A startup founder and ex-Facebook engineer’s story of the BSD + Patents license
medium.com
medium.com
That's not a good enough reason for developers or startups to give away legal power like that. Forgive me if I don't feel like waiting for them to turn evil.
Agreeing to the Facebook BSD+Patents license doesn't rest on the assumption that Facebook will continue a defensive stance on patents. It gives you rights or mostly preserves your rights if Facebook were to proactively claim patent infringement. From my reading:
1. The patent grant specifically gives you patent licenses for Facebook open source, so Facebook couldn't rightfully claim patent infringement for the licensed patents.
2. The grant also says if Facebook were to proactively sue you for infringing its patents, you'd keep its patent licenses even if you were to countersue.
(Disclaimer: I'm not a lawyer, nor is this legal advice.)
Let's suppose that Expo SDK 2 has valuable IP that you've protected with a patent, and that you are now seeking investment so that you can grow a business around it.
It works! Investors are excited, customers love it, and business is growing! Well, until Facebook comes around and releases the Fxpo SDK with a large media launch at F10. It contains some of the same technology you added to Expo SDK 2, perhaps even some of that patented technology that enticed your investors. Wow, that sucks. So you call up your lawyers and setup a meeting with Facebook.
At the meeting Facebook says, "Tut tut tut. James, you can't sue us for patent infringement because we'll pull your license to use React. James, your entire business is built around React and it might cost, what, $1M USD to replace it with Angular. And how long might that take? Months? Years?! James, we see that you're a smart businessman. Look, we'll buy your company for $200,000. Think it over."
What will you do? Sell Expo Inc to Facebook for pennies, or fight them in court with the lawyer's fees and the loss of use of your money making product? Will you have enough cash to cover the gap? Will your investors, anxious to get their 5% return over the 10 year life of the fund, stick behind you or will they write this one off?
When you look back at the time you lost to dealing with this crap, wouldn't you have rather just used Angular or Ember or... Elm?
But for several reasons, the Expo team is working without the assumption we need the option of suing Facebook for patent infringement to be successful. I find companies that are sufficiently durable for other reasons to be more appealing to people whose livelihoods depend on the company in some way, including developers, the team, and investors.
That said, Expo is sort of an outlier in this regard and other teams using React or other affected technologies in the process of building their businesses are unlikely to have the protection of such a natural alliance.
Beyond strategic alignment and intellectual property protections, it is hard to imagine what else might balance the scales between a global gigacorp and a $5M SV startup.
IANAL but I don't believe this is correct.
If I'm using React and I decide to sue Facebook for infringing some other software patents I hold, I lose the patent grant for any potential patents Facebook might hold concerning React. Which they could go after me with if they do indeed hold such patents. There's nothing proactively forcing me off React.
I just don't see anything but good from this BSD+patent grant situation. It lessens software patent litigation in general and lets me know I'm safe from Facebook suing me specially. It seems fantastic!
Most developers don’t understand basic copyright, let alone licenses and grants.
...nothing is going to happen. There's no submarine patents possible here. (...from Facebook, anyhow.)
So, better make sure nothing you use has any form of smart overdraw reduction, dom diffing, etc., before you pick a patent fight with Facebook.
Of course, a cursory glance suggests every modern frontend UI library will violate that patent, so I still don't see a reason to avoid React; Vue, Angular, and recent versions of Ember are all just as much in violation. Guess we're back to static HTML and PHP. :)
(More seriously, hopefully it won't go anywhere; it's pretty clearly got a ton of prior art. But given how broken the patent system is, who knows?)
However, imho one of the major problems with software related patents is allowing an extremely ambiguous language in a field where exact language is the native form of expression.
It simultaneously makes it excessively expensive to challenge a patent, and almost impossible to divine if a particular implementation is covered.
There is code I've written that a client wanted to patent, and knowing the nature of the code, it's not a snowball's chance in hell I would recognise that (my own) algorithm if it was written in patentese, at least without spending days on it.
I don't even want to think about how many hours of legal fees it would cost to challenge even such a minor algorithm.
