Copyright infringement by German contact tracing app
github.com
github.com
And as one comment in the linked GitHub issue states, calling their license "open source" is really more of a marketing joke. Although the seem to have changed their restrictive license [1] to the GPL License [2]
Edit: Although its not the official apps, its heavily used by some official instances such as the health departments of some cities/states. The Luca app is financed by those departments purchasing a license. According to news, some licenses cost around 440k€ of taxpayer money [3]
[1] https://gitlab.com/lucaapp/android/-/commit/a30432ec4a01c2ca...
[2] https://gitlab.com/lucaapp/android/-/commit/4433884f00462bae...
[3] (German) https://www.faz.net/aktuell/politik/inland/mecklenburg-vorpo...
This sounds like they do the same thing. But the luca app is for check-ins ( which are mostly still done with pen in paper in germany ). Check-ins are not supported by the official corona-warn-app (yet).
Also 2 states already purchased the app and 8 other announced to purchase it [1]. So if you live in one of these 10 states (out of 16) then you can consider the luca app to be official.
[1] (German) https://www.heise.de/hintergrund/Corona-Apps-Die-wichtigsten...
According to [1] version 2.0 will be released in two weeks and will support check-ins.
[1] (German) https://www.tagesschau.de/inland/corona-warn-app-check-in-10...
Having a rather small company "devside" to build the app ( it had references and a credible portfolio of > 100 apps) was a good thing for a good price.
They won from those that build the app in Germany and wanted big belgian telecom to join for the infrastructure for a much higher cost. While they only needed to change some parameters and localize it.
Result: 1 week of delay ( 8 weeks was budgeted) and everything opensource from the start, is what I consider a good result.
Respect where it's due! Hat off
[0] https://www.chip.de/news/Kontaktverfolgung-mit-Luca-App-von-...
[1] https://www.heise.de/newsticker/meldung/Smudo-vs-Napster-Da-...
So I think the sarcarsm was valid ... but probably not the whole discussion about
That being said, Bubelich should definitely sue
"If the penalty for a crime is a fine, then that law only exists for the lower class."
Of course, it hinges on being able to tell how much income they have, which is (at least in Germany) the hard part, as the defendant is not required to help.
I'd say it's a pretty decent step, especially when combined with confiscation of the vehicle if it's a repeat offender or a severe case. As you said it may not be perfect...but I'd rather see that than some careless people risking lives of others just because a speeding ticket is small change for them.
Edit: Same with using the phone while driving. It's one of the biggest contributing factors to road accidents, yet here the fine for doing it is barely above the price for a decent headset. So most just don't care and trust the fact that well under 1% will ever be caught because the police either doesn't care either or just doesn't have the manpower to effectively enforce it.
Details might need tweaking, but a version of this could really work.
Someone with obscene wealth can be imprisoned and still buy a yacht - even incarceration has a much greater impact on a poor person.
As such, I'd rather fine them in proportion to their wealth.
Depends who is responsible for the actual "action", specially looking at Iraq.
I'll let things go after that much time has passed.
Nope.
I can understand in the abstract that of course you could rap in German, but it's quite another to encounter evidence of this in the wild so to speak.
Having investigated further, I must say it's probably unfair against Gemany to not include the adjective old in the above statement, as Smudo (or at least the group he's in) is of early 90's vintage.
Depending on what you consider "in the wild" but German rap is very popular in Germany and other German-speaking countries. People from Germany usually don't rap in English or French. Smudo is an old school, but are quite a bit of rapper that are popular right now, like Capital Bra, Apache 207, Samra, Lea, Mero, Loredana, Bushido, Sido, Olexesh, Kollegah, Farid Bang, RAF Camora, ... just on top of my head.
- We are talking about a file of 200 lines of code.
- It's replaceable functionality that isn't exactly rocket science.
- The issue was fixed within a few hours.
[Edit: replaced "error" with "issue" to avoid implicit judgement and establish a common baseline]
It was fixed and nobody was harmed.
The outrage in GH issues is ridiculous.
Their marketing comes with weird "trust us" vibe and the German tech scene went through these conversations already with the concept of the official app.
Add to that their attempts at transparency which are often a little too late and vague, and you have internet outrage. (With this release for example people were expecting to see server-side code, not that of the Android app everybody could already find in the apk).
Apart from that the official (indeed publicly funded) Corona-Warn-App did a much better job at this. (They actually did follow all the recent best practices in software-develoment + it's (mostly) run as a free software project, taking community contributions seriously, reacting to feedback and issues, etc.)
