Microsoft forked MIT licensed repo and changed the copyright [fixed]
github.com
github.com
We have merged a pull request that restored the correct LICENSE file and copyright, and are in touch with the upstream author Leśny Rumcajs who emailed us this morning. We'll look to revert the entire commit that our bot made, too, since it updated the README with a boilerplate getting started guide.
The bug was caused by a bot that was designed to commit template files in new repositories. It's code that I wrote to try to prevent other problems we have had with releasing projects in the past. It's not supposed to run on forks.
I'm going to make sure that we sit down and audit all of our forked repositories and revert similar changes to any other projects.
We have a lot of process around forking, and have had to put controls in place to make sure that people are aware of that guidance. Starting a few years ago, we even "lock" forks to enforce our process. We prefer that people fork projects into their individual GitHub accounts, instead of our organization, to encourage that they participate with the upstream project. In this situation, a team got approval to fork the repository, but hasn't yet gotten started.
To be as open as I can, I'd like to point to the bug:
- The templates we apply on new repositories live at https://github.com/microsoft/repo-templates
- The bug seems to be at this line of the new repository workflow: https://github.com/microsoft/opensource-management-portal/bl...
- The system we have in place even tries to educate our engineers with this log message (https://github.com/microsoft/opensource-management-portal/bl...): "this.log.push({ message: `Repository ${subMessage}, template files will not be committed. Please check the LICENSE and other files to understand existing obligations.` });"
I always appreciate communication that acknowledges I’m a person, not a data point or a customer. I wish more companies ditched the greasy PR approach and allowed folks like Jeff to do their talking for them.
If we remove this feature of common law legal systems, I think you will get far more admissions of fault like this one.
If you hurt people, organizations, etc for admitting their mistakes, they're going to stop doing it.
I don’t have any doubt that it was an honest mistake. They also took accountability for the mistake, shared their steps to prevent it from happening again, and they’re in contact with the original repo author directly.
At this point, anyone digging for excuses to further demonize Microsoft isn’t interested in honest discussion about this issue. This is a textbook mistake followed by rapid resolution (on Christmas Day, no less), with great communication on top.
Had a similar experience with AzureCli v2.30, where the environment variable to ignore certificate errors suddenly did not work anymore.
It turned out it was removed but there was no mention of it in the release notes.
On the GitHub page quick response was provided by Microsoft.
> Prescribe not to malice that which may well be a buggy edge case.
The thread would have been a lot more fun if we could have spent it talking about what prompted your team to build this thingy, and bounce other people's approaches to the same problem off, and maybe share some war stories about dumb things bots have done on our behalf.
Thanks, regardless, for the information you've provided here. It's interesting.
Another good reminder that Hacker News is not above assuming the worst and gathering pitchfork mobs like any other social media.
The issue looked like a mistake from the start to anyone paying attention (committed by a bot, changes were consistent with a boilerplate LICENSE file being checked in).
If someone at Microsoft wanted to steal some code, forking it on Github and then publicly documenting the history of the code in the most visible way possible would truly be the dumbest way to do it.
I would go so far as to say almost no group is, they just have different preconceptions that encourage assumptions of malice in different ways and directions.
There is no substitute for more facts about the situation, no matter how much we'd like to assume the details that aren't given.
Track records matter and Microsoft doesn't have a clean one. Scrutiny of companies of their size should be the norm. Maybe they would do more to improve "mistakes" if more people held them accountable in a continuous fashion.
The Microsoft STL issues are usually quite fun and entertaining, at least if you don't have to use it: https://github.com/microsoft/STL/issues/1603
We are still working on it. And, it will take time.
Jeff's team, my team, the java team whose forked repo this unintentionally highlighted are working with dozens of other teams every week. Satya says we're all in on open source.
Hold Jeff and Me and all the leaders of Microsoft to that vision. Keep us accountable. And, know this takes time. Let's make technology and humanity healthier and more sustainable in 2022.
I was all in on MS as a kid/young teen.
Eventually I started looking at the actions of Microsoft, and as stupid as it is, felt betrayed.
I still don't trust MS, and still hate the direction Windows is heading, I will probably never daily drive it again.
However, comments like these give me hope that MS can turn itself around. Maybe some day MS will be the company I thought it was!
Tl;dr: Thanks for making changes!
You're not, just as your competitors aren't.
None of the secret sauces are Open Source: Windows, Office, Visual Studio, SQL Server, the Azure control stuff, and I don't expect them to be.
