Police conducted search in the Nginx office due to a copyright claim
twitter.com
twitter.com
- Interesting: you were working at Rambler while developing nginx. Did Rambler had any rights? That's a subtle question. How did you manage to keep the rights for project?
Yes, that is a subtle question. It interests others beside you, and we thoroughly worked on that. Russian law works this way: the company has the right on anything which was in employee's field of work or by it's own contract. So there has to be a contract with someone with purpose "to make a software product". In Rambler I was a system administrator, I'd developed in my free time, product was distributed under BSD license since the beginning, as an open-source software. Rambler started using it after the main features were ready. More than that, even the first usage was outside of Rambler, it were Rate.ee and zvuki.ru websites.
The Rambler Internet Holding (edit: it's legal name is Rambler Group LLC) company found that it's exclusive rights on NGINX web server, which was developed by it's employees with use of corporate resources, were violated by third parties. The company gave the right for infringment claims to Lynwood Investments CY Ltd (named A&NN Holdings Limited at the time of the deal), which has a competence in this type of cases.
Lynwood Investments CY Ltd had appealed to law enforcement bodies for the evalution of this situation. They recognized Rambler Internet Holding as victim of actions by unidentified violators (sic!) and initiated a criminal case.
Lynwood Investments CY Ltd would not comment the case until the court's decision. Wherein we would try to restore the justice with all ways possible and we reserve right to file lawsuits in any jurisdiction where it's needed to protect our interests.
[0]https://t.me/thebell_io/4315 (NB: yes, Telegram)
Sysoev was developing in his work time, in the office, with company's equipment. (quote from the order: edit)
1. Bullshit. There isn't anything on that in our laws. You have to very accurately prove that there was an assignment on that. "In his work time" or "with company's equipment" - doesn't work. Everything's allowed - and IP is within authors.
2. Besides, when I hired Sysoev - it was in 2000 - we have talk specifically that he had his pet project and he'd have the right to work on it. It was called "mod_accel" or something, he renamed it in 2001-2002.
I can make a statement about that in court, if needed. And my partner in my companies, Dmitriy Pashko, then-CTO of Rambler, could, I think.
3. He had worked as a system administrator. Software development wasn't in his responsibilities at all.
4. I think, Rambler cannot provide any paper, more so an assignment, on development of a web server.
I asked our advocate, ..., to look what's going on. The lawyers of Runa Capital (edit: early investors of Nginx Inc.) already work in the case, so probably our help wouldn't be necessary.
I think, skunks would fail.
[0]https://roem.ru/12-12-2019/281134/rambler-nginx/#comment-292...
edit: link to the source
I am surprised Russian law is that pro employee - would wreak havoc for offshoring
I think it only seems that way because we're so used to the US model where software you develop in your spare time at home with your own equipment might still be owned by your employer or even a university (even if you're just an undergraduate student already paying many tens of thousands in tuition fees). I read a few IP policies over the years, and, if they are to be believed, apparently, even if you're simply using WiFi to work on your student project in a university building, they may claim to own the whole copyright and patent rights to any resulting work; I don't quite understand how everyone else doesn't find it as demotivating as I do.
If you look at the actual reasons for Rambler not owning nginx — this situation is actually better for offshoring because anything developed for the client per the spec would be owned by the client, yet anything that employees work on in their own time, they could package as their own offering (e.g., separate packages and/or modules) and ramp-up work for more than one client without violating anyone's IP rights.
TBH, I don't actually understand how software craftsmanship consulting is supposed to work in the US. As an IC SWE consultant, I was negotiating a nginx consulting project with one relatively big company, and the sample MSA I got from them basically would have precluded me from ever working on nginx again had I signed it as-is. I think it's really amazing how more folk don't get sued in the US for these sorts of things; I can only imagine that it's merely for lack of trying on part of most of these corporations, not for lack of standing (unless all these terms everyone agrees to are somehow unenforceable in reality).
