Of regrets
laanwj.github.io
laanwj.github.io
edited to add "claims he" based on a comment
Edit: I see that you were referring to Wright, not to Laanwj.
It's somewhat common for commercial click-wrap agreements to include indemnifications now, but it probably shouldn't be-- they're potentially unfair and over-powered which is why I haven't tried my hand at drafting language.
But you're right that the license isn't the primary problem as they can't do something about an excessively dysfunctional legal system. The UK courts already have a pretty bad reputation internationally in other areas, such as in abusing them for defamation lawsuits resulting in US legislative action to block them (e.g. https://en.wikipedia.org/wiki/SPEECH_Act ).
And of course if volunteer open source developers are found to be liable, I imagine commercial open and closed source developers (Microsoft, Google, Apple, etc.) will be liable for immense damages as well, so that will be interesting.
As I explained in other comments-- even if you believe/hope it would be unenforceable it can still be unwise to ignore foreign litigation because you won't get a change to fight the case on its merits later should it turn out to be a problem. Perhaps if you were facing a likely unenforceable foreign case that you were sure to lose then you might be best off ignoring it.
https://www.coindesk.com/business/2023/02/03/craig-wrights-u...
The only logical conclusion from fighting this battle is that Craig Wright is a liar.
So what happens if they just don't show up to court? Sure you'll lose by default judgment, and then you can ignore the judgment, right? If I got a court summons from some random country like Sudan or Botswana or the UK I would just ignore it. How could that backfire assuming I don't plan on traveling to Sudan in my lifetime?
The UK government ? Not so much. If the case has enough clout and import, the UK government has enough “multilateral conventions and bilateral extradition treaties” to make your life really miserable.
I suppose a court could compel core devs to accept such a change, if it came to that. But how could a court compel Bitcoin node operators to run that version of the software? That's what would actually need to happen, to give someone back their coins (or rather, a version of their coins that most people actually value).
Wright could make the change himself (or get someone else to do it) because the software is open source. It's getting everyone else to run the software that matters.
"Here's the code he wants, I've written it, he's welcome to it. Now you just have to get 13k nodes worldwide to run it. I can't do that. Good luck."
There's a plausible claim that the Bitcoin developers exert enough control over the Bitcoin network through their control of the official repository that operators would just accept it.
The claim has not been proven (and I think we all know that it wouldn't), but the court of appeals has correctly determined that it isn't their place to summarily decide that it wouldn't and that it needs to go to trial.
The court would not compel node operators (there's been absolutely zero entertainment of the idea that node operators are fiduciaries).
Part of the challenge here is that in summary judgements the facts are assumed in the facts are assumed in the favor of the non-movant so if you're in court against someone who is willing to tell arbitrary lies (because, e.g. their goal isn't to win, it's just to make you fold) you're severely disadvantages when it comes to discharging the case on a summary basis.
The situation described in nullc's comment seem pretty horrible!
I wonder if the license were modified to add, "if you do not agree to these terms you do not have a grant of license for this software."
Separately, when I look at the case, it seems to be a provision of service issue, so the software itself should be a red herring. Of course anything can happen in a lawsuit, even one that appears to be as illegitimate as this one.
The lawsuit was originally dismissed without trial since the lower courts thought that the lawsuit did not have a chance of succeeding due to resting on the claim that the Bitcoin developers had a fiduciary duty to Bitcoin users (i.e. to act in the users' best interest). The appeals court thought that there's a legit case to be made for such a fiduciary duty existing. They did not say it exists, or under what circumstances it would exist. Just that there should be a trial to determine that.
The cost of winning at trial is great enough to be ruinous especially relative to a volunteer effort.
In the case of Bitcoin we're probably better off in the sense that there are wealthy supporters willing to step up and take on costs. But there isn't anything about this that couldn't be applied more broadly to impose far ranging duties on other open source developers.
(FWIW, a fiduciary duty is far broader than just a duty to act in their best interest, it is a duty of single minded loyalty to put their interests over all others, including the fiduciary's own).
