Oracle's Newest Audit Tactic: Focusing on Java
forbes.com
forbes.com
Want to use commercial software? Pay accordingly.
Not wanting to pay for it? Plenty of options available.
https://aws.amazon.com/corretto/
https://www.azul.com/downloads/zulu/
Oracle has also demonstrated in court that the Java API is their intellectual property, and that they are willing to go after people for reimplementing them. OpenJDK might be blessed, but I'd still be afraid of having anything to do with their intellectual property. That's also one of the primary reasons I'm not very excited about ZFS.
If you use OpenJDK you get an implicit patent grant to run OpenJDK (as it's licensed under the GPL).
If you use any other non-OpenJDK runtime you might still violate some of Oracle's patents, but you don't get any patent grant.
So if you're concerned about patents then using OpenJDK (instead of not using it) would actually be the safer way to go.
Furthermore, OpenJDK is licensed under the GPL. Even if Oracle stopped contributing to OpenJDK the GPL license would ensure that OpenJDK and all derivative works can still be freely distributed and are still subject to Oracle's original implicit patent grant.
I don't see how that's relevant? I wasn't aware of any aggression towards Google, until Oracle suddenly decided to aggress. The fact that Oracle hasn't been aggressive towards non-Oracle OpenJDK distributions in the past doesn't mean they won't be aggressive in the future.
I can probably agree that Oracle is relatively unlikely to start coming after people for patent infringement related to using OpenJDK or forks thereof, when OpenJDK is licensed under a license with a patent grant. My biggest concern is just that Oracle seems like a thoroughly evil and unpredictable company, and I wouldn't like to use technology they own and which uses patents they own. I wouldn't have imagined that Oracle would ever come after people for re-implementing their API; I can't imagine what Oracle will do in the future, but I won't build a business or institution around the assumption that they will do nothing. It's not like there aren't a plethora of other solutions for anything developed by Oracle, most of which are better than Oracle's alternatives.
I think that even if it made sense to assign virtue judgments to corporations, it would be a huge stretch to claim that Oracle is any more evil than other companies of similar size, like Google, Facebook, Microsoft or Apple, but as I work for Oracle, I'm obviously biased.
It’s hard to say that when we’re still clamouring for generics without type-erasure. It’s been over 14 years since the CLR had it and it’s definitely holding back the Java ecosystem in my opinion.
But in response to GP, type erasure sucks and makes a lot of things harder.
No, it is not. Most JVM languages (except Ceylon, I think) choose to erase generics, as that's the right thing to do if you want good polyglot interop.
On the other hand with my Java hat on, I look enviously to proper unsigned types, value types, explicit SIMD, and the language support for low level coding optimizations.
Still looking forward for Valhalla and Panama to arrive.
I wonder if C++ compilers "collapse" things like `vector<Foo⋆>` and `vector<Bar⋆>` (or even `vector<size_t>`) if they can figure out that all of their respective methods end up generating the same machine code... Maybe not?
(Stars because I can't seem to escape asterisks properly...)
[0] https://blogs.msdn.microsoft.com/oldnewthing/20050322-00/?p=...
Edited to add link.
I wonder what the standard says about it, what the linker can/could typically prove is "safe", and what performance/size changes are seen in practice.
The talk Diet Templates[1] has some suggestions for how to reduce template bloat.
[0] https://ai.google/research/pubs/pub36912
[1] https://accu.org/content/conf2011/Jonathan-Wakely-diet-templ...
Edited to add the second paragraph.
Anything oracle is tainted. And that's putting it lightly.
If you're using Java now, its probably a good idea to start looking at migration to something not Java. And until the API lawsuit is resolved, even things like Kotlin are probably not safe.
And well, if you choose Java now, you're just a fool :/ It is a footgun and the trigger is controlled by a pack of lawyers at Oracle.
BTW, Google has used OpenJDK extensively even throughout the court case, and still does, and has even forked it internally.
But isn't that their problem? The Oracle claim is that APIs themselves are copyrighted , and need permission from Oracle to even use the APIs?
It wouldn't matter of the software package was licensed. If Oracle's argument is accepted, then even invoking the APIs need a separate license outside the permission to copy JDK.
I really hope the judge finds in favor of Google. APIs should absolutely not be copyrightable.. But that's the main issue. And I still stand by my assessment that Java-anything is harmful for your health. And if your company has $$$, using Java is attracting sharks.
They are very aware that big companies wouldn't be nimble enough to switch to openjdk in time to avoid the license fees.
