Otonomo, with nearly $55M in funding, is cloning our product
smartcar.com
smartcar.com
And that is why startup companies go through all the hoops of being "stealth" and having NDAs and what not. There was a German VC firm that was, as I recall, very upfront about this. Clone a successful US company before it got to the European market.
On the one hand it is great to have validation of the idea, on the other its a pain to have someone with more money in the bank able to spend it on marketing and spinning the narrative in their favor.
Since the ability to get a foreign company (in this case Israeli) to do anything is limited, your best bet is to out execute them. Also, love them or hate them, having patents helps in situations like these.
The reality is that if an idea is really good, the people who came up with it know it better than anyone and that gives them a tremendous advantage in terms of knowing what is important and what isn't. Companies have been known to talk about expensive and complicated features or options in order to get people trying to copy their success to waste time and money on something for which there is no actual demand. It is no doubt worth investing in understanding how one's enemies are getting their information and shutting that off if possible.
For all the ethically ambiguous things they do, I still remember fondly their creative ways of using AdTech.
Theft, sabotage, ad hominem attacks, even murder, could all be considered "competition" if your ethics and morals are on a different plane.
So saying there is nothing wrong with competition as a blanket dismissal is a bit myopic.
Their salaries, too, put [competitors] in the same state with a merchant who attempts to trade without a bounty in competition with those who trade with a considerable one. If he sells his goods at nearly the same price, he cannot have the same profit, and at least, if not bankruptcy and ruin, will infallibly be his lot. If he attempts to sell them much dearer, he is likely to have so few customers that his circumstances will not be much mended.
-- Adam Smith, Wealth of Nations, Book V, Chapter 1.
https://en.wikisource.org/wiki/The_Wealth_of_Nations/Book_V/...
https://techcrunch.com/2018/09/27/wimdu-rocket-internets-air...
If I was the OP, my reaction would be shock and horror too. But then I'd realize the old axiom of imitation is the best form of flattery.
You never know. When someone ripped off Parse we were able to deduce which version of our JS SDK was ripped off by which bugs weren’t fixed. We had a weird moral dilemma: we were upset at the copycat yet concerned that their users had security vulnerabilities unpatched.
[Edit: added quote to clarify to what I was responding]
The article discusses Microsoft's anti-piracy measures. And it brings back horrible memories. So I had this server, running Windows Server 2000. And there was a nearby lightning strike, which bricked the motherboard.
But hey, service contract. Except that the company had gone through reorganization. So they sent me a motherboard that was comparable and compatible with the box. But it had a different seller code, so my copy of Windows Server 2000 wouldn't install.
Microsoft couldn't/wouldn't fix that. So I had to return the replacement motherboard, wait for another replacement, and install it. But hey, it all worked out in the end.
https://en.wikipedia.org/wiki/Cadence_Design_Systems,_Inc._v...
To lose copyright, the author has to explicitly volunteer to sell the rights or give them away. A work has copyright protections the moment it is created.
https://otonomo.io/about-us (see bottom of page)
Which might be the best news Otonomo gets all day. In addition to outfunding them, now their competitor is going to focus their time and cycles not on the competition for this market space, but in expensive legal actions with a dubious chance of success.
If I were smartcar I would ignore Otonomo (or at least their shameless ripoffs of your public facing code bits) and double down on the business of beating them with your product.
Doesn’t hurt to have a court order in place. Chances are they’ll settle for a material fraction of the cash you know they have.
I have to disagree with you emphasizing this point. If someone/entity manages to get your idea or code, they may be able to sell the solution at a fraction of the cost since their R&D was lower than yours. When the entity is 10x+ your size, they can also afford to gather the resources that increase their odds of success (e.g. marketing specialists, engineers,etc) at a rate which you can't compete. By then, you may have spent 2-3 years creating a business that is destroyed by an external entity acting in bad faith.
These things happen quite often.
For example, Uber and Lyft. (Point being: survival is not just about the long run, but also the short run.)
If Otonomo have raised ~$55m, it means they have very powerful, very rich backers (Bessemer, NTT, SK, Aptiv). They might realistically have another $100m over the coming years instead, if they continue making progress.
We have a competitor who copies our features, but they don't know why we built the feature. The result is they end up copying the wrong stuff or tweaking the feature in a way that completely misses the point.
But, I agree with you in that creating a feature isn't an advantage in and of itself. Rather, it is the domain expertise that led to the creation of the feature that is the true advantage.
This example however seems to play in a different league, the extent of ripoff here is absolutely staggering.
If I were OP, I‘d immediately call Daimler‘s PR department. After the whole dieselgate shitshow, none of the German automakers are out for the slightest bit of negative PR...
https://www.globenewswire.com/news-release/2019/01/10/168588...
This will waste their time if its a harder problem with their backend / implementation.
Another fun thing you can do is using something that looks like a 3rd-party service/API, but is really just another domain controlled by your company. Make it something specific to your business, so they'll be tempted to use it.
IF they use it, the least you can do is terminate their access at an inconvenient time. This will frustrate their customers as they scramble to do their own implementation.
Final thing you can do is not doing incremental updates, but instead doing big rollouts with many features at once.
That way they'll always be weeks to months behind you.
Basically, when someone is following you, mine the path to the point that it's cheaper and more effective for them to find their own.
Edit: Bonus round is talking about some near-useless feature on your dev blog that would be hilariously expensive and complicated to build, without actually building it. Hope they waste time on it.
This reminds me of the old days when Adobe Illustrator and Macromedia Freehand. I learned both apps, as each release from one would leap frog the other in features. I actually learned from a roommate that was taking college courses, and I would do his homework assignments. Not do them for him, but on my own just to learn the software. Saved me from needing to take the course!
Apple wasn't the first company to make an MP3 player, but the generic term is basically 'iPod'.
Apple wasn't the first company to make a smartphones or touchscreens, but the generic term for a touchscreen smartphone is basically 'iPhone'.
Apple wasn't the first company to make a tablet, but the generic term is basically 'iPad'.
Apple didn't invent high resolution displays for personal devices, but the generic term is basically 'Retina display'.
We can go back in time, too. Apple didn't invent the mouse or a GUI, but lots of people pointed to the Macintosh as inventing them.
https://en.wikipedia.org/wiki/List_of_generic_and_genericize...
Some of the category names don't even match up - adhesive tape is definitely not what comes to mind for Durex for me.
Consider: thermos, escalator, linoleum, trampoline, zipper, scotch (as in tape), jeep, xerox, jacuzzi, dictaphone...
I think branding to generic really depends on linguistics of target market, brand writers and brand saturation in target market.
A brand name that is hard to pronounce is less likely to be used and how often do you think about the Slovakian pronunciation of your brand?
The US being a large linguistically similar market would be more susceptible to this.
Here in the UK people just have "Smartphones" and "tablets" (tho I do hear people calling generic tablets "iPad" sometimes).
Edit: How about Google? They copied Yahoo and AltaVista, and their search engine has become so ubiquitous with searching that it's a word in the dictionary now.
The USA, love it or hate it, is the most dominant marketing force on planet earth.
Are you from the US? Because here in .eu "iThing" is definitely not the generic term for pretty much anything.
“Apple Pay” being used as a generic for “phone-based contactless payment system”, “iPad” as generic for “tablet”, and “iPhone” as generic for “smartphone”.
I've never heard someone use Apple trademarks as generic terms. The generic term people use for a touchscreen smartphone is...a smartphone. Likewise, a generic term for a tablet is "tablet". I've never heard someone use "iPhone" to refer to all smartphones or "iPad" to refer to all tablets.
Though as a kid, I know my parents would say to "put away the Nintendo" when it was the PlayStation stuff that was all spread out on the floor.
How about the IBM PC? Plenty of home computers existed prior to the PC, but today 8086 code dominates at all levels of computing.