The legal case is not that the Bitcoin developers are liable for their software alone. It's that they might have a duty owing to the control they can exert over the Bitcoin _network_ (through their control of the "official" software repository). There are a couple of careful points to temper this judgement:
1. It's has not been decided that Bitcoin developers _do_ have some control over the Bitcoin network. The question of whether Bitcoin is centrally controlled to some extent or truly distributed cannot be summarily decided by a judge or the court of appeals. It _should_ go to trial. 2. It's not been decided that the Bitcoin developers have a fiduciary responsibility even if they do have control over the network. 3. It's not been decided whether or not Tulip could successfully argue that the Bitcoin addresses do in fact belong to them 3. It's not been decided what action, if any, the Bitcoin developers should be compelled to make if all the previous points are decided in Tulips favor.
If this analogy were closer to reality, it would be like claiming that a bank has a fiduciary duty to someone who not only doesn't have an account with them, but also put their cash money in a barrel and deliberately burned it.
Except it's not even that, because there's no bank-like structure going on here. The code itself didn't create the forms of money that followed—it merely recognizes it as valid on an ongoing basis from people who used it to perform that work themselves.
So, I mean the analogy is false at any rate..
It's helpful to read the trial court decision which was being appealed here: https://www.bailii.org/ew/cases/EWHC/Ch/2022/667.html
The license is discussed at 110, with the judge concluding that it wasn't strong enough to be dispositive in isolation.
Edit: The appeals court opinion that was posted elsewhere in this thread appears to bear out what I said above. Paragraph 40 of the ruling says:
"The essence of Tulip’s case is that the result of all this is that the developers, having undertaken to control the software of the relevant bitcoin network, thereby have and exercise control over the property held by others (i.e. bitcoin), and that this has the result in law that they owe fiduciary duties to the true owners of that property with the result that, on the facts of this case, they are obliged to introduce a software patch along the lines described above, and help Tulip recover its property."
In other words, Tulip is claiming (rightly or wrongly) that Bitcoin is its fiduciary because Bitcoin controls what version of the software is used on their network, and therefore controls how Bitcoin assets, which are valuable property, are transferred from one party to another. That's a straightforward financial argument and does not have anything to do with any software license. It certainly doesn't imply that any open source developer assumes a fiduciary duty merely by publicly releasing software.
The software itself is not; but Bitcoin's control over what version of the software gets used on its network is a financial function, since it controls how financial assets (Bitcoin holdings) get transferred from one party to another. And that function is the basis for the claim of fiduciary duty, not the fact that Bitcoin publishes its software as open source.
> It's nothing more than a peer to peer network with a novel consensus algorithm.
The software itself is, yes. But the network is more than that: it has a particular party, Bitcoin, that controls what version of the software is accepted on the network. That control is what the plaintiff in the lawsuit is claiming as a basis for a fiduciary duty.
> With this precedent you could effectively sue BitTorrent developers for not modifying the code to keep backups of your data.
No, you can't, because there is no corresponding financial function provided by the BitTorrent developers. They don't control where you download files from or where you store them.
There is no such entity as Bitcoin, fwiw. Bitcoin is a protocol, a language, spoken by users (or more precisely, their computers) to bring about the bitcoin system. Like Roberts rules of order bring about a meeting. Bitcoin isn't the only system resulting from the software we wrote-- many people have created alternatives using the same software.
> But the network is more than that: it has a particular party, Bitcoin, that controls what version of the software is accepted on the network.
Well it doesn't but it's fair to say that the plaintiff has asserted it does.
> That control is what the plaintiff in the lawsuit is claiming as a basis for a fiduciary duty.
What the plaintiff didn't do is give any coherent argument for this control existing or even explaining why it isn't the plaintiff itself that has it (after all, he claims to be the creator of the system).
> No, you can't, because there is no corresponding financial function provided by the BitTorrent developers. They don't control where you download files from or where you store them.
Nor does anything with Bitcoin.
By "Bitcoin", I mean the Bitcoin developers, since they are the ones the plaintiff is making the fiduciary responsibility claim against.
> it doesn't but it's fair to say that the plaintiff has asserted it does
And if the plaintiff's claim to that effect is false, their case collapses, since that claim is, as the quote I gave from the appellate court opinion makes clear, the "essence" of the plaintiff's case. That's all I am trying to make clear: that the plaintiff's case is based on its claim about the Bitcoin developers' control of the software version the network uses, not on a simple claim that the Bitcoin client software is released as open source.
Also the claim you are asserting is laughably false. There is no magic button the developers have that can just force everyone to run their software.