Additionally, they know that companies have 3rd party software that bundles what was once "free" oracle jdk. The end user gets to foot the bill for that rather than the 3rd party.
As to new JDKs, Oracle has open sourced (or discontinued) all previously commercial features so that now OpenJDK and Oracle JDK are the same software: https://blogs.oracle.com/java-platform-group/oracle-jdk-rele...
Infamous or not, the licensing situation is now clearer and better than ever before: Oracle offers the same software under a commercial license for those who wish to buy support, or under a free license to those who don't. The download pages for either option clearly identify the license, and point the user to the other option, if that's what they want:
* https://www.oracle.com/technetwork/java/javase/downloads/ind...
* https://www.oracle.com/technetwork/java/javase/downloads/jdk...
The "UnlockCommercialFeatures" doesn't catch everything either. For example, Oracle once added a clause about "embedded devices" needing a commercial license. With a very broad definition of embedded.
This is pretty clearly a cash grab.
Also, If the bits are truly the same as of version 11... what's the point of making people download a duplicate codebase where the only difference is one text license file?
No, field-of-use restrictions had applied under Sun, too, as licensing Java to mobile/embedded devices was Java's income source. Later, various commercial features were also a source of income. Oracle has now completely opened the JDK (and there are no field-of-use restrictions for the free license), opened all commercial features, and has switched to a support model.
Like all companies providing open source runtimes/languages, Oracle, too, must fund Java somehow (as I explained in another comment https://news.ycombinator.com/item?id=19069655). You're free to think that the funding model now is less preferable to you personally than the previous ones, but I don't think anyone can claim it is any more of a "cash grab" than the previous monetization strategies.
I think that if anyone claims that recent changes to Java's licensing and release models are not for the better, then they are either misled or misleading.
Not sure I understand the whole funding argument. Swift, golang, v8, typescript, etc, seem to be fine as open source.
In any case all this jockeying around with the license will certainly reduce the user base. From talking to my peers at other companies, we're all putting together our "get off of java" plans now.
I can tell you that the amount of software switching from other platforms to Java is significantly higher than that switching away. Those switching away are those with lesser requirements (e.g. in terms of performance, data size, management and tooling), and those switching to Java do that because they want the scalability and tooling. The full open-sourcing of the JDK and the new release cadence are big improvements that make Java even more attractive to those that were on the fence before, and the pipeline of major OpenJDK projects (Valhalla, Amber, Panama, Loom, Metropolis) is deeper than ever in Java's history.
A large majority of corporations aren't that allergic to software licenses, they have other issues on their top list.
Because with Java someone actually pays for its development.
Swift is reasonably independent from Apple these days. It’s stable starting version 5 and most new features are geared towards other applications than Cocoa.
So, those big companies would first have to switch to an affected version of the JDK anyway, so they could as well switch to OpenJDK.
Further, I always suspected some kind of dodgy dealing at some clients I’d visit since there’d be an army of their employees who’d be negative about Oracle but always a single big-wig that managed to be super passionate about Oracle.
Of course I never found evidence of anything dodgy - just a number of clients where this was a notable pattern.
It would be very interesting if some evidence came to light in an FCPA filing.
The only people who liked Oracle were VP and above. They were so short sighted they signed a deal with Oracle after they drastically cut support costs the first year. They were so shocked in year 2 when costs went north of 1 million. Making Oracle much much more expensive than the competitors who also bid. Everyone knew the competitors were less expensive in the long run and actually good products.
Not to mention the time they were audited and owed big time due to a webservice sending changes to our ERP system.
We were close to finalizing a sale for a huge company before some non-technical exec insisted on using Oracle for the backend. Then it became a huge sticking point. Our cto joked that he must be getting a kickback.
The reason they are a huge company is the way they are predatory towards their customers. Probably why sun didn't survive as well, its kind of sad that this is the way of the world.
I started the same thing with C++ but found that i spent too long getting libraries to work with each other without clashing (especially on windows)
I've also found java to be a terrible memory hog and require significant tuning to run stable without having long periods of garbage collection and non-responsiveness, i've not had that problem with go out of the box.
Thats the one thing about go that is great, goroutines and the (much much better) garbage collection.
Yeah, i'm a bit of a go fanboy :)
Lately I am on the hunt for a good closer-to-the metal language because I feel that even though the Erlang runtime (and thus Elixir's) is extremely stable and with unmatched concurrency and parallelism primitives, there still is a need for a native hyper-optimized code every now and then (crypto and compression come to mind).