You're half in, at best, only Red Hat was all in. And they were bought out by IBM, so here we are.
Edit: I guess the truth hurts :-)
So, for the sake of the feelings of the innocent people who work there, I would ask everyone to please modulate the volume and intensity of ire that they project. Please speak truth to power, but don't be harsher than is needed to get your point across.
But as for some background: I am a PM for Microsoft Build of OpenJDK and from late last year to around May this year I made contributions to the gRPC_bench repo as a Microsoft employee for some experiments we have been working on, to evaluate and improve different ways of implementing gRPC exchange in Java. [1]
This fork was intended for newer experiments, one of them being about coding and running these benchmarks on GitHub Codespaces. For that, I needed the repo on an org where we, as employees, have Codespaces enabled.
The rest is HN history (back to Jeff's reply above [2]).
Merry Christmas all!
[1] https://github.com/LesnyRumcajs/grpc_bench/commits?author=br...
https://github.com/microsoft/opensource-management-portal/bl...
I hope that despite all the harsh words, you can have sympathy with that behind them are legitimate concerns and suspicion stemming from past bad behavior from various part of your organization. Due to this, and Microsoft's position of power, you have a much, much lower budget for these kinds of mistakes compared to the most other orgs.
Even if there was nothing intentionally malicious at play here, it would not be far-fetched for an outsider to interpret as "implicit maliciousness through neglect".
Here's hoping that 2022 will be a year of bridging the divide and sincere alignment.
This comment speaks towards that this is the case:
https://news.ycombinator.com/item?id=29686347
> I know Jeff personally and he's great. This happens all the time at Microsoft though. Teams try to do OSS themselves, haven't a clue how GitHub or licensing works (e.g. they think the CLA transfers copyright), and after a slap aside the head, I send them to Jeff for guidance and all is well.
(I mostly agree with your sentiment, though. I do get the impression that leadership is sincere in wanting to do right. It's just that it's not that black-and-white or easy. As another MS employee commented, this is something that has to take time and they need to be held accountable along the way. https://news.ycombinator.com/item?id=29684127)
I certainly understand how scandalous this looks to crowds like Hacker News.
But this seems a little bit blown out of proportion, as if Microsoft just forked the kernel or something and put their name on the license.
I don't. I'm with the Microsoft employee who was pissed at how people think it's edgy to diss on Microsoft. What were the chances that Microsoft was openly doing that? Some dude who has now deleted his post said Microsoft was trying to "create a monopoly of web IDEs". These are clearly people who barely have a passing knowledge of how Microsoft works these days.
People think critical thinking means complaining endlessly. It doesn't. You can't think critically if you don't think clearly. And you can't think clearly if you're only looking for a reason to lift the pitchforks.
https://keivan.io/the-day-appget-died/
https://web.archive.org/web/20180715225433/https://threadrea...
It took significant public outrage and press coverage before either of those were even acknowledged, a long time after.
> What were the chances that Microsoft was openly doing that?
After reading the above, is it really that edgy to be assuming the worst? If it's truly just recurring instances of different rogue employees, doesn't that speak to a systemic and/or cultural issue that needs to be addressed with additional internal safeguards and/or deterrents to prevent it from happening again?
To the credit of the relevant team here, today this was promptly addressed as soon as it got their attention. But it will take more than that to set to rest decades of precedence.
(I did not partake in the flaming and don't find it constructive or beneficial; just saying I have full understanding of the suspicion and understand that MS are still on probation)
https://github.com/microsoft/cups/commit/8100595a3a3a6d5c7d0...
Again, this is a person, not a robot. How does this play into a "software bug"?
My guess is that they were going through a checklist of what to do when releasing open source changes, and didn't understand what they were doing.
A lot of why we've had to put some guardrails in our system has been to point people to guidance and training on open source.
I've sent the team that works on this repository an e-mail, but I don't expect to get a response on the holiday.
The pitchforks will come down, anyway :-)
Courts will take a far more generous view than you are here. If Microsoft is not profiting from the change, and fixes it promptly when pointed out, the courts will shrug at any case - no harm, no foul. It's not even clear to me that it's illegal to have the wrong license on GitHub, assuming the shipping product does not violate the correct license. As nobody has pointed to any infringing Microsoft product... What are we talking about?
That is not, however, a complaint - being smart enough and giving a damn enough to realise that straightening it out immediately was a really good idea is impressive and laudable in and of itself.
