PolyForm Noncompete Licenses
writing.kemitchell.com
writing.kemitchell.com
The funny thing is that they are trying to protect themselves from Amazon and other competition before it usually exists, and that in reality, they are doing themselves more harm because the big co lawyers are starting to reject these unusual, project specific license. "If it takes more than a few minutes to understand, then I tell the devs No"
To all those would be users of the Faux Pas OSS licenses, why did you make it open source in the first place? If you want to protect your code, why no make it private? Why use one of these licenses?
Of course, they also likely don't get the development model advantages of open source but anecdotally these companies don't much care about that. (And TBH a lot of single-company products/projects don't get a lot of outside contribution anyway.)
But, yes, "Why doesn't the AGPL solve your perceived problem?" is a reasonable question to ask in the context of these non-compete licenses.
Success in advising these companies on crafting a license does not imply that the project or their choice to embrace this style of license will result in success. If they still call themselves open source, they are lying. The proper term is "source available."
No license guarantees success in any dimension. Not MIT. Not BSD. Not Apache 2 or GPLv3 or WTFPL or any of the PolyForm terms. Most open source projects, as I suspect you define open source, fail. Very little uptake. Very little outside contribution. Net loss, financially speaking, for the developers.
You're free to argue for or against whatever meaning of "open source" you like. But disagreeing with you, or refusing to accept the brand you'd force on them, does not make anyone a liar.
I was quite doctrinaire about the issue myself, for many years. It wasn't until I got beyond reading what the OSI said about itself---parsing the OSD, reading its history, dealing with the mailing list process, seeing the shifts in FSF position, reading up on the "open" buzzwords wars before 1998---that I realized the "right answer" I was so proud of having wasn't so right and rigorous, after all. I regret how badly I treated others, for the sake of my own feeling of "correctness".
We do have organizations that observe the actual usage of words and attempt to capture their use descriptively. Here's a fairly well-regarded source: https://dictionary.cambridge.org/dictionary/english/open-sou...
It is inaccurate to call someone a "liar" for something that falls into the realm of opinion.
Personally, I don't care what OSI says, though I do care very much what some of the individuals involved in it say. My clients occasionally care about OSI approval, but far less than you might expect.
I've also been a part of drafting licenses that I suspect nearly anyone would call "open source". The Blue Oak Model License, for example. I won't be submitting those licenses to OSI or FSF. As far as I know, none of the other folks involved in drafting them care to waste their time on that process, either.
Essentially, it will be an uphill battle for companies using these license to claim they are part of the open source community. Just because you are on GitHub doesn't mean you are COSS. I now consider Microsoft to be the biggest COSS company.
Is CC0 (not OSOI approved) software open source? How about AGPLv3 (approved)? Ethically licensed software (in process)? BSD/MIT (approved) code from standards bodies under separate patent? Adaptive Public License (approved) software that explicitly opts out of patent coverage? NASA's latest license (not approved)? RPL 1.5 (approved by OSI, not by FSF)? Apache 2 (approved) API wrappers that only talk to closed cloud services? WTFPL (not approved)?
I've released noncommercial licenses, avoided calling them "open", had others do so quite despite me, then hear, basically "I know, and I don't care" when I pointed it out. On the other hand, I know people who don't think copyleft counts as open source, or shouldn't any more.
There is a kind of lowest common denominator of sorts around MIT, BSD, Apache 2.0, maybe Artistic 2, assuming no patents. Some would add GPLv2, LGVPLv2.1, and maybe MPLv2 and EPLv2, for copyleft. All of those licenses have well known legal and practical limitations. Some are truly ancient, like MIT and BSD, and wouldn't be considered competently drafted now.
Free as in speech, without bias or contempt of others, will win in the end (I hope). This is why FSF "free" software (strong copyleft) is different from "open source" and they have different governing bodies. We are already seeing a pull back from copyleft and the overreaction the other direction (to non-compete) will both lose out to best in class humanity found in truly "open" source ideas.
Definitions are evolving, people will abuse language for personal gain, and the world goes on.
I am personally hopeful that open source will gain a wider and more pure definition beyond software and licensing. Like GitLab, transparency, and their handbook, or the maker movement and DIY / distributed / local production.
My license choice (of BSD-3) was based on the projects I work most closely with. (Golang / Cuelang)
- Companies are trying this out, like it's the best way forward, but we don't really know. We are seeing push back now. - Corp lawyers are defaulting to "No," one of the big COSS trying this out reverted after their license denial, Amazon open sourced their ES tools - Google and Microsoft have partnered with the big COSS companies to offer their products as a seamless experience (literally right next to Google products in the GCP UI with the vendor logos) - With the increasing ease with which software is being created, and in particular SaaS platforms, the license and interface defenses may quickly be replaced by open source alternatives. (re: Joe Jacks talking about COSS eating SaaS)
So we will see how this plays out. I am personally staying with BDS-3 Clause for our open source code and keeping other parts private.
> PolyForm is not Open source or free software. There are plenty of existing open source licenses. PolyForm is not a substitute for them, but an alternative for those who want to license source code under limited rights.
My opinions still voiced, substituting PolyForm for licenses which are of the offending nature I describe.
How is any of what you write above a problem? If the big companies are willing to pay me, then I'll sign whatever commercial license they want--and if they're not, how does it benefit me for them to use it for free?
