Proprietary Software Is Often Malware
gnu.org
gnu.org
Hmm, well based on that super broad definition, sure, proprietary software is "often malware". But usually "malware" is understood to mean software that exploits vulnerabilities in a computer system, not merely software with DRM, paywalls, banners, ads, etc.
I think GNU might need to pick a different term here than "malware" unless they are intentionally fear mongering to get the free software conversation going.
> Software whose functioning intentionally mistreats the user is called malware
There is nothing stopping you from removing GNU Emacs. There are features missing in Roam Research. But in Emacs org-roam, if you are missing a feature, you can ask any programmer– they don't have to be an org-roam maintainer– to add a feature as it is free software. Roam intentionally takes away the freedom to modify the software.
I think it's this.
However, they aren't wrong, per se. Users should have control over their systems and their privacy. But hyperbole and fear mongering are not very effective at affecting change in the system.
I would argue that they have a noble mission but take it to such an extreme as to not be very practical.
The way I remember it “malware” as a term was invented to be a bigger umbrella term to account for things like bonzi buddy when “virus” wasn’t quite as good of a description.
> Programs are also considered malware if they secretly act against the interests of the computer user
It's fair to say proprietary software often creates an ability and incentive to act against the interests the user which results in it becoming malware.
What is malware? Is that browser toolbar your aunt has on ther internet explorer Malware? Probably yes.
Is a "Cleaner" Program that does effectively nothing except Phone home Malware? Probably Yes.
Is a software that does similar things behind your back without your knowledge, but that has some useful parts to it Malware? Maybe Yes?
If Bonzi Buddy counts as malware, so does the Facebook app.
The definition of malware is social construct, not a technical one, otherwise Powershell.exe would light up like a Christmas tree.
The only reasonable way to talk about malware is with respect to users' wishes and desires.
I'll note that AV vendors invented a "less bad" label, PUP, for less-destructive malware. That doesn't make it not malware though.
So if someone says "I won't give you X software unless you pay Y dollars" that is fine
However if they do pay the expectation is they also get access to the source code if they're running the software on their own machine (depending on which license we're talking about of course)
How can you say that though if someone can just get a copy from a peer without paying you? People just go around the paywall and grab a free copy without payment which is why DRM exists at all. So then I make it so the software has to connect to a server to check if you've paid for it, and now suddenly that's mistreating the user?
GNU picked the term "malware" on purpose. I think the purpose was to (slightly) confuse, connect a known bad thing with commercial software, and spur further dissuasion. I doubt they intended to fearmonger though. That said, your intuition that they picked it to "get the free software conversation going" is, IMO, spot on.
They did the same thing with "free" in "free software". When people misinterpreted what they meant, they used that as an opportunity to ... explain their point of view. Many here may not remember when conversations like "it's free software" ... "no, not just free in cost, but free as in freedom" ... "yes, I know it's cost free, but you can charge money if you want" ... "yes, I know no one charges anything, but it's really about freedom!" was a common conversation in tech circles. I suspect a similar goal for "malware" now.
If clarity was a primary goal, they would have, IMO, picked different words.
You can call it DRM, you can also call it user restriction.
You can call it serving ads, you can also call it remote code injection.
You can call it subscription based, you can also call it user lock-in or remote killswitch.
There is not a lot of modern proprietary software that wouldn't fall into these categories. I know a lot of people claim not to care about it, that is a separate issue, but the fact is that most proprietary software is in fact malware, even if people don't mind installing malware.
> You can call it subscription based, you can also call it user lock-in or remote killswitch.
If you stop paying for your gym membership and your access card gets automatically revoked, do you consider that to be some kind of physical instantiation of malware?
Metaphors don't work as well as people think.
Today, Windows itself comes bundled not just with ads, but with a keylogger and monitor all you do on your computer.
Mainstream software have turned themselves into malware in a desperate attempt for monetization in a world where nobody wants to pay for software (in parts because FLOSS alternatives exist, but not only).
Try to find me a modern closed source program, with big userbase without such telemtry.
I understand the point that's trying to be made. People use software because it provides value to them. I certainly have used or seen software that's abusive (anti-virus/malware products are pretty bad in this respect), and I don't use them.
Unfortunately, proprietary software generally has much more funding and thus can create a much better product than open source alternatives. A recent example for me was looking for an alternative to Lightroom Classic. I found a few different open source projects that replicated different aspects of Lightroom, but not provided the full feature set combining library management with raw editing.
The question then comes down to, how much privacy am I willing to sacrifice to get the extra value?
The answer to this question will be different for different people. As people become more and more privacy focused, we see additional pressure on companies that provide proprietary software to improve privacy in their applications.
I have a couple of years of experience working with that, and I strongly disagree.
It’s also quite buggy. I’ve hit crashes several times while working with large drawings.
There are better examples of desktop OSS that beat proprietary ones: Blender, vlc, ffmpeg+Handbrake, Firefox, 7zip.
Hmmm, I am sure this happens to Adobe products too– is Krita worse?
[0] https://hyperallergic.com/195922/what-happens-when-you-try-t...
And yes, "anyone can be hacked" but if the various companies compiled their admin software from source, things would certainly be harder - even if dubious source got through, the action of the software of "phoning home" would be a lot more suspicious, etc.
Apart from the horrible style and lack of nuance, it's simply not true. To reply in the same style: who pays for proprietary software, often can demand changes. With OSS, the user is in no position to do so at all.
There is of course nuance here, since large companies with many end users do not listen to their paying customers, and OSS developers can be responsive, but I don't feel particularly kind to someone who uses false and nonsensical premises to make a political point.
> the proprietary program's developer is tempted to design the program to mistreat its users
I mean ...