Why? I would actually expect offshore development to be the least problematic - typically there is a spec and agreed-upon set of deliverables and the rights to these deliverables are cleanly transferred. It is the common employment situation where your boss tells you your objectives in more or less vague terms which is more muddled.
1. Keep your servers abroad.
2. Register your domains abroad.
3. Register your company abroad.
4. Keep your money abroad and don't put all eggs in one basket.
5. Seriously, don't put all your eggs in one basket!
6. Keep your database abroad.
7. Document everything regarding your office setup.
8. Split the risks and assets.
9. You can give youself up voluntarily. Find a large patron or manage law enforcement protection yourself.
10. Leave the country.
Rambler sold their NGINX "copyright rights" to a shady law firm (Lynwood Investments CY Ltd).
Maximum time for a detention is 48 hours until the court's decision. The difference is how much time one would have to actively prepare his defence themselves, not via advocates.
Because the OP's list was likely referring to a very different reality than what you imagine: https://www.theguardian.com/world/2008/jun/24/russia.interna...
That kind of stuff does happen in Australia too, it's not just widely known or reported on.
A good friend - (now-ex) business owner - several years ago had her company taken from her at gun point. With nothing to be done about it ("or else") by people who the police won't fk with.
A little bit on that Alexander Mamut guy: http://rumafia.net/en/dosje/12 . One of the "7 banker" group.
He is the one who racketeered Euroset into selling itself at 990% discount.
Evroset was the largest retail network in Russia, built from scratch buy a man with a lot of talent, but no mafia connections. Alexander Chichvarkin was pretty much the most renowned businessman of his generation in Russia.
Chichvarkin fled to UK, and left a director to be his proxy.
They used the same tactic — director detained, and offered a trade at gunpoint. The director however managed to escape the capture too. In this case, after his bodyguards made a scuffle with police in his office.
As an outside business you want no servers in the US or use US dollars in any form as you may end up being sanctioned or worse extradited for things that are not illegal in your country.
You're of course conflating problems that are very common in Russia (hyper corruption, few human rights, zero business law protection, no functioning independent judicial system) with problems (the need for huge insurance, extradition, getting sanctioned) that are rare in the monster size $22 trillion US economy filled with millions of businesses.
List of countries currently meaningfully sanctioned by the US: Russia, Cuba, Iran, Venezuela, North Korea, Syria
I certainly hope you don't live in North Korea while commenting freely on Hacker News (which is, naturally, located in the US).
It's only one among thousands of cases when putinists rob successful companies. The world must put more pressure on putinism, because eventually all the stolen resources turn into imprisonments of people in the country and deaths of people in the countries attacked by that putinist machine.
So whether or not the claim was unjustified, it might become a huge problem not just for the individual developers of Nginx but for everybody distributing it or using it. And that has a lot to do with how copyright works.
Anyway, you should read up on the BSA copyright raids. Fortunately they seem to have fallen out of fashion.
https://mobile.twitter.com/AntNesterov/status/12050861295041...
Doesn't the potential for this exact sort of issue point out a flaw in how copyright law works (especially under international law?)
I kindly ask you to stop believing that Russia is a place where unicorns shit with rainbow and courts work. No, they do not. And by not acknowledging putin's terror against us you literally deprive us of a right to become a normal country again one day.
(just in case, I didn't downvote the post above)
From my understanding of how copyright law works, if the local court determines that who a copyright holder is, international courts are required by treaty to uphold that determination.
Source: I'm from Russia.
https://twitter.com/AntNesterov/status/1205121533963841536?s...
That is why there is so little technological innovation in Russia, in spite of its being a huge developed country with a highly educated workforce (except, of course, for hacking). People with ideas know they will just be stolen, so they either leave them undeveloped or move to another country with real rule of law.
Securing control over the web server software (indeed popular for solid reasons) plays well into this lockdown objective and yields to the state a product that it would struggle to create on its own otherwise. Think of those failed attempts at creating a "national OS" to break dependence from Western originated Windowses, Linuxes, and macOS alikes.
