A EULA in FOSS clothing?
dtrace.org
dtrace.org
to the more recent entry, which is that open-source is facing an existential crisis: "we need your legal voices before these creatures destroy the village!"
I don't see how Confluent can respond directly to Bryan's 3 questions, though. They have the bigger social network, so i expect them to ignore him and just talk to their cool-aiders. It is a risk to ignore Bryan, though, as he's massively influential.
Greybeard says, people using $LICENSE are filthy heathens. You should use $OTHER_LICENSE instead. Film at 11.
It's a ruse. If MongoDB or CockroachDB for example want to describe their project as open source they should also act accordingly.
They don't!
"The Confluent Community License is not approved by the OSI and likely would not be as it excludes the use case of creating a SaaS offering of the code. Because of this, we will not refer to the Confluent Community License or any code released under it as open source."
They could have instead said : Confluent Community license is not a FOSS licence, but tries to provide many of the rights afforded in FOSS licenses.
That would have cleared up the status in a jiffy, and people would have made their decision to use or not use. But the intention seems to be to have their cake, and eat it too.
FWIW, "Community" in the license name seems to indicate "not free software" and "not open source software". There's only one OSI or FSF approved license with that word in the name.
They write 'Strictly speaking it is “source-available.”' That description has its own Wikipedia page. https://en.wikipedia.org/wiki/Source-available_software points out that it doesn't always meet "the criteria to be called open-source".
Confluent was treated and used as open source and that changed.
Or is it a "wink, wink" to those who didn't know? In which case, don't the many other community-but-not-F/OSS licenses mean that Confluent is being consistent with what others do?
AS someone who hasn't used Confluent but knows about issues related to F/OSS licensing and the difficulties of getting sufficient funding for developing F/OSS software, the explanation was pretty much what I expected for a company switching to an open core model from one which was all open source.
So, why might it be a "wink, wink"? That's likely my stumbling block in understanding your g'parent comment.
That's the rub, it doesn't. An honest statement would be: "We give you the source code not to grant you any rights, but just so you can fix our bugs for free."
> Strictly speaking it is “source-available.” Many people use the phrase “open source” in a loose sense to mean that you can freely download, modify, and redistribute the code, and those things are all true of the code under the Confluent Community License. However, in the strictest sense “open source” means a license approved by the Open Source Initiative (“OSI”) which meets a particular set of criteria. The Confluent Community License is not approved by the OSI and likely would not be as it excludes the use case of creating a SaaS offering of the code. Because of this, we will not refer to the Confluent Community License or any code released under it as open source.
Your last paragraph seems self-contradictory, unless you possess some unique insights into Bryan’s supposed influence. I also think disparaging everyone disagreeing with you as “cool-aiders” is somewhat cheap, and orthographically ahistoric. But someone from confluence already replied in the comments here, so I guess the point is moot?
Would they have liked it any of the things that they used said "you're not allowed to put this on a server and make money off it"? I wager they wouldn't.
People are saying that Confluent have every right to be doing this. They certainly do, but it's not very reciprocal of them to do so. If we're going to be so worried about Confluent's income, we should also be worried about the income of all the forgotten software developers that Confluent has likely based their business on, and I don't think the answer is for everyone to start forbidding making money on servers unless they wrote all of their money-making server software themselves.
These new breeds of licenses with anti-AWS clauses trying to make sure that Amazon doesn't make too much money are also harming in their wake many other developers. Software development as a whole is going to be getting poorer if enough people want to forbid making money on a server.
I don't really have a problem with it- I think it's fair. I think the question of whether it should be allowed on Github is fair- can someone accidentally find themselves legally bound? But it's probably an edge case.
Edit: microsoft
The problem of this whole discussion is that they try to confuse as much as they can by using terminology that surely sounds like they're doing "Open Source".
Read this: https://www.confluent.io/blog/license-changes-confluent-plat... Yeah, they don't write "The Confluent Community License is an Open Source License", but they use the term a whole lot and they also don't clearly write the accurate thing: "We're no longer using an Open Source license."
I think this whole thing would be much less of a controversy if some companies just said clearly: "We tried the Open Source way, it didn't work for us, now we do something different." But they don't want to be that company, instead they use all kinds of confusing terminology to obscure that fact and try to be the "We no longer use open source, but we surely want you to believe that we still do"-company.