How about Google's search, or Google Maps? AltaVista and MapQuest came first.
You mention Nintendo and PlayStation, but Atari was before both of those!
How about Facebook instead of MySpace?
The point is that saying that the person who comes along and copies you will do it worse because they don't understand it is often wrong.
I think "pop" is a hold over from the older English fizzy pop
Beyond that, though, your other examples just seem weird, because I don't ever hear anyone use iPad or iPhone as a generic term. "I have an Android iPhone." "Hey, that's a cool Microsoft iPad." Nope. And the Mac was the first computer anyone outside of nerdspace ever heard of using a GUI and mouse, and I'm sure that's led to some pop culture confusion, but that doesn't strike me as comparable to the other examples anyway. "GUI" and "mouse" are generic terms.
It was generic enough to form part of the word "podcast", which has stuck around.
i've never heard anyone use iphone as a generic term. phone, mobile, cell, cellphone. these are the only terms i've heard.
and while i'm add it, mp3 player is what i've heard EVEN it is in reference to an ipod.
ipad? nah, generally i've heard tablet.
and finally, i've heard no one say retina, i have heard HD, HiDPI or 4k (even if it's not).
Or heck pitch it to the same investor too.
Investor: "Oh I wonder what other IP we can steal from them under the guise of due diligence"
You can definitely win a war with superior marketing, but it's not a sure thing if your product is inferior.
They are being abused, but if you can close that loophole (prevent non practicing entities from enforcing patents), then software patents are critical to protect innovation.
Patents need fixing from both ends - the enforcement end for non-practicing entities, as well as the assignment end, where patents are examined under harsher conditions.
It should be clear however that patent and patent giving has massive costs on the state and a great boon to lawyers.
And at the same time, its still not enough, as you still need to do counter-espionage at companies anyway.
The Chinese also do this. (As in, the government seems to encourage it outright.) The culture and language barrier do make for an effective moat. It usually takes significant effort and even some cultural change for a company to get its legs for international operation.
This phenomenon appears to be unique to situations where the accused party is Chinese. No other nationality/ethnicity seem to suffer the same treatment on HN and elsewhere on the Internet.
Actually, it gets applied to all Asians. I know this firsthand as an Asian. It used to be applied to the Japanese with just as much fervor, especially in the 80's. (I lived through this.) I should think it was applied to the Americans in the early days of the US. I suspect it was applied to Germans and Russians when they were consolidating and industrializing those nation states.
Here's where bigotry comes in, in the 2019 style: When white people do it, it's "appropriation." When Asian people do it, it's because they have no creativity and can only imitate. In truth, it's all cultural appropriation, and cultural appropriation is actually an engine of human progress and creativity.
The charge of copying gets levied as a protectionist tactic by those already of generally higher status. The charge of appropriation gets gets levied as an aggressive tactic by those who desire that status for themselves. Either way, it's a waste of time better spent learning, growing, and changing.
Appropriation is good. It's how progress is made!
My response was- 1) Copying an ISA is not copying architecture 2) JP was innovating in manufacturing, not ISAs, which is why they got 95% yield, not 65. 3) Yes - they weren't great systems software guys, and 4) Have you seen Nintendo's games? Clearly they can create and innovate and program.
The trope irritated me, but it seems to be a psychological defense move whenever an emerging contender challenges an incumbent (got to get the base features first == copying)
No, it is not. The world would be a much better place if we all started doing what is right. This isn't difficult: stealing and copying API design and API documentation is wrong.
Make a note of the company, people who work there, and VCs who invested. Computers are good at quickly finding information: one day you might want to do business with one of those people or VCs and digging up this information might change your mind.
https://slatestarcodex.com/2014/07/30/meditations-on-moloch/
That doesn't mean we ought to just give up and worship whatever worst thing capitalism produces. If you look at Ginsberg's long history of political activism as an example it's certainly not what he and those around him lived.
At a separate scale from that discussion we need to "play our side" of the game, and that will necessarily involve your personal interpretation of ethics. I believe it is a kind of laziness to dismiss that.
And I would happily live in a poorer society with better ethics any day (given some minimum threshold of live quality).
So inferior goods (using the economic term) can add low-cost options for consumers and are thus a social benefit.
While copying itself isn't bad, in practice those companies often releasing products that are unfit for sale or engage in deceptive advertising.
I hope most here can agree that taking a web page, doing command-C, command-V, changing a few words in a small amount and passing it off as your own work is wrong.
This is not even about cloning an API.
But I can spot you that anyhow, because there's a perfectly reasonable fallback position: This is illegal. It's a copyright infringement at the very least, and possibly other things as well. And being "illegal", the "what are you gonna do about it" actually has clear, well defined answers. Smartcar.com is doing them a favor by serving a cease & desist, as there is nothing preventing them from moving straight to legal action.
That you wish something was true doesn't make it so, unfortunately.
What is not OK is copying the documentation verbatim, that is copyrighted. However, that is, frankly, the least of the problems (and easiest to rectify) when someone is taking your product idea wholesale.
Copying text or pictures would be copyright infringement.
Copying APIs is fine, as far as I'm concerned.
The world is as better place if hardware and software is compatible with each other, and common interfaces enable that.
https://www.wired.co.uk/article/inside-the-clone-factory
https://www.forbes.com/sites/ryanmac/2014/07/31/samwer-broth...
Anyone know of a specific documented example of this? I'm not really doubting, just interested.
This is really a different case though.
The German VC is saying: "Food delivery is working in the US, they've validated the model + EU VC's will now get behind that, so 'do that like they are'.
They are more or less competing, not exactly cloning.
Copying API's is a whole other level.
Literally copying docs etc. is another level.
The thing is - the small company may have some power here. The bigger company does not want an ugly, permanent lawsuit hanging over them. With the screen-scraping and blatant copying, it's going to make it seem, at least popularly bad, and possibly add emotive impetus to a judge. The copier cannot say with a straight face that they were not copying to a judge.
Germany VC's will still very rationally imply what I wrote above.
If Rocket is behind this, well, they might have laid a bridge too far.
Does it though? There is no global patent authority. If the ripoff is not for the US market, only a patent for their market will help. Which might be impossible to get in the first place.
This situation looks very egregious though.
Only in the short term. In the longer term, it may no longer be worth the risk for any Company A to begin in the first place.
Love them, hate them, never underestimate them.
Whether you are creating, disrupting, stealing, copying or cheating... just be the best at it. There is reward for that.
Rocket internet, clone then sell to the U.S. company when they expand.
That's not the same as copying their manuals,code or other copyright though.
It's more akin to lyft to uber.
I searched for one of the unique tokens in the docs: https://www.google.com/search?q=0facda3319
That pulls up their SDK github repo: https://github.com/smartcar/node-sdk/blob/master/doc/readme....
Which is published with a standard MIT license: https://github.com/smartcar/node-sdk/blob/master/LICENSE.md
Which says (among other things): "Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software."
Which may have significantly complicated their copyright claim if Otonomo includes the MIT license and attribution to smartcar.. At the same time, I can't find Otonomo's docs anywhere.
Something to think about when setting up your GitHub license!
The API client is MIT licensed but that doesn't mean the API itself is MIT licensed. Smartcar obviously would not release their server code as it is proprietary so the question becomes whether it is unethical or illegal to copy the design of it without seeing the code. Most people would also say it is unethical to copy your competitor's docs down to the examples and randomly generated tokens.
Note that the docs in the blog post are not the same as the markdown document in the repo that appears to be MIT licensed.
Since they copied the docs verbatim, I suspect they will change the docs very soon. I'd be quite ashamed if I were Otonomo. Whether they have to pay financial penalties or admit guilt in court, we'll see.
Blizzard was able to shut down the private servers.
https://github.com/mangoszero/server
https://www.google.com/amp/s/arstechnica.com/gaming/2017/07/...
