Microsoft Joins the Eclipse Foundation
blogs.msdn.microsoft.com
blogs.msdn.microsoft.com
My team was initially acquired; we were originally a small company in a cornfield in Illinois called Teamprise, where we built the original TFS plug-in for Eclipse. At the time, we were Eclipse Foundation members and reasonably happy about it. Certainly it was nice to give back (in terms of membership fees) to a project that we were a part of and took advantage of. And the Foundation has a few really solid employees and it was nice to talk to them about tech stuff.
But our larger goal in joining the Eclipse Foundation was largely unmet, which was to actually partner. For example: we hoped to bring in a contractor who could occasionally tackle some bugs in Eclipse on AIX which ultimately affected our customers. We were a tiny company and going deep on some weird problem that only affected the Motif AIX build was not particularly rewarding. So we hoped to engage the Foundation to help us out here: we would pay this contractor if they could help us find them. But we were rebuffed in a manner that I found rather off-putting.
Despite this, after we became part of Microsoft I still pushed for us to join the Eclipse Foundation. I stopped pushing when Microsoft had a booth at Eclipse Con one year and a member of the Foundation (apropos nothing) went on a nice, long rant about Microsoft. I don't think it's particularly classy to make fun of your competitors, nor do I really appreciate inculcating an "us vs them" mentality. But to do that after we had paid a big hunk of money to sponsor that conference seemed particularly poor form, and if the Foundation is going to make fun of the people who are paying to sponsor their Conference, what does membership buy you? A steaming pile on your doorstep once a year?
In any case, that was when I stopped advocating for Microsoft to join the Eclipse Foundation and instead advocated for us to ignore them wholesale. I hope that my old team has better luck working with them than I did.
I took a job working on an open source product / stack precisely to get experience with how a consortia (kuali.org) manages to do things.
TL;DR: it doesn't.
I'm told the Apache Foundation is also like a tarpit. Would love to hear stories from people with direct experience.
My utopian view is that all government software should be citizen owned. That dream took a hit by my recent experience. I'm still searching for projects, efforts, teams, whatever that cracked this nut.
Preparation. The world isn't ready yet for Microsoft joining the Linux Foundation.
I'm going to assume you're serious and agree with you; I wouldn't be at all surprised if Microsoft did end up joining the Linux Foundation. I'll guess within the next 2 years.
The business unit that would open source Windows is Windows Development Group, who are mostly stuck in neutral. They can barely perform builds of Windows themselves, it's so huge and tangled and poorly organized. They can't change anything because they're crippled with decades of technical debt. Whether they want to or not (and I don't think that they really do want to) to try to open source that monstrosity is quite far away.
That said, I'm sure some people within Netscape said the same thing about Mozilla. So I'd love to be proven wrong.
I swear Microsoft's business model was to bring people in to their ecosystem and then charge them for what is hopefully a superior development experience.
Is there a new business model? How do they lock people in and squeeze them for money? Is their cloud solution radically different from the competition that they can put all their eggs in that basket? What's the big picture plan? Or is the new CEO just going rambo and pandering to DIY geeks who want everything for free ? (myself included!)
I feel like there has to be some parallel universe blog where these press releases explain what they're doing to investors beyond "we're going to take your money, and we're going to make things with it. And then give it away for free! Please give us more money"
Like awesome dude... but what the hell is going on?
So, marketshare and marketing.
What's going on in a new strategy.
Microsoft wants people building applications in Azure. They want people using ASP.NET technologies. Given that Azure competes with AWS and Google Compute; that ASP.NET and C# compete with Elixir/Phoenix, Clojure, Scala, Koitlin, etc, there is absolutely no way they can maintain any form of lockin. Even in the conservative companies, they compete with Java. The pitch to the investors is that by opening up their toolset, it gets more people on their cloud services and boosts recurring revenue. Which is what everyone else is doing.
We might be looking back at this CEO with incredulity in 10 years when MSFT is struggling to keep the lights on ("they did what?! They just gave away all their products for free??")
Right now, I can't think of any vendor that forces a lock into their platform for development purposes. Even Apple made Swift free and cross platform. Lock in on Visual Studio and C# makes no sense. C# is a nice language, but there's a wide variety of alternatives that are just as good. Visual Studio is really nice, but people have been building stuff with Eclipse, Sublime, and Emacs for quite some time.
They are making a long-term push to subscription oriented services.
Isn't it? How much growth do you see around the PC and Office business?
I actually agree with you. I think Microsoft's evolution is mostly done. The XBox is their consumer device and everything else is all about enterprise and small business users.
Microsoft is a boring, mature, very profitable company. It isn't such a bad thing to be.
Their hardware is in an interesting place though. They are really the only company making decent Windows hardware (and I say that as a longtime ThinkPad fan). I would be so happy if they took the Surface Book and simplified it into a traditional laptop with battery life as good as or better than similar Apple machines.
(Nokia are now a wholly owned subsidiary of Microsoft. If Microsoft collapsed, who would buy them? Apple?)
Windows is a commodity, a) it won't pay for its own engineering team and b) unlike other competitors, Microsoft hasn't been able to capture as much value from the current Windows ecosystem and marketplace.