I like Go a lot. The authors got a lot of things right and the language's tooling is exceptional. Goroutines are no match for the true preemptive scheduling that the BEAM (Erlang's VM) can provide though. But I don't intend to use Go where I would use Erlang/Elixir anyway. They serve different niches.
---
Have you evaluated other languages outside of Go and C++? For example Rust or OCaml? If you did evaluate anything else, what are your impressions?
I think rust is overly complex, and very quirky but.. It has some good ideas that i have taken and used in my own experimental languages i have developed like the error/ok branch structures.
I think Ocaml is even more quirky than rust, they are using symbols (|) to define select statements, i would to be honest rather have something more readable. Reminds me of perl a lot.
Both use "let" for defining variables that i'm not a fan of as a keyword.
IMO OCaml is a less sciency Haskell, and more focused on getting stuff done -- but I am still evaluating it and it definitely has warts in the tooling. Time will tell.
Rust... I looked at it but it struck me as a modern C++... too many ways to do one thing.
We need opinionated tech. Programming is not an art class practice session.
Syntax Libraries Runtime
I picked syntax briefly, because i think its the most important part of the language.
The libraries can be written, the runtime improved but if the syntax is bad its hard to change it later.
Downside is: the library ecosystem is less open. Some libraries are proprietary, which is not something I've encountered in other ecosystems. This seems to be changing though, now that C# itself is open source.
Microsoft has sued/legally threatened companies over Android and extracted many billions of dollars from them:
* https://www.forbes.com/sites/ewanspence/2015/11/01/microsoft...
* https://www.computerworld.com/article/2475440/android/micros...
How do you figure? The Csharp compiler is Apache licensed.
Just make sure you don't use the Oracle JDK and use Open JDK or similar
[1]: https://blogs.oracle.com/java-platform-group/oracle-jdk-rele...
As to GPLv2 and patents, see http://en.swpat.org/wiki/GPLv2_and_patents
But note that patents are unrelated to copyright, and licesors may only grant their own patents. Third-party licenses always apply (e.g. see how Microsoft was able to extract billions from Android vendors through patents).
Sure in the short-term they'll rinse companies for large amounts of money, but people tend to remember when that's been done to them, and aren't exactly keen to have it happen again.
Whilst I have no direct experience, a quick search indicates that IBM have similar practices. I wonder when/if that'll bleed across into Redhat.
Then again, there are plenty of other JVMs available since the 2000's, and many customers do pay for them.
Do you feel that the surprise audit approach to license compliance is a good one?
There are even international organizations that collaborate with national police on that regard, https://www.bsa.org/
To me it provokes an adversarial relationship between software vendors and their customers and is quite likely a factor in the rise of the use of Open Source software in enterprise.
If the propietary software industry is to continue to prosper, it seems likely that annoying their customers with this approach to licensing is not a good one.
Now you could argue that this will have a knock on effect on Open source as many devs are employed by software companies, but that won't necessarily stop it happening.
The demise of proprietary unix in favour of Linux is one striking example.
another is the rise of open source products like Docker and Kubernetes. They are being heavily deployed in organizations that might once have considered more proprietary software options instead.
To take one example Kubernetes, one of the most popular projects around at the moment is Apache 2 licensed which has been agreed with the FSF is an open source license. Other popular projects like Tensorflow also use this license
Likewise very popular projects like Visual Studio code, React Native and Angular make use of the MIT license which is also GPL compatible.
I see the opposite with languages and runtimes these days. If anything, I'd say there's a failure of trying to make money on the language/runtime itself instead of thinking or other parts of the company.
That's totally fine with me and the beauty of restrictionless freedoms, you can do what you want. I license lots of my work that way, keep other parts hidden, etc. It's a healthy model instead of this rampant litigious approach often coupled with an irrational fear of theft. To be truly open sans restrictions is to take the bad with the good and recognize that what you open is not specifically where you make your money. Happily the industry continues to move towards unencumbered software especially on the language/runtime front.
Personally I'm not a huge fan but if you are using copyright material then obey the law.
* https://blogs.oracle.com/java-platform-group/building-jdk-11...
But don't worry you shouldn't feel sympathy for enterprise companies as they are often just as bad as the vendors.
Not just Oracle but pretty much anything that is standalone software.
The tech personnel, yes. The guys who accept corporate sales pitches, no. They only hear "Oracle" and are thinking "big name, nobody gets fired for buying that".
Companies stick with Oracle and IBM for multi-decade stretches, maybe the move to cloud will be what it takes to dislodge them, but then again, in a world where Azure, AWS and GCP exist some people still choose Oracle and IBM, so there's no explaining it.