Big tech companies have done an incredible job of harvesting the value of free software developers working for free. I don't see why a license that makes that harder for them is bad, except for the big tech companies. Perhaps defining "competitive" will be too mushy to make these licenses practical for anyone, but I appreciate the attempt.
What I can say is that the Defensive license comes from folks who deal with M&A, noncompetes, and resulting complexities all the time. 1.0.0 has a number of provisions addressed to potential operational and structural changes that could affect scope:
https://polyformproject.org/licenses/defensive-licenses/1.0....
https://polyformproject.org/licenses/defensive-licenses/1.0....
https://polyformproject.org/licenses/defensive-licenses/1.0....
My own personal view is that the 1.0.0 terms will be perfectly well recommendable for a great many companies and use cases starting today. But also, emphatically, that any set of terms can be improved, especially in how they interact with external sources of complexity, like the corporate laws. I hope we'll see 1.0.1s and 1.3.0s and 2.0.0s and beyond for all the PolyForm licenses.
If anyone is or has the gas to contribute to those conversations, please reach out: https://polyformproject.org/contribute/
Let's say a database gets licensed under the defensive license by $CORPORATION_0. And let's say that $CORPORATION_1 makes many contributions to that database under the same defensive license (where they retain copyright). A little weird, but presumably both companies are comfortable with the situation.
Let's then say that $MEGA_EVIL_DB_CORP buys out the contributor $CORPORATION_1, and now $MEGA_EVIL_DB_CORP owns the copyright and has competing databases.
I'd assume both companies can no longer use the defensive licensed DB. Meaning all Oracle has to do to destroy the competition is buy whichever company is cheaper.
That seems like a bad attack vector.
Though he recently told me that he thinks all OSS should bootstrap and never take investment, which doesn't exactly align with top COSS co spreadsheet he also maintains.
Steph and I have been breaking things down from our chat, and basically came to the same conclusion, though often favoring closed source where one might GPL/NonC license that crust around the core. Also that outside investment is to add fuel to an existing fire, COSS or fully private makes less difference than showing you've built something people want.
Do you have any new videos or podcasts? Always love to hear your thoughts, you put things very succinctly!
I appreciate attempts to standardize the law, and make it more accessible and cost-effective to rely on.
Hmmm, guess there are issues though
Publication of standardized legal building blocks is a big passion of mine. I think it's essential, both for the good of law clients and for the mental health of their lawyers, that we do a lot more of it. Besides PolyForm, see also:
I'm not sure any of these "non-compete" licenses have been rejected by the OSI. I'm pretty sure at least some of them haven't been submitted because they almost certainly would fail to be approved.
But to be clear, anyone can claim their license is an "open source license" just not that it's an OSI-approved license if it's not.
This is one of the top results when searching
See cal civ code section 16600: "... every contract by which anyone is restrained from engaging in a lawful profession, trade, or business of any kind is to that extent void"
I also found an unpublished opinion from SCO Group, Inc. v. Novell, Inc., that deals with a similar issue that also makes me think that this software license could work:
> The license in the APA and the TLA does not preclude Novell from pursing its business. Rather, the license merely restricts Novell's ability to use SCO's property and is part of an ongoing relationship between the parties. Therefore, the court finds that there is no restraint on trade and the restrictions are not void under Section 16600.
More precisely, using software written with these licenses would be something I would never do, either in an Open Source project or a commercial project.
Consider for example the 'Patent Defense' section of the Polyform Defensive license. If I am reading this right then if you have a patent and use Polyform Defensive licensed software from Example,inc. to the point that stopping using the software is a major hardship, then Example, inc. can infringe on your patent and be safe because you won't risk losing the right to use their software.
Or the 'Sales of Business' section. Let's say Example,inc. is building a blog hosting platform and Open Sources a library for an image carousel under Polyform Defensive. Exemple SA start using it for their Computer Based Training site. Later Example,inc. enters the CBT market. If I am reading this right then Exemple SA now has to either stop using the software, or leave the CBT market - and might not even have a choice about leaving the CBT market.
A lot of work has gone into making useful and effective Open Source licenses that benefit both sides when a company open sources their software (software user and the company making the software). A company has a range of protectiveness they can choose: Affero GPL, GPL v3, BSD, MIT, Apache, EPL are some well known ones [1]. Why do we need the PolyForm licenses, especially when they seem to me to be several steps back toward the dark ages of commercial licenses, and being so ambiguous you need a lawyer to evaluate it every case.
You also have the question of legality in every region. Aren't noncompetes heavily restricted in California.
I also am of the mind that 98% of noncompetes and NDAs are hubris and unnecessary, other than to use as a collar to retain employees. Better to retain through incentivizing than threatening. And also, ideas are a dime a dozen..most people are not going to steal your idea as it's the execution and the funding backing it that will make the difference.
Lastly, a key thing to not is that the Polyform Project itself says these are not Open Source licenses[2]:
PolyForm is not…
Open source or free software. There are plenty of
existing open source licenses. PolyForm is not a
substitute for them, but an alternative for those
who want to license source code under limited rights.
There are Open Source licenses out there that legal experts state will protect you, whatever your range of needs if you are willing to abide by the Open Source ideals[3]. Why not embrace the Open Source movement, instead of saying mired in the past?[1] https://en.wikipedia.org/wiki/Comparison_of_free_and_open-so...