Developing for Windows is becoming a liability: a) your team can't develop only for Windows anyways; b) your team can be more efficient by using a wider set of tools and technologies than Microsoft's own developers, and c) if Windows is not profitable and your product depends on Windows, it better pay for part of Windows' cost.
Internal OSS adoption, investing on cross-platform development and in Azure seem all strategic investments in managing the risks above while remaining a software (product) development company.
Every other gain from the same strategies (the ones affecting their customer base) are cherries on the top of the cake.
> Are investors onboard with that?
Not sure they realize what's going on. If they did, I couldn't explain the current P/E ratio in days of declining revenue, a prospect of shrinking revenue streams (overall; medium-term at least) and large bets on lower margin businesses.
> They just gave away all their products for free?
They probably wish they had invested in Office for the Web, Android and iOS much earlier on and with much more intensity, and still have given it for free. They were lucky none of the competitors really stepped up to fill the void. In a cloud-first and mobile-first world, there are multiple revenue stream available once the data information workers process is more closely tied to a provider; specially with the synergies in their product line.
We may like it or not, or agree that it makes sense or not, but at least it looks like a rational strategy.
They still have a very strong lock-in in graphics though. Why didn't MS join the Vulkan working group? And that's their attitude in general - they didn't become any better than before. They just drop lock-in under pressure by competition. Other than that, they pursue lock-in all the same.
Really? Might want to check that again.
Although, I am curious, considering Apple does the same thing with Metal that Microsoft does with DirectX. The difference is Apple has no dedicated console device they sell.
ahem ... http://www.apple.com/tv/ :P
Does that mean they're altruistic and want to save the world at their own expense? Definitely not. But they also recognize when when they're not going to win a fight and have started to compete in markets they can't own.
That being said if they own a market (e.g. PC Gaming) they aren't going to exchange money for warm fuzzies.
> I'm also certain most companies use a tool like Unity which does that double duty for them.
That doesn't justify the lock-in tactics of MS, Apple and the like. If that burden shifts to engine developers, it's still a burden and effort that could be spent on something more useful like improving actual features of the engine. In the end, it's simply a tax that everybody will be paying.
These are businesses with an interest in making money, not people with an interest in making the world a better place. I'm not saying it's right, just that it makes business sense.
Rather herding their market share and mind share, and making it hard to go outside the herd. I.e. if you want to be cross platform - pay the tax. That's the whole purpose of their lock-in.
> Once you have a developer comfortable with a platform, it can be hard to impossible to get them to switch.
Yes, and it's disgusting to use development tools for lock-in. MS do it like forever.[1]
> These are businesses with an interest in making money
Lock-in is a crooked method of making money.
[1]: https://en.wikipedia.org/wiki/Criticism_of_Microsoft#Vendor_...
I.e. imagine you bought a light bulb and can't use it because it's XYZ lightbulb that can't work with fixture ABC and requires you to rewire the whole house. What a wonderful MS style experience. Luckily it's not the case most of the time.
Such as? Sure you can replace your iPhone with an Android device, but it's not pretty.
Because they can make life easier for developers and also benefit from the shared effort. But their whole goal is to make life harder for developers (i.e. those who don't want to be limited to MS walled gardens) as a way of taxing them for not falling in line. A usual crooked monopolistic behavior that MS is so accustomed to.
Assuming Vulkan drivers are ironed out (now they are still fresh), it makes life easier by removing the need to implement different APIs for each platform. By sabotaging such option, MS taxes developers which want to target their Xbox for instance requiring them to use DX12 instead.
By not supporting it on Xbox which is a walled garden. Since Xbox has a significant market share, they essentially force developers not to use Vulkan (and use DX12) if they want to target Xbox. Compare it to browser wars of the past. MS did the same thing exactly, and the only reason they magically started supporting shared Web standards is because they lost those wars. Today it's a real wonder - they even decided to support free video codecs in the browser (while Apple still refuses).
Your entire complaint is that developers have to do more work if they want to support multiple platforms, which has always been the case. I don't recall the original Final Fantasy getting released on the Sega Genesis. There's never going to be a magical catch-all graphics API because technologies like Metal and DirectX take advantage of known hardware specs and OS features to make the games look good and run fast.
In order for cross platform solution to offer value of avoiding duplicate work, it should be really cross platform. MS prevents prevents it by not supporting it on Xbox.
> which has always been the case
Exactly because of such lock-in.
> technologies like Metal and DirectX take advantage of known hardware specs and OS features
Let's not try pretending that MS and Apple do it for any technical reasons. There are none.
The two largest platforms, MS and Apple have their own stacks, Metal and DX12. And they have been maintaining those from years, especially DX12 which comes from decades of DX development.
They should throw all this away (and lose any competitive advantage for their platform in the process) just because there's finally a competent new stack (that's not even ready yet)?
>Let's not try pretending that MS and Apple do it for any technical reasons. There are none.
Would wanting to offer the best possible experience for your platform, to control how and when any new feature is implemented according to your long term plans, and to not mess with lower-common-denominator cross-platform design-by-committee APIs counts as a "technical reason"?
