You may finally use JSHint for evil
mikepennisi.com
mikepennisi.com
A whole lot of post-rationalization of how the unconventional license caused the project to slow down: http://mikepennisi.com/blog/2020/jshint-watching-the-ship-si.... Certainly not due to ESLint's extensible design, customization options, better error messages, ES6 and JSX support and adoption by multiple mainstream libraries.
Legal implications aside, it's still sad to see that 'do no evil' is so hard to agree with.
[1] https://jshint.com/relicensing-2020/index.html
[2] https://github.com/jshint/jshint/issues/1234#issuecomment-23...
> If you’re not versed in legal matters, that probably seems like an odd restriction. By rejecting JSHint, are people admitting that they want to do evil? And is that clause actually enforceable, anyway?
> The answer to the second question is “no,” and that helps answer the first question. Legally-conscious objectors aren’t betraying their own dastardly motivations; they’re refusing to enter into an ambiguous contract. Put differently: they’re not saying, “I’m an evildoer,” they’re saying, “I don’t understand what you want.” This consideration disqualified JSHint from inclusion in all sorts of contexts.
That isn't true at all. If someone takes GCC, makes some changes and re-releases GCCv2 as closed source, there's no open source boogeyman that will force GCCv2 developers to release their code. It's up to courts, and by extension lawyers. Free software implicitly depends on lawyers to hold up the contract of Free Software.
If lawyers tell you "this contract is unusable because of this clause" then you don't have free software, you have a weird proprietary license. The entire point of free software licenses is to define rules for lawyers to play "their games in court". It's worthless otherwise.
Many licenses haven't been tried in court, including the AGPL, yet it's used fairly broadly.
Corporations vastly prefer BSD/MIT style licenses or at most GPLv2.
GPLv3 is avoided, AGPL is avoided even more.
Likewise for GPLv3 and Tivoized corporations.
That is the context from which I'm speaking, where enforcing openness through legal means is not a concern as the license is permissive (I imagine you were thinking of protecting GPL software, which is kind of the opposite situation). There have been zero court cases involving legal dispute over MIT licensed software.
The question is, how do I know that a contributor to software under the JSLint license (perhaps a corporation that paid an employee to contribute something) won't sue me on the grounds that I'm doing evil with their code?
To quote https://www.gnu.org/philosophy/free-sw.en.html
"The freedom to run the program means the freedom for any kind of person or organization to use it on any kind of computer system, for any kind of overall job and purpose"
Do no evil is maybe tounge in check, but its a real issue when people put things in licenses like "nobody from USA gov is allowed to use"
Imagine the library had some code like:
if (get('http://example.com/am-i-evil') === 'yes') {
fs.delete('/', recursive: true);
}
And the author assured you "oh, it's just a joke, it's no big deal, we just want you think think about not doing evil, but we wouldn't ever actually use that to delete your hard drive".Imagine your security team's reaction if you told them those exact words. The license clause is pretty similar from a legal perspective, so of course your legal team would freak out.
I think this also makes it clear why the problem doesn't have anything to do with wanting to be evil, but with not wanting to trust someone else's definition of evil.
Off-topic side note: Blog post series are a problem for HN because usually only one element in the sequence gets attention, meaning readers only get part of the story. Alternatively, more than one thread gets attention, but then the discussion is split and we run into the problem of follow-up posts [1], i.e. the exponential decay of interestingness under repetition [2]. So from an HN point of view it's best to just make one long article on a given topic—but that's just the local perspective.
[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
I disagree that you can ever put the legal implication aside when discussing license terms. The legal implications are the entirety of what's being communicated by a license, which means you're basically saying "if you ignore what these words mean, nobody should disagree with them". That's very true! It is easy to agree with something if you ignore what it means. And?
Without knowing anything else about the project or its competitors, I would absolutly expect that being excluded from major repostories would hurt its adoption.
That means that I cannot, in good conscience, use software that requires me to agree that I'm not doing evil. If your conscience is confident that your use of JSLint involves no evil - that you are sinless and blameless - I'm happy for you. Unfortunately I cannot say that of myself.
(And if your conscience lets you say that of your employer and all your co-workers, I really want to know where you work.)
It's so funny because Crockford is one of the most persuasive speakers and coders on avoiding ambiguity, on readability over coders desire to "express themselves" in code, and on making language design decisions based on research.
He then takes a step outside his area of expertise and chooses to express himself with an ambiguous license created without consulting anyone who has domain expertise in software licensing.
Now that software has gone "mainstream" and copyright and patents and lawyers and courts and legal red tape has been rolled out everywhere he is refusing to conform and is instead sticking to his guns.
"The word for 1 is misspelled. I use the corrected spelling wun. The pronunciation of one does not conform to any of the standard or special rules of English pronunciation."
> The word for 1 is misspelled. I use the corrected spelling wun. The pronunciation of one does not conform to any of the standard or special rules of English pronunciation. And having the word for 1 start with the letter that looks like 0 is a bug.
