GPL Enforcement Organizations always restore rights anyway once the violator achieves compliance, so the final impact of both interpretations ends up the same in most enforcement actions, unless of course your goal is to abhorrently use strict termination to extort gobs of money, in which case, this detail matters a lot.

I would expect that most users of software that violates the GPL are not lawyers, so I don't see how your statement "in the end you're only helping lawyers" could possibly be correct: enforcement to gain compliance is never going to primary help lawyers in an event.

The law is a tool that can be used to achieve certain goals. Similarly, software is a tool that can achieve certain goals. We wouldn't suggest that people shouldn't use software (which, in turn, requires employing programmers) because "in the end, you're only helping programmers", would we?

I'm no fan of the legal profession: the only sticker I have on my laptop reads "Keep your lawyers off my computer". However, I work with lawyers a lot because they are experts on the law, and I (or my organization) can hire them to utilize the law to promote good in the world.

I find proprietary software abhorrent and those who write in my mind are doing something harmful. I find Free Software wonderful and those who write it in my mind are doing something wonderful. Similarly, some lawyers do good in the world and some do bad, just like programmers.

I don't see in there all the accounting configurations you'd need to integrate that with Conservancy's accounting system, nor all the legal research to figure out how it impacts Conservancy's Form 990 filings, nor all the workflow code to make sure transactions are auto-imported, identified with people who want to be identified, so they can be sent their t-shirts.

Too often, people think "it's easy for me to set something up for myself to use, it must be just as easy for a non-profit it do it". It just isn't.

And yes, I'm Bradley Kuhn.

I think you'll find that it's very difficult to set up other payment options with 100% Free Software. If Conservancy were willing to use proprietary software on our website for payment options, we could probably implement others somewhat easily.

PayPal is annoying, but at least it integrates easily and doesn't require you to install proprietary Javascript or the like on your own website (like stripe.com does).

Bitcoin is possible to do with 100% Free Software, but it's very difficult to set up.

I think most people don't realize how much work goes into these things. Most non-profit organizations have a huge staff that can set up things like this. Conservancy doesn't.