Let's not pretend you ask for this for any technical reason. It's all about developer convenience at best.
It's the only cross platform solution. So yes, it should be pushed forward to make it work. It's not a "blind" push - it's the only reasonable thing out there. Neither Metal nor DX12 plan to do anything comparable. Petty greed of Apple and MS prevents them.
The XBox is not a tech test platform. Neither are the mobile handsets.
Claiming this reality amounts to "sabotage" is somewhat absurd.
It's not. MS is not new to sabotaging portability. Learn from history.
It wouldn't be the first time. "Learn from history."
Lock-in is about whether, after adopting technology X, it takes substantial effort to go to an alternative technology Y -- not about whether you can take X with you in a different platform/hardware.
Wanting control of your platform and how it evolves is not "petty greed".
If anything it's the developers that want to save money, by only coding their apps once.
I don't believe platforms should have lowest common denominator standards (and evolve in lockstep) just to make porting easier.
OpenGL started development in 1991 by Silicon Graphics and it's primary focus was on CAD/CAM utilizing expensive hardware accelerators. It was initially only available on IRIX and was never intended for video games. It was not open and the Architectural Review Board that maintained the API was controlled by Silicon Graphics.
Direct3D was developed by a company called RenderMorphics starting in 1992 and was bought by Microsoft in 1994. Direct3D was added to the DirectX suite in 1996 specifically for video game acceleration. At the time Microsoft was shipping their own OpenGL Drivers and would continue to do so until Windows 2000 was released.
Microsoft and Silicon Graphics actually attempted to unify the two APIs under Project Fahrenheit in 1997. Project Fahrenheit consisted of low, medium and high end drivers with Microsoft providing the low-end and Silicon Graphics providing the mid and high end portions. Microsoft abandoned the effort in 1999 because DirectX adoption had taken off and they were focusing resources on the original Xbox console. Silicon Graphics was in financial trouble at the point and it no longer made sense to pursue a project heavily reliant on them.
Silicon Graphics trouble's were reflected in the stagnation of OpenGL development with only incremental releases up to version 1.5 in 2003. SGI would eventually go under and the API would get turned over the Khronos in 2005 but it wasn't until 3DLABS got involved that anything happened and it wasn't until 2007 that OpenGL 2.0 was released. At the point the Xbox 360 has been out for 2 years and Microsoft was heavily invested in DirectX.
Vulkan doesn't need to be cross platform because there are tools like Unity which abstract away the graphics API and let developers target a number of platforms.
However, you are lodging a complaint against Microsoft that has been the case for every console device since the first ones were released. However, that being said, not supporting Vulkan on the XBox harms Microsoft more than Vulkan since all that means is some games will not be available on the XBox. Just like there are XBox games that are not available on the PS4, the PC, or the Wii U. There's nothing Microsoft is doing that's out of line with the rest of the console makers. It's the console industry in general.
Unity developers will be doing that double work in such case. And not everyone is using third party engines anyway. Don't think that if something is abstracted, it somehow magically happens for free.
I'm pretty sure they're well paid for the efforts.
And that cost is passed along the way reaching those who use it including end users ;) Someone will feel the tax.
With Vulkan they finally dropped backwards compatibility, something Microsoft had been doing with each successive version of DX, so it would have been a good time for Microsoft to transition away from DX. But what motivation do they have at this point? OpenGL adoption isn't yet threatening their platform, and with Apple pushing Metal they have even less to worry about. Vulkan has only further fragmented the market because anyone that wishes to use it must also write fallback renderers because of the limited support.
In any case if/when Vulkan does become the industry standard, Microsoft will only need to make an Xbox One API because Windows already has support for Vulkan, better support than any other platform at that.
The motivation can be pretty simple - don't be a jerk. But it's MS. Lock-in is practically in their DNA already.
Being on the group means zero if the actions don't follow.
When are you going to properly start bashing Sony, Nintendo, Apple alongside MS?
> When are you going to properly start bashing Sony, Nintendo, Apple alongside MS?
When their influence will be comparable in damage. Apple is probably closest, but not in graphics APIs. Metal is non existent. Apple causes more damage in browsers these days. Remember all the recent articles about Safary is the new IE?
Nintendo was the company that introduced the concepts of gated development on the aftermath of 1983`s crash.
Also why not bash NVidia given CUDA or their influential part in DX designs, to the point their cards are almost a mirror of the API?
Google so praised for Vulkan, pushes its own computing API instead of OpenCL.
Intel spends more resources in their DX drivers and their OpenGL support is still pretty shitty. One just needs to delve into the OpenGL developer forums. They were quite known in the games industry for having the driver lie about supported hardware features.
Or by announcing at GDCE 2009 their new graphic analysers tools, with DX only support. To my question what about OpenGL I was given the email of some random dude at Intel.
Yet, only MS gets the bashing.
MS is opening their platform to run on Linux because they want people to continue using Windows, Visual Studio, and .NET as development platforms. The core of MS's business has always been Windows, and secondarily, Office. Since so many people want to use the cloud, and on top of that since so many people want to use the cloud via sexy vendors like AWS, Microsoft needs the heart of their Windows lock-in strategy, which is .NET, to work on it.