<standard not-a-lawyer disclaimer> Would it be okay if they changed the tokens and kept everything else? Who benefits from Otonomo changing the examples?
Assuming a REST API is a non-enforceable contract for the sake of interoperability, it doesn't make sense for any party agreeing to it to "own" the contract itself, even if they were involved in writing it.
https://en.wikipedia.org/wiki/Oracle_America,_Inc._v._Google....
What exactly is Smartcar's product? Is it just the API design?
If so, I personally think this is in the same boat as that case, and I don't really see having the same API as copying either.
The docs would be something different thou, but again, I don't know how the docs were licensed.
Moreover, the court ruling makes it seem that if the intent is interoperability, fair use may apply (only the court rules Google's intent was not interoperability, as their implementation was intentionally incompatible).
Although in this particular case, it appears they can claim copyright violation on the documentation.
[1]: Most notably, in order to be copyrightable, a work has to be "fixed in a tangible medium of expression" (https://www.law.cornell.edu/uscode/text/17/102), i.e. you need to have a specific text (or image) that you can say, this is the work (although then even derivatives are protected). This is true for APIs, but not for protocols (or REST "APIs"). Whether this distinction makes sense to programmers or not is irrelevant. The same distinction holds for programs vs. algorithms: programs are "fixed in a tangible medium", and are subject to copyright, but algorithms are not, and not subject to copyright (but can be protected by patents).
I'm with others who say that an API should not be copyright-able, however it appears that in this case it doesn't matter. They may have a license! I haven't looked into it at all, but if it's true that Smartcar have implemented this API and distributed it under an MIT license, I think it will be really hard slogging to say, "We only meant to license some of the IP. We just gave a license and decided we'd wait until after the fact to tell people what it covered".
I am a huge advocate of free software, but it really bothers me when people license something without having any clue what it actually means. I can't tell you the number of projects I've encountered who say things like, "I put it under the GPL, but you can't sell it", or "I put it under an open source license, but you can't use any of the code; just look at it", or "I put this game under a free software license, but you can't use any of the story for the game because software licenses only cover code", or "I put my code in the public domain, but that doesn't mean you can make a few changes and claim that it's yours", etc, etc. If you want a "I'll tell you if it's ok after you've done it" license, don't grant a general license! Reserve all your rights and handle licencing on a case by case basis.
The entirety of his examples are focused on the Oauth API, which is a standard, and all the concepts and var names he shows as a steal of API are present in each and all Oauth authentication servers.
I mean, we have in our own api about 90% of the same verbiage for our own authentication doc, this is bog standard Auth code..
The wording of this is found everywhere on the internet. Just search for one of the phrases you find and you'll have plenty of matches: https://www.google.com/search?q=%22The+number+of+seconds+the...
I understand the frustration of the guy, but this is not like they copied the business API, this is just the standard Oauth.
Anyways.. I'm starting to sound like an Otonomo PR guys.. I'm not, it's just that reading this article, I found myself pondering whether my current employer could be sued for this kind of trickery. I wrote the Oauth2 code in our product, and found myself writing the exact same doc (probably with different words).
It's usually not an issue but I have run into some small repositories that had no license, meaning I could -not- fork and modify for myself or a PR, legally. But this is not obvious at all unless you look for the license file or a manifest file.
Note that this is governed by GitHub’s TOS and supersedes anything in the License file.
So I can "perform" and "reproduce" content through forking, solely on Github. But I couldn't clone it, nor make modifications to my fork, if I read that correctly.
It makes little sense and could be avoided altogether by disabling forking for un-licensed repositories. Or by simply giving all new projects a default (with an opt-out option for no license or alternate licenses).
A disabled fork button unless the repo did a positive action would dilute the whole concept. The fork feature is key to the whole thing and is what made them different.
This is absurd. You don't have to use the "fork" button to copy a repository. It's as simple as cloning it and pushing it. Such a restriction servers no purpose at all.
My idea was to use Github, but then I didn't want to go through the cost/effort, and I am using my own version system, AWAY from everyone. The only way for someone to get my code is: a) laptop gets hacked b) laptop gets stolen (disk is encrypted), c) backup gets stolen (carbonite is encrypted) d) Apple gets hacked.
Git should not bother people with a bunch of different alerts (imho). A COMPANY (apologies for the caps) that has been working on code for "a few years" and doesn't do the MINIMUM to protect their Intellectual Property (IP)... well that is suicide.
Don't they pay someone with GRC/Audit/Security skills to put some sense into them????
If you want it open source, understand what that means before complaining about it. Otherwise don't release your software on an open source platform.
> other GitHub users have the right to view and fork your repository _within the GitHub site_
^^ That's from the github website. Note that they only have permission to fork from within the website.
So such a restriction serves as a legal barrier - it leaves no legal way to copy the code.
The main point of putting something on GitHub is to allow people to git clone it. Every git clone is a fork of the project.
If you don't want something forked, don't put it on GitHub.
This seems a reasonable balance.
I'm specifically discussing a situation wherein someone has uploaded non-licensed code to github. I am not advocating for this. I am discussing what should be the default behavior for a repo if unlicensed. Another alternative is not having the repo be usable at all (so not private) if one attempts to bring it public without a license.
And you are continuing to misunderstand how this works. If you can view it, you can copy it. Nothing prevents someone from viewing a public repo. So nothing prevents someone from copying it. Therefore any attempt to make it difficult is just a PITA.
That's why Github has a default license for all non-licensed public repos. Because it's a public repo. If it wasn't supposed to be available to copy, the source code shouldn't have been made a public repository.
So again. If what you're looking for is a private repo solution, Gitlab offers this enterprise-level solution for free. You are barking up the wrong tree.
The point of uploading to a public Github repo is to let others clone it. Pure tech tools like that shouldn't implement features that require searching a repo for a file that could be a license and then determining whether the file gives others the right to do that clone. After all, letting others clone is the entire point of the tool. If it's not allowed, don't use the tool.
With that in mind, to enforce your argument, they would need to create a list of licenses that are okay to fork/clone. Why should they create a finite list of that?
I'm willingly using WTFPL[0] that can be summarized as "as long as you change the name, do whatever the fuck you want to". I know it's not a serious license (I only use it for non-important collaborative Markdown documents I've started), but thanks to its use of the word "fuck", I'm having hard time believing that it would find its way into any whitelist. FSF mentions it on their website, but GitHub doesn't list it as an option on choosealicense.com.
Unless you want to pay thousands of dollars per repo presumably everyone is going to continue not giving a damn.
If you don't want people to clone a repo don't upload it to a public github repo. If you are thinking of cloning realize that the ability to clone it gives you zero legal rights.
Anyway you cannot fix legal complexities with technology in this instance.
Which they did not do.
I'd already reviewed all of our competitor's terms to get a sense of what other people were doing. So, when I reviewed the final documents that they wanted $5,000 for, they looked oddly familiar. A quick diff verified my suspicions. They had copy-pasted from one of our competitors and then search-replaced the company name.
When I called them out on it, they said it was common practice and not to worry. I found a new law firm and they never bothered to try and collect on that invoice.
Of course it was unethical for them to do it without telling you and trying to charge you $5k for it, but law would be a heck of a lot cheaper if openness and code re-use were the default.
[1] The meta data was leaking the names of their other defunct dotcom clients.
/s
This company is about the closest I've seen to disrupting anything so far.
My experience and observable reality show that it's hard. There's a reason even the techiest of companies still pay an army of lawyers in house and still go to the best firms for major transactions and disputes:
Lawyers usually use forms / boilerplate because they have worked in the past. Many of these forms are the sum total of thousands of hours of time and refinement over tens of years. Nobody wants to pay a lawyer to reproduce that -- at least, nobody in retail law (big corporate settlement contracts? Those see many many hours of revision and negotion, but ultimately are still based on a core form that rarely changes).