0: https://www.usnews.com/news/world/articles/2019-05-01/new-ru...
- Never give work full rights to everything you make on your own time.
- Never use company hardware, software, time or offices to develop a side project you might want to monetize commercially later.
- Charge work a "1 node license fee" of $1 with an invoice and a standard commercial software EULA if you intend to try your creation at work. Also specify that it includes maintenance for the duration of your employment and that all modifications, including those made on work time and on work hardware, are your property and that they are granted a license to them for 1 node.
IANAL.
I agree with the first two though. I personally am leery of suggesting the use of my own products and services to a current employer, and would only do it if it's very clear that there's both not other great options and that there's not a conflict of interest (decision maker is in another department for instance) and recognize that I may need to quit my job to avoid the perception of a conflict of interest or legal issues with government grants or other awards that may prohibit employees from also being vendors.
It's definitely riskier than just not using your personal projects at work unless your employer is actively pursuing using it fully independently (ex: your project is the only good solution to a problem and it's unreasonable for your employer to be the only people who can't use it). But even then, I'm largely unable to do work that only I can possibly do (i.e. I worked on two projects as an independent contractor for my current employer before they were my part-time employer) for people in another department despite being part time simply because it's too much of a mess to get it approved. I could probably get it done, but it's a huge hassle and not worth it for $1.
But your current employer might also take major issue with you having a side business selling to their competitors stuff that they want to use, regardless of the technical legality... at the least you might get fired even if you've done nothing legally wrong it might be against their employment guidelines to do this if you're a full time employee. I specifically chose to be part time because I still do contract work on the side (and make more money doing that than I do at the part time job, but I really enjoy my part time job so I don't mind).
I think when it's literally "pay me one dollar for a company-wide license, so there's mutual consideration for license and it's clear what the arrangement is"... one does not need to worry about a substantial fiscal conflict of interest or appearance of impropriety.
I mean, it's a whole lot of work to squeeze one more dollar out of your employer ;)
What happens when you leave the company and try to increase the price to make a business out of it? Did you create a situation through the course of your employment such that the company you left is now dependent on your products? Would they have made different choices in what tool to use if it cost more at the time? Will even bringing up the idea of charging your employer cost you a lot of social capital with your supervisor and make you look like you're aiming to resign soon to work on a new project and aren't fully committed to your job?
Will they expect you to offer software for a $1 indefinite license including free updates for life or not including support or upgrades? Will they balk when your support or custom features cost $200/hr and cry foul? Companies are led by MBAs. They don't want to spend money and are very good at avoiding it at your expense.
Will they use their vastly larger capital to sue you for it, if indeed it is critical to them, arguing that if you felt it was useful enough to the company to sell it to them then it was part of your job responsibilities to work on it (excepting the case where you did the project prior to starting work at the company). Will you somehow be able to prove that it was done outside of work hours and relied in no way on your confidential knowledge of what the company does?
It's just messy and the potential for really really messy. You might manage to pull it off, but I personally would not try this unless the case was extremely clear cut and everyone involved knew everything so that no one could retroactively claim it was done in an underhanded way. But I was a boy scout so I learned that if you aren't willing to be totally transparent in your approach you probably actually don't think it's ethical. Clearly not applicable to today's top business schools, of course...
The discussion here relates to open source stuff. You give your company a bypass to the license agreement (attribution requirements, etc) in exchange for $1. That's a small business benefit, and in turn you create a clear papertrail of ownership with consideration. Yes, everyone would do this eyes wide open.
You can set the terms however fits the requirements of all involved. If you leave, they are an open source user like any other. Maybe they are allowed to redistribute without attribution, etc, indefinitely. Maybe it includes giving you the right to say that <employer> is using the package.
You do this when your employer already knows you tinker on open source, and a project is getting serious enough that it deserves to have its IP rights explicitly protected.