Dunno, they are very clear about this in the FAQ (https://www.confluent.io/confluent-community-license-faq):
"Is Confluent Community License open source? -- Strictly speaking it is “source-available.” Many people use the phrase “open source” in a loose sense to mean that you can freely download, modify, and redistribute the code, and those things are all true of the code under the Confluent Community License. However, in the strictest sense “open source” means a license approved by the Open Source Initiative (“OSI”) which meets a particular set of criteria. The Confluent Community License is not approved by the OSI and likely would not be as it excludes the use case of creating a SaaS offering of the code. Because of this, we will not refer to the Confluent Community License or any code released under it as open source."
I totally see how people have different opions on whether that move is good or bad for the community and/or Confluent themselves, but I don't see where they are being confusing intentionally; IMO it's the opposite, the announcement is very clear and open what it is and what it isn't. Compare that to "Commons Clause", which indeed is a super-confusing term.
Same for the whole "many people" portion, which could instead have been more honestly written as "Many people misuse the term "Open Source". We won't do that, but we really wish we could."
From their own FAQ:
> Is Confluent Community License open source?
Strictly speaking it is “source-available.” ..
So if Bryan's analysis holds up and indeed, you don't own your copy and instead you merely were given the right to use and modify it, as long as you abide by rules X, Y and Z, then.. well, isn't that okay too? Isn't that better than nothing?Is there some sort of hidden rule somewhere that if you sell (or give away) the right to read and modify your proprietary software, that then you're suddenly evil?
I think I must be missing something, but what's the core argument here? This sort of thing makes the rounds on HN frequently, but I get the feeling that all but the most avid FSF-supporters are okay with 100% closed, proprietary, SaaS, etc software existing, and also okay with 100% OSI-approved open source. But somehow people get super angry about anything that falls in the middle. Why is that? Why is proprietary software nothing to worry about, but proprietary software with a "here's the source, have fun" notice tacked onto it totally evil?
To be honest, I don't always buy the argument about muddying the definition of "open source". Yes, there have been companies that called their thing open source even though it wasn't, by the OSI definition, and that's a shitty move. But my impression is that Confluent is not one of those companies.
I don't know your jurisdiction, but in the US, this isn't just a matter of copyright law, and copyright law itself has developed to support rules about use in license terms.
Many old open source licenses came from legal activists who opposed the application of contract law to public license terms and conditions or restrictions on use under license, for whatever reason. Overall, US law hasn't gone their way.
When you take an open source project and re-license it under a proprietary license (without changing the name, the repository, etc), a lot of scrubbing will be required to erase all representations of the project as being open source.
For example here it took one page view and about 5 seconds to find an example: the ksql repo [0] still has the open-source tag.
Knowing the FOSS community a bit, I'd personally imagine every GitHub repo flooding with subtly pedantic but well-meaning issues and pull requests titled "fix licensing".
Thanks again for your thoughts by the way.
The source code for Windows is also "available" ... "to qualified customers, enterprises, governments, and partners..." [0]
IIRC, Microsoft shares limited slivers of Windows source under specific programs, which include nondisclosure and other terms. Those programs do not permit publication.
When the folks I talk to say "source-available", they tend to mean "source publicly available". I don't think usage is clear on whether that publicly available source must come with a public license for re-publication and distribution. When code is "source-available" primarily for audit purposes, it often doesn't. Otherwise, it often does.
In practice, there is, at least among some vocal activists.
It's not a short read, but I've brought up this very point, and examined it, here:
1) They are re-licensing a formerly open source project, turning it into a closed source project. I am not familiar with their community, but there is a good chance that they have attracted users and possibly contributors based on the fact that they the software was open source. While these folks can continue to use the old version, such a betrayal of the community cannot be expected to be taken lightly.
2) The product relies on and is built on top of open source software (Kafka). As it is a part of the Kafka ecosystem, it can bee seen as a betrayal to the entire ecosystem to change course like this.
So it is certainly within their legal rights to close their source like this, and it is within the communities rights, both legal and moral, to decry the change.
Vernor v. Autodesk
Why didn't 17 USC 117 save the defendant?
What are "notable use restrictions"?
Artifex v. Hancom
Did terms end up a license or a contract?
Why?
I thought the FAQ said you wouldn't refer to it as such:
> Because of this, we will not refer to the Confluent Community License or any code released under it as open source.
IMO it’s a deliberately deceptive technique to try to confuse the market and dilute open source.
I think you mean "dilute Open Source" with capitals :P
More seriously: most terms dilute over time, and it takes a lot of effort to prevent that. I wouldn't assume every instance is malicious
Source available. Your license is not open source as understood by OSI or free software as understood by FSF.
On a personal opinion (I don't represent my employer), the new license affects both behemoths like AWS and smaller providers like Aiven alike. It may be a bargaining chip for the business, a trojan horse or it may backfire; only time will tell. I think many HNers know first-hand how hard it is to balance business and open source. It is a sign of health that the community is concerned and the best way to ensure an open platform going forward imo.