I agree that a copy+paste job seems like you are getting cheated. But like an engineer, a lawyer isn't charging you for typing, or turning a screwdriver. They are charging for knowing what contract you need, etc.
What's honestly shocking right now are the alternatives. What LegalZoom gave my friend to start an LLC would have been malpractice had it come from an actual lawyer. (But surprise! You can't sue legal zoom as easily for that thing as you can a lawyer).
Imo what really needs to go is hourly billing. But that's another conversation, and a really hard problem.
Honest legal Invoice
Task. By. Rate.
------------------------------------
Fix form. Paralegal $ 100
Knowing what Lawyer $ 3,900
form to fix.
Accepting. Firm $ 1000
liability
------------------------------------
We already live in a world where reuse of forms save clients money.True disruption changes the obvious problem above: how do you replace the cost of professional judgement and trust?
If you're an engineer today, you don't get paid poorly because Mongo and Postgres already exist. You get paid well if you know whether a document store or a RDS is the best fit for the systems problem at hand based on a careers worth of experience.
As someone who has done both for a living, it's shocking how much overlap there is (overlap that I assume exists in among doctors, accountants, consultants).
If a standard, simple will is entirely boilerplate with some search-and-replace, then it can be replaced with an app.
You decide whether to pay the lawyer based on your confidence that the boilerplate stuff is right for your case, and will hold up in court. Individuals are likely to take this risk, large companies are not. So the large companies will still get boilerplate search-and-replace, but with the added confidence that they have lowered their risk.
On the other hand, I wonder what the job of lawyer should look like. Writing a similar document but carefully choosing different wording to avoid to be sued?
However, charging 5K for a copied document is just cheeky.
The game was cancelled due to lighting. But the contract supposedly copy and pasted from his old job at a costal school only addressed "tropical storm, hurricane and flood."
It's amazing what people will or will not do when it comes to important legal matters.
Always best to use "Act of God", which is a legally accepted (and often defined) term.
I'm not talking about your case though.
Your attorneys may have been using the same base template that was used to create your competitor's documentation. Lawyers reduce the need to copy/pasta code, just like developers do. If an attorney's game of 20 questions leads to a bunch of templates that were drawn up before they ever knew you, values are filled in for your specific use case, you're not getting ripped off. You're (hopefully) not paying for words in a document. You're (hopefully) paying to have the contents of those documents cover your butt when shit hits the legal fan.
The trick is to know templates exist. If you hire an attorney to do a bunch of work, and you are pretty sure that all of that legal work is just going to be generated using boilerplate templates, then you can negotiate a better rate based on the fact that the attorney is doing very little custom work. The more boilerplate being generated, the more leverage you have to negotiate a better price.
Source: I learned this from a mentor to get favorable pricing on attorneys fees.
Quoting:
“[Because] the vast majority of contracts prepared by law firms are either outright copies that aren’t entitled to copyright protection or are contracts that derive copyright protection from their status as compilations, a law firm would likely have a hard time demonstrating breach of copyright.”
And:
”It is standard practice for corporate lawyers to copy—from deal binders, the SEC’s EDGAR database, and elsewhere—and revise contracts drafted by others.... It’s a safe assumption that the vast majority of contracts are either outright copies that aren’t entitled to copyright protection or contracts that derive copyright protection from their status as compilations. Because any compilation contract would resemble countless other contracts, a law firm would likely have a hard time demonstrating breach of copyright of its compilation contract. And even if were able to do so, its damages would likely be nominal, because compiling such contracts is a relatively quick scissor-and-paste exercise. So you should feel free to copy a run-of-the- mill compilation contract, not because doing so constitutes fair use, but because the likelihood of someone knowing of that copying and having any interest in preventing it are exceedingly remote.”
https://www.adamsdrafting.com/downloads/Copyright-NYLJ-8.23....
What likely happened here is a remote team was paid to generate docs with a directive like, “Smartcar has a good API,” and stole them directly. Then the management team didn’t bother checking.
This is great PR for Smartcar all things considered, and I actually think has a fantastic silver lining:
The value of a good API isn’t the API itself. It’s the expertise of designing them. APIs are difficult, the majority of the industry sucks at designing and delivering them. Otonomo can always copy you, but if you have the actual expertise to continually deliver a fantastic API experience you will win in the long-term. Stripe and Twilio are your proof points. Go get ‘em, team.
Bessemer invested in Twilio and they know this, and the Otonomo team just showed them that they’re incompetent in the API space. So — I think you’ve got a bigger leg up than you think.
If a remote team is writing your API documentation by copying and pasting, then what is the actual implementation team building from?
I’m not saying that’s what happened here necessarily, but I’ve seen this pattern repeated before (less egregiously). Founders can only do so much and most people are completely ignorant of the value of a good API, so it’s not hard for an executive team to say, “make it like that other one,” instead of staffing out the proper team.
For what it's worth, the usage here means "from within."
Can you confirm that more of their API other than the authorization code was duplicated? Honestly duplicating auth APIs are perfectly fine. If you showed proof of business APIs being duplicated, I'd have more faith in your claim. Right now this looks like a publicity stunt on a baseless argument.
You don't get to say this.
They didn't steal the docs (not only the docs). They stole the whole public facing architecture as evidenced by the fact that they are using in some instances the exact same API resources names and method names.
Duplicated parameter names would be expected in this case, and preferred actually, so that they conform to the OAuth spec :-) The descriptive text is not an exact copy as well. From what we know, the only damning bit is that parameter values were exactly the same as in smartcar's documentation, which while not condonable, is not as egregious as it would be, had Otonomo cloned the business API as well.
I would like to believe that interoperability trumps copyright in this case - a competitor copying an API/protocol and making a compatible, competing service is good for the consumer.
There are enough people on here who can point you in the right direction, or arrange introductions.
Spend at least one of those millions on PR and lawyers to ensure it's clear who has the moral high ground, and who should be hired if a company has to choose between you - I mean if they are prepared to breach copyright so blatantly here, who knows what other problems they have in their repos - enterprises can be very conservatice on unknown legal risks like that
Summary: They are vulnerable - Get 'em
Or, go get $55 Million in VC funding from someone else.
You have a major head start. Your company is theoretically worth at least as much as theirs.
Complaining about competitors copying you might slow them down a bit. But it will probably slow you down a lot more. On the other hand, using their valuation to raise $55M+ would be a huge boost for you.
Maybe.
Having worked in the auto industry (albeit well over a decade ago), it is one of those industries where connections, and knowing how to navigate the relationships, goes a long way. I don't know much about either of these companies, or their founders, but in B2B scenarios like this, the value is often related to much more than just the underlying technology.
If I were Smartcar, I would look closely at relationships, physical and virtual proximity to major automotive players, and how their suppliers prefer to do business. And, perhaps they already have...
Instead, think of the work as a means to an end, the end being revenue.
Company X was able to raise $55 million because they were able to demonstrate that the potential market could support the revenue necessary to justify such funds, and that they could use the work already done by SmartCar to get to market more quickly.
Now, in my opinion this is very shady and should be grounds for a lawsuit, but in terms of raw business savvy, the $55 million is for a smart business that knows how to execute for less. If money raised was in direct correlation to a quality product or the ability to produce such a product, rather than in direct correlation with e.g., the team (cabal?) involved and their ability to make returns for investors, then we’d be living in a very different world.
I can imagine the "Kickstarter scam" running in the VC scene, the Kickstarter scam being: you show ads for a product on Kickstarter with the line "300 thousand dollars in backers already! Get yours too!", but that money isn't from genuine backers, coming from your friends instead. Then a chump seeing the ad will think "Oh, this new gadget is popular, it must be good, let me buy 1 for the introductory price!" and gives you his money. Then you just keep the chumps updated with "Sorry for the delays, we have manufacturing difficulties" month after month.
