Microsoft now credits maker of AppGet but offers no apology
zdnet.com
zdnet.com
The "Andrew" in question who courted Keivan (AppGet's dev) is Andrew Clinick. He wrote a blog post in response to this a few days ago:
https://devblogs.microsoft.com/commandline/winget-install-le...
Still seems pretty tone-deaf to me - obviously MS seems to be in the legal clear, but the moral high ground and lots of dev goodwill has been lost.
It also damages the ability for devs to informally meet and chat with PMs at larger companies everywhere - adds a lot of mistrust to the eco-system.
This is not that MS came up with their own package manager. It's the entire song-and-dance routine that was conducted about potentially hiring Keivan, and then ghosting the engineer whose open-source product you were simultaneously cloning.
Of course, people will forget, but many will still remember. This is still a net-negative all-around when it didn't need to be.
Edit, this ZDNet article adds no new information and nothing has changed since the other articles have come out, but I guess it's good that more places are covering it to signal boost this properly.
https://github.com/microsoft/winget-cli/issues/353
Disclaimer: I opened that issue
And credit for what? Unoriginal ideas that have been around forever?
They didn't even build WinGet in the same language as AppGet!
You can see the rest of my response to the top comment here - https://news.ycombinator.com/item?id=23377936
Regardless of that, I'm guessing he didn't engage them in dishonest attempts to hire them just to learn more about their ideas and then walk away.
I was replying to someone who only regarded the point of the credit.
> I'm guessing he didn't engage them in dishonest attempts to hire them just to learn more about their ideas and then walk away
...allegedly.
The onus of evidence is on you. Until then, we can safely assume cock-up before conspiracy.
Many, many big companies don't call you back after an interview and we all know this.
How so? It was an interview for him to bring AppGet in-house to Microsoft. That's normal software business.
Honestly, based on what this Keivan said - I think he scared Microsoft away with his demands that they take the project only in a direction that he approves of.
And when they went away, they took some of the most banal ideas, ideas that have been done a thousand times in other projects and used them in their own - which they built in a completely different programming language with exception to the very, very common YAML configuration.
> Second, be honest; do you have any stake in the game yourself? Do you work for microsoft?
Nope. People who disagree are simply wrong and I'm attempting to correct their ill-formed point of view.
Meanwhile, you're shitting up the comments with this trashy ad hominem insinuation of shilling. It's against the rules and you should stop doing it - https://news.ycombinator.com/newsguidelines.html
- we released a thing
- yes we spent time courting the guy who made a version of the thing that ours looks suspiciously like, turns out he’s really good
- well yes our thing has a lot of features taken from the other thing!
- we’re excited for the future!! Maybe that guy can even help us out since he loves open source so much hahaha
Tone deaf at best, implied fuck you at worst.
If they really want to fix this, they need to pay AppGet's author some money, and get something in writing so they are legally protected from copyright suits. I assume they're negotiating this right now, and that once this deal is done there will be another blog post that is more genuine.
They really messed this up because it would have been cheap to get something in writing before releasing WinGet. Someone at microsoft legal dropped the ball.
If I gave credit to everyone who influenced the code I write, the file would be huge. Does the world have enough disk drives to hold all the credit where credit is due?
decency, morals, thoughtfulness, that kind of thing
> If I gave credit to everyone who influenced the code I write...
They directly ripped it off.
Big companies will try not to pay even when they have money. To not even give the minimum of non-monetary credit is even less reason for me ever to release code under a "what's mine is yours licence".
No, they used some very common and unoriginal ideas that were implemented in AppGet.
Can you point out exactly what was "ripped off" here?
- https://github.com/microsoft/winget-cli
- https://github.com/appget/appget
They're not even written in the same language. And everything done in AppGet has been done before. Yawn
> Big companies will try not to pay even when they have money.
I will try not to pay, even when I have money. I think this applies to most people. Who wants to pays for something that's already free? I'm not running a fuckin charity over here.
> To not even give the minimum of non-monetary credit...
They've given it.
However, I wonder if during all of this Keivan has credited Microsoft for all of the open source tools, services and frameworks that he's used in his other work???
from his blog
"When I showed it to my wife, the first thing she said was, “They Called it WinGet? are you serious!?” I didn’t even have to explain to her how the core mechanics, terminology, the manifest format and structure, even the package repository’s folder structure, are very inspired by AppGet."
> I will try not to pay, even when I have money
Then people like you will kill off exactly the things they leech off, by pissing off those people who made them from their goodwill.
> However, I wonder if during all of this Andrew has credited Microsoft for all of the open source tools, services and frameworks that he's used in his other work???
I don't know, has he? Why raise the question instead of answering it.
You're curiously willing to defend microsoft.
How many products have "Git" or "React" in their name? Does everybody accuse these people of ripping off Linus Torvalds or Facebook?