If I were a CIO I would announce that this year's bonuses will be funded from savings on Oracle licenses, then sit back and let nature take its course.
In the past OpenJDK was missing critical features so that companies often used the commercial closed-source Oracle JDK. At the same time even then Oracle JDK was somewhat of a trap when it comes to licensing, as it included features not covered by the free licence that might be accidentally used by developers.
With Java 11 there is finally feature parity: Oracle contributed missing features to OpenJDK. Features that couldn't be contributed (due to licensing issues) were removed from the commercial Oracle JDK. So starting with Java 11 those two versions of the JDK are pretty much equal.
With Java 11 there's no reason to use the commercial Oracle JDK. Most of the companies that used the Oracle JDK before are better served by using one of the open-source OpenJDK builds: Either Oracle's OpenJDK build (which is only going to provide support for 6 months after each release), or one of the third-party builds that most likely are also going to track LTS releases such as Azul's Zulu or AdoptOpenJDK.
Oracle is very upfront about those changes: When you try to download Java 11+ from Oracle's website there's a huge yellow box with a warning about the license changes. In addition, that box also links to the GPL-licensed OpenJDK version.
As a Java developer I'm very happy about that new approach: With the feature parity between OpenJDK and the commercial release it's finally possible to develop and run Java applications on a 100% open-source stack, which is something that was much harder to do with earlier OpenJDK releases.
Initially, not all code was available under a GPL license.
Separately at the same time, Apache led the Harmony project to produce an open source implementation of Java SE 5 & 6. This was successful.
As time passed, Sun (and maybe Oracle) open sourced more code into OpenJDK, leading to supporters switching from Harmony to OpenJDK. Additionally, Sun made the unfriendly move of licensing the TCK in a way that precluded any non-OpenJDk release from ever being able to claim Java compatibility. In response, Apache resigned from the Java board. And as of 2011, the Harmony project was stopped.
Because of the platform-independent goal of Java, there's a lot of ancillary "not-Java, but needed" libraries to build and run Java. These were not all open sourced by Sun / Oracle, but were reimplemented by RedHat under a project called IcedTea.
So, in summary, you can run OpenJDK/IcedTea and tell Oracle to pound sand.
The primary risk is that Oracle withdraws the things they do still control from the OpenJDK project, or stops working with the project to coordinate new releases. But they'd be shooting themselves in the foot if they did.
https://blogs.oracle.com/java-platform-group/building-jdk-11...
Many java-relate patent grant require passing the TCK.
In addition, every three years one feature release will be designated as the Long Term Supported (LTS) release. We will produce LTS releases for at least four years. This assurance will allow you to stay on a well-defined code stream, and give you time to migrate to the next, new, stable, LTS release when it becomes available.
[1] - https://adoptopenjdk.net
I have even seen a super super tool that simply allow user to go through a questionnaire, which a paper print out will more than likely enough and faster, to be implemented as an Oracle database, with the business logic embedded inside the database, and a super thin UI. User will need to know the correct schema name to use though, because they use schemas for versioning, and it's not like 1.0 and 1.1, it's latest_with_iso_compliace, test_only_production_for_customer_A and beta_for_production or similar.
I do - I doubt that there are many organisations licensing just the Oracle database these days - I suspect most of their sales are in the ERP/finance areas where there are relatively few competitors.
How many competitors are there for Hyperion FM/Planning?
Edit: Note that I'm definitely not defending Oracle, but the market for their products is quite complex and much wider than a relational database engine.
As for competitors to hfm/epm: there are a few (onestream, tagetik, whatever sap is peddling...). But it doesn’t matter, all this thing about auditing will go away when every Oracle customer is forced at gunpoint to move to cloud versions - where they can be squeezed for more money at the touch of a button. Hfm licenses, for example, are basically not sold anymore unless you get special blessing from an Oracle VP; it’s FCCS or nothing.
I did a lot of integration work with HFM for my previous employer - I was actually rather proud of the reporting solution we built on top of HFM, infinitely better than the reporting tools that Oracle provided. I sometimes wish that we'd productized that and sold it!
We look down on what's going on in the pharma industry, but the software world isn't all sunshine and lilies.
>That’s why I think Oracle is sort of hedging its bets with Java audits and not going in there as strongly. It’s too soon. Give it five years when you’re stuck in Oracle’s ecosystem and Oracle needs money. Then they’ll start auditing.
This is burying the lede...