These moves are defensive of .NET's place in enterprise development, and consequently Windows's place on the enterprise workstation. Once MS feels that .NET is far and away the clear choice for development in the cloud-centric world, they'll work to bring more people onto Windows as the cloud OS of choice (Azure, etc).
Like many people, you are missing the point. The operating system is irrelevant. You have people editing Excel spreadsheets in an iPad on iOS, and then switching to Excel on some form of Windows. They've been trying to get Windows Server and IIS as the platform of choice, and they have lost to Linux, Apache, and NGINX.
From a technological perspective, they can't afford lock-ins, not when there are so many alternatives. They want you using their services.
In the way described in my original post. Open-sourcing the .NET framework means people will help them port it to new platforms. It means that people will be able to get the .NET framework running on whatever is running in their corporate cloud. This means that users will continue to develop in C#, using APIs developed by Microsoft that will always work best on Windows, using development tools provided by Microsoft that will also always work best on Windows.
If your company switches from .NET to Java because .NET doesn't work well "in the cloud", then your company starts to ask other questions, like "Well, we don't use Visual Studio anymore, so we don't need to keep paying Microsoft $xx,xxx per year for that. Everyone likes Mac a lot and we don't have to use MS's dev tools anymore, so why don't we move everyone to that? We can start to phase out our Windows Server and SQL Server licenses too since we're not using any other Microsoft stuff and then we won't be paying them another $yy,yyy and we'll be one of the coolest companies around because everyone will be using a Mac."
MS's strategy of opening the foundations of their platform so that the applications can run on any backend makes it so you instead say "Oh, we still run .NET apps on our AWS cloud, so we still need Visual Studio, better keep paying MS $xx,xxx." And "oh, SQL Server runs in our cloud infrastructure, so we can stick with that; that's another $yy,yyy for the license this year."
If you stay on MS's platform, they can then call you up at any time and say "Hey, switch to Azure, it's a lot cheaper than AWS because we don't charge ourselves license fees." On the other hand, if you move off their platform because MS tech doesn't work well in the cloud, they lose a lot of existing revenue, a lot of potential revenue, and a lot of mindshare and exposure that decreases their relevance in general.
The key to MS's lasting success has been .NET. That's what's been propping up Windows and consequently Office. If they lose .NET, they're in deep trouble. They are going to do everything they can to keep it alive, even if it means making it so your ASP.NET web app runs on a Linux server.
They are just another empire. Enter the new world! This is the smartphone and cloud era!
Who else is trying to cover all your needs (1) both on-premise and in the cloud; (2) across platforms from USB thumbdrives to smartphones, tablets, laptops, desktops and servers; and (3) has cross-platform apps on Windows, Android and iOS?
Google is pretty much cloud-only and Apple is pretty much Apple only, and neither of them supports anything like the same range of devices.
It's a long play, but Microsoft has been executing this strategy for a few years now....
Yes. But for about the last 10 years, that ecosystem hasn't been doing very well. Most Windows hardware is garbage and (except for games) there's virtually no excitement around software. What's the last Windows application that went viral?
Their developer strategy (universal Windows) is interesting and if I were in charge I would probably go down a similar path, but as a developer it doesn't interest me at all. Applications that can run on a phone or a desktop is an interesting trick, but in reality I normally want a substantially different UI on each. That would lead me to think about separating the UI from the application and then I might as well make a web app.
Survive now, figure out how to make money later.
If Microsoft does nothing, very little new development will be done to run on Windows. You don't need Windows to access Gmail of Facebook. Their backends don't run on Windows. Why would you deploy your software to Windows if it's cheaper and more effective to deploy it to Linux? Shortly, all their technologies will become irrelevant.
It's true they are doing interesting stuff in the JavaScript space, but what does it do to improve their bottom line? It's not unlike Sun with their Java ecosystem, but from an even worse position than Sun held.
All of the comments here are all about "Microsoft is advancing OSS" and "Microsoft grew a heart" and "Mind blown", but all I see in the article is "We'll be providing some tools to help you use our paid cloud services".
What am I missing here?
But if you remember the Microsoft of 10 or 20 years ago, when they were bashing open source at every turn, spreading FUD and exploiting their monopoly on the desktop to crush competition, things have changed a lot. Not neccessarily because the "new" Microsoft is made of nicer people who just want to be friends with everyone, but because the world around them has changed.
The end result, though, is the same - Microsoft appears to be embracing open source and community-driven development processes.
Yes. I understand that that's the message here in the HN comments, but my question is why. In what way does this mean that MS is embracing open source? Many replies to that question (including yours) have been along the lines of "Remember when they were saboteurs? They just took an action that wasn't overt malice!"
Again, I assume I'm missing something, but it all sounds like "Hitler doesn't spend all of his time engaging in acts of genocide; Sometimes, he eats cereal." (BTW, no, I don't think of MS as inherently evil. I make my own living on closed-source software.) I'm not seeing the "complete reversal" people are talking about, nor even a partial reversal. Nor do I see the opposite. These things appear orthogonal.