I'm not the one asserting the claim: the plaintiff is. As I have already said, if that claim is false, the plaintiff's case collapses, since that claim, according to the appeals court, is the "essence" of the plaintiff's case.
If there's been no exchange of money; how would they be beholden to stake holders?
"Craig Wright’s [UK] lawsuit against multiple Bitcoin developers will go to trial"
https://cryptoslate.com/craig-wrights-lawsuit-against-multip...
This was posted by a Bitcoin developer. Apparently we are supposed to recognize them by name and immediately remember whatever lawsuits they’re involved in, in the UK.
It's not even like I didn't explicitly said it.
I just made a change to my licenses ([1]) to fight something like this. It basically makes the license null and void if any part of the disclaimer is not recognized by law. [2]
And because of this, I'm going to expedite getting these licenses picked over by a lawyer.
Nevertheless, I'm not working on any more FOSS until that lawyer says it's safe or the UK pulls back from absurdity.
[1]: https://yzena.com/licenses/
[2]: https://yzena.com/yzena-viral-user-license/#legality-of-disc...
> 5. No Discrimination Against Persons or Groups > The license must not discriminate against any person or group of persons.
In all seriousness, aren’t you overreacting a bit?
Sure, the likelihood doesn't seem very high, but the very fact that this case is going forward means that the floodgates are open. I think it's likely that more cases like this will be filed.
In addition, if something like this happens to me, the results will be catastrophic and out of my control. A small likelihood of a catastrophic result is enough to say no because I have a wife.
The only thing in my control is to say no completely. So I will if I have to.
I'll probably start writing fiction again if that happens.
However, as much as I'm usually cautious, I cannot feel good hiding behind a pseudonym. This is personal, though; there's nothing wrong with it. But for me, I don't want to hide from the consequences of what I say even if those consequences are stupid and unjust.
Hence, why you see my real name here on HN.
[0] https://soundcloud.com/alabpodcast/episode-3-faketoshi-the-p...
All developers can/will be served papers (and forced to travel to the UK?)
That shouldn’t discourage the use of contracts, licenses, etc. But it should make you prudential when it comes to appropriate level of concern related to legal matters.
Let's see how their economy will work then.
- For a contract to work it should be accepted
- OSS projects which are just available online, could be download without performing or even reading a license
- One of the important clauses to shield from legal liability is limitation of liability clause, i.e. you use the software as is, and won't be able to make the author accountable for damages caused by software
- MIT license has such a clause
- We now have a precedent when a developer is held liable due to damage allegedly caused by such software
Consequences of this precedent are super scary
It's even worse than that, of course, because creating the backdoored version they demanded wouldn't and couldn't make anyone run it (and it's inconceivable to me that more than a negligible number would-- particularly seeing how there are no automatic updates by design for security reasons). Their position is that we're responsible for it being effective too.
I think if it were just a demand to backdoor the software one of the defendants might have done so-- "Here you go, now screw off". But that clearly wouldn't have made the plaintiff go away (and might have landed them in litigation from the actual owners of the assets, even though the backdoor had no effect except maybe the creation of yet another forked blockchain that no one uses).
Forced to go to a full trial over it, instead of being able discharge it on a summary basis.
This sounds a lot better, but in terms of the impact it's not clear how much better it is-- the cost from this will be almost entirely in defending it.
Archived copy:
https://web.archive.org/web/20230206215930/https://laanwj.gi...
Of course it shouldn’t be necessary, I’m just trying to think of a practical way for an individual to avoid this scenario.
Recommended a scheme to shield OSS developers from liability. I am not a lawyer, so it looked a bit overly cautious to me, but it seems that was a good idea.
I think in general structural improvement like that are most effective against 'honest' opponents-- someone whos goal is to win and recover their costs and damages. A legal structure that limits liability makes recovery less likely, so they don't bring the action at all.
For an opponent who's goal is to harass and ultimately crush the opposition, I think that kind of tool is probably less effective. It's also harder to justify doing when you're just following a volunteer passion over something speculative and worthless (as was the case of the Bitcoin related defendants-- almost all of whom started close to the beginning of Bitcoin).
[And as an aside: to the extent that development is done on an uncompensated purely voluntary basis, it would be difficulty to legitimize the LLC, e.g. little to no income or expenses or other documentation that the LLC is anything but a piece of paper.]