So how do I demand that Windows 10 stops spying on me?
This model works less well for free software / open source, which often has a lack of financial incentives to motivate (or demotivate) developers.
So I have to convince thousands (for Windows maybe a million) of people that the thing that irritates me should be removed. Nope, that seldom happens. I find better luck in FOSS where there is enough tweaking potential that I can remove the irritating thing I don't like. Maybe FOSS maintainers and developers have no financial incentive to do what I want, but I can always have a local patch to do that.
This is not an option most software users have, but it's probably an option for most readers of this forum.
Yes, but the good thing is that more and more people are learning how to program so I am hopeful that things will get better :)
No, you can alternatively pay money for a different tier of license that lets you turn it off.
What do you mean by that? With OSS, I can demand any change that I want and have any software development shop that I choose implement that change at a competitive price.
Quite on the contrary, paying for proprietary software does not mean any right for changes as such - even when paying for really expensive enterprise support contracts; I recall a case where not only the vendor would not make such a change, but we were prohibited by the contract to make the change ourselves (by patching the compiled code, which we were technically capable to do for that particular change we wanted).
Sure it can. There are enough cases where the rights of proprietary software are transferred to the client, or the contract includes the right to make changes or get changes made.
That's not at the scale of MS, of course, but that's exactly the kind of qualification missing in OP's statement.
Not if it's incompatible with available alternatives (such as Windows), and you're paying for the privilege of merely having security updates.
Have you ever seen a payer demand a change from a proprietary vendor and get it? Whereas, people fork and make distros of free software all of the time.
This happens constantly, but in private. Usually the conversation goes like this:
customer: opens support ticket, asking how to do some task X
vendor: sorry, that needs a feature added to the product
customer: fine, we'll switch to $other_vendor
vendor: oh look at that, our engineering department scheduled the feature for next release.
Granted though that when dealing with vendors as large as Microsoft that's not going to happen.They're called "table-stakes features."
The primary aspects of adult interactions are consent based on honesty and good communication about any arrangement.
If you are ok delegating services and other work, you are already trusting another person or organization. There is nothing wrong with trusting a software vendor if the benefits are there and the vendor behaves in a trustworthy manner.
Companies often pay for parts they need to create products, where the parts are made with a proprietary process. Whether depending on a vendor for a unique part is worth it depends on the situation.
And there isn’t an open source or free state-of-the-art-software solution for every problem.
Proprietary software is generally just referred to as "Software".
Also known as the stuff that makes phones ring, cars start, satellites communicate, banks able to track money, grocery stores track how many bananas they have, airplanes not collide...
Fundamentally software makes the world go around, and a huge chunk of it is proprietary.
Ubuntu GNU/Linux was the first OS to support Kurdish.
Don't forget when Apple removed Hong Kong protest safety apps from the app store.
That's an interesting point. The GPL does not restrict what software can do. GPL software can potentially do all of these things. Heck, a virus or malware could be GPL licensed, there's nothing stopping that.
The advantage is that under the GPL, they must provide sources which allows the user (who must have software engineering skills) to modify the software to change behavior.
Always fun to see someone out there still trying to fight the fight of owning word definitions that much of the rest of the world has agreed on.
It is incredible how much time you lose by using Linux and open source tools. GIMP, Darktable, LibreOffice, Eclipse, etc. the list goes on and on. Any tool that you need in your daily workflow usually sucks when it is open source, compared to their commercial counterparts. And the lack of understanding of the open source community that "normal" people don't care about "open source" and simply want a good user experience, didn't help over the past 20 years to improve anything. Using OpenSource makes you feel like you are back in 2000.
Having funding and a coordinated team and management focused on solving customer problems and shipping the right features is something that just doesn't work when a bunch of unpaid devs "team up" and loosely work on solving problems they "think" people have and building UX that "they" like, as opposed to what customers like. My experience with open source is much more along the lines of "a bunch of nerds building software for themselves that nobody else can use or wants to use". This is not a recipe for success.
And god knows I tried. I tried to switch to Linux about once a year in the past 20 years. It always ended up to be an utter disappointment UX wise. Linux is not something people want to use. It's a great accomplishment. But without focusing on UX, Linux will never reach any adoption outside of the server realm. Period.
Free software developed by a major corporation is still free software. It may not use the open-source development model, but it's still free software.
> GIMP
https://krita.org https://penpot.app
> Eclipse
IntelliJ IDEA Community
> usually sucks when it is open source
The UX argument has been well-worn. In my experience Jitsi Meet, videoconferencing software, is far more reliable than Zoom and Google Meet.
Having Linux available made it much more cost effective to store data and do computation on the server, instead of the user’s device.
You think Facebook would exist if it had to buy per CPU licenses of Windows NT Advanced server?
Frankly, we would have been better off in the Microsoft world of individual PCs running proprietary applications on the computer the user owned. Because it ran on your system, you had defacto control over what it did, and if you really wanted to, could reverse engineer and patch it (witness game hacks, and what Microsoft did for backwards compatibility).
Now thanks to the economics of GPL software such as Linux, we are being pushed to a model where all data is stored and computed with on servers you don’t own.
Maybe it was the GPL’s requirements to contribute back changes that resulted in Linux rapidly developing a lot of capabilities?
Low-cost server software -> more power to server-based systems and companies -> more centralization of data -> less privacy
Expensive server software -> more power to standalone computing and individual users -> more decentralization of data -> more privacy
On a related note, I wonder what would be the threshold at which the cost of servers and software would make social media and ad-tech companies economically unviable, and which would have prevented Facebook, Google, and others from becoming what they've become.
Apple seems to default to push computation and data onto the device.
Google seems to default to push computation and data into the cloud.