It seems like you're assuming that there's a decent chance that FB doesn't actually hold any patents on React. This seems unlikely, and is contradicted by what the author wrote (indicating that popular React alternatives may also infringe FB patents). Or am I not understanding your line of thinking?
My view, as a former lawyer, is that if you want to sue FB for patent infringement, you would be very unwise to continue using React. Willful infringement = treble damages.
If you want to sue any company for patent infringement, you would be very unwise to continue using their software under most common licenses. The most-touted alternatives to React are plain MIT license with no patent grant at all, creating exactly the same risk. Why does the license that prevents you from being sued first get all the condemnation?
IANAL, but as far as I understand, MIT license contains implicit patent grant.
I believe the fear of a grant revocation also revoking the BSD copyright license has been thoroughly settled. If that were the case that would be an issue but FB themselves have put in writing that that is not the case.
You're correct though that if one does have aims to sue Facebook they should cease using Facebook led projects.
My main point is that the patent grant is nothing but gravy. Without it you have a plain Jane BSD license. Certainly not a worse situation.
That's very likely actually. Patents are public; people have searched around for obvious concepts and phrases involving the virtual dom, synthetic events, etc., and nothing has been found. (There's also nothing novel in what React does, so you'd kind of hope there'd be no patents.)
> This seems unlikely
Why do you think Facebook having patents on React is likely? (Come to that, why is it any more likely than them having patents on the tech behind, say, Angular?)
> and is contradicted by what the author wrote (indicating that popular React alternatives may also infringe FB patents)
IF a patent on, say, the virtual DOM exists, then Preact, Vue, etc., will all violate it. But it seems fairly clear that no such patent exists. So the author is quite right; popular React alternatives almost certainly use just as many of Facebook's patents as React does...it's just the number is probably "zero".
Someone shared this one with me recently: https://www.google.com/patents/US20170221242
That said, if you're using React, I don't think you should be suing Facebook for using your patents - after all, you're using theirs. If you do want to do that, then by all means, skip React.
So if they infringe on your patents you shouldn't sue them because they let you use some of their code? Note that this covers any patent (design patents too and not just software patents) and for any reason you sue them. That's not how this is supposed to work, and precisely what's wrong with the license. The grant shouldn't be revoked if Facebook is infringing on your works. It encourages you to not litigate against them if they're in the wrong simply because you're using one of their open source components.
The Apache 2 license is much better worded in this area:
> If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
That Apache 2 approach is entirely fair, the grant gets terimnated if you sue for patent infringement, and only that. If that's all that Facebook wanted to protect against, as the author alledges, they could've used the Apache 2 license just fine. They didn't because they're trying to leverage their patents much further.
No, if it's really just "some code" to you, then you should simply not use it if you're really afraid that Facebook is infringing on your patents and that you will gain harm from that. However, if:
- you're profiting a lot from either React, or other Facebook patents
- you're not afraid that Facebook is infringing on your patents, or
- Facebook infringing on your patents doesn't really harm you, just like you using Facebook's React patents doesn't really harm Facebook
...then you can just use React. And I believe one of the above holds for almost every React user.
And I'm afraid I don't really care how patents are "supposed" to work - we've known for a long time already they don't work like they're supposed to....
Eh, what? There's a very big difference between someone infringing on a patent, which does harm no matter if you care to enforce it or not (because it sends a signal to others that it's fine to infringe on your patents, if you don't care about them make them public domain instead), and an open source project including a patent grant so you don't have to worry about any patents that might govern that code. The two situations are not identical and can't just be compared like that.
> And I'm afraid I don't really care how patents are "supposed" to work - we've known for a long time already they don't work like they're supposed to....
Ah yes of course! The system is broken anyways so lets just not give a fuck about it being further abused. Just do as you please. Sound argument.
https://www.google.com/patents/US20170221242?dq=facebook+use...
I hope this application doesn't go anywhere, as there would seem to be a lot of prior art. For example, the Cocoa API in macOS implements the method of Claim 1 pretty much to the letter:
https://developer.apple.com/documentation/appkit/nsview/1483...