But this also follows along the answers "since you're not in the UK why not ignore it"-- if a court later decides to allow recovery of assets that came from the LLC or pierce the corporate veil entirely you're screwed-- at that point you lost your chance to defend yourself.
Paraphrasing, the answer I got was: "Anyone can sue anyone for any reason, and then we have a legal process to determine the result. If you're a director of the company, they're probaby going to sue you personally, and you're going to have to spend a lot of money to argue that you personally shouldn't be liable. Hopefully you'll be successful. It'll all depend on the facts, so you'll need to get sued first before I can give you a better answer. Either way, it's going to cost you money."
My conclusion is that the legal system is not super great when a bad-faith actor is involved. Though, really, it's also not super great when good-faith actors are involved, either.
A Ltd company would help a little, but individuals within a company still have fiduciary responsibility.
Unfortunately, it will likely be quite traumatic and expensive to get through the trial first.
https://www.coindesk.com/markets/2021/06/29/uk-court-orders-...
"Unfortunately, the court rules allowed for me to be sued pseudonymously, however, I couldn't defend myself pseudonymously. So I was put in an impossible situation of losing my privacy or losing the case in a default judgment. It sucks, but there's nothing more I could have done, really."
The 35k was an amount the judge awarded pending a cost assessment from Wright's opposition. The fees were then increased to ~£600k after they submitted the cost assessment, which Cobra attempted to challenge but was denied again on the basis of anonymous parties having no due process rights in the the UK.
I have no idea if Cobra has the means to pay such a large amount, if they'd even take it either, but even if he did-- it would be terrible and not just for him personally since all that money would be sunk back into suing other Bitcoin community members.
You're also screwed if you run out of funding along the way-- which he'll try his damnedest to make happen, but won't work here.
It did, however, pretty much work in another lawsuit which should have been a win no easier than ours where the defendant ran out of money mid case and was forced to pull his defense and gain an almost automatic loss. Fortunately, he was able to prove on the way out that Wright brought the case on a fraudulent basis and his loss was reduced to 1 GBP (plus the 900k GBP he already owed from earlier stages, though with the potential for further reductions by a costs judge).
I’m concerned that any court… at least any court with a reputation remotely in the realm of “not a plainly obvious farce intentionally designed to boast its illegitimacy for intimidation purposes”… would pick a precedent-setting case of this magnitude, where the defendant is anything but flanked by an army of lawyers.
By all means, set the obvious precedent. But there has got to be a case which isn’t set up to probably ruin the life of an eventually vindicated open source developer defendant.
Edit: and I should also clarify I’m not concerned about crypto or whatever. I’m concerned that anyone at all working on clearly warranty-free software can have their lives sucked up into a case of national and probably international impact just because some court decides to make an example of their plaintiff.
They didn't decide to take it to trial for this reason. If they needed it for precedent they'd just wait for the next case instead.
They decided the case needs to go to trial because there are questions around fiduciary responsibility that they can't answer without a trial.
Both in the decision and the permission to appeal the specifically cited the public importance of the subject area as a factor.
Which is great for them but of no concern to us -- you could say that it's an "some accident of immediate overwhelming interest which appeals to the feelings and distorts the judgment" to quote Oliver Wendell Holmes Jr.
It will almost certainly not serve as precedent because of this fact alone.
The poster of the linked article, Wladimir Van der Laan, was one of the most active developers of Bitcoin since 2011. I'm also another early bitcoin developer, now former, and another one of this conman's legal attack targets.
A key point about vexatious litigation, especially in places like the UK which lack protections against SLAPPs, is that the attacker doesn't need to win the lawsuit to achieve his goals: He can cause his victims millions of dollars in legal costs, phenomenal impositions on their time and privacy, and great psychological stress-- losing nothing himself but what he paid for his attorneys. Winning or not is more or less incidental, as the culprit here said quite explicitly online before commencing his lawsuits (saying that the intent was to destroy his targets and their families financially and psychologically). That fact that none of us were in the UK or had any dealings in the UK doesn't matter because open source software is available everywhere.
For that reason its important that it be possible to discharge frivolous litigation as quickly and efficiently as possible. As open source developers the cost/benefit of publishing our work can be pretty dicey to begin with, so it's important that the licenses we use not gratuitously open up avenues for litigation from the users since there are no revenues to pay for such things as a cost of doing business.