Because everyone here is a coder and puts a lot of effort into their work, and doesn't want it get stolen.
We put a lot of effort into the Open Source projects we publish. Some of us are very generous and publish things to the public domain, but most of us at least want attribution for our work.
If you copy & paste code, strip the license, claim it's your code, and sell it for money, we consider you the scum of the earth. That's just not something that decent people do.
It could be an error; a junior dev may not know that just copy/pasting code from google search results is generally not allowed. But it's really something that everyone in our profession should know.
Just like a musician is expected to know that they need clearance for samples, or journalists know they need permission for publishing a photo, a programmer is expected to know that they need a license for reusing other people's code.
Meh - I'd speculate it's a result of an underpaid coder with too much work - I've seen these kinds of projects before - people with connections in the public sector get the contract and then basically hire the lowest cost developers available.
> Just like a musician is expected to know that they need clearance for samples, or journalists know they need permission for publishing a photo, a programmer is expected to know that they need a license for reusing other people's code.
And yet those get violated all the time, even in big time publications and by big time artists.
I'm not defending the guy who did it - he did something wrong, but they corrected it and malice attributed to project seems misplaced.
On the flip side I think this could be handled better industry wide - like we already have security vulnerability scanning tools bundled with major code hosting platforms, they should probably figure out a way to do copyright infringement warnings .
If I had copied Culture4Life's code and used it in my own project, they would be suing for tens of thousands of dollars in damages; and the law would agree that I should have to pay tens of thousands of dollars in damages for that infringement. Asking for attribution and a proper license declaration is the polite way to handle a license violation.
Also it’s a shame that there is no code to the rest (like backend) of this System.
I am totally fine judging something even for minor things when it was paid by tax money and it holds sensible data.
You're talking about the older Corona Warn App which does similar things (and is generally considered too limited), but without direct data transfer to public health authorities. That's what the Luca app does.
Warn App is more for chance encounters tracking a person meeting other people.
Luca is more for checking in and out of stores and other locations.
[Edit: I stand by every single word, in case people doubt it.]
See https://github.com/corona-warn-app/cwa-documentation/blob/ma... for details on how they do it.
It is as if a certain political class had this dream scenario of a new location registry of every move of the population. That they did not get via the CWA app, and since then they attack it. But Luca could create it.
Don't forget: This is Germany. Very low corruption at the lower level of society (you will never see a bribe in everyday life) and the basic organisation of the country seems competent. Incredible high amount of corruption and incompetence in the higher spheres - Wirecard, Cum Ex, Kohls schwarze Kassen, the governing party (CDU) currently has a scandal about members gaining millions via corruption when organising FFP2 masks, the country completely failed to contain Covid after the first more or less successful lockdown. Luca fits right in.
Not only politicians, I assume entities like Rundfunkbeitrag, Schufa, conuntless Inkasso will pay fortune to access such data.
> Very low corruption at the lower level of society [...] Incredible high amount of corruption and incompetence in the higher spheres
This is incredibly shocking for an newcomer to Germany. One swiftly hits the ceiling of 3-4k EUR net monthly and mortgage of 400-600k EUR with nowhere else to go, while watching enormous amounts of money being shuffled, fortunes hidden in idyllic villages, faceless dynasties owning chunks of industries, >1mln EUR apartments being purchased.
They already get your location (edit: I mean address here) when you register to the local administration (Anmeldebescheinigung).
My address is no secret, where I was last friday night (and tuesday morning) is.
I don't know why this new thing is your choice of how they'd get the data other than it being probably run as effectively as parler (edit: no data - gut feeling).
This plus Jehovah Witnesses who stalk intercom labels and decide that you are a perfect (victim) fit for their "community", and you have the full German experience. Copyright bullies, debt collection predators, religious lunatics.
That's not true, you can see lot of small bribes in normal day-to-day transactions. Almost every single technician I met (for internet installation, electricity, washing machine installation, etc. Even insurance brokers) offered me to pay them cash directly to get some benefits or falsify some recorded data.
Cash in order to avoid taxes, sure, that happens, but again: it's not common. Almost always I simply get a paper bill, without any attempt to skirt that.
It's not about me, I live a perfectly normal, boring life. I'm not the one asking for bribes, and I always rejected them (I'm way too paranoid regarding regulations to accept that kind of stuff).
Unreported work/income is estimated at about 10% of GDP: https://de.statista.com/statistik/daten/studie/20063/umfrage...