>SQL Operations Studio was built on the back of many open source projects that all use the MIT License for a reason: it's the right way to keep moving the community forward, empowering your users to do cool stuff and build useful things for the community.
>We're just asking SQL Operations Studio to use the same license that Visual Studio Code does.
For those that don't know Polish it means Forest Rumcajs (https://en.wikipedia.org/wiki/Rumcajs), probably a joke of the author that wants to be anonymous.
So, yeah, hugops, mate.
It is good to be reminded that care and integrity can exist, even in large corporations.
Don't worry, man, nobody expects people from Microsoft to write code that behaves as intended. Merry Christmas.
“It’s a big company”, you say. They should have a process! And I’m sad to say, they do/will have a process exactly because of this attitude. Then, everyone wonders why it takes forever to fix that bug they’re furious about or why features are slow to come.
Full disclosure: I work for MS, though have nothing to do with this. It’s a huge company. I know hundreds of people and most of them are upstanding and try to do the right thing.
ippsample (Apache -> MIT) https://github.com/microsoft/ippsample/commit/938bff17c72868...
huggingface-transformers (Apache -> MIT): https://github.com/microsoft/huggingface-transformers/commit...
health-cards-tests (MIT changed) https://github.com/microsoft/health-cards-tests/commit/5649b...
CUPS (Apache -> MIT) https://github.com/microsoft/cups/commit/ad69bcc78bdea3fea3f...
Credit to this reddit comment: https://www.reddit.com/r/opensource/comments/roa9xz/comment/...
It seems the automation is also triggered when Repos are forked into the Microsoft GitHub org which isn't correct behavior.
This isn't a deliberate action. If it were plenty of employees (myself included) would be outraged. I assume it's a bug in the bot - an edge case that was not considered. It is very rare to fork something into the Microsoft GitHub org after all.
I'll pass it along to some people I know.
1. They made similar mistakes in the past.
2. They didn't fix it for half a year.
3. They can expect strong financial benefits from making these mistakes.
4. They've recently burned a lot of goodwill by deliberately infringing licenses on a large scale when they trained Copilot.
5. They could have easily prevented this kind of mistakes.
My summary would be that Microsoft deserves to be punished for making this mistake. If nothing bad happens now, then we'll have the same discussion again in half a year from now.
A healthy org doesn’t blame individuals, it blames failures in process. Thus Microsoft should own this mistake. Stating it’s the fault of an individual sounds more like your team operates a blame culture. Which, frankly, is a major red flag for a failing organisation.
However, if you look at the changelog, I don't know how you are gonna say with a straight face that it's a "mistake".
> Full disclosure: I work for MS
It is difficult to see the reality distortion field you are in from the inside.
Could just be normal practices, and doesn’t check if a license already exists because it’s usually handling non-forked OSS repos. What’s the phrase? “Never ascribe to malice that which is adequately explained by incompetence”.
This is the peril of the imaginary "corporation" identity. People expect a company to be one coherent and consistent entity, but although a company can be managed well, establish culture and processes, and progress towards cohesion, it can never become as coherent as one person. And a person is not that coherent in the first place.
I am sure I subconsciously make the same mistake when I think about other companies. But I am making conscious effort to get better, take a more forgiving view on the humankind and give people as well as corporations chance to try again and be a better version of themselves, build the mental capability to remember that corporations are comprised of real people, and people make mistakes, and reasonable people who make up the majority of the population are constantly seeking (just struggling) to be better versions of themselves.
It doesn't have to be a debate on "good vs evil" I've always hated those terms applied in these contexts, it's childish and for the naive. Fix the problem and move on.
That said, I can relate the the cynicism especially for the giants. But painting them all as 'profit-seeking corporations' may deaden a satisfaction that comes from being a customer for a company you believe is good.
I mean come on the seismic change in leadership at Microsoft is just former lower echelon leaders during the time frame that MS was doing wrong now moving up and taking the helm.
We are after all talking about the company that tried to destroy the competition by funneling money into a fraudulent lawsuit/pr campaign that was a front for a pump and dump. The only thing separating MS leadership and felony charges is meeting notes between them and SCO and the fact that important people don't go prison in the US if can at all be avoided. Lest we forget the current CEO was at this time an executive VP as well.
Maybe it boggles your mind merely because you yourself are an ethical person who comports themselves properly professionally and would want people to see your efforts good and bad in context of who you are. This is entirely reasonable but people don't know you personally whereas your company makes headlines for bad behavior.