Is this all because their new Azure-specific tooling is open source? Or is it simply because they're shaking hands (harder) with an organization that has OSS street credit? Or something else entirely?
That still does not mean, of course, that Microsoft is an "open source company" now, but I think it shows their attitude has changed significantly. Given their past, I think this is at least a very good sign. Of course, they still engage in plenty of lock-in, and their baroque licensing terms can drive a poor sysadmin insane. But there is some progress, and a lot of people are happy to see that.
Of course, the main reason for this is that the world has changed, and Microsoft can no longer exploit their monopoly on the desktop when a fair amount of people have - at least at home - ditched laptops or desktops completely in favor of smartphones and tablets (rarely running Windows). Developers like to build web services and web apps on Linux, and if Microsoft just refused to support any non-Windows systems on Azure, they would lose a fair amount of business. So they seem to look for ways to make money in a world where Windows and Microsoft's conventional software stack can coexist with other software and operating systems.
So if, for example, they open source the .Net framework, that means they can win over developers on other systems. Developers who then might want to use, say, Visual Studio, so they still can make money of those.
(Alas, with regards to Windows and Office, their cash cows, nothing has changed.)
Personally, I love this. Have recently been learning ASP.NET and started using Azure simply because I find it to be one of the easiest frameworks and platforms to iterate quickly on.
I love the new Microsoft, I hope this continues. It feels like they have had a lot of brilliant people previously held back by rules and constraints which are now removed.
I'm not saying it's bad. But it's not a "MSFT open sources xxx" headline either.
It's not like they're going to throw money on something that they believe never will benefit them in any way. This is completely fine and how it should be.
It's a nice reminder how important OSS has become.
I don't think that is relevant, but of course open source is important and probably will be in the future as well.
To answer the question: Canonical. While they're aiming to become profitable, I don't think Mark Shuttleworth has any illusions about getting back all the money he invested.
But the point is that everyone is self-interested in OSS.
Canonical has an ad on their page for Ubuntu Advantage, they run training and offer certifications, etc. They are not a philanthropic organization.
If we're going that far, everyone is self-interested in everything, even if it's just because doing something (like, say, giving to charity) makes them feel good or suffer less guilt.
What I mean is it doesn't matter for what reason you're contributing to open source for. The sole thing of open sourcing code, contributing to existing projects etc is inherently a good thing.
At least personally I don't give a crap about why someone creates an open source project. I am just happy people do it.
Microsoft is a shady company and they have contributed to projects in the past to cause damage.
But let's scope the discussion just around this announcement.
Majority of the topics here are around azure for non-.net market. There's TFS but only because this is how IDE works: provide plugins for a source control systems to reduce task switching.
Yes, in Visual Studio publishing your application (even node.js) is as easy as going into the meny and pressing publish. You can setup git-push deploy, databases etc easily. I believe they want to integrate their tools into Eclipse which seems awesome. Think if you could set up cloud management in your IDE for java/C++/php projects as well. That would be awesome for the people using Eclipse and Azure.
Treat the non .net platform as a second class citizen and their potential customers will smell that from far away...
By your own logic if Linux were a Microsoft product that wouldn't be good enough because it is only GPLv2.
A lot chunk of the .Net framework are under MIT license and include this:
https://github.com/dotnet/corefx/blob/master/PATENTS.TXT
Seems pretty comprehensive to me.
Not sure if you've actually looked at Microsoft's CLA or tried to contribute to any of their projects. The CLA signals that, despite having chosen how their projects are licensed themselves, they don't hold those licenses in high regard. And like most CLAs, it creates a needless barrier to entry and turns away real contributors. (Not that this is actually seen as a big concern within MS—at least it doesn't seem to be. Based on the projects I've been watching, development is very cabalistic [read: top-down] and that they might get some outside contributions because they're open source seems more like a nice also-have rather than an outright goal.)
And since you brought up the .NET patent grant, it's hardly comprehensive. It severely limits the practical chances of anybody doing anything with it outside of Microsoft's own .NET Core project and Mono—which is more or less another project under Microsoft control, now that they've acquired Xamarin.
All signs point to the .NET patent grant being specifically written to enable Microsoft's very own version of Sun/Oracle's "don't fragment Java" lawsuits. (Especially ironic given that the whole reason C#/.NET came about in the first place is because, in addition to Google being a target because of Android, the only other big target of such a suit was Microsoft themselves because of Visual J++.)