I'm not from Germany, and do have a foreign name, I guess that may play a role.
That's a good point I hadn't considered.
But it's not "you have to pay more". More like "just so you know, I have access to this internal tool, you pay me now and this thing that isn't supposed to be possible due to your situation is now done".
(a)P offers, promises or gives a financial or other advantage to another person, and (b)P intends the advantage— (i)to induce a person to perform improperly a relevant function or activity, or (ii)to reward a person for the improper performance of such a function or activity.
The definition of improper broadly boils down to
> the test of what is expected is a test of what a reasonable person in the United Kingdom would expect in relation to the performance of the type of function or activity concerned.
Tipping at starbucks, or tipping a barman, or tipping a hotel member holding open a door, is certainly not what a reasonable person in the United Kingdom would expect.
"Tipping" is quite normal in the US. "Tipping" is quite normal in many African countries too. If you don't tip, you'll struggle to get any service (when you're running a project or whatever). It's a whole can of worms when normal activities in a country require a small payment.
Note also that if I tell my local project manager to make it happen, I'm on the hook for it if he "bribes" someone just as much as if I did it myself.
I'm sure the intent of the law is to prevent UK citizens from paying money to bypass bureaucracy (I had a very painful process importing some equipment at an airport once, they did not want to give me a receipt for the $1500 I wanted (and was supposed to) pay, they just wanted $50 to waive me through, or to stop me from paying an official $200k to let me build a pipe through a village, or whatever.
However it also means it's harder to make their project run smoothly in Guatemala ("Oh yes you can unload your lorry of course, this paperwork seems fine, but unfortunatly I need to check with my manager and he's currently out of town for 3 days. cough."), and means that you'll be subjected to a lengthy search at an airport (just long enough to miss your flight) for no reason unless you donate to their orphan fund or whatever.
I struggle to see the difference between that (which wouldn't be the case in the UK) and tipping a postman (which again I've never seen in the UK). The former I assume is illegal, the latter not, but it's not clear.
By enshrining English exceptionalism in UK law does seems rather off to me -- basically "treat all countries as if they were Britain, salute the Queen, and up the East India Company"
It comes down to the definition of "improper".
I see multiple probable origins on the net : - Coming for the german "schwarzarbeit" during end of 1st, in-between or during the occupation during 2nd WW and translated in French/Dutch from there. - Patron making employees works during the evening/night during the Middle albeit work was restricted only during day time.
I did not really find authoritative sources for the origin of the expression so take that whole bag of salt.
so it doesn't matter who developed it, it's being used as an official app (at least in some places).
"Official" means that the government has adopted it and given it a special status.
The federal government and state governments have endorsed the Corona Warn App. No special privileges in lockdown are connected to it. No special use by public health authorities is made of it.
Several state governments and municipal government have endorsed (and bought licenses to!) the Luca app. Special privileges in lockdown are connected with it, not everywhere, but in many places. Public health authorities are directly connected to Luca's servers.
If anything, the Luca app is more official than Corona Warn App where it's in use (several German states), and poised to become more important as more states introduce it.
The federal government actually owns the IP of the Corona Warn App. Luca is merely licensed by various state and local governments. You can’t expect the buyer of a software to assume responsibility for copyright violations. It’s like blaming someone for a (hypothetical) copyright violation in Windows because they sell a server that has Windows pre-installed.
Yes you can. Certainly true in the US. Liability depends on state law and in how the contract is written. If the buyer did not specifically make that carve out, a judge may end up deciding.
If the seller specifically carved that in, the buyer can be liable too (along with the seller).
This is why most government entities are difficult to contract with. They have buyers that insist in specific contract language. Govt entities have templates preapproved by lawyers to prevent this sort of thing coming back to haunt them. So if you want to do business with the govt, that's the hoops you will need to jump over.
They will only send letters to people who cannot defend themselves.
If the open source developer hires a lawyer I'm sure they'd be happy to make them some money. I wouldn't be surprised if they already got contacted. There are a lot of German lawyers out there looking for "victims" to sue on their behalf.
It would be interesting to see if one could make a bot that could detect minified versions of popular libraries and see what the compliance rate is.
Infringement is only frowned upon when it's your independent musician playing Bach on a YT video and of course he's "stealing" from the big players.
[0] https://www.sciencemediacenter.de/alle-angebote/rapid-reacti...
> The architecture follows a decentralized approach – based on the DP-3T and TCN protocols, as well as the Privacy-Preserving Contact Tracing specifications by Apple and Google.