This API was introduced in OS X 10.3, so that would be 14 years ago.
"Although many embodiments are described herein in the context of React, embodiments are not limited to React or to rendering only updated views as determined by React libraries."
It isn't just React. The PATENTS file is in most of their repos.
It seems like it will basically allow Facebook to infringe on patents from many companies once their software has crept into the dependencies of critical parts of the open source ecosystem. (I'm not sure if it would be accurate to call React Free software.)
Basically, the grant guarantees that you can't be sued if you don't sue first. No grant means that you can be used in any case.
Not just that, but if Facebook patents covered any similar framework (eg Vue.js) they could still sue you if you use that other framework.
I have head a theory that the BSD licence has an implicit patent grant. If FB sued you for using a plain BSD licence, you could argue the BSD covers it, if the courts agreed, you'd be fine.
One objection to the BSD+Patents licence is that it sorta removed the ambiguity, and explicilty implies the BSD has no patent aspects.
Even the experts admit that it's untested, and every law student knows that anything up to an actual test in an actual court is little better than a guess. Also, beware of "experts" who aren't even talking about copyright law. For example, consider the three cases mentioned in the "US" section here.
http://en.swpat.org/wiki/Implicit_patent_licence
The Hewlett Packard quote is clearly about products, which I know for sure are not legally the same as licenses. The Bottom Line quote's mention of purchases casts a similar shadow. Only the De Forest quote passes even a rudimentary sniff test. The case for this implicit license is weak indeed.
But fine, let's say there is such an implicit license. I have good news for you: it would apply to the Facebook code as well. The same principle used to argue for the existence of an implicit patent-license grant under plain BSD - i.e. that trying to bring a patent action would interfere with the still-operative copyright permission given in the LICENSE file - would still apply. Nothing in the PATENTS file would change that.
Belt and suspenders still beats belt alone, no matter how strong or weak the "implicit license" belt might be.
IANAL. You are safe only if you use any React related patents. They are free to sue for infringement of any other patents they hold.
Not just React - you also lose status on Caffe2, React Native and ReasonML.
I can't believe I'm defending Facebook though. A company who's data-mining practices completely creep me out. I definitely try to reduce the reach of their tentacles into my life but in this case I see nothing to take issue with.
Im really not sure how it can be worded to let legitimate lawsuits through. But that is the problem. Tomorrow if you build a new AI algorithm on caffe2, FB can pretty much use the whole code and you would be bound by the patent clauses.
I know many stories like this; Facebook M&A meets with the founders of a promising company under the guise of a "we're about to acquire you" only to have Facebook copy their companies and then follow up with Facebook's lawyers knocking on said startups' doors to shut them down.
As such, I will not touch Facebook with a 10 foot pole, and I strongly recommend, from personal experience, that you do the same with your company.
Since I started looking into the M&A world I've learned you just can't take stuff like this too personally.
If we take a look at Apache 2.0's patent grant:
> ... If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
It seems to be more fair to me. It doesn't give any special right to Facebook or any other entity. I.e. Apache 2.0 revokes the patent grant if anybody sues for patent infringement arising out of the work. Facebook's license the patent grant if anybody sues Facebook for anything, or other parties for patent infringement arising out of the work.
1. Anything about react is patentable.
2. Licensing of unspecified patents is a thing.
3. Licensing of software without disclosing related patents held by the author does not invalidate those patents on the basis of bad faith acting alone.
In what obscene legal reality does adding a patent grant that can be revoked in certain circumstances puts the licensee in a worse position than a license that does not mention patents at all ?
if you called it a patent 'clause' - rather than a grant - then does it make more sense? More clauses == more legal conditions.
The fact is that patents are obsurd in software. It should be treated like in the fashion industry - notice how clothing design is _not_ patentable, and the fashion industry has not an iota of being un-innovative or impeded! In fact, the very reason of being able to make any design copy in fashion leads to the large proliferation of innovations, as each designer tries to one-up another.
I agree that software patents are evil but then so are many other parts of the modern legal system, but even with them it feels that what facebook (and other companies) are doing shouldn't have any legal standing - see my comment down the original thread.
and i'd argue that the license that facebook is using _is_ indeed a new license! It's BSD plus something added to it!