The summary is that we're committed to open source software and this change won't affect our users. We'll follow-up with a more details about our plans in early January.
Not a copyright lawyer, but honest question: what would it mean to “own” a digital copy? How would you define that ownership? Is it attached to specific devices? Should it make exception for multiple temporary copies? What tangible rights or advantages would that give the owner above and beyond the rights that copyrights currently provide to someone who acquires a legal copy?
I’m asking because it makes some sense to me that digital assets are handled differently than physical copies, because digital copies don’t transfer the same way. With digital assets, you don’t automatically relinquish a copy when you give yours to someone else. It can be incredibly hard to know exactly where your digital copies are physically located. It can be easy to have two or three or four copies sitting around and not know it. Perhaps one consumer advantage that licensing has over some notion of ownership is that you can legally have multiple copies, even make multiple copies, without violating copyright law.
If you want to prevent Amazon to use your software for SaaS, just license it with Affero GPL, it was invented for this usecase (as far as I know)
edit: okay I was wrong, see replies.
I stand corrected then
> BY INSTALLING, DOWNLOADING, ACCESSING, USING OR DISTRIBUTING ANY OF THE SOFTWARE, YOU AGREE TO THE TERMS AND CONDITIONS OF THIS AGREEMENT. IF YOU DO NOT AGREE TO SUCH TERMS AND CONDITIONS, YOU MUST NOT USE THE SOFTWARE. IF YOU ARE RECEIVING THE SOFTWARE ON BEHALF OF A LEGAL ENTITY, YOU REPRESENT AND WARRANT THAT YOU HAVE THE ACTUAL AUTHORITY TO AGREE TO THE TERMS AND CONDITIONS OF THIS AGREEMENT ON BEHALF OF SUCH ENTITY. “Licensee” means you, an individual, or the entity on whose behalf you are receiving the Software.
"... you agree to the terms and conditions of this agreement" seems like a dead giveaway for an EULA -- specifically, an attempt to bind the licensee by contract law in addition to copyright law.
I'm sure that's legally valid. Perhaps it is in the USA.
For example, that's why a railway operator (a private company) can fine you when you cannot present a valid ticket. When you get on the train, this action creates a transportation contract between you and the railway operator.
There is also some additional fun extras in contract law, like the concept of fair terms. This very old idea is that a contract should be a balanced deal. Terms that unfairly give one party undue benefits can then be challenged as invalid.
US and state laws have a concept of "unconscionability" for extreme cases, as well as prohibitions on penalties, as opposed to prior agreements to fix damages based on reasonable estimates, and so on. But "the deal wasn't fair" isn't any general defense against breach of contract claims. Courts generally avoid digging into the business or other advisability of contracts. They err on the side of giving parties the deals they agreed to.
Perhaps you were speaking from the perspective of a different jurisdiction?
Here's an illustrative example that may or may not accurately correspond to the current state of the law in any particular jurisdiction, but it show why this implied contract stuff doesn't work in practice.
A farmer might put up a big notice saying: "By camping overnight on this field you agree to pay me £100 per vehicle per night." Then a bunch of travellers might camp there. Can the farmer sue the travellers for the £100 per vehicle per night? My guess is that he could only sue them for damaging his grass, because, despite what the notice said, the travellers didn't "agree"; they camped illegally and without permission, like they usually do. Probably they smashed up the notice to show what they thought of it. Therefore the farmer can only sue them for trespassing, not for breach of contract. (He might also sue them for the cost of replacing the notice if they did smash it up!)
Likewise, you could put a notice on the front door and every window of your house saying that by breaking into the house burglars agree to pay you X pounds. Would it help you in any way? Of course it wouldn't. You'd get laughed out of court if you tried it.
"End User License Agreement" has no reliable, specific meaning in the industry. "EULA" for short gets thrown away even more willy-nilly, in all kinds of circumstances. I've seen it used for SaaS terms.
> EULAs are an attempt to get out of copyright law — where the copyright owner is quite limited in the rights afforded to them as to how the content is consumed — and into contract law, where there are many fewer such limits. And EULAs have accordingly historically restricted (or tried to restrict) all sorts of uses like benchmarking, reverse engineering, running with competitive products (or, say, being used by a competitor to make competitive products), and so on.
The most defining characteristic of a EULA is usually the "licensed but not sold" part.
I suspect adding this particular entry does more harm than good for you - it makes you look like you ignoring the meaningful argument here.