So in the VC scene, you could get your friend to invest in your idea for $$$, get other investors interested, and... profit? I can imagine it'd be nice to spend the genuine VC money on company Lamborghinis and penthouses for a few months, declare bankruptcy, rinse and repeat (just steal the API from the next "Smartcar"...).
or simply refocus the startup on used lambos and penthouses :)
If they don't have the engineering chops to build an API how are going to handle the ops of it.
Copy/pasting docs and rewording everything to try and hide that fact is a lot lazier and shadier IMO.
I think the intellectual property is in the APIs/"headers". That is what Android uses from Java and what this company is copying from SmartCar. Its not easy to write a good API. (But, I should say, once you have the headers it is not as tough to populate them with code.) As for coping actual documentation, that is just plain stupid but not the _worse_ crime here.
Now, what is different is that many of us don't approve the way Oracle is enforcing the rights on this information. Java is not like the SmartCar APIs in that it has been free to use for so long. All the same I think Oracle should have the legal right to do this.
Many may disagree about Oracle vs Android but I think it is devaluing the work of people like James Gosling _and_ SmartCar if you say there is not intellectual value in the code/API headers.
It is not the same simply because Java is an open-source project. SmartCar, on the other hand, is not. I would argue that, because of the nature of open-source, Google should have been able to do as they pleased to facilitate allowing java code on their OS. I know that many would disagree. But to say that there is not intellectual value in the code/API of Java would be disingenuous, and ultimately incorrect; I can say with certainty that I would never say that, so thank you for putting words in my mouth.
I appreciate your response. I am not clear on if that particular information is open source. A quick Google search does not seem to give a good (single) answer.
"The redirect_uri provided in Authorize User step" appears exactly once on the Internet according to Google: at smartcar.com. It looks like Otonomo did in fact copy/paste from the SmartCar website.
https://www.google.com/search?q="The+redirect_uri+provided+i...
When I tried to file an appeal with Google I had to agree to abide by California jurisdiction and American laws. I am not even American. Why should I ?
I am happy if Google blocks my site in American owing to DMCA because US traffic for me is next to zero. But I am not sure why DMCA should apply to India.
I would rather focus my energy on getting Indian government pass laws that will protect us rather than pay an attorney for my non profitable website.
So they could choose to not do anything, which means the only companies approaching them in the future are the desperate ones, and they lose the capital anyways to the markets due to a shoddy portfolio.
Don’t knife your intangibles.
We have a team of people that exhaustively search for players in the same space. The 'Google on various phrases' is more or less the gist of it, the more unique the better.
It's not an automated process so fairly time consuming.
> Are you checking for your customers our on your customers?
We do not check on our customers, we check for our customers. And usually pre-investment.
> If the latter, why do you care (most vendors wouldn't).
You are probably wrong about that, copying something verbatim will get you a C&D pdq in most cases.
I sell a SaaS reading product and don't care what my customers are using it to read, or whether their own websites our products contain any infringing content.
What they are using your product for might very well turn into 'aiding and abetting', make sure your TOS is up to snuff and that you have it checked over by a lawyer to verify that if your customers do something illegal with your service you don't end up being on the hook.
As for the second, that might be a good hint that your customer is not above-board and will bear closer watching.
Napster is one end of the spectrum, but I'm not sure how anything short of that is a legal risk. Are there cases or legal theories I'm unaware of?
Off the top of my head: anything payment related and two sided market places (money laundering, false binning), anything that allows large volumes of data to be moved around (copyright violation, child pornography, exfiltration of data from corporate networks), proxy services and spider services (DOS attacks, harassment, TOS circumvention and copyright violation) etc.
So nothing that would require legal theories, just the usual abuse of service.
So could Mozilla be on the hook if people used Firefox Send to do any of these things?
You hereby represent and warrant that your content will not infringe the rights of any third party and will comply with any content guidelines presented by Mozilla...
We may suspend or terminate your access to the Services at any time for any reason, including, but not limited to, if we reasonably believe:... you create risk or possible legal exposure for us...
You agree to defend, indemnify and hold harmless Mozilla [et al] from and against any and all third party claims and expenses, including attorneys' fees, arising out of or related to your use of the Services (including, but not limited to, from any content uploaded by you).
(https://www.mozilla.org/en-US/about/legal/terms/services/#se...)
In one court case - where a company I had a majority stake in was the plaintiff - the defendant basically had to admit that they copied the code and content of our website. Their defense: 'we did not copy it from them, we copied it from someone else' (without specifying what the 'someone else' was). Needless to say that did not end well, we were surprised they actually went to court but since this was in a country where the loser pays the court costs of the winner that did not overly bother me.
https://webwereld.nl/overheid/10591-webcamsites-bevechten-el...
(Dutch)
The quality of your lawyer will help in the gray areas, and may get you a reduced sentence in case of a criminal affair but in general you will lose if you go to court with a case where you were in the wrong. It's not a perfect system but for most cases it works out.
>And the only reason you bring it up is because it is exceptional
So you need exceptional lawyer.
>The quality of your lawyer will help in the gray areas
An exceptional lawyer will make seemingly black and white situation to looks like grey.
> in general you will lose if you go to court with a case where you were in the wrong
Sure, the point of court is argue that meaning of "wrong"
You don't 'win' a criminal suit. The standards of proof in a criminal suit are different than the standards of proof in a civil one, because the punishment in a criminal suit is much heavier than in a civil suit (where the maximum is some monetary penalty, whereas in a criminal suit it is imprisonment or in some countries even death).
I really think your view of the legal system is somewhat theoretical, there is no such case that it can always be won given the right lawyer or argument.
The reality is legal system consist of human in various capacity, judge, lawyer, jury, even public opinion. Its all boil down to convincing these human. Given the right method or argument, you can convince any human. Sure some case are harder then the other but doesn't mean it impossible. Really really hard != impossible.
>there is no such case that it can always be won given the right lawyer or argument
What is your reasoning ?
It'd be like YouTube using your videos for ContentId, but not having any avenue for you to profit from said videos. Oh and uploading to Youtube would be mandatory.
There was a lawsuit about this, decided on TurnItIn's side, but I still disagree.
Bessemer & Co. probably don't know that the docs are literally being copied though.
It does raise an interesting question though: how will the OP prove that their work is the original, that might hinge on a lot of unknowns, more difficult still if the work was originally lifted by an employee of the company and then passed on to Otonomo with them being the unwitting recipients.
So it is definitely possible that the codebase got stolen and the perps missed changing a few hints, resulting in the Otonomo samples generating identical sample code, as shown.
Anyone considering that should be aware that Oracle vs Google is still not finished.
I almost wish you had done my technical diligence, Jacques. I spent a week preparing for it and was very proud of what I’d built.
It's five of us for a week with a super intensive interview on the Wednesday and it is always the highlight of the week for me. What is also neat is that most of these turn into very long term relationships post deal, not necessarily financial ones, just that the interview day makes the whole thing a two-way street where the tech team will occasionally reach out when they are stumped on some problem or need outsider perspective.
Ultimately, the VCs probably just ask the founders "Hey, your product looks very similar to product A, how is yours different and did you develop it on your own?" If the founder denies copying and gives a reasonable answer for how they developed it on their own, the VC then makes a judgement. They also may hire some consultants or have some outside experts look at the tech stack to make sure no red flags pop up.
However, you can't dig through every line of code and every document in diligence and compare it to several other companies code/docs. It would take too long and everyone involved (VCs, lawyers, start-up) would be annoyed.
It's a Series A, serious DD doesn't usually happen this early and a jr. analyst with a finance background wouldn't catch something like this.
https://otonomo.io/pr/otonomo-announces-25-million-strategic...
And even then, series 'A' requires DD as much (and sometimes more so) as later rounds.
There are lots of VCs, some are better at this than others, some really suck. On the whole though they tend to do their homework at least on the commercial front and a competitor with a feature-for-feature identical offering would have most likely been spotted even at the 'not so good ones', irrespective of whether or not the API docs were made public.