Unless the end user has the choice to not take the patent clause ("grant") as part of their license. IANAL, so i dont know if it is possible to cherry pick like this.
Whenever something about software patents in general comes up, the majority of commenters seem to condemn them - at a minimum in their offensive usage. And a vast majority of commenters seem to be opposed to them at least to some degree.
So if as a general position you do not support the offensive use of software patents, why does the react license matter _at all_ to you? The only time it would matter would be if you would sue facebook for violating your patents. Am I not correctly understanding the license? Does it apply any other time?
The trouble is when you go to implement some of this stuff at work and get pushback from your team or higher-ups about the licenses for the software.
how is this different from pushback on (any) other issue?
Empirically, almost no large software companies have ever used patents offensively. They have repeatedly spoken out against the very idea of patentability for software (and "business methods").
> Notwithstanding the foregoing, if Facebook or any of its subsidiaries or corporate affiliates files a lawsuit alleging patent infringement against you in the first instance, and you respond by filing a patent infringement counterclaim in that lawsuit against that party that is unrelated to the Software, the license granted hereunder will not terminate under section (i) of this paragraph due to such counterclaim. [0]
As I read it, it only applies if you are the original instigator, not if they are.
[0]: https://github.com/facebook/react/blob/af312ce006ebe76307662...
The extremely clear and explicit purpose of the patent grant is to disallow "first strike" use, so this could only happen as a countersuit. How is that worse than the mountains of open-source code released with no patent grant at all?
Hope that makes it clear.
Edit: I've been drinking.
Except that's not what happens. What would really happen is that the patent grant would be revoked, but the license to the software (a matter of copyright) would remain in force. So they could sue you for patent infringement, just as they could always have done under most other licenses, but not copyright infringement. Under most other licenses they could even have sued you first, but they gave up that right. In fact, that's the only effect of the much-maligned patent grant. It's a pure giveaway compared to what the situation would be without it.
Let's change this to Facebook will sue you for patent infringement. This was never theoretical and it's rational for Facebook, if you read the post.
Nope, that wouldn't trigger the patent revocation.
this is the mutually-assured destruction analogy. If you can't get rid of them altogether you don't want someone being immune to them.
Is the community changing towards a demographic intent on striking it rich, instead of the previous morals of openness? There are also more condemnation of, for example, the GPL now than there have been in the past.
So, for a while, everyone in upper management will continue with such policies as Facebook's, since they came up at a time where patents where anathema. We'll see if this changes when today's entry-level programmers climb the ranks–or if their views change over time, or if the latter selects for people of certain opinions.
Facebook made their own license for a reason. Compared to Apache, the Facebook license gives Facebook greater power in the user-developer relationship. They only give users use of React patents, but in return they demand protection against all patents from their users.
I'm not a huge fan of the patent system, but I'm even less a fan of hoisting Facebook into a position of even greater power over smaller competitors.
tl;dr: The clause isn't fair. It grants uneven protection. Their refusal to use a similar, existing, popular license that does grant equal protection is concerning.
I feel it's a little like this: https://www.xkcd.com/463/. Yes, the new license is providing explicit guarantees that do not exist in the MIT license. But... I'm not sure I like the thinking behind it when other licenses already address this in a fair way.
The MIT license says plainly that you have the right to use the software without restriction. To me, a layman, it would seem contradictory and unfair if the author later claimed that they held previously unmentioned patents that restricted your use of the software.
Google and Microsoft are just as big, yet they can manage open source perfectly fine without this ridiculous licence.
It's easy to "manage open source perfectly fine" if you just open-source less of your code, or release it without any patent grant at all. I'm not sure how much credit should be given for those non-efforts, though.
What about Google and Microsoft's FOSS contributions do you consider "non-efforts"?
It's not the FOSS contributions that are non-efforts. It's the things that were never released at all. What percentage of engineers at Microsoft work on code that has been or ever will be open source? How is releasing 10% of your code with no patent grant better than releasing 20% of your code with a conditional one?