Personally, I'd remove it until you have some reasonable response.
> The most defining characteristic of a EULA is usually the "licensed but not sold" part.
Public licenses for software, say MIT or BSD, also arguably license, rather than sell. But they still include disclaimers of warranties, like merchantability and fitness for particular purpose, implied by the Uniform Commercial Code, which governs contracts. Huh?
At least under the US law I've seen, from Jacobsen to Hancom, there's no hard, meaningful legal distinction between contract and license, as some activists theorized early on. Even when those activists drafted licenses, like the GPLs, that explicitly claimed to be licenses and not contracts, they still included contract-like disclaimers and limits on liability.
Realistically, license and contract rules coexist and overlap. How do we interpret license terms? By rules of contract construction. What claims do plaintiffs make for violations? Copyright infringement and breach of contract. What makes a license irrevocable without consideration? Promissory estoppel, a contract doctrine.
This is factually untrue. Many EULAs grant additional rights, such as the right to make a backup copy of the software. In the case of Freeware (ah, halcyon days!) the EULA often allowed redistribution of copies.
Software licensing seems like a beast unto its own but what do you suppose would happen if you bought a car, a camera, a kettle, a pair of glasses, duplicated it 1:1 and tried to sell those copies? You'd fall foul of a thousand protected designs and trademarks. IP is everywhere.
It's not about what you own. It's about what rights are granted to you. Software is only strange in this regard because as developers we're [often painfully] explicit about what you can do. It isn't yet obfuscated behind decades of evolving law.
Please stop throwing "ownership" around as something you expect when you download something. It's silly to expect it.
The same works in reverse. You own your modifications. Nobody else owns (or has right to) them without your grant. But could well be compounded into a license, or more commonly a contributor agreement... But it has to be explicit.
Edit: After getting a couple of downs, I assumed my pre-coffee acidity may have burned through, so edited it to be softer... but I've had another since. If you've got a point to make, please leave a comment.
To reiterate: I have no earthly idea nor opinion if Confluence is the confluence of everything that’s wrong with earth and beyond. I just think the argument would benefit from a sharp pencil more than a pitchfork, for now.
A lack of clarity about what sort of transaction or license terms give rise to ownership of a copy of software is not justification for entirely rejecting the notion of ownership of a copy. The existence of that ownership status is rigidly established by statute, as are some of the consequences. It's only the prerequisites that are nebulous or at least very complicated, but that doesn't make ownership status any less important of a question. In legal disputes, the tricky questions are usually more important than the ones with obvious answers.
Sure, but that's not what is at issue here.
A more apt comparison would be if your glasses manufacturer says you're in violation of their EULA if you try to read anything ever written by Hemingway (because that goes against their business interests for whatever reason) and so your license to use their glasses becomes null and void.
Copyright, on the other hand, is much different -- and also implied by the name -- the right to copy (well, really, to distribute) the work.
The copyright to the software resides with Confluent, because of the copyright assignment clause that all contributors must sign. This is no different than Apache projects, which also require copyright assignment. For example, if you git clone Apache Hadoop, you do not acquire the copyright to Hadoop. Does Bryan really not understand how copyright assignment works?
To foundations concerned with software liberties, including the Apache Foundation, the Linux Foundation, the Free Software Foundation, the Electronic Frontier Foundation, the Open Source Initiative, and the Software Freedom Conservancy: the open source community needs your legal review on this!
Why do any of those foundations need to review the license or EULA that Confluent chooses? Confuent isn't claiming that their license is OSI compatible (in fact they explicitly state that it is not.)
If you don't like the license, don't use the software. Or use Amazon's software, which does require a EULA (see https://aws.amazon.com/agreement/ ).
That's not at all what he's asking. To quote from the article: "And to be clear: I’m not asking who owns the copyright (that part is clear, as it is for open source) — I’m asking who owns the copy of the work that I have modified?"
> Does Bryan really not understand how copyright assignment works?
Bryan's understanding of copyright seems to be quite correct. Your understanding of his point seems to be lacking.
Per US Code §117, which Cantrill links to, there is a concept of "the owner of a copy of a computer program" (direct quote from the law). So that can't be right.
I would assume they mean they have a legal cough limited cough monopoly on the distribution of said software through force of law.
That's an interesting analogy...
Is creating KSQL-as-a-service the equivalent of renting copies of the software? What would the "library exception" look like (which AIUI includes both private and public libraries)?
> If you want to prevent your users from re-selling their copy when they're done with it, you have to assert that you have retained ownership of their copy of the software.
Attempts to do that contradict the "first-sale" doctrine, but that doesn't stop folks from trying.