If you're using JetBrains IDEA Ultimate, the official JetBrains plugin for Go works really well. It's the same piece their GoLand IDE uses.
It is not about Oracle not having competitive producta or services but about Oracle being stuck with their thinking in the 1991-2008 era.
* Under the old BCL license the Oracle JDK was a mix of free and commercial features. Using the commercial features required explicitly turning them on with the flag `-XX:+UnlockCommercialFeatures`. You could not use them accidentally. Current JDKs no longer contain any commercial features, as explained below.
* Starting with JDK 11, Oracle has completed open sourcing the JDK[1], which no longer contains any commercial features. Rather than a mixed free/commercial license, Oracle now offers the same software under two different licenses, the commercial OTN lincense, intended for those who wish to but a support subscription from Oracle, and a free and open-source license, for those who don't[2]. The commercial license download page[3] clearly states the different options:
Oracle Customers and ISVs targeting Oracle LTS releases: Oracle JDK is Oracle's supported Java SE version for customers and for developing, testing, prototyping or demonstrating your Java applications.
End users and developers looking for free JDK versions: Oracle OpenJDK offers the same features and performance as Oracle JDK under the GPL license (with the non-viral "Classpath Exception")
The page also links to the free option. The particular commercial JDK download page[4] also contains a big bright warning and links to the downlad page for the free license.
* That Oracle now only offers six months of free support (as oppsoed to before) is misleading. For at least the past seven years, Java had a major release every 3 or so years, and "update releases" (containing substantial new features, but no language or API changes) every six months, plus quarterly security and bug fixes[5]. The releases were also not supported for more than six months, and to be up to date on security, one was always required to upgrade to the semi-annual update releases. What changed recently, due to community demand, is how the features are distributed among the releases. There are no more major Java releases. The last one (ever) was JDK 9. Starting with JDK 10, the semi-annual releases are not major releases but "feature releases," that are allowed to contain API and language changes, but are small, so that instead of a major upgrade every three years, the upgrade process is more gradual (e.g. compare JDK 9, the last major release, with JDK 11, a feature release[6]). The feature releases are therefore somewhere between a major release and an update release but much closer to the latter. While major releases were supported for a number of years and the feature releases only for six months, the feature relases are by no stretch of the imagination major releases.
* Similarly sized runtimes/languages -- Apple's Swift/iOS, Google's Android and Microsoft's .NET -- are all part of ecosystems entirely or largely under the control of the companies owning the projects, and that generate billions of dollars annually, and so fund the development of the platform. Oracle has no control over the Java ecosystem, and so must fund the development of OpenJDK somehow. This is now done by offering long-term support for some of the feature releases, for companies that don't wish to upgrade to every feature release (in the past the funding came partly through the commercial features, which have now all been open sourced, and the annoying search toolbar that came with the JRE, which is gone now, too).
* Oracle employs hundreds of full-time developers who manage the OpenJDK project and contribute the lion's share of OpenJDK development[7]. While Oracle developers will continue to contribute most of the work, including security updates to current OpenJDK versions, they will not commit to backporting those contributions to old feature releases via OpenJDK's "JDK update" projects. Other companies have said they will do that work, so that there will likely be OpenJDK update releases for some feature releases, probably those that correspond to Oracle's LTS versions. Oracle encourages other members of the OpenJDK community to contribute even more.
[1] https://blogs.oracle.com/java-platform-group/oracle-jdk-rele...
[3] https://www.oracle.com/technetwork/java/javase/downloads/ind...
[4] https://www.oracle.com/technetwork/java/javase/downloads/jdk...
[5] https://java.com/en/download/faq/release_dates.xml
[6] https://openjdk.java.net/projects/jdk9/ vs. https://openjdk.java.net/projects/jdk/11/
[7] https://blogs.oracle.com/java-platform-group/building-jdk-11...
http://openjdk.java.net/legal/gplv2+ce.html
(The same JDK is also offered by Oracle under a commercial license for those who wish to buy a support subscription from Oracle, and other companies license the code to make their own commerical JDKs, e.g. Azul's Zing).
Ahhh. Your other responses were so positive and promoting of Oracle, I nearly accused you of working for them.
Turns out you really do.
It’s too soon. Give it five years when you’re stuck in Oracle’s ecosystem and Oracle needs money. Then they’ll start auditing. Right now, there’s so much buzz going on around Java, they don’t have to audit.
I thought that the main differences between OpenJDK and Oracle java was the nicer font rendering and some Swing-ish stuff, is there a good comparison as to why people even use the Oracle Java?