Also, "no explicit patent grant has been sufficient" is no excuse for bashing a grant that has exactly that as its worst case. Any non-zero protection is still greater than zero. By way of analogy, would you yell at people on your team who you felt weren't working hard enough, then give a big pat on the back to one who played video games the whole time? Well, maybe you would, but an objective observer might think it seemed unfair. They might even wonder about what other motivations might be involved.
* Release lots of software with a conditional patent grant: awful.
* Release lots of software with no grant (e.g. BSD): OK.
* Release very little software, and that under the no-grant license (e.g. MS): you rock.
Sorry, but that's completely f-ing backward. It's literally impossible to get to there from open-source principles, so what what principles are people starting from?
It's true that, practically, most companies won't ever have to worry about Facebook infringing their patents, but I think it's garbage on principle to reserve first-strike litigation while making it impossible for someone else to do the same and use software you've made available under a supposedly permissive license.
That phrase alone should swing the "legal risk" argument the other way that how it's being portrayed here.
There are plenty of reasons that someone might choose not to open source code (e.g. they like working on only internal infrastructure or don't want to bother with external maintenance), but I don't think the patent grant has anything to do with why a developer at {Google, Facebook, Microsoft} would choose to open source (or not) a library.
The whole process is documented here (https://opensource.google.com/docs/releasing/approval/) but here's the tl;dr:
1. Googler tells their director that they want to open source some code; the director approves it.
2. Googler tells the Open Source + Patents Office that they're releasing code. The OSPO says to use Apache as the license unless you have a good reason not to, and does a sanity check to ensure that the license information is in all the right places in the repo.
3. Googler posts the repo to GitHub.
Googlers don't usually even think about licenses. The OSPO says to use Apache, so that's what we use.
You are right in a sense, but Google/MS also take more risk to do so.
Google did also try something not quite like this, but in the same vein.
The initial webm license terminated both patents and copyright if you sued over infringement. (Apache, et al just terminate patent licenses. You could still use the software if it had no patents).
The practical upshot you couldn't use that software if you sued over infringement.
This was done, of course, because of the state of the video codec world.
Fortunately/unfortunately (depending on who you ask) despite being okay with it prior to release (IE we asked, ran it by the a lot of folks, etc), certain partners later decided they weren't okay with it because it wasn't GPLv2 (but was GPLv3) compatible.
So we changed it.
The point of all this is that: License innovation by itself is not a bad thing. Needs change of communities change over time, including open source. IMHO, innovation in this space needs to be done for a good reason, and needs to be done collaboratively, if you want any chance at success.
The engineering manager responsible said Yahoo would only use patents as a defensive measure, to defend themselves against patent threats from other companies. Same promises, same logic. Two years later Yahoo launched their software patent action against Facebook.
Software patents can only be used offensively. Because their defensive capability is limited to the threat of using them offensively. If there is no substance to the threat they are useless. So the value of software patents rests solely on their offensive capability.
Here's a question though. Let's say you're a startup investor and you have a choice to acquire one startup and one startup uses react and one uses vue.js both have stable apps and both have the same revenue which one would you choose.
IANAL :) but was once acqui-hired by a patent troll.
Well, not really. This exists:
https://en.wikipedia.org/wiki/Open_Invention_Network
http://www.openinventionnetwork.com/I'm picturing a scenario where the idea is patented, but the patent holder reserves no rights on it, de-weaponizing the patent.
Thus no one else can patent the idea and use it offensively nor is there a question of the original patent holder "turning evil" and using the patent as a weapon.
Given the mess that it was born from, it makes sense for developers to think about staying away from this if building anything of consequence.
It also is incompatible with free software.
However there are a lot of things that are worth developing that are neither of these things and react can be a great choice there on the technical merits.
What this means is they can infringe on your patent on say “tinder for dogs bark swipe mechanism” and they can infringe all day long knowing you would have to migrate off React Native and GraphQL before sueing them over it
These teams need robust protection from large organizations intent on acquiring or replicating their hard-earned results. Facebook's licenses undermine that protection for the shiny carrot of a flashy webpage. It's a bad deal.