The interesting questions to me are:
- what was the exact timeline?
- was an (ex) employee of the company involved in the copying?
- is Otonomo itself aware of the fact that they have this sitting on their website?
- How far down does it go? Is it just the API documentation, or also the underlying code?
The most severe move they could take would be to enforce whatever contractual mechanisms they have to block additional financing pending an independent investigation and replacement of responsible parties. Or they could directly force the matter if investors hold a majority Board vote.
They could recoup a huge part of their investment before things get worse. But again, afaik this requires a shareholder majority, barring any strings/triggers on the investment terms that could be activated.
Is it illegal to just copy some docs from somewhere on the web?
are APIs copyrightable?
The latest decision in that saga is that yes, they can be. Whether that holds up in the Supreme Court is an open question. Most of us hope it doesn't, I suspect.
Copying documentation is definitely a copyright violation. Similar situation exists with recipes - a list of ingredients can't be copyrighted, but the wording of the steps can be. You have to at least put it in your own words.
Otonomo sounds like a deeply unethical and shady company. If I was doing any kind of business with them I would not continue to do so. While it would be hard to sue them, hopefully when you Google them in the future the fact they ripped of Smartcar will be one of the first results.
I mean, you might eventually be right. But why "immediately"? What's wrong with taking some time to talk to people, hear the other side, find out more details, do a proper investigation, and then decide what to do?
One side of a story is never the whole story.
https://web.archive.org/web/20190422150111/https://smartcar....
(And a reminder to donate to archive.org if you can!)
You can tell they copied them but this is likely the work of a single lazy employee rather than indicative of an entire company.
Consider that the value of a company is more than API documentation. It’s the customers, the business relationships, and the employees. The actual tech is last in the things that are valuable.
If you want to survive in this industry you need to understand that eventually someone is going to copy your product. They might even do it better than you. Unless you can prove fraud, there’s nothing you can do. There’s no crime in copying someone's public API and offering an identical service; people do it all the time.
Instead of worrying about your competitor and some lazy employee they hired there, worry about your own product, customers, business. Start planning your next feature or next way you’re going to WOW your customers. That’s your real job.
Now get to it!
But I totally agree with not worry about competitors. There's always going to be people copying you, and if they do that means you're doing something right. Think Stripe - I'm sure they're a huge source of 'inspiration' for a lot of sites when it comes to design and documentation.
Is it lame to blatantly copy someones API docs? Sure. But even looking at the screenshots in their blog post, which I presume is meant to highlight this issue, it's clear that there are changes as well, so it looks more like derivative work than just blind copying (I'm not sure if there's a meaningful legal distinction here, but it feels more ethical).
It is super lame and dumb to have ripped off their doc, but the API format itself is not an issue to me. If I were going to implement a competitor to Google Maps, it would make sense to copy the Maps API so people can migrate seamlessly. That is the nature of SaaS.
The core value proposition is not in API design, it's in the implementation.
The copyright of the structure of the API, however, is still something to be debated about.
Our project died in 2014 due to lack of support and funding on Europe, while our "Chinese partners" started raising mega large rounds literally copying everything from us, from business plan to technology.
You can also see an overnight quality jump on engineering and powertrain from the Chinese EVs (pre-2014) to 2015+, based on our previous work.
what company was it that went out of business in 2014?
That's bad for sure.
However, most "Oauth2 flow" documentation pages look like that. They all have a table that's basically copied out of the Oauth2 spec. They all have very similar language.
This is a good thing. Oauth2 is a well defined spec, and there just isn't a lot of ambiguity there.
If it weren't for the copied random state, I'd shrug this off.
I do have major issues with verbatim copying of documents and websites, there's an obvious copyright violation there.
Unfortunately, the market does not care about who had what first. This is a validation for you. Frustrating validation. You likely do not have the resources to fight them for anything meaningful. Stay focused on your customers.
What do they mean by "standard" here if they object to this API being copied?
The very goal of API standardization is to have a common interface for TWO parts to talk to each other in a consistent manner. An API that through whatever means allows for only one specific backend doesn't really qualify for being a "standard".
> How Otonomo is illegally cloning our product
So am I to understand that the API spec is their product?
Or is their API not as standard as they claim?
Can't have your cake and eat it too.
Since when copying some API docs is illegal? We don't even know yet if API are copyrightable, right?
Ever since Facebook copied snapchat's features like it was nothing it became clear for everyone that the best clone will win. You have a product? Expect a clone of it.
To me this post is just "they stole my idea" whining.
If they'd copied Snapchat's "how to use <feature>" documentation verbatim, typos and all, that'd have been a copyright violation.
First, someone like me flagging this has killed or crippled potential acquisitions by big tech companies. In most cases, the startup has no idea that the plagiarism was discovered but it follows their reputation. It is a giant red flag since it raises questions about the provenance of the rest of the IP. Plagiarism reduces your probability of a successful exit.
Second, in some cases, it puts you in the position of tacitly trying to execute someone else's technical vision that you may be lack the expertise to replicate. I've also seen this failure mode multiple times. Plagiarized documentation makes a promise that will be difficult or impossible for the startup to deliver on because they lack specialized expertise that the company they copied it from has. This is a form of self-sabotage since it puts the startup in the position of executing from a position of weakness in order to match the content they ripped off from some other startup, which leads to poor product and poor customer experience.
Copying abstract ideas is fine, there are many possible implementation variations, but blatantly ripping off other startups is a very low ROI strategy for startup success.
Updated to include my tweet: https://twitter.com/MattHurewitz/status/1120356791932604421?...
One could argue that the market is okay with these types of things. But, we talk about doing the right thing. And if it's not just lip service, this could be a great opportunity to prove it.
OP should figure out if the public stuff is all that was ripped or if it went further, it would not be the first time that an ex employee made off with a copy of the company crown jewels.
Turns out not everybody working there agreed with the tactic and the day they raised money I got a very nicely worded anonymous email with the name of the investor. The ink on the press release was still wet when I mailed the VC for their legal contact because we were still well within the statue of limitations and now they could actually pay up.
The only message I got back was 'we will not be investing'.
I guess literally copy-pasting the docs is a flagrant violation, but it seems like that's the least of their problems. Presumably BigCorp will now get a cleanroom team to re-document the re-implemented API.
In theory, if you copy an API, you also copy its semantics. The docs for it are supposed to be interchangeable. Its touchy. For example, wouldn't most people rely and use the Java doc even for Android?
Now obviously, redistributing a copyrighted doc on their own website without permission is something else. Cause I'm guessing docs are copyrightable, but not APIs. The whole thing is getting more interesting to be honest.
I think that is just life in tech now. You put out a 'feature' in your app that is new and cool. Two weeks later the same feature shows up in your competitors app.
In our case, always better to be ahead of the curve. You've got a small team with 20 folks who are putting pressure on the 100 person teams at these giant companies.
The way they did it looks much shadier, but I doubt it's actually illegal. The longer text blocks are all original, even if clearly inspired by smartcars. The descriptions of paramters is mostly copied verbatim, but I have my doubts it's copyrightable, after all there are only so many ways to describe what "access_token" does. The overall structure of the documentation is also clearly copied and is probably protected by copyright, but it's easily changed.
I doubt it is so, but even if those tokens pass the threshold of originality[0], does a few blobs of superficial text justify a lawsuit?
Things would be dramatically different if they'd copied source code, but so far, it's just documentation.
Whether or not any violations occurred in copying code probably depends on whether any employees with company secrets were poached and involved in development. That's a very big, well known no-no amongst tech companies. It's why Compaq had a complete "clean room" to reverse engineer the IBM PC.