In his first lawsuit, he alleged to own billions of dollars in Bitcoin (coins which are already well known to have belonged to the MTGox exchange) and that in 2020-- coincidentally just as his obligations to repay his lenders were coming due-- thieves entered into his home to install a "wifi pineapple" to hack his computers and steal the keys and that when he discovered this "hack" he wipes his computers to clear the compromise, conveniently making sure there would be no evidence of the "hack" or ever owning the coins to begin with. The coins in question have not moved. He then filed a lawsuit against a dozen former and current developers arguing that as developers they have a fiduciary responsibility to introduce a backdoor into the bitcoin cryptosystem to "recover" "his" coins. In three years there has been no comment or apparent action by the police over this theft which, if it were real, would likely be the highest value heist in recorded history.
The case seemed obviously baseless to us, owing to obvious falsehood of his claims, the impossibility of his request (people would not adopt this backdoored version, even if anyone was willing to make themself complicit in his attempted theft by writing it for him), the pointlessness of it (he just pay someone to write it (or do it himself, if he could program) and half the defendants had long since stopped working on Bitcoin), the fact that even the police don't have a positive duty to save anyone from harm, and the unambiguous disclaimer of liabilities in our software license -- without which we never would have published it in the first place.
And keep in mind that he's already been found by judges in several countries to have perjured himself, submitted faked evidence, etc. in other cases (as shown in this collage of rulings against Wright, https://pbs.twimg.com/media/FoMUonbXkAEbJbL?format=jpg&name=... )
The trial court agreed ( https://www.bailii.org/ew/cases/EWHC/Ch/2022/667.html ), ruling that his case didn't have more than a fanciful chance of success. But he appealed and the decision was reversed ( https://nt4tn.net/scammer-craig-wright/Tulip_v_Van_Der_Laan_... ). He's now gloating on slack and twitter that he's already "won" because we'll be 'ruined' by having to pay the 7-figure cost of his successful appeal and by publishing whatever dirt he can extract from our private data obtained in discovery.
(The second lawsuit, which has yet to come before a court alleges that the targets are violating "his" copyright by distributing the Bitcoin "block format" and bitcoin documentation, nevermind the fact that Bitcoin has been released under the MIT expat license since day one, and that this bozo's claims of being Bitcoin's creator are totally discredited and obviously false. He's also filed additional lawsuits against community members and journalists for expressing the view that his claims of having created Bitcoin are false).
Regardless of what you think about Bitcoin, the enforceability of the disclaimer of liability is critical to all of open source and the court's unwillingness to summarily dismiss an effort to compel the authorship and publication of a backdoor in a cryptographic security scheme from a supposed user who hopes to benefit from the backdoor should be a concern to all open source developers.
So far we've been able to keep our costs fairly modest, but as the case (now cases) go to trial the costs will likely balloon rapidly.
It's always a concern though because support might stop at some point, especially since the total cost is more or less unbounded. For example, in the defamation lawsuit against Peter McCormack his sponsored pulled out after the funds expended crossed a million UKP sticking Peter in the middle of some complex and expensive litigation and forced to withdraw most of his defenses because he couldn't afford the cost of them.
Fortunately, at the 11th hour he was able to prove that the claimed damages the case rested on were totally fabricated (the plaintiff claimed to have been dis-invited from academic conferences; McCormack got a statement for the organizers that Wright's submissions were rejected by peer review for being rubbish), resulting in McCormack ending up with a 1 UKP judgement against him ... plus some 900k UKP in legal costs (which he's currently fighting to get dismissed).
A challenge future fundraising may face is that the time-scales of court are not compatible with the attention span of the public-- the number one thing I hear when I have updates is "oh, is that still going on?". The second most common is "that guys a joke-- just ignore him, he only wants attention". Well, I wouldn't argue that he's not a joke, but even a joke can cause tremendous damage especially when everyone's reaction is to ignore it.
The opensats fundraiser was able to raise about $1.5 million dollars for hodlnaut's defense, which on one hand is a tremendous success--- but on the other hand is about an order of magnitude too low. Which is why I'm attributing problems here to the legal system and inadequate protections of open source licenses in light of them (MIT's waver of liability is arguably stronger than most too) rather than saying the community hasn't stepped up in support.