For many it’s not just Microsoft. Many assume negative intent from others most of the time. It much be such a frustrating, draining way to live.
From my personal experience, every software engineer that works in a company of this scale is obligated to take a training course on software licensing and understand the differences, and the "dos and don'ts".
If Microsoft doesn't have such a program in place then that's a big problem and should expect harsh criticisms when such events take place and if they do then it probably needs to be revised because it doesn't seem adequate.
On the other hand, outside the context of MS, if a software engineer doesn't feel they are doing something dirty as they are replacing the license or the thought of I might get in trouble with legal doing that doesn't cross their mind, then they probably shouldn't be allowed to be at the front line taking actions that represents the company's name.
...Given that several engineers employed at Microsoft have been part of armchairing this along everyone else now, why is not one of y'all (not necessarily you but come on, this is getting absurd, holidays aside) still just busy discussing around it rather than spending the <5 minutes required per repo to start actually fixing the fallout of it?
* Bugs in the bot inevitably assign ownership to the writer rather than from the writer.
* Bugs in the billing system invariably overcharge customers
* Bugs in the image recognition system invariably select white people.
Well-meaning people still follow their incentives. Corners have to get cut somewhere.
I totally agree this isn't specific to MS. We have seen the enemy, and it is us.
Microsoft doesn't really gain anything here – there's a clear "forked from" qualifier in the repo, they aren't republishing these packages, etc. The only people who noticed noticed in a negative light.
All future changes to this repo are copyright Microsoft, so Microsoft's copyright should be in the statement.
Arguably there should be an additional statement indicating that LesnyRumcajs holds copyright to bits of code that Microsoft hasn't changed.
But
(1) exactly which bits have LesnyRumcajs's copyright would have to be verified by examining source control history. Since LesnyRumcajs's copyright statement is visible on any commit where LesnyRumcajs holds copyright, this setup makes actually makes it easy to verify which portions LesnyRumcajs has copyright claims on.
(2) Including LesnyRumcajs's copyright statement in repo history seems to be all that the MIT license requires. The license doesn't forbid there being another more easily accessible copyright notice that doesn't list all copyright holders. It only requires that LesnyRumcajs's statement be included in all copies of the software, which it currently is.
It's definitely the case that at a given snapshot of the repository which has copyrighted code owned by someone else the copyright notice has to be there at that same revision.
How can you work for Microsoft AND do the "right" thing? I guess it depends on your role, but still...
Everytime I've taken the route that there is some evil, no good as come out of it but when you give a group of people the benifit of the doubt, I would argue the majority of the time it's just a mistake.
I don't work for Microsoft.
If you care about this issue, try to get it fixed within your company and move on.
If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future. They're here: https://news.ycombinator.com/newsguidelines.html.
We particularly don't want the online callout/shaming culture here. nhttps://hn.algolia.com/?sort=byDate&type=comment&dateRange=a...
Never. Trust. Microsoft.
It was just accidentally run in a script. No worries right?
That doesn’t seem to be the purpose of the bot. It’s supposed to add them to new repos, not alter existing. This ensures that all their projects have an explicit license rather than ambiguously public.
Only on hackernews I see this level of crazyness. You need to reduce your caffein intake drastically.
"When disagreeing, please reply to the argument instead of calling names. 'That is idiotic; 1 + 1 is 2, not 3' can be shortened to '1 + 1 is 2, not 3."
and this one:
"Please don't sneer, including at the rest of the community."
2) bot2 takes data for copilot
3) we are "sorry" for bot 1
4) bot2 took data
The part that caught my interest is: How many people consciously picked the MIT license when they actually meant a non-attribution license?
It's far from the first time I see this kind of reaction and, IMO, rather than everyone spending time on piling on the flamewar, how about opening the door for MS to set this straight and do the right thing? Assume good faith even if you personally don't sincerely believe it? Give them an easy way to save face and present a plausible narrative rather than having everyone dig their trenches deeper? If you'd prefer MS not to screw people over, it helps no one to solidify them in doing just that.
Already so many people shouting "YOU ARE THE DEVIL", not one going "hey, looks like this is a mistake, let's sort it out". IMO the latter is more constructive. It's almost as if people want Microsoft to do bad things. Remember it's a huge organization with all kinds of people and ideologies internally. It's too early to tell which way the individual behind this particular change is leaning.