> Will they use their vastly larger capital to sue you for it, if indeed it is critical to them, arguing that if you felt it was useful enough to the company to sell it to them then it was part of your job responsibilities to work on it (excepting the case where you did the project prior to starting work at the company). Will you somehow be able to prove that it was done outside of work hours and relied in no way on your confidential knowledge of what the company does?
That's the whole point here-- you demonstrate that the company considered it yours at that point in time, and entered into a license agreement for it.
I have been on both sides of deals like this. Not all employers will do it, but it is a not-unreasonable way to protect everyone's interests and record what the parties considered the ownership to be at the time of employment. I've also sold company-owned code to an employee for $1 and an indefinite license because we didn't want to maintain it anymore.
Work for Red Hat? You own your free software contributions, even those made at work. Work for Google? They own even the small lump of green putty you found in your armpit one midsummer morning.
Many companies will apparently put in grab-all clauses but back down (but Google won't) if you call them on it.
Even in California, where a company can not own inventions done on one’s own equipment in one’s own time (as long as it’s not related to their day job), before signing an “inventions” clause, I am very careful to tag my GitHub repos with a date stamp before the date I signed the inventions clause, and only use versions of my open source software at work which I wrote before I started working for them (e.g. I have a secure password generator shell script, and when I use it to generate the dozen or so passwords I need to do my work, I use a version which existed before I started work at the company).
https://www.joelonsoftware.com/2016/12/09/developers-side-pr...
There is something very ironic about a blog posting claiming that a company owns all of the software a developer makes in their free time, running on an open source server initially developed in Igor Sysoev’s free time while he was working for Rambler.
Given that almost all media in Russia are subordinate to the state, a very small number of people find out about this situation and this is very sad.
First, lawmakers are crashing Yandex stocks, now this. It is sad that I live in Russia ...
Just wanted to note that it is not a very good way to gauge opressiveness or fairness... In a perfect world, charges would only ever be brought against the guilty, and only the guilty would be found as such by court. In such a World the ratio would be 0:<division by zero error>...
I agree on a perfect world scenario, but we in Russia have a big pile of ridiculous court decisions every month.
I would point out that the conviction ratio of the US is indicative of massive flaws in the powers that DAs have in most jurisdictions to force time limited plea agreements on defendants who have limited information and are under threat of charges with much higher penalties. This can usually be done without any oversight or approval from judges.
> In a perfect world, charges would only ever be brought against the guilty, and only the guilty would be found as such by court. In such a World the ratio would be 0:<division by zero error>...
That sounds like a world with complete surveillance, no privacy and a judicial system with absolute power. Doesn't sound like a perfect world to me.
It is usually 3 years for such cases, but it counts since the moment of time when alleged infringement was discovered.
The same happened to MySQL when Sun was bought by Oracle when MariaDB was forked - though I concede MariaDB isn't as popular as I hoped.
As it is, nginx is licensed under BSD - that would include the many contributions by anyone else (which cannot be claimed if the original project's copyright is found to belong to someone else) - so if the official nginx goes private but the BSD license is found valid, then the community can continue to publish their own "not-nginx" under BSD.
In a worse-case-scenario where copyright of the original nginx project are reassigned and the BSD license annulled, then the community need only replicate something resembling the original codebase that the community's subsequent (and fully legitimately BSD-licensed) patches/changes/commits can be applied to (though this will take some time) - so in either event, the prospective future "owners" of nginx cannot realistically hope to control the world of nginx deployments and the extended nginx developer ecosystem.
That has just been cast into doubt.
> copyright of the original nginx project are reassigned
Not reassigned. It would be found to never have been licensed.
> need only replicate something resembling the original codebase
Which is impossible without it becoming derived of the original. If you want to apply a patch to something it must first look like the original. A good chunk of the patches will have been derived from the original substantially. Which means they'd need to be rewritten too.
> the prospective future "owners" of nginx cannot realistically hope to control
Yes they could exert a lot of power and force people into paying. A clean-room effort would take a year! In that year they could go after everybody who is distributing old copies.
This is as bad as it gets if that company is found to own copyright.