Qualcomm reorganized itself several years ago so that their employees who interact with open source would be assigned to one corporate entity while all sensitive patents would be held by a separate corporate entity.
Other large organizations muddle through with closer oversight of the open source teams by the legal team than either would like.
It is a difficult problem to solve.
And if they're feeling the pain, have any of them sued Facebook and won? If not: Is it because they're using React? If not: How does the patent grant make a difference then?
You can sue Facebook for infringing a patent with Oculus and they'll come after you for your use of React/GraphQL/etc.
Can someone clarify what the author means here?
Which is nonsense because there's really nothing patentable in React.
---
The real concern is using React's license has conditions on other patents. But this is irrelevant for Preact, etc.
Just to make sure I am getting it:
Does this mean if you never used React, but use Preact or Vue that Facebook can still countersue you in the same way if you used React?
The majority view seems to be that there are none.
But Facebook has a very large patent portfolio, so if they wanted to sue/counter-sue you, they could probably find something that was close enough to lock you up in litigation for a long time.
...if Facebook has a patent on the virtual dom. In point of fact, they appear not to have any patent on anything underlying React, so none of this matters one bit. The time you've spent reading this comment is already more time than this non-issue deserves.
https://en.wikipedia.org/wiki/Oracle_America,_Inc._v._Google....
An API is already not patentable, and while the case included some patent claims, Google successfully argued they were not violating them.
There's actually a big difference between the patents grant of a license like Apache 2.0 and FB's license and I quote (from Apache 2.0):
> "If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed"
In other words the patents grant and its revocation is made explicitly in the context of "The Work" being licensed. So you can still sue a company like Facebook for unrelated projects and still be protected by the license.
By contrast Facebook's PATENTS license says that:
> "The license granted here under will terminate, automatically and without notice, if you (or any of your subsidiaries, corporate affiliates or agents) initiate directly or indirectly, or take a direct financial interest in, any Patent Assertion: (i) against Facebook or any of its subsidiaries or corporate affiliates ..."
Let me spell this out for you:
1. if Facebook infringes your IP, but you happen to use React, then you can't sue them without also risk infringing on their React-related IP and be counter-sued for it
2. their PATENTS creates a unidirectional relationship; when Facebook accepts your contributions, they are protected because MIT / BSD are said to have an "implicit patents grant" (which supposedly works in the US) due to the estoppel principle
Btw, Microsoft is taking steps to do what Facebook is doing as well. See for example how they are switching from Apache 2.0 to MIT and the disingenuous way they are communicating the change:
https://github.com/Microsoft/visualfsharp/issues/3440
But folks, this is not how Open Source or Free Software is supposed to work. When you release something as Open Source, you need to allow others to use your work as they wish (Freedom 0, or in OSI parlance, no discrimination against fields of endeavor).
Patent-encumbered software is NOT Open Source or Free Software.
Apache asked Facebook to license React under plain BSD, and they declined.
The main reason that I don't like the patent grant isn't because of React specifically, it's because Facebook revokes ANY patents if you sue them for patent infringement, even ones unconcerned with the technology you're suing them for. This is why I prefer OSS licenses with explicit patent grants better, because they're worded in such a way that the only patent grants you lose are the ones that concern the technology under license (see Apache 2.0).
1. Somewhere in FB's patent portfolio is a patent that is broad and vague enough to cover some part of React, so the patent grant/revoke clause has meaning and value. Changing the license would mean that they were giving up something that they value, and they don't want to do that. That might not be true for RocksDB, in which changing the license is relatively low cost.
2. React is more widely used and more easy to detect (public facing websites) so the patent clause offers protection against a wider range of potential threats. Lots of sites use React, or react-like libraries.
Since the purpose of the patent clause is as a protection againt offensive patent suits, they seem to think (probably with good reason) that React is a worthwhile shield that they don't want to give up. For RocksDB they feel that balance is different.
So one can either ignore the PATENTS file altogether or to formally fork the repo while omitting this file and it would be as if that file never existed.