> For example, the number of random version-4 UUIDs which need to be generated in order to have a 50% probability of at least one collision is 2.71 quintillion [...] This number is equivalent to generating 1 billion UUIDs per second for about 85 years, and a file containing this many UUIDs, at 16 bytes per UUID, would be about 45 exabytes, many times larger than the largest databases currently in existence, which are on the order of hundreds of petabytes.
https://en.wikipedia.org/wiki/Universally_unique_identifier#...
The probability that they generated the same text 1:1 and a UUID in it by random chance is very, very, very, very slim.
Perhaps the company even used decompiled code, it's not out of the realm of possibility that they simply directly stole the whole thing.
I'm not sure any of that is actually likely, but I think that the fact that some paragraphs are directly lifted is a massive red flag.
This appears to be a lawyer's dream case and I wouldn't be surprised that, if this case makes it to court, discovery finds some actual stolen code. If this company ever poached employees they'd better be very, very careful.
IBM "bluewashes" their terminology and vocabulary for this same reason. They can easily catch someone else using IBM-specific language, and they'll often call very common things by unique and very different names compared to other companies. This can also help cover for any perceived issues with employees bringing over ideas from their previous company.
It looks like API copying violates copyrights on the US, so go for it. In a democracy crazy laws can't be crazy just for the bad.
If they actually believe the idea has merit, they should do right by Otonomo.
Playing fast and loose with the law—whether it's competitors legal interests or regulatory conpliance—is often part of the economy of disruption.
As someone that worked for one, and knows enough people that work in other Israeli startups, I can tell you it isn't true.
True, some startups get acquired, but no more then any other place (the only difference I see is that in some tech areas Israeli talent is considered very good, so when looking for an acquisition, big corps are probably more likely to go for the Israeli options)
However, copying the _docs_ like that is a clear copyright violation, always has been, still is, not really a legal gray area, I don't know what the heck Otonomo was thinking, and I hope they get their hat handed to them.
One per offense.
Also, if the docs are registered copyright, willfull infringement per offense is over $100k per instance.
$50mil/$140k = 357.14
Thoughts?
It just isn't something a judge would ever agree to.
Federal three letter agency's were heavily involved in wielding the stick side of things.
That is the angle OP should pursue.
It is very similar to an issue with phone chargers. There were times, where each phone manufacturer had a different charger, and if a new company decided to use a charger desing from Nokia, they would probably sue them. I am so glad those times are over and we use USB everywhere. Arent you glad, that your API could be used everyhwere?
Or another example, imagine if every web browser had a different "web language" like Javascript, and developers would have to make several versions of their website for each browser. And if a new browser wanted to display webpages ment for Firefox, Firefox would sue them.
And to say that someone is cloning your startup when they only (supposedly) stole the documentation is extreme in any case, especially when they're not really a very new startup, so it's not like you can claim everything they did was just copy from you.
I don't know what legal recourse smartcar has, but I would think it is time to seek that advice.
https://developers.google.com/identity/protocols/OAuth2ForDe...
Because these APIs all look very similar to me.
Amazing that they have 55M$ in funding and still hire a bunch of amateurs. I bet the design for their docs is based on some free online template too because it looks very cheap.
I wish you all luck!
Have they cloned the API docs or the entire product? Copying API docs is stupid but I can see how that would have been done in a hurry.
However, if I were building a Saas product with an API and a competitor to a popular tool who has it, I will deliberately keep the basic functions as similar to ensure seamless transition. Its not about uniqueness but moving fast. Companies which might want to switch will have it easier given they wont have to change their code much, and by extension can be deployed faster, and I will try to sell them on the features we offer extra over the competitors.
I am not sure about copyright/patent infringement so cant comment about that. Part of what I wrote above might not be allowed, but maybe mentioning explicitly might be ok .
ideas mean nothing, execution means everything.
you had the idea, but they had the connections(VC, industry, etc) and knowhow to execute on it faster and bring it to market faster.
Sad, but this is the market we have created! The rich can steal ideas, or do whatever they want, with impunity because they can defend their questionable actions in court. This is what AirBNB and Uber were built on.
Copying and pasting the docs seems a little egregious, but that's a pretty small issue that could be changed in a day.
Using the Wayback machine, I looked at both company's docs and the navigation isn't the same - https://twitter.com/CaseySoftware/status/1120521768723255297 - so even the copy/paste job looks like a single page.
Yes, it's absolutely poor form and may be a copyright violation but the screencaps cover OAuth 2.0, therefore everything - yes, including the parameter names - MUST be the same, according to the spec.
Without more evidence, this is a nothing burger.
Would love any feedback you may have!
From my understanding though they're just a wrapper API around the car manufactures existing apis?
Yep, think EasyPost for car functions
The requirements/supported brands & models should be somewhere prominent on the front page, and I'm honestly still confused. Similar any country restrictions. This being limited to the US should not be hidden three levels deep in some FAQ.
The Otonomo isn't any better though, it doesn't even seem to have any links to the docs.
AFAIK the is not a single car manufacturer (not even Tesla) that has any API available. Most cars don't have internet connectivity anyway.
Disclosure: I do NOT work for Smartcar, but have build multiple backends for P2P carsharing and bike rental platforms.
This is patently false. Smartcar does not require additional hardware. Quoting from their product page:
> Our API works with the embedded telematics module built into most new vehicles. No need for aftermarket hardware like OBD2 dongles.
As it stands now, the documentation is very much misleading as Smartcar makes it sound as if you can use this on any vehicle. Look again at sahaskatta's response, he/she made it sound as if you just have to read the docs to 'unlock your car with an app'. But in reality, you'll also need to have a brand new and very specific car if you want to do this.
Sahaskatta also asked for 'any feedback I have'. I gave that and now I'm being downvoted for my criticism...
My 2014 Chevy gave me 2 years of their mobile app which could unlock/lock the car via cellular for free. I know the car still has a data connection available because if I play songs via bluetooth it pulls in album art that doesn't exist on my phone via Gracenote. I can also hit the OnStar button and talk to someone via the car and I don't pay for that.
That Chevy lock/unlock API may not be a public API but there is nothing stopping someone from reversing it. Or just signing up to use it: https://developer.gm.com/vehicle-apis
Most modern cars offer the same features.
Yes, it does kind of suck they stole your idea. But the fact that they have $55 million in funding, probably means they're willing to buy you out for a couple million. One, just to avoid any legal issues. Two, because you've already done a lot of work on the problem.
Maybe it's worth fighting. But maybe it's also worth considering getting a multi-million dollar payday, and moving on to something else.
[1] https://www.crunchbase.com/organization/smartcar#section-ove...
The smart car documentation is worth some amount of money. But there is no way in hell that it is worth 10 million dollars.
In law, there is this concept of "damages". Smartcar did not get lose 10 million dollars because a company stole their docs.
If SmartCar goes for damages, then that's an entirely different ball of wax.
They did a 1:1 facebook clone for example.
Are there entities that protect American IP from other countries? Maybe the US chamber of commerce, or maybe reach out to the government itself.
1: https://en.m.wikipedia.org/wiki/Oracle_America,_Inc._v._Goog....
Youtube & Vkontakte hosted pirated content knowingly.
In the early days, iOS apps juiced their valuations with vanity invite metrics that entailed invite-walls that juiced downloads to access full functionality of apps. (invite 50 people to use full app features). Some of these were acquired for 8 figures plus.
Paypal created a bot that bought goods on eBay and then, insisted on paying for it using PayPal.
Rentoid bought and rented the items themselves.
Dating networks seed enough fake accounts on both sides to start the demand.
AirBnB allegedly created a bot & fake email addresses that would automatically respond to posts on Craigslist.
Marc Benioff of SalesForce hired fake protesters to disrupt his biggest rival’s conference and commandeered all the taxis at the event to deliver a 45-minute pitch about his own product. In another instance, he cancelled his keynote at the Oracle Conference and drew crowds to his own speech at a nearby restaurant.