I think these are just good legal and business a lot of the time. They are the legal protection and audit trail showing that the person really did intend to license their IP.
colby@ruta-corsica:~/src/antiholism$ cat ./_drafts/clas.markdown
List of open source software projects which used to have CLAs but no longer do:
- Neovim ([Keyes])
- Node.js ([Cantrill], [Fontaine])
- Yeoman ([Monge])
List of open source projects that have never used a CLA:
- Linux
- Mozilla
- Swift
[Cantrill]: https://www.joyent.com/blog/broadening-node-js-contributions
[Fontaine]: https://nodejs.org/en/blog/uncategorized/notes-from-the-road/
[Keyes]: https://github.com/neovim/neovim/issues/3036
[Monge]: https://github.com/yeoman/yeoman/commit/5661a34df899126f0372d2c70c48f80b2a03a28f
All told, CLAs are actually a terrible way to achieve the things they set out to do, except to grant the org additional rights that the existing project license doesn't handle. They're all ritual and guarantee nothing. (It doesn't help that the ritual is friction-inducing and helps turn away contributors, as I said before.)Here's how most CLAs work, including how it works at Microsoft: The org bugs an anonymous contributor about signing the CLA after contributor submits his or her first change, and if sufficiently cajoled, said anonymous contributor sends in the signed CLA and is never bothered again. If the intent is to protect your org by ensuring you don't accept changes that the contributor doesn't have authorization to submit, then the CLA process outlined here is so ineffective against accidental violations that it's not even worth using. And that is to say nothing of deliberate violations.
Here are some questions to ask:
If I get my employer to sign off on a CLA today, who's checking four years from now to make sure I haven't changed jobs and the whole situation is still kosher?
If I wanted to submit changes to a project without getting permission from my employer, how does the CLA stop me from doing that, given that all of them allow an unemployed/underemployed contributor to say that he or she is the only one who owns rights to the code?
If I can't be trusted not to copy code from another existing project distributed under a conflicting license, how does the CLA stop me from doing exactly that and just lying about it?
If I wanted to sign the CLA with a false identity and submit code using that, how does the CLA stop me?
If the CLA is meant to be an assertion that the org is authorized to accept my changes, how is that at all different from the same assertion I make when I publish my fork or my patches under the same license the original project is using?
> They are the legal protection and audit trail showing that the person really did intend to license their IP
If you want to prove that the contributor really meant to allow you to distribute their changes, then point to the bug where the contributor submitted those changes.
> If you want to prove that the contributor really meant to allow you to distribute their changes, then point to the bug where the contributor submitted those changes.
Lawyers that I've spoken to don't agree with your analysis. Several subject matter experts have articulated a specific risk that a court could find that just because someone apparently submitted code to an open source project does not mean that they knowingly and intentionally did that. It's especially not clear what will happen if the audit trail is scant, in the sense that a commit shows up without any supporting documentation from the person who submitted it explaining their intentions. Just having licenses on the files, or just submitting patches to an OSS project is not enough to be an airtight legal defense.
There's also another aspect of this situation that you might be overlooking. Just because you might prevail in trial either way does not mean the cost of litigation will be equal. Imagine the discussion that I hinted at above playing out before a judge. The open source project owner claims that the code was submitted intentionally under the GPL. The alleged submitter claims that they never did that, and that the code audit trail is incorrect / doesn't capture intent / wasn't a binding contract. Now that's going to play out in a complex way during trial. Even if the court rules in favor of the project owner, that conversation might take a whole lot more time and energy than if there was a clear, obvious, specific contract showing that the submitter was releasing their rights to the project owner.
This audit trail has the capability to significantly simplify and fend off a frivolous lawsuit. Large companies are often sued in a frivolous way, and simply fighting off even totally baseless lawsuits can cost more dollars than settling, so steps taken to make the legal defense airtight have meaningful value from a business perspective.
The other things you're mentioning about CLAs won't be an obstacle to a trial judge. The investigation during a lawsuit will be able to establish whether a CLA was really signed by the submitter, and whether they truly intended at that time to contribute code under CLA / open license. The CLA will make this easier to establish. The other risks that you're talking about are largely risks of fraud which make the situation messy. I'm not sure what will happen if one person submits (and claims to have the rights to) IP that they don't actually own. There's probably precedent for who is liable in that situation. The project owner who requests a CLA and explicit assignment will probably be viewed more favorably by a trial judge, in the sense that they'll be seen as a business that's attempting to do the right thing in the legal landscape sense. An OSS project that just says, "We just take whatever code someone sends our way, while trusting blindly in what they say", will not necessarily receive the same positive treatment. The opposing counsel could easily spin the situation to make it look like the OSS project was knowingly accepting code that they did or should have known was not theirs to accept. The trial judge is going to have to disambiguate those facts. The CLA translates the situation into, "And the person submitted the code committed outright fraud and deceived the project owner", which will not necessarily be easy to establish merely from a commit. CLA demonstrates more of the submitter's mental state than a mere commit. It's far less likely that someone will "sign a CLA by accident" than that a commit could end up in the wrong place by accident.
There are a lot of ways in which CLAs are believed to provide meaningful value to organizations that employ them. Until these things go to court, it's hard to know for sure what will happen.
Even Microsoft's CLA has a backdoor that doesn't require the author of the code to sign the CLA. You can, for example, copy and paste some procedures from a compatibly licensed open source project and mark your submission as containing code from a third party source. (E.g., "What's <project>'s module resolution procedure? Ah, just copy the file defining that class into the source tree; it's already under MIT.")