It took me all of 1-2 minutes to make this PR[0], probably less than any of the meme pictures in that commit thread. Let's see how it goes. Last time it went through[1].
[0]: https://github.com/microsoft/grpc_bench/pull/1
[1]: https://github.com/dotnet/sdk/pull/22262
EDIT: ...And, it's merged. I'm assuming the rest of the affected repos will be fixed as well and an apologetic blog post issued by Monday. Anyone who feels that's too long time can always open corresponding PRs instead of wasting their time by replying to this with how that's not our job. Happy holidays.
2) Assuming it's even true, what should this person do instead?
3) What do you think the outcome would be if this person did contact Microsoft? Since it's a mistake, I assume something bad?
https://github.com/microsoft/cups/commit/ad69bcc78bdea3fea3f...
You interacted with one part of Microsoft, maybe we are seeing the works of another part.
> This is the open source management service account used for performing key GitHub operations on behalf of Microsoft employees and users.
Combined with the nonsense README change, this looks like a bot mis-use accident.
Edit: to clarify, in no way am I saying that this is a "honest mistake" which does not deserve scrutiny.
What is the point of using all caps? For me it makes legal texts like these really annoying to read. I'm not a native English speaker, is that really correct English writing? Aren't there clear rules when to use capitalization? Like, at the beginning of sentences. Feels like they are abusing the language.
Can they just lower case the paragraphs, to make things more convenient to read? Or does that change the legal meaning? For me it would feel like they would stop screaming :-)
Conspicuous could mean all caps, contrasting text, or different colors. My guess is that CAPITALIZATION was used because most typewriters at the time could do caps, whereas doing different font sizes, colors, bold would have required a special expensive machine. When technology evolved, lawyers being process oriented creatures, stuck with all caps because it was the way things were always done, and therefore safe to do.
[1] https://www.termsfeed.com/blog/all-caps-legal-agreements/
It’s legally important
It seems Microsoft has now automated this practice.
Edit: It's easy to jump the gun and start accusing Microsoft of something nefarious here. To be clear, I'm personally giving Microsoft the benefit of the doubt and assuming that this was an honest mistake, and that the folks at Microsoft who had something to do with setting this up were well-meaning.
My point is that we're living in a culture that, as a standard practice, sprinkles "(c) [year] [company]" on things like salt, that such claims are frequently invalid or misleading, and that this broader issue may be partly to blame for incidents like the one we are discussing today.
I know I can run "Update Copyright" on my projects in JetBrains - could just be an innocent mistake that hit the wrong folder.
I know everyone jumps on the big corp as everything they do is intentional, but it's the holidays, someone was doing a bit of work, maybe not fully concentrating and hit push.
Seeing how quickly this was plastered everywhere, and the responses to it, do you really, like REALLY think that this is a deliberate play?
"Oops. We f*d up? Well, you can't talk with a human unless you pay us lots of money. Oh - you don't have money for a lawyer? Tough. Good luck getting through our layers of trained monkeys."
Make no mistake, gravity will always pull MS towards their default behavior. Just wait for VS Code becoming a subscription-based product.
Yes, there will always be a community maintained project. But it will not be MS Certified…
Original author could send a DMCA, or they could simply enjoy Christmas and assume a ticket will undo this sometime in January.
Copyright laws have one major purpose: protect the right holders. It does so by giving them tools to mitigate their loses by deterring people from infringing.
If a right holder has to invest more time in complaining on people about infringement than actually having time to do other stuff, like creating, then we've got it all wrong.
IANAL, but the MIT license specifically does not say you have to redistribute with the same copyright owner notice. It says the copyright notice and terms must remain, and that you can sublicense it. It doesn't say you can't change the copyright notice.
That would solve any ambiguities around the script Microsoft wrote.
"Are you sure you want to change the license?" Yes / No.
Perhaps a specific API call when you are doing it with a script.
Thanks, 3np
> This repo has been populated by an initial template to help get you started. Please make sure to update the content to build a great experience for community-building.
Perhaps this is "updating content"?
Pretty much MS' only useful contributions to open source are from MS Research, everything else feels like a Trojan horse, designed to make you like them and then lock you in to something proprietary later.
Lots of plugins don't work on open-source VSCode, they tried a bait and switch with .NET features, Windows 11 has a bunch of anti-patterns, GitHub is being dodgy about how they train Copilot, etc...