> Then people like you will kill off exactly the things they leech off, by pissing off those people who made them from their goodwill.
Because I don't want to pay for the air that I breathe?? Mmkay.
> I don't know, has he? Why raise the question instead of answering it.
You should be answering it because you're the one accusing Microsoft without knowing the whole story.
> You're curiously willing to defend microsoft.
Whenever I see imbalanced, ill-informed or illogical conclusions I speak out against them.
This is "ripping off" now? Maybe they did steal it wholesale, maybe not, but I haven't seen any evidence (nay, even allegations) of it.
The allegation is right there. His blog. Which I quoted from. But didn't link to, so sorry, here it is https://keivan.io/the-day-appget-died/
https://help.ubuntu.com/community/AptGet
I wonder if he mentioned his name was inspired by the extremely more well known and 22 year old default package manager in linux that happens to be called apt-get.
I mean honestly if he's saying that as justification in his blog post, I'm immediately off his team. That's insane. Obviously a layman would think the name was ripped off if they didn't know about apt-get.
I compared the manifest format, that's different terminology. And WinGet has more insightful supports, e.g. MinOSVersion, License, LicenseUrl.
And the folder structure is different also. That's per version per file on WinGet but single YAML on AppGet. I'm pretty sure his wife can't handle that if she is not a developer.
"Core Mechanics" => It needed more proof.
If Beigi was smart he would've asked them to purchase the copyrights as he's the only one legally entitled to do so.
If he's developing his software altruistically he should be satisfied with his credit, well knowing that his project will now be overshadowed by Microsoft's and will eventually pass into oblivion and be forgotten.
edit: This is explicitly not a judgement of ethics.
That Microsoft didn't do any of that indicates that they do not believe that WinGet is a derivative work of AppGet under copyright law, so the copyright license granted by the Apache License is not needed.
ETA: That is, Microsoft believes they don't need a copyright license. My personal position is that I would have liked to see a proper fork under the ALv2 with attribution, which would have avoided all this mess.
You have to adhere to the terms of the copyright license granted in this case by upstream License. If you do not, you lose the copyright license and the ability to redistribute under any terms.
Maybe you're thinking of license subsumption? That's when (say) a project under a more restrictive license (e.g. Apache License 2.0) bundles a dependency which is under a more permissive license (e.g. MIT), yet the package is advertised as being under "Apache License 2.0" even though the licensing is polyglot.
But even under subsumption, you still don't get to do things like removing copyright notices or declaring unilaterally that somebody else's work is now under some new license they didn't grant. The license headers in the bundled dependency's source files don't get modified, it's just that you summarize the terms of the complete package because fulfilling the terms of the ALv2 suffices to fulfill the terms of the MIT license. (Sort of. License subsumption is a complicated issue.)
- https://github.com/Lutando/Akkatecture/issues/19
- https://github.com/Grover-c13/PokeGOAPI-Java/issues/490
- https://github.com/dsiguide/dsiguide.github.io/issues/14
Such problems do not end up in court for two reasons.
First, it costs very little to bring a project into compliance with a permissive license — all you need to do is give attribution. It's not like GPL enforcement, where you have to choose whether to open source your proprietary code or to purge the GPL'd code from the project in order to achieve compliance.
Second, the culture of permissively licensed open source communities is such that they don't generally want to foster a litigious environment which would frighten business users.
AppGet is released under Apache License 2.0, Winget under MIT, I'm not sure how copyright would be an issue.
AppGet's author addresses that point here
https://keivan.io/the-day-appget-died/#edit-to-clarify-some-...
It was well-received on GitHub. 15 thumbs up, 3 thumbs down. This is in a thread where people are showing a lot of support for @kayone.
https://github.com/microsoft/winget-cli/issues/353#issuecomm...
Side note: It's amusing that @aclinick doesn't have an avatar on GitHub, given these three facts: 1) @aclinick works for Microsoft 2) GitHub is a Microsoft property 3) LinkedIn is also a Microsoft property and has a very strict avatar policy
Nobody should get fired (Keivan himself said so in the Github issue), but now that there is some public attention on this, let the parties involved find an amicable way to resolve it their own satisfaction.
This is bullshit. Keep him quiet with the hope of a job (embrace) until they release their version (extend, extinguish). Changing CEOs doesn't change everyone who works there.
They did string the developer along, but I'm not sure it was anything nefarious. I think the people at MS who were looking to acquihire Keivan ran into roadblocks at MS from higher-ups for whatever reason and it just fell apart. It probably wasn't a nefarious strategy to string Keivan along in order to boost their WinGet announcement - but just general inconsideration and rudeness in not communicating.
You have clearly embraced EEE, but now you are extending it way past what it actually means, and if people like you continue you will extinguish it because it will not mean anything anymore.