Facebooks' (et al.) claim that these two files together constitute the governing license should be challenged as fraudulent - if they want to relicense react under a new license that contains terms regarding patents they can do so but the last revision before that would still be BSD licensed and the community can fork it. </still not a lawyer>
If you have such a monopoly, only legal protection would protect you.
What if Facebook starts a foundation where every member makes the same kind of agreement. "Sue one of us over patents, we'll all withdraw our patent grants from you".
That might end the patent craziness.
This hockey stick (https://en.wikipedia.org/wiki/Patent#/media/File:US_patents_...) shows the problem with patents clearly: what worked 200 years ago can't work the same today. The world is moving much faster than ever, yet patents are still granted for very long times. At this rate, how can you expect to NOT infringe on a patent?
Everybody's paying huge sums to lawyers to play what has become a null-sum game in the end. I think Facebook illustrates this: "sue me for infringement, and I'll do my best to show you're infringing too". Null-sum game.
If you're not ok with Facebook's BSD+Patents, then you shouldn't be ok with BSD alone either.
There are licenses with a decent papent grant (notably, Apache) but BSD and MIT aren't among them.
If you're all up in arms about Facebook's OSS licensing and at the same time use OSS that is licensed without a patent grant at all then you're a hypocrite.
Is this the only way to stop a patent troll? Or does FB want others to think harder before suing?
First, Facebook grants you a patent license only in conjunction with the software. You are not granted a license to use a patent that React requires in some completely different piece of software. The only thing this patent grant prevents Facebook from doing defensively is countersuing the users of software that Facebook gave them for using the software that Facebook gave them. Unless that is Facebook's idea of defense, the patent grant (without the retaliation clause) does not impair the defensive capabilities of Facebook's patent portfolio in any way.
Second, the patent grant terminates if you (first) assert any patent claims against Facebook whatsoever. So in exchange for a very narrow grant of a handful of patents, you in effect agree not to assert any patent claims against Facebook for any reason, even if they're totally unrelated to the software that Facebook's patent grant came with.
IMO this sort of asymmetric grant of rights is a very bad development for open source. It's also quite disconcerting that Facebook (and it's surroundings, I realize this guy is no longer employed there) never acknowledges this even though they're surely aware of this. If Facebook were content with merely not increasing their exposure to patent problems through open source the Apache style patent grant would have sufficed. Instead they have decided to militarize their open source projects in the service of decreasing their patent exposure in completely unrelated areas.
It's my "not a lawyer but spent way too much time in legal negotiations" understanding that if you sue FB for patent infringement then you lose license to the patents you get in the BSD+PATENTS, not the software. This would prevent you from saying "well, I've got a license to those patents because I've got a license to use React" (including a possibly implicit one under standard BSD/OSL). This agreements says that at that point, you can no longer assume you have a license to whatever patents could be construed to coverer React, etc., which could be all sorts of wonky over-arching crap from the 90's that FB bought.
The reason you is your whole org and patents is everything is because it would probably be really damn hard and expensive and risky to try to slice it finer.
Don't take this as an endorsement of the license. I'm still not sure what I make of it. FB has done a poor job of communicating about their motivations and indented mechanism, leading many to suspect treachery, and that's not an unreasonable position, but from I can kinda start to see where they may be coming from.
That's correct.
The license for React says that Facebook has given me permission to use it. It doesn't seem that they can then sue me over patents related to the code, because they've just explicitly said I can use it.
If I sue Facebook over patents, then the patent grant no longer applies. But the BSD License does.
Past performance is not an indicator of future outcomes.
Isn't it that one is not a lawyer until proven otherwise?
Hire less by automating. Fire less by retraining staff.
This is the excuse. Facebook wants to dominate the small companies who might threaten their business model with patents on future technologies.
The fact is that every big company named by that post undoubtedly has an expensive cross licensing agreement.
The other fact is that the original react license (apache 2) defended them perfectly well, but they went out of their way to change it and further out of their way to explicitly keep it.
That's not FUD. It's simple business sense to avoid complications.
Sorry, that's simply not true.