And as for "knowingly and intentionally" submitting code, Microsoft's CLA in particular exacerbates this rather than ameliorates it, because it broadens the definition of a submission to one that I'm sure would surprise almost every contributor who has actually signed the thing. Any code that you even discuss in a channel affiliated and run for a particular project by Microsoft constitutes a submission if you are the original author of that code, regardless of whether you actually submitted a patch for inclusion in the project, or even made any sign of interest in the development of that project whatsoever. (E.g., signing the CLA and submitting changes for project X means Microsoft gains control of your work around project Y if you link or distribute a personal project on the message board or mailing list for such project Y). So that argument is bunk.
> The other risks that you're talking about are largely risks of fraud which make the situation messy.
I'm at a loss for words.
> An OSS project that just says, "We just take whatever code someone sends our way, while trusting blindly in what they say"
Weird to even use this characterization, since that's an accurate description of exactly the sorts of CLA processes we're discussing.
> The CLA translates the situation into, "And the person submitted the code committed outright fraud and deceived the project owner", which will not necessarily be easy to establish merely from a commit
I have a sort of rule of thumb that I think most readers follow whether they realize it or not. It goes like this, "The first person to use the word FUD loses." Even so, I'm having trouble seeing this comment coming off as anything but that. It comes off as nothing more than casting incredibly dubious aspersions.
Can you point to an instance where such a thing has actually come up in litigation? Alternatively, cite an instance where even just a credible threat of such a thing has come up.
Both Mozilla and Linux each have long and storied histories; both are poster children for what large, successful open source projects can achieve; and both have corporations with serious money backing them. They somehow have managed to get along fine for decades without anything like that posing a realistic problem for either project, or even worthy of a footnote in their history, for that matter.
For a more recent example, I'll point out again that Apple deliberately chose a CLA-free contribution process for Swift, which was initiated as an open source project only months ago. Do you think Apple has reason to believe that the threat you mention is a credible one but that their project (or maybe just some characteristic of the company) has some inherent detail that renders them immune to it in this case only?
CLAs, in the form that we typically see them, are bullshit, and almost every defense of them fares even worse. Once again, CLAs exist for one reason, which is to grant the recipient org rights beyond those they'd ordinarily only receive through the license (that they chose!), e.g., so they can redistribute it under alternative terms, should they decide to do that for whatever reason.
This would be a more productive discussion if you'd actually focus on that, rather than invoking unverifiable claims about advice from phantom counsel and the threat of submarine suits.
The whole SCO Linux controvery also seemed like a major problem for Linux at the time: https://en.wikipedia.org/wiki/SCO/Linux_controversies - it seemed to have a chilling effect that turned a lot of companies off to open source. The court case seemed to take several years to litigate, just to establish that Novell and not the SCO Group owned the copyright to the code. Why did that take so long to establish? The submission governance and CLA were put in place by some companies specifically to mitigate the threat of such a risk applying to them later. As Wikipedia explains regarding the rationale of CLAs: https://en.wikipedia.org/wiki/Contributor_License_Agreement#...
"Contributor Licence Agreements (CLAs) can be used to enable vendors to easily pursue legal resolution in the case of copyright disputes, or to relicense products from which contributions have been received from third parties. The purpose of a CLA is to ensure that the guardian of a project's outputs has the necessary ownership or grants of rights over all contributions to allow them to distribute under the chosen licence."
Emphasis is: "easily pursue legal resolution in the case of copyright disputes" (e.g., SCO Linux)
A lot of your argument seems to boil down to that because some people don't think there is a risk, that no one is right to rationally recognize a risk. I can't really comment on Apple's motivations for not requiring a CLA in Swift, just like I can't really comment on Apple's motivations for masterminding a criminal conspiracy to fix the price of ebooks (for which they were recently fined $450m). I can guess but I don't know for sure.
I think reasonable people could disagree about the risks involved in CLAs. It's not always the case that lawyers agree. As I pointed out originally, we don't have case law for all of this space. Insofar as you're implying that open source projects have been run without legal problems, I think you're wrong. Things like the SCO Linux controversy and the Oracle v. Google lawsuit about Java APIs make me feel like the industry as a whole is on less stable ground than everyone seems to think. Given that there are real cases where such problems have been specific issues, and given that many qualified people (not just me) explain this as their rationale, I don't think it's unjustified FUD. Can you provide a court case where one company sued another about an open source contribution, and the court clearly and convincingly ruled (in a short period of time): "You chose to contribute to open source, so live with it and stop wasting everyone's time". I haven't seen that. I've seen rather the opposite. The court will only muddle through what's happened with years of litigation at exorbitant cost. I've provided some examples of where this actually happened and has been messy, so if you wish to assert that this is all simple and CLA's aren't beneficial, then I'd like to ask you to provide a citation of a court case where such an issue was trivially resolved.
See also Jacobsen v. Katzer for case history. "The case is noted for its contentiousness, the parties filing 405 motions and other pleadings with the trial court, and two appeals to the Ninth Circuit Court of Appeals." (Wikipedia) The case was only resolved in 2010, and since it was settled out of court, I'm not clear whether it establishes binding precedent. As I understand it, the summary judgment left it open whether damages were owed. This is another example where litigation took years.
Are you also aware that the FSF employs copyright assignment to ensure that they can enforce licenses? https://www.fsf.org/bulletin/2014/spring/copyright-assignmen...