Please don't EEE EEE.
Agreed and also this AppGet story wasn't EEE anyways. It was just a plain good old "Fuck you". There was no embrace or extend at any point :)
EEE refers to a specific business practice that is not related to this story at all.
You can use other words in the language to convey that this particular move from MS is a dick move without having to use EEE. And reserve talking about EEE when it is actually relevant.
Using it all the time just completly dilute it until it becomes totally meaningless.
They've invited Keivan to their headquarters with a bait, giving him the wrong impression that they wanted to help him with the project when really they wanted to extract valuable information from his experience. He's been working on AppGet for a while, ran into issues, thought about problems which users are having, dealt with certain challenges and iterated until he got to a certain understanding/vision of his product. This is all very very valuable information not published anywhere in an open source thoughts database. It's just the experience and knowledge that only lives in Keivan's head and Microsoft knew that they had to bait him with some false promises and hopes in order to get access to that information which he might otherwise not have shared with a competitor. Also they didn't forget about Keivan. They knew what they were doing. At the beginning of the process someone put in their calendar to contact him the day before BUILD 2020 to send him this email, which is why he got the email the day before the announcement of WinGet. This was no coincidence.
That is fraud in my opinion. Who cares about his source code, they stole much more valuable stuff from him. Anyone who doesn't see that is ignorant or blind.
Keivan should take legal action.
> Unfortunately, I don't see what legal action to take
Good for you. Someone else might still feel differently and want to check with a legal advisor to explore their options.
It is a massive ball drop from MS, but there is nothing illegal about it.
The Apache License 2.0 requires attribtion!
There's definitely things to gain from talking to the author of the project, but seems a bit reaching to suggest they wouldn't have been able to do what they did without talking to him. And it seems like a particularly pessimistic read to assume they were just lying to him outright to pull from his experience. Very little to gain from being a shark in this scenario, tons to (potentially) gain from acquiring an existing package manager. Gotta follow the incentives.
It's also worth mentioning that he mentioned the name similarity in his post in this way:
> When I showed it to my wife, the first thing she said was, “They Called it WinGet? are you serious!?” I didn’t even have to explain to her how the core mechanics, terminology, the manifest format and structure, even the package repository’s folder structure, are very inspired by AppGet.
He did not go on to mention that his own name was (nearly certainly) inspired by apt-get (stylized as AptGet on Ubuntu[1]). Implying he was the originator of the name [X]Get for a package manager seems aggressively dishonest, to the point that it throws his entire side of the argument into question for me.
I haven't looked thoroughly into the code, but this feels like someone who was expecting something to come out of his hard work and is (understandably) bummed it will now likely amount to nothing. I have trouble putting much blame on Microsoft for that.
And is the assertion that Microsoft took code from AppGet as part of WinGet? The fact that the word "copied" is in quotes makes me wonder what the beef is... and did anyone ask the APT team if they feel ripped off by the existence of Windows package managers?
So it's an opinion, one that the WinGet team decided to go with as well. Okay... not sure that's massively compelling just because the author says so but I'm willing to be convinced. I guess I need to go back and dig deeper on this scripting being referenced in Chocolatey: isn't it just powershell scripting?
Having something like YAML seems cleaner than the Chocolatey approach, but there are almost 8,000 Chocolatey packages and it works pretty well. Implementation > architecture here.
There are still too many nasty installers out there, I'd be very worried about the ability to do what I need without a full scripting language at hand.
https://chocolatey.org/docs/helpers-install-chocolatey-packa...
I think his complaint is they copied the functional interface.
"We have already talked with a few of the well-known package manager teams...." https://devblogs.microsoft.com/commandline/windows-package-m...
In my point of view, they do the comparisons and created their own product. The interface is too basic.
The worst infringement as far as I'm concerned is that MS tricked him into giving up all his secrets before they implemented it themselves.
If Microsoft ever came to talk to me about one of my projects the only thing I'd tell them is: "How much?" (are you willing to pay for it).
It's a shitty situation for him, but that's just life. Sometimes it sucks.
Agreed; reading the article makes it sound (to me) like they copied his "idea" rather than actual code.
Better names?
As someone who does not install a lot of things on my Windows systems, if I got a package manager named Chocolatey to install something I'd have trouble remembering the name the next time I want a package manager six months later. I'd remember that I already installed a package manager, but not what it is called.
AppGet I'd remember. I might look for it as app-get the second time, but would quickly remember it is spelled a little different than the Debian program. WinGet would be a little harder, but I think I would remember it.
Seriously, I'm getting a bit tired of programs whose names have nothing even remotely apparently related to with what the programs do.
While on a bit of a rant about names, what the heck is up with the naming of backup programs? There is Duplicacy, Duplicati, and Duplicity. Part of the reason I went with Arq was I kept getting those three confused with each other when reading reviews and comments.