I'm assuming you mean open as in communication. Apple basically is a stone wall, facebook just spouts empty platitudes, google processes are opaque and unyielding (unless you know a someone or raise a massive community response on social media), but Microsoft continues to be staffed by humans.
They aren't a shining pillar of FOSS, but they've taken some good steps in the right direction in the past few years. And of all of them, user feedback, support, and escalation seems to still be handled by people instead of algorithms
These mostly link to repositories under one of their GitHub organizations: https://github.com/apple-oss-distributions/
Apple's open source projects: https://opensource.apple.com/projects/
Which mostly link to repositories under their main GitHub organization: https://github.com/orgs/apple/repositories
I'm curious to know how you're measuring openness. I agree Apple is the least open of the group, but Facebook and Google owe their existence to FLOSS, and were always in harmony with it from their origins.
This was a while back, but Tim Cook apologized[0] after a poorly received rollout of Apple Maps. That said, I applaud this response and agree that more like it is needed across the industry.
[0] https://techcrunch.com/2012/09/28/tim-cook-apologizes-for-ap...
Apple have caught huge flak recently e.g. for the phone-local image scanning software.
People take it for granted that you can just run what you want on your windows machine but they could have turned it into smartphone style locked down system. Imagine if every app developer in history had to fork 15-30% of their sales over to Microsoft just for building on Windows, they could have made a trillion bucks or something.
Oh and don't forget googles ridiculous amount of effort poured into Android open-source source tree, just to name one of many.
I honestly can't tell if you are trolling here or not.
If Microsoft had the most popular search engine and the most popular mobile operating system, they would be gathering all our data and putting ai robots to answer our questions.
These big tech companies do not have the best interest of us in mind. They are a force for centralization of power into the hands of billionaires.
It doesn't have to be this way but it requires users to smell the coffee and want another Internet and another big tech industry.
EDIT: also if there are any forks of your project, you should ask people who forked it to restore the original copyright notice as well. If the original copyright holder sees your name instead of theirs, they'll know who to sue.
I see it as a honest question.
Instead of voting down, vote up so more people can read replies and see that it is not something that should be done.
I'd advise you to fixup any forks on GitHub, e.g. https://github.com/fiatjaf/jiq/blob/master/LICENSE, which are currently in breach of license.
You'll need to inform anyone who forked your code, too.
This is something you agreed to in the following part of the license:
> The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
We needed an always-on VPN. Intune supports several, but all insist you run some proprietary server software. If you don't understand why that would make someone feel uncomfortable, PulseSecure [2] was one of those options. There is open source GPL software that replaces the proprietary back ends called OpenConnect [3], but that violates their client licensing.
Then I discovered Microsoft has their own VPN called mstunnel. That's when I felt like I had fallen down the rabbit hole. I dismissed mstunnel initially because since it is a Microsoft Product, it would run only on Windows, right? Turns out it only runs on Linux. I thought you installed the mstunnel client on Android, because among other things it existed - but nope it was superceded by this thing called "Defender for EndPoint".
The server came as a Docker install, but we didn't have the required version of Docker so I unpacked it and ran it in a chroot. That all worked in the end, but in the process of unpacking it I discovered what it was under the hood. It had two things - an "agent" written in dotnet whose sole function as far as I could tell was verify with Microsoft's servers you have paid for it and ... a copy of free as in beer OpenConnect.
Nothing wrong with that really. In fact it's the reverse - it being OpenConnect under the hood gave me a lot of confidence I wasn't dealing with another PulseSecure. The only fly in the ointment is OpenConnect is GPL. They are completely free to use it the way they did - in fact I suspect the OpenConnect authors would be very happy to see the project used in that way. But you do have to comply with the licence. There was no attribution whatsoever, let alone instructions on a copy of the source as the licence requires.
I'm sure it's just an oversight, just like the subject of this article. Maybe it's another mess for Jeff to fix. I don't know you from a bar of soap Jeff, but keep up the good work.
[0] Intune provides a uniform MDM like experience across many platforms - including Windows. If you need to control Windows like that you probably don't have much choice, you have to use a Microsoft product. Maybe it works very well on Windows, but it's an ugly, buggy thing on Android, and the UI is a confusing mess. If you only need an MDM for Android I can heartily recommend headwind (https://h-mdm.com/), which we rolled out before Intune because it took literally months to get the licences (in fact, we still don't have them). Headwind is open source, is cheaper than Intune and has free tier, and frankly was a joy to work with - once you discovered their doco was all in the FAQ's.