I see this having only two outcomes: either nothing happens (it stays BSD), or it becomes nuclear waste, and new owner cannot sell it because it is plagued by mutually incompatible legal status of different portions of the code.
I can't see how the third version, where it stays clean, but the new owner can milk it, is possible.
The other patch authors could retroactively agree with the robber that their derived publications have been without license. Then they too could block usage of Nginx by pledging to go after anybody who gets a license from the robber.
If not, what's to stop other companies doing this in a predatory way? Start an "open source" project, gather years of valuable contributions from a enthusiastic community, then pull the rug?
Pulling the rug would mean revealing that your company never really owned the copyright, so at the very least you make yourself look bad.
Also, I don't imagine courts take a favourable view of transfers of ownership which are essentially fraudulent. I'm not a lawyer, as you can doubtless tell, but I presume it wouldn't be good for you if they could prove you'd planned the thing from the start.
There's an analogy outside of copyright: stolen goods. Sale of stolen goods isn't a legal transfer of ownership, but you don't want to be caught knowingly selling stolen goods, much less proven guilty of it (and the whole point of 'pulling the rug' is that things play out in court). I presume a similar principle would apply with intellectual property.
But since the project is under BSD license, they could make a case that they are allowed to use your changes (under that license). I'm not sure how that would eventually play out in court, though.
I would think that's more due to the huge boom in Postgres popularity than any failing of Maria. For the projects that do still use MySQL, all the ones I know of are on Maria or Aurora rather than the Oracle implementation.
Oracle has one goal, and that is to make money. They've realised due to the competitive pressure in this case that they can't abandon the community and go straight into value extraction mode.
It's all pretty arbitrary in my opinion -- if Monty and company hadn't whined so much when Oracle bought Sun, I doubt there would have been a fork.
Anyway... it never bothered me one way or the other.
Rambler used to be a somewhat successful and independent Internet company, but in dire straits recently because it's lost the market to its primary competitor - Yandex. So very much like Yahoo vs Google.
Now it's been bought out by Sberbank - the largest state bank run by a good friend of Putin. Sberbank is looking at becoming at becoming an IT monster, being a provider of just about everything - from food delivery to banking, with huge amount of Big Data at its heart. Delusions of grandeur at taxpayers' expense.
This lawsuit is the first big move of the new Sberbank's management team in Rambler.
(yeah, i know there's a pro version of nginx. never used it)
[1] - https://www.f5.com/company/news/press-releases/f5-completes-...
Clandestine ops have an extremely low probability of success using this strategy and nobody who does them is this incompetent. Especially not Russia.
To put the "over there" remark in context, I grew up in a neighbourhing country.
So in that respect it isn't that impressive that he stayed in Russia even when (mostly non-state) news became more and more disturbing. Probably even less so if you assume a line of reasoning that nobody would bother with relatively small foreign company built around open-source product, a company that's already sold to larger foreign company (conveniently forgetting about the price that F5 paid for that company).
(edit: s/american-registered/foreign/: Nginx Inc. was registered in British Virgin Islands)
Looking at the search warrant[1] the claim is that Nginx was developed while the author still worked at Rambler and during work time.
[1] https://twitter.com/AntNesterov/status/1205086129504104460
Introduction
nginx is one of the most popular web-server software, used by hundreds of millions of websites worldwide. It was written by Igor Sysoev in early 2000s, was released and is maintained as an open source software.
At the time of initial release Igor was working for Rambler (a Russian internet company). In 2011 Igor and his partners founded a BVI company Nginx Inc. to provide commercial products and support for the software. The nginx software remained (and still remains) open source. They raised some VC financing and in 2019 were finally acquired by a public company F5 Networks, Inc. for an impressive $670 million.
What has happened?
Today Igor and his partner Maxim Konovalov were arrested in Moscow and are being interrogated. A search is performed in Moscow office of the company. It became public that Rambler filed a lawsuit for breaking its IP rights on nginx.