Many, if not most, Corona "tracers" (note, the missing K) at least in Europe, work similar, if only because both Apple's iOS and Googles Android require such an architecture in order for those tracing apps to stay online and stay tracing.
Both CEOs of the company "Culture4Life GmbH" are politically well connected in Berlin. One is a clubowner, frequently in talks with government for tax-exemptions (eg. you pay less tax if you've employ a DJ...). The other one is a member of the Green party.
And we all know: Anyone who critcizes the left-wing sphere of Berlin is nothing but a racist. So there comes the rug.
EDIT: Also, the former CEO of said company is a lawyer with a reputation [1] whose main business partner is the ex-ceo of "Service und Dienstleistungen der ver.di GmbH", a temp-staffing agency run by Germany's biggest Union. Man... nothing to see here!
[1] https://www.agrarzeitung.de/nachrichten/agrarspitzen/Maerche...
It's not my fault that under the guise of being the force of good, of being the moral highground itself, of being pampered by decades of softball questions from nearly the whole of German Journalism, curruption can flourish.
It can do so even better if adherends of Berlin progressivism are being nurtured in the belief that, and opponents of Berlin progressivism are being threatened with that, every criticism of the left is guilty by association: Tin-Foil-Hat > Right-Wing > Nazi.
Just look at the FB profile of one their CEOs… full of "Nazis everwhere". It's the modern day.
> And we all know: Anyone who critcizes the left-wing sphere of Berlin is nothing but a racist. So there comes the rug.
which distracts from the valuable rest of your comment.
I do this myself sometimes and have noticed that it usually steers the discussion away from the subject matter.
When people violate the GPL, it's most likely due to ignorance.
I really think we should encourage and act positively when commercial/corporate/enterprise crap opens up their source code.
When we find a GPL (or any license violation), why can't we approach it politely (in the first case), educate on the license terms and ask them to comply.
In this case, it's seems that's what happened. We notified, educated and they complied. Shouldn't this be rewarded and hailed as a success?
But now my worry is, with the amount of hate these guys received, other companies that are already worried about opening up their codebase and contributing back to OSS, have had their fears confirmed.
This is true.
>When we find a GPL (or any license violation), why can't we approach it politely (in the first case), educate on the license terms and ask them to comply.
I partially agree, but those companies often have an army of lawyers. It shouldn't be the responsibility of the internet to find GPL/license-violations in their code.
>But now my worry is, with the amount of hate these guys received, other companies that are already worried about opening up their codebase and contributing back to OSS, have had their fears confirmed.
Hate is too strong. It's more criticism.
"OH, hey, a licence file. Let me delete that, I don't want to be bound bit it".
> When we find a GPL (or any license violation), why can't we approach it politely (in the first case), educate on the license terms and ask them to comply.
That was done, wasn't it? It was pointed out to the rightsholder that this commercial company was selling a product that included his code and were not complying with the licence.
> But now my worry is, with the amount of hate these guys received, other companies that are already worried about opening up their codebase and contributing back to OSS, have had their fears confirmed.
They can sometimes pay for separate licensing, or they can spend the money and write the software themselves. They want to keep it closed source and earn money by selling licenses (oh, the irony!) but shouldn't be called out when they violate other's rights because it might deter other violators? meh, I'm not buying it.
This isn't even a GPL violation as the code in question was licensed under a BSD license. They simply removed the original copyright notice, which may have been a genuine accident caused by misconfigured tooling (especially since someone mentioned they changed the formatting).
The reason people are outraged is entirely that this is a publicly funded multi-million Euro project that is already facing accusations of corruption/nepotism and tried to open-source wash a proprietary product (as the app wasn't even published under an open-source license at the time). You can't really point at this incident and derive a general point about "people's attitudes towards violating the GPL".
At least with GPL that would most likely be the case.
If so, regardless of their "accidental tooling removing the copyright notice", they would be violating that copyright.
Also, IANAL.
I think most in the mob are aware that their reaction is overblown. The list of OSS licenses is usually buried deep inside the docs and few ever read it. Luca made themselves vulnerable by opening up their code and the mob is using this weakness to attack them.
It's really about not wanting this app to succeed, because they are making good money and because there are valid privacy concerns. Maybe Luca should not be widely used, but then the politicians who bought it are at fault, not the developers. Also nobody is forced to install it.
Then there's the complaint about Luca's license. They open up their codebase and people complain that the license is not free enough? Mind blown, try that with any large company and see how far you get. Microsoft, give me your Office source code, or... I'll write an angry tweet!