Sure, you might not immediately think "backup" when you hear the name "Arq", but at least there is not also an "Ark", "Arque", and "Ourk" backup too.
People who decide to "work together" should carefully read and understand the terms under which they're doing so:
https://opensource.microsoft.com/pdf/microsoft-contribution-...
Because you sign your code over to them, they are free to CLOSE SOURCE future versions at ANY TIME.
Sure, you could attempt to fork, but the platform is proprietary and can lock you out (very likely in this case for "user security"). They are the biggest company in the world (by market cap) and those deep pockets mean they can outspend you until you go under or fall too far behind. It wouldn't be the first time.
This is a "thank you", not an apology. But, at least it is better that what they did last week.
Not apologizing doesn't make them less wrong. It just means they are covering up whatever they did wrong.
Wealthy entities (including even moderately rich humans) can't admit error for legal reasons. That seems like a recipe for continued abuses, frankly. I'd like to see that changed.
> Usually, apologies are admissible into evidence. Admissability into evidence does not necessarily mean useful as evidence of guilt. Since an apology usually can be admitted into evidence, and because some plaintiffs choose to understand an apology as an admission of guilt, it seems safest not to apologize. Case law suggests, however, that courts do not see it this way. Judges and juries seem to like apologies and treat them favorably. Often, an apology does nothing to satisfy the plaintiff's burden of proof. In some proceedings, an apology can be a mitigating factor, and the lack of an apology can be an aggravating factor.
and concludes:
> This article illustrates that judges and juries understand that expression of sympathy, regret, remorse and apology are not necessarily admissions of responsibility or liability. This serves the public interest because such expressions have the potential to reduce the number of lawsuits, rather than attract litigation. When someone goes to court armed only with an apology, they may find that it does nothing to satisfy the elements of the case they need to prove. Additional evidence is required, almost as if the apology did not exist.
Cool.
[1]: https://scholarship.law.missouri.edu/cgi/viewcontent.cgi?art...
But the lack of UI to browse/search I think is too lacking so I put this up a few days ago: https://wingetit.com -- I imagine Microsoft is going to copy/replace this soon, but I won't mind.
That being said, I think it's likely a loss for Microsoft: Keivan obviously had thoughts they considered of value, and he probably would've been a solid hire. The PR hit from this probably costs them more than a year's salary for an engineer, so they probably should've considered the risk here. The fact that Microsoft engaged in a "dick move" is obvious, and for what? Something that feels like a tack-on side project by a couple of Microsoft engineers, that'll probably never graduate to mainstream adoption?
https://github.com/microsoft/winget-cli/issues/353#issuecomm...
So far I don't see @aclinick or @kayone addressing the later note. I see 15 thumbs up and 3 thumbs down plus a thumbs down from ZDnet. I happen agree with the 15 thumbs up that the blog post is a step in the right direction. It's not what is typically considered to be a non-apology.
0: https://github.com/microsoft/winget-cli/issues/353#issuecomm...
It likely got no views because the title is worded in such a way as to avoid the actual topic at hand. Given how it's written, my gut is that it was titled to avoid being picked up, so I'm glad a news source caught wind and is calling them out with an appropriate title.
Perhaps devs should upload every package with a readme that includes a reminder for developers, something like:
"This package is dedicated to Keivan Beigi. Read more about what Microsoft did to Kevin here: thankyoukevin.com"
Any better ideas?
In most areas tool choices are less about objective benefits and more based on familiarity/popularity/etc.
Whether this is planned or not I don’t know, but as they are putting this in the App Installer package right now which also has a public API I would not be surprised.
It would be one thing if there were trying to to hide it with closed source, but this was stupidly evil out in the open.
That said, I basically agree with you. If you have specific expectations of whoever uses your code, you should absolutely pick a license that requires the behaviors you want. (With the understanding that fewer people may use your code as a result.)
You speak of academic code, and precisely some projects require (or at least ask for) citations in their license file if use in a research context.
Of course you can copy someone's design and not acknowledge it unless it's patented. You're going to be a dick then, not a criminal.
Of course if your goals are different it is the wrong license, but that isn't the fault of the license or Microsoft from using it as intended.
Note, I have not read the apache license in a while. I might not have the exact details of what it encourages wrong. The point should stand anyway.
Incorrect. See clause 4, especially 4.c.
https://www.apache.org/licenses/LICENSE-2.0.html#redistribut...
> c. You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
In the case of WinGet attribution was theoretically not required because the code was not copied directly, so a copyright license was not needed and the Apache License did not come into play. (Of course if AppGet's creator had Microsoft-level lawyering available, he could quite possibly persuade a court that copyright infringement did occur.)
But the Apache License 2.0 absolutely does require acknowledgment!