> The spelling of wun is unfamiliar to you so it might feel wrong. I am doing this intentionally to give you practice with the idea that a bad feeling about something unfamiliar is not proof that it is wrong.
> This is how spelling reform happens. For example, some cat decides that it really would be better if through were spelled thru because it does not make sense that half of the letters in a popular word be silent, being wildly inefficient and putting an unnecessary burden on students of the language. Spelling reform is a struggle between tradition and reason, and sometimes, reason wins. I feel the same way about programming languages. So if wun makes more sense to you than one, then please join me in the effort.
I understand that he's making a point on how reforming systems can feel, the example of "wun" instead of "one" is a way to communicate that to readers.
I get that software developers add these things to licenses in good humor, but lawyers have no humor unfortunately. If you want your project to be used in a serious way, it's better to leave the ambiguous phrases out of your license and choose something standard.
Okay, this is misleading. You can install tons of non-free packages using apt from the official archive. They are in the multiverse section.
Frankly that makes me doubt the author's central piece of evidence (that JSHint gets much fewer downloads than ESLint).
* Graph from this URL in case it changes again: http://mikepennisi.com/blog/2020/jshint-watching-the-ship-si...
https://npm-stat.com/charts.html?package=jshint&package=esli...
Because this is a linter, that will help coders code well, and not a facial recognition suite that will facilitate totalitarian regimes as they crack down on dissidents.
Put another way, the issue here is not software licenses in general, it's the fact the author picked an obscure one with with dubious requirements. Picking no license would have actually been worse than the license he had.
That's an unsound argument - it suffers from a confusion of agency. The most I can be responsible for as an author is the intent of my software.
If I'm a wrench manufacturer, I have no moral obligation to attempt to control how people will use my wrenches. They are amoral tools with a good intent (to help with construction projects). Whether my wrenches or those projects will end up being used for evil is beyond my purview.
The intent of deepfake software is clearly either fraud or development of deepfake detection tools. If you're a vendor and your intent is the latter, it would be morally commendable to do your best to sell to reputable customers only... but with security tools like this the authorial intent almost doesn't (and shouldn't) factor in. Unfortunately, if you try to go soft so it won't "hurt someone" then the fraud detection R&D can't be as robust.
Regarding guns, they're either for killing people, killing varmints/animals, or defending oneself against bad guys. As a salesperson, you can reserve the right to refuse sales to known crooks -- that would be morally commendable (as far as it's possible). But it's your decision based on your own judgment. As far as the gun itself is concerned, if as a manufacturer your intent is defense against bad guys (or legal hunting/varmint control) and your product reflects that intent, then you're morally in the clear.
Incidentally, I'm strongly against sales of surplus military gear to police departments, because of the mixing of intentions that are at-odds. The intent of military gear is to fight foreign armies commanded by bad guys -- which is an intent that police departments should never have, as they're dealing with civilians. That's why in the US, we have the National Guard if an army of bad guys ever appears within our borders--it's different from the police, with different training and different intent.
I think there are a ton of positive, creative uses of it. For instance de-aging an actor for a flashback sequence, with their permission. Deepfake software can potentially do this way cheaper than the state of the art, such as the young Tony Stark / Peter Quill's dad / Leia. And eventually, it should be able to do it better. When the technology is truly indetectable, it will be used all over the place in filmmaking and even video games.
Because then I worry about deepfakes making actors obsolete (as we have made obsolete so many other professions)
Or how about movies making stage actors (and set builders, etc) obsolete? I mean, when you only have to act it out once and millions can see your performance, as opposed to actors performing shows every night in small venues in towns all over the country, it puts a lot of people out of work. There are pretty few people today making a living as actors.
And of course photography put portrait painters out of work. And high quality cameras in cell phones probably put a lot of photographers out of work.
What might happen is that there will still be actors, but all they have to do is act, not be beautiful. They can use a model for the beautiful part. And then you can have talented people on computers merging it all together.
I do like the idea of bedroom production of movies, which can happen if you don't need actors. Previously, if you want to be a film director, you needed to be born into a rich family, and then after extremely expensive film school, you needed to get big money to finance your movies. So there's that.
Also just shooting inanimate targets for sport because it's fun.
Freely provided software unifies the producer and distributor into one agent. That person has responsibility. The absolute minimum they are morally responsible for is restricting the uses of their product to ones they do not find morally objectionable.
What an ideal world.
It's not hard to justify developing a compiler or CPU (or a JS lintier) and deciding that it's just a generic tool and you have no control over the code compiled with it - and that's perfectly fine. You might however find it harder to justify writing functionality that's designed to track people or that you know is intended to be used for nefarious purposes, and in those situations you should be willing to hold yourself to whatever moral standard you have determined. Just because everyone below you hasn't prevented you from doing it isn't a reason to go along with it, you know more directly what your software is going to be used for than they do and they're effectively trusting you to make these decisions.