Otonomo cloned some code, nothing that was impossible to deduce as well.
Nearly every API is going to need solutions for these, and they all look very similar. I'd be surprised if the redirect and auth parts weren't at least in some way inspired by other APIs.
"smartcar" feels like a weak trademark and is likely not registrable. "Otonomo" is inherently more distinctive - making it a stronger mark.
To avoid this problem - "smartcar" needed a stronger trade mark in the first place. Secondly the API copyright licence needs to work in combination with the improved "smartcar" trademark.
The Artistic Licence 2.0 for Perl 6 is an example of a copyright licence that works in combination with a trade mark.
Copyright licences are incredibly flexible - it's possible to restrict server-side implementations for example. Depending on the business objectives it should be possible to strike the right balance - binding the API to your trademark via the copyright licence - could be a good move if your API is a market-maker.
It's not a good example to use of someone stealing an API.
Also their stats dashboard isn't secured: https://dashboard.otonomo.io/dashboard
you can see public data here
Or are they complaining this other company is copying their documentation, which is evidently released with a permissive license? Is Smartcar's product the API documentation?
Either way, this is far removed from my understanding of how computers work. Copyright exemptions for compatibility work have a long precedent. If Otonomo's business model is to build Smartcar-compatible products, and Smartcar does not like this, it seems like they should have more carefully considered what their product is, and how to protect it.
also looking at the other company documentation, it's different from the screenshots: https://docs.otonomo.io/docs/getting-started (archive.org history is quite limited so may have been scrubbed)
edit: yes those "screenshots" are very disingenuous: https://smartcar.com/docs/api#introduction
https://web.archive.org/web/*/https://docs.otonomo.io/docs/*
And many were saved to archive.fo today:
https://archive.fo/docs.otonomo.io
The screenshots look accurate to me, what discrepancies do you see?
I meant that it's just copying the API format (e.g. probably to make migrating from the other service easy) which isn't uncommon (e.g. most of AWS services copied APIs)
I think Otonomo needs to decide whether they using oauth v1 or v2.
Point being, the quality of work is speaking for itself.
JSON FROM OTONOMO ------------------- https://consent.otonomo.io/oauth/v1/authorize?response_type=...
curl https://consent.otonomo.io/oauth/v1/token \
Documents Shows ------------------- response_type
This value must be set to code. OAuth2 outlines multiple authorization types.
To me this looks like a smart business strategy: Otonomo can migrate SmartCar customers to their platform with very few code changes. With that said, copying the identifier from the SmartCar's documentation could be seen as lazy or clever.
Anyway, it was archived:
https://web.archive.org/web/20190416030526/https://docs.oton...
The full list of archived otonomo doc pages:
https://web.archive.org/web/*/https://docs.otonomo.io/docs/*
(found on another internal forums/board) Save a copy maybe?
> Did none of the over 100 Otonomo employees (according to LinkedIn) think that what they were doing was wrong?
> Today we are taking legal action. We have sent Otonomo a cease and desist, demanding that they immediately stop ripping off our hard work.
Is publicly available documentation protected by intellectual property rights?
Since I'm not familiar with the subject I'm trying to understand the grounds for taking the legal action in this situation.
Yes, by copyright. Copyright is one of the most straightforward and easiest to enforce IP rights.
The idea here probably isn't patentable. "Locate and unlock a car's doors remotely" is not exactly original.
Just rewording the docs is cheezy. The other party should have done a full rewrite.
I don't want to be disrespectful and also don't want to condone somebody ripping off API docs. But if the whole product is nine pretty simple and straightforward RESTful API endpoints with OAuth2 integration(eg. [1]), then I have a hard time to understand why there are not hundreds of other companies doing the same thing. Where is the value here, is it the integration with car manufacturers?
To conclude from this that Otonomo is "illegally cloning [their] product" is misleading at best. The Smartcar CEO is obviously pissed that they have a direct competitor with more funding so he tries to smear them over some trivialities.
Even solid companies like Arista got bitten by their doc writers cloning Cisco documentation.
So while this sucks, the most likely explanation for the evidence presented is at that layer.
It's also a stretch to say their product was cloned. It looks like what was copied was just a pretty standard OAuth setup, which most developers cut-and-paste anyway. There's nothing core to the product or even having to do with cars here.
However, I expected to see that SmartCar (which somehow is not a trademark violation against the BMW marque?) was a scrappy indie startup being violated by a company backed by serious institutional money.
TL;DR; Smartcar is backed by NEA and A16Z. (Crunchbase says they have raised $12mm, which would likely put them comfortably in the top 1% of companies by capital raised.) This is a spat between two well-funded and well-backed companies.
None of this is to excuse the behavior of the Israeli company, just recognizing that the violated company probably has access to more levers than most to fix this.
Go for funding, your idea is already validates.
I'm soon to be jumping into a crowded market as well. Many of my competitors have had VC funding and do billions per year.
It doesn't bother me in the slightest. I can be far more nimble than they can. Doesn't matter if they try and stomp me. A bigger company will always do something in their own interests and piss off a segment of their customer base which means they will move eventually.
Not only that, because I don't have VC funding. I can always have lower prices CapEx and move it OpEx instead. As long as I am much lower costs compared to being with the incumbents then it's a better prospect cost wise to my customers.
Finally, better customer service, features, ease of use, pricing and roi to the customer is what matters at the end of the day. If you simply have a much better product and able to generate and retain trust in your user base. You'll be alright.
My advice. Just start the business today. Whether or not you get stomped on is neither here or there. What matters most is the experience you'll get vs in 5 years time when you wish you had started and still scared!
Otherwise, if you published and they cloned, that's the way the game is played.
why does this post read like david vs goliath? i hate to be such a cynic but given those two facts this reads to me like a marketing piece
[0] https://venturebeat.com/2018/03/01/smartcar-raises-10-millio...
I made a dev-focused SaaS and struggle to find a good way to document API's directly via the codebase, so that code changes can be reflected automatically in the docs.
Lawyer up and take them to the cleaners.
In this case this company is being accused or taking the API design as well as the supporting documentation. Not for compatibility reasons but to represent the design as their own.
I'm tired of building things, getting knocked off and then having to say "welp didn't see that coming" because I totally did from miles away.
It takes good engineers and good founders. If one group are bozos who don't listen it doesn't work.
Does that not mean anyone else can use the API?
APIs are not copyright-able. See the whole Google-vs-Oracle Java debacle.
You can try and go the bad-press route but there's not really much you can do. That's how the free market works, basically. Also, if an idea is good, it would have attracted competition sooner or later.
isn't it for the court to establish?
Let's not do witch-hunting.
Try this mirror: https://outline.com/FfSCUm
I'm still getting over the fact I upgraded the radio on my car back in 2010 with a USB stick and using the driver's side door to control the process. I think a well-documented API that shows exactly how my car is vulnerable is a step up.
In either case, how does that relate to the existence of a reasonable explanation?
Although I am not a huge fan of many of their business practices, Oracle has been quite successful in defending API copyright violations.
https://searchoracle.techtarget.com/news/2240220840/Oracle-t...
That's why they wrote it up as a blog post and are trying to garner PR from it.
I am no Paul Graham, but I think you are wasting your time. Let's say you win the case next Tuesday and the judge miraculously orders them to shut shop. They dissapear on Thursday. Then what?
You still wake up next Friday with 99% of the problems (and opportunities) you had, before you "came across Otonomo’s publicly available API documentation" a few days ago.
If there's still a little voice inside your head that's sayin - Paul Graham didn't say that, you are missing the f*ing point. Start over.
The judge won't order them to “shut shop”, but to pay damages. Though it will obviously take longer than next Tuesday (but the real objective is to use the likelihood of a verdict and the harm on both sides to secure a pretrial settlement which either involves stopping and compensation or just more compensation that amounts to a buyout.)