> In order to make sure that all of our copyrights can meet the recordkeeping and other requirements of registration, and in order to be able to enforce the GPL most effectively, FSF requires that each author of code incorporated in FSF projects provide a copyright assignment, and, where appropriate, a disclaimer of any work-for-hire ownership claims by the programmer's employer
CLAs are all about copyright assignment.
So in conclusion, I don't find your arguments convincing, in part because you seem to be overlooking or glossing over case history. From my perspective, there is a long and storied history of people actually running into problems in this area, and companies engaging in malicious lawsuits that are without merit specifically to harm competitors, and so on. There are examples of well-informed companies like the FSF taking steps specifically to mitigate these risks. For these reasons I understand why a company would want to protect itself from apparent and legally-advised risks with a CLA, and in general rely on more explicit contractual relationships rather than an open license agreed to without a clear meeting of minds.
http://ebb.org/bkuhn/blog/2014/06/11/nodejs-no-cla.html http://ebb.org/bkuhn/blog/2014/06/09/do-not-need-cla.html http://ebb.org/bkuhn/blog/2011/07/07/harmony-harmful.html
What is going on in Microsoft? Have they finally seen the light? First today comes SQL Server on Linux and now this.
It makes a refreshing change. Long may it continue.
Now the great majority of the .NET development stack is completely open, aside from Visual Studio itself. But there's always Visual Studio Code, the lightweight, open source alternative. Runs on linux too.
Open source, apparently.
Office is available on other platforms, and they've been adding new platforms in the last couple of years.
Currently supports: Android, iOS, Windows Phone, Mac, and PC. Not including their in-browser suite which runs on Chromebooks and your smart fridge.
They also haven't killed Skype for Linux. Skype for Linux was terrible before Microsoft purchased Skype. If anything Skype for Linux hasn't been improved while the Skype for Windows client has become progressively worse.
Seen this way, the slow transformation from lock-in to charm-in that we observe today is more a return to the roots than a dissolution of identity for Microsoft.
I hope it's not too late for them, for me there is no way to get back to Windows environment for any kind of development.
I suddenly realized that, Linux has won already, from Smart phones to the cloud servers, all the way.
Awesome! You don't need to:
https://dotnet.github.io/getting-started/ https://code.visualstudio.com/#alt-downloads http://www.omnisharp.net/
*It's a stretch to say "Linux won on the smart phone".
Can someone explain exactly what Microsoft would get out of this (and what they would theoretically give back in the process)?
[1]: https://en.wikipedia.org/wiki/Embrace,_extend_and_extinguish
https://en.wikipedia.org/wiki/Embrace,_extend_and_extinguish...
At this point I really don't think it's useful to cite a Microsoft strategy from the mid 1990s. It's clear at even a cursory glance that their approach has changed dramatically.
- old IE installs
- PDF printing functionality not included in older versions of Office and Windows
More experienced people/sysadmins can probably bring out lot more issues. And I totally agree with you that Java didn't suffer in the end, but how many lawyer hours were spent on stuff that shouldn't have been an issue in the first place?
I respectfully disagree. MS has spent a long time building up a lot of bad-will. Just because they've done a couple of nice things lately doesn't mean we should forget all that.
I hope they become awesome, and continue to be pro-FOSS, but it's going to take more than a couple of good steps to convince me.
Also, they didn't just stop in the 90's. A lot of their questionable practices have continued on, and are still going on. I'm not basing my mistrust only on the 90's. It's just one factor out of many, but one I still feel should be taken into account.
How many of the employees that were there in the mid-1990s work at companies you adore or support today? Maybe other companies are where Embrace, Extend, Extinguish lives today.
Technology moves at an incredible pace. Acting like any news story from the mid-1990s is relevant today is incredibly silly.
"Fool me once, shame on you. Fool me twice, shame on me."
Don't trust Micro$oft. Let them die.
The claim is that Microsoft omitted the Java Native Interface (Allows Java code to call C/C++ code) and instead used their own J/Direct interface for calling Win32 APIs directly.
That said: 1. I have to admit J/Direct was an awesome idea. Being able to call Win32 apis directly without writing JNI wrappers is very useful. You wouldn't be able to port python code that uses the win32api module either.
2. JNI Code is very often not portable as it is. If you're writing JNI Code, you're most likely already using native OS apis, and relying on OS specific features.
I have (somewhere ;-) RMS's John Hancock on a small cheque I wrote and he cashed for the FSF nearly thirty years ago.
I did my duty on hating Microsoft and pushing Linux for those years when it mattered. By 2005 I was estimating Microsoft's 'packet' TTL at about 10 years ...
Nowadays Microsoft are like a beaten bully, out-eviled by much creepier players, and they're acting reasonable, mostly just asking to be paid for decent products that do not rape the customers and sell their info to whomever.
Why be stuck in the last century?
If you have any evidence of this, you should email links to hn@ycombinator.com so we can investigate them. We've banned pro-MS astroturfers before; one in particular who made dozens of accounts and used them to reply to himself in arguments. But I don't know of any evidence that they're "hard at work on HN" now.