Again though, a JS linter doesn't exactly have these concerns ;)
Your tracking someone explore a new cave and recording paths found. You kill someone who is about to kill other innocent people. Pushing a kid into bushes to avoid a car could save their life.
Evil depends on context. What's evil to you is not evil to me either.
Courts generally throw out clauses like these unless the definition of evil is part of the agreement.
I think it's also somewhat interesting to compare these comments against the ones on articles where we find out a company is helping China (or a different country) censor their website, either locally or globally. In those situations people are upset they were willing to do it - but why wouldn't they if they have no moral responsibility for what they're making and it brings in more dollars? Someone in those companies had to approve it and eventually add those lines of code or those entries in a database, and good or bad they should be willing to stand up for those decisions and say no if they truly disagree with what they're doing. They are, quite literally, our last line of defense against such actions - and it might not be "fair" to them, but it is reality.
Do you think Linus would be willing to adding a driver for a USB device developed by North Korea that could or would be used by them for nefarious purposes?
Do you think he would be willing to adding code that would make it easier for the NSA to spy on Linux users?
Do you think he would be willing to add code to track Linux usage?
Do you think he would continue to develop and work on Linux if it turned out North Korea was the only user of it? Not just one of, but the sole consumer?
The real world involves actual hard problems and questions, and in some cases (In Linus's case, probably more often than not) your choices will have a direct impact on people. And while I can't tell you Linus's answers for those questions, it's not the answers that matter. What's important is that he should be willing to stand up for those decisions. It shouldn't be acceptable to us or him for him to simply throw his hands in the air and say "well I don't have any responsibility here so who cares how this software is used".
Software that is morally gatekept by its creator is not free (as in freedom) software. I value freedom more than I value "preventing harm" or whatever you're worried about. The whole world is trending toward less freedom (of speech, etc.) in the name of "preventing harm" which I think is a big mistake.
You really missed the point. Yes, anybody can maintain a fork, but Linus still has to make the judgement on whether to add such a driver to Linux. And making such a call is a big deal, it means he and the kernel developers are committing to maintaining it (to some degree) and makes it easier for North Korea to keep it up to date and functioning. And Linus's tree is the tree people get their Linux Kernel from, just because forks exist does not mean he doesn't need to think about what he adds to his. Linus is a "moral gatekeeper" whether he wants to be one or not, and in some cases he has to answer such questions, the only relevant part is how he chooses to answer them.
> Software that is morally gatekept by its creator is not free (as in freedom) software. I value freedom more than I value "preventing harm" or whatever you're worried about. The whole world is trending toward less freedom (of speech, etc.) in the name of "preventing harm" which I think is a big mistake.
These are two completely different things. There's a big difference between "I'm not going to prevent you from writing X" and "Here's X, it's only used by you and I wrote it or I'm keeping it up to date for you". That was the whole point of the example questions I gave. At some point it's not just some theoretical boogeyman, at some point you are aiding those who are doing things you don't consider OK. Just because they can fork Linux doesn't mean Linus has no responsibility for what he puts into his fork and develops.
> I value freedom more than I value "preventing harm" or whatever you're worried about.
And what's your point? Refusing to develop software or maintain software for someone is expressing freedom, I would argue that very thing is what will protect freedom from various nefarious actors. Or do you suggest such people (like Linus) should just blindly develop whatever they're told without any concern for what the results may be?
The real irony here is that some of the software I'm talking about is software that is currently restricting the freedom of people across the world. And I can guarantee you that some of the people who go on Hacker News help develop it, and justify it via "It's not my responsibility, it's just code and I get paid to do it" - and that shouldn't be acceptable to them or us. My whole point is that they should have a higher standard and realization of the affect the code they write has on other people, and I think we're actually in agreement on this part.
For that reason, I will never, ever use software with a license like that. Therefore, I will never, ever create software with a license like that.
I suppose if you really wanted to, with GMO seeds sold as a service, you could conceivably enforce that.
Ultimately, these questions of how we translate morality into a system of rules, that we use to punish people, shouldn't be decided by a few technical experts, but by the everyone, and we already have a system for that.
I have to accept that some of my work may be used for things I do not agree with. I do not believe this is a stain upon my honour.
But if I were writing a compiler for a mainstream programming language, then I don't think I could be expected to lose sleep over the fact that _someone_ might be using it to write missile control systems.
Then you can even extend and say because the missile system wasn't built (because you left) when another country bombs and kills kids you are at fault.
You could even say because the missile control wasn't built the next Hitler was born and all of those deaths are your fault.
It's no wonder all presidents age so rapidly for those 4/8 years.
But suggesting that a software developer is responsible for any and all possible uses of their software, whether they could have reasonably thought of all of those uses, is absurd.
Regardless, a tool is a tool. If something has, say 60% good use and 40% bad use, should it not be built? Where is the cutoff? 90%/10%? 99%/1%?
Should hammer manufacturers be responsible for murder done using their hammers?
Neutrality doesn't mean much, although I agree as an industry software can be very naive ethically.