[1] For the uninitiated, all Android devices (and iOS) allow a company to take control of a device by installing an MDM, something that can happen only immediately after a factory reset. Thereafter Android displays "your company can see everything you do on this device".
[2] https://threatpost.com/pulse-secure-critical-zero-day-active...
We forgive you...
;)
In return, you receive hosting from GitHub.
The writing is on the wall. You MUST host your own code on a stand-alone website.
Here is an example. This Go program (a compiler) generates and serves its own website: https://NN-512.com
It runs on a Linode shared CPU cloud instance that costs $5 per month: https://www.linode.com/pricing
Another example, look at what Fabrice Bellard does: https://bellard.org
Also the point you're making is controversial, and definitely isn't widely agreed on. As a human, I can read public code on Github, and use my internal neural network (brain) to regurgitate sections of code, and don't need to attribute anyone (who can say which codebase I'm recalling code from? I certainly can't). So a neural network doing the same thing, but external to a human, is certainly questionanble, but it isn't a cut-and-dry case of copying without attribution.
Wrong. Lets say a GPL project is not hosted on GitHub officially. I can easily setup a mirror for it though on GitHub as the GPL doesn't prevent me from doing it...
Point is that anyone can put my work on GitHub, even if I don't want to.Assuming the project is under a free license though.
If you don't like that,don't release your code as open source. I'm not going to host my open source projects on my own website. That's just hard, it's much more difficult to get people to check it out if it's on Broblog.net
I personally don't believe extremely short code snippets, like the ones copilot tends to copy are problematic.
In these situations, whether it be originating from a human or robot, the knowledge comes from looking at public code on GitHub and it's always been a risk that your public code might not be used with proper attribution at some point. Think about how many OSS projects have core code and algorithms copied daily by companies with no public name and keep all of their source code private - it's surely caused more damage than CoPilot ever will.
Even if Microsoft currently only uses GitHub-hosted code as an input to Copilot, their theory of the legality does not depend on code being hosted there and applies to any code they can get their hands on. The idea that hosting code publicly at some non-GitHub location is going to keep it out of Copilot is not well justified.
How would self hosting your code prevent Microsoft/GitHub from using it in the Copilot training dataset? If using content from GitHub irrespective of their license to train Copilot is legal, so is training from code available on your website.
Not a very good one - clicking the link produces a download dialog on Firefox (I'm guessing because the website neglects to indicate a Content-Type).
Ironically this is an argument against trying to do everything yourself - you might waste time chasing the long tail of thousands of little details that had been solved many times over elsewhere.
I think this can only be valid of Github's terms of use clearly specify that or the chosen license allows it.
I actually see copilot benefiting GPL projects: suppose a programmer uses copilot to develop a proprietary software and copilot regurgitates GPL'ed code: now the proprietary software is a derivative work and must be GPL'ed too.
You may be practically limiting copilots use of your code but I don't see any licensing difference if Microsoft hosts Copyright code or scrapes copyright code.
So yeah, you are donating your work to Google when you put it on a publicly accessible web site.
[1] https://www.google.com/search?q=how+old+is+queen+elizabeth
I think that’s on purpose, not to “steal” code from GPL’ed softwares’ authors, but to get GPL’ed code into commercial projects. Then Microsoft can say “oops, we were right all along! The GPL is so dangerously viral that you can’t even host your software on the same server!”
I know that sounds stupid, unless you were there for the Halloween Documents. After all these years, it seems to me that Microsoft hasn’t done the 180 they portray.
I might put this in my public ones as well.
I am a happy Sourcehut customer. Roughly the same cost as a VPS, but comes with tech support.
[0] https://www.reddit.com/r/opensource/comments/roa9xz/microsof...
For some reason I doubt they've bought the copyright to CUPS.
Embrace, Extend, and Extinguish
But now not even bothering with the extend. I’d guess this is a mistake of some kind.
> The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
Also, I'm not sure you can just change the copyright information, and change the history of the code like that.
However, this is typical of Microsoft. Like DOS, like Windows App Store / Packaging ripoff (they asked the guy some questions, sherlocked his software, even didn't thank him later), etc.
Here you go:
https://github.com/microsoft/TypeScript
Just fork TypeScript, change the copyright holder to yourself, and do what you want with it. I sure Microsoft won't mind.
Only the copyright owner can license the work to others, or issue under a different license if they like.