It might look like a typical IP ownership conflict, but there are details: a) Worldwide internet infrastructure relies heavily on nginx. b) People are under arrest, which illustrates a serious intention and may lead to unpleasant consequences. c) It all happened some months after a successful acquisition, while Rambler was aware of nginx for more than 15 years since the date of the initial nginx release.
What's next?
It is extremely unlikely that Internet will meet any short-term consequences. No, there's no way to turn down nginx remotely, there's no backdoors, etc – so Internet is safe.
No, there is no chance that Russian secret service or someone else will use this situation to introduce some backdoors to nginx server. As any popular open-source software, nginx is developed by hundreds of independent individuals from various countries. The source code is always publicly available, and each developer is highly aware about security.
Long-term consequences are possible, including decline in nginx popularity and development of alternative software. If nginx will be forced to change its licence or shut down, it's very likely that community will instantly make a fork and/or a complete rewrite of this webserver under a new name (which has happened before to MySQL, for instance).
We all hope that this conflict will be resolved, and Igor and Maxim will be safe and sound. All we can do now is spread this information in as straight and clear way.
Source: https://roem.ru/12-12-2019/281134/rambler-nginx/#comment-292... (Russian)
location / {
add_header X-Supports "Igor Sysoev" always;
}I've read documents provided by nginx employee Igor Ippolitov, and I'm convinced Rambler is commiting a offence under article 306 of criminal codex.
In brief, in Russia an employee retains all rights on his/her/it's intellectual property if he/she/it was not instructed to do this job. Former Rambler CEO confirmed that Sysoev has no instructions to create a web server.
At the same time, Rambler claims that: "unknown person at an unspecified time acting within the scope of his duties and on behalf of management".
unknown person cannot have a scope of his duties. management cannot give orders to an unknown person.
google translate: http://translate.google.com/translate?hl=en&sl=auto&tl=en&u=...
Then the licenseing Igor put on it is null and void I assume, so everyone's instance would become illegal upon that court decision?
As such, they did not have the typical "We own the ideas you came up with in the shower" clause that most companies have.
Because of that, I was able to develop a fairly popular OS package (popular in a limited demographic, so it's not "A-List").
https://threadreaderapp.com/thread/1205086129504104460.html
TLDR: Igor Sysoev started Nginx while employed by Rambler, who did not then claim copyright, but now they have. The police raid is a result of that claim.
/sarcasm
Both cases are quite similar to my eye.
There is also Caddy, a go based webserver, which is Apache licensed I think. [2]
Then there is also lighttpd, which is small and fast, but 3-clause bsd. [3]
If you want simplest non-bloated and secure - OpenBSD's httpd is absolute king.
But for many generations of IT people Apache had (and still has) that nice homey feeling.
One of Best things that happened to IT world.
Edit: s/https/httpd :-) bloody phones and their "smart" keyboards
Software developer got greedy, rich and robbed by state actors.
Should have contributed to Apache instead.
as in "we would comply if we could but you guys scared the system and it hid, we have to wait until it comes out again"
Don't know that many swear words in Chinese, but I know that that "ginks" isn't really pronouncable in Chinese. You could do "ging", but the "k" and the "s" would then need to be separate syllables; the best you could get is "en ging ke se", which isn't really close enough to "N-ginks" to be dangerous.
(Similarly, "golf" ends up as three syllables: "gao er fu", plus "qiu" added to the end to clarify that it's a game involving a ball.)
> How do you pronounce “NGINX”?
> Correct: en-juhn-eks, Engine-X
> Incorrect: en-jingks
I wouldn't be surprised if it's actually an abbreviation of "engine-x", but I can't find any better source that explains how they came up with the name. Still, this source pretty much implies it.
[1] https://www.nginx.com/resources/wiki/community/faq/#how-do-y...
> nginx [engine x] is an HTTP and reverse proxy server, a mail proxy server, and a generic TCP/UDP proxy server, originally written by Igor Sysoev.
location / {
add_header X-Supports "Igor Sysoev" always;
}