I presume you are referring to https://wikipedia.org/wiki/Pound_sterling ? If you are doing it because of political beliefs, perhaps avoid that on HN, and should maybe using the £ symbol would be a suitable compromise instead? Although maybe it was just a typo, given you used “dollars” later to refer to USD
(And I'd never heard of anyone calling it UKP as a political statement, but presumably it would have something to do with Northern Ireland being a part of UK but not part of Great Britain.)
What a shame it would be to lose a transparently baseless case through mismanagement. Ironically, it's the strong cases that you're almost sure to lose that you might as well phone in or not defend at all.
In this case the plaintiff does everything he can to jack up the costs, including bombing the case with irrelevant stuff, gaslighting, etc. The courts have caught him doing this in other cases and chasized him in their rulings (complaining for forgeries and perjury) but the recourse so far has been confined to wrist-slap grade consequences.
A lot of the structure we have in our courts (both in the US and UK) to ensure good faith behavior is setting things up so that cheating makes you ultimately lose the case. But if you didn't seriously expect to win on the merits (instead only by the other side screwing up) and were mostly just trying to use the process to cause harm then it doesn't really matter if your forgeries and perjury ultimately cause you to lose.
So for example, in Wright v McCormack, McCormack was able to show at trial that Wright's claims of damages were intentionally falsified. This got McCormack a 'loss' where he only had to pay 1 pound and where he was awarded his fees for the trial (well probably 70%, that hasn't been decided yet)-- but in the interest of finality the trial court declined to reverse the 900k pounds in fees he had to pay for the other sides costs in earlier motions.
This also potentially provides an additional avenue to hit your opponents during a SLAPP-- sandbag your costs so that whatever the opposition does have to pay on motions they lose are ruinous, and also so they have to spend a lot defending themselves so that 30% they can't recover is also ruinous.
Full cost on trial like this-- with discovery and experts, etc-- may be on the order of 10 to 20 million pounds. Would you expect a volunteer open source developer to be able to pay a non-negligible part of that, on top of the substantial imposition on their life and time that fighting the case and winning entails?
To extend the parent question, why can't the people accused, not being in the UK, simply ignore this?
There are good reasons to expect that in this case they would be unenforceable in the US, but that isn't a guarantee-- and if they are you don't get to go back and fight the cause you lost by default and would have expected to win on the merits. So you're risking a kafkaesque situation where everyone is saying "yep, it's wrong and unfair, now hand over all your assets. thems the rules".
It's also the case that ignoring a judgement in the UK can get you found in contempt and subject to prison should you happen to find yourself (perhaps accidentally) in the UK in the future. Personally I have no problem never going anywhere near the UK in the future, and though "outlaw in the UK" has a nice ring to it, this does add to the incentives.
The person who runs the bitcoin website was sued by the same con for distributing the bitcoin whitepaper, and defaulted because the UK wouldn't allow him to defend himself without divulging his identity. He took the whitepaper down from the UK under threat of arrest (if they ever find him) and now facing hundreds of thousands of pounds of the opposing side's legal fees under threat of potentially losing the domain name (and/or prison, again if they can find him). There really is no silver bullet.
That said, other countries will frequently enforce foreign judgements. In this case, the specific performance they're asking for would likely be unenforceable in the US (and useless regardless) -- but damages might well be enforceable.
The most horrible part is that _they are allowed to drop their case anytime_ in the UK civil court. In previous cases when the accused has run out of money, the defendants have to pay their costs [1] to keep the trial running - with zero chance of being able to recoup costs because the accused will be bankrupt anyway. The UK state should not make private individuals fund the creation of novel case law; it's absolutely stupid.
[1] https://www.dpsa.uk/wp-content/uploads/2021/11/Malkiewicz-v-...
If you read the appeals decision (and the decision that granted the permission to appeal)-- that seems to very much be the motivation here too: Case law on this subject would be intellectually interesting and potentially important in the future, so lets leave these foreign defendants on the hook to help establish it.
Beyond the ethical problems with that position to begin with, this is a terrible case to try to establish anything because it's so factually conflated that all the resources are going to go to sorting through the plaintiffs lies. The defendants don't have any particular interest in the UK establishing good law except to the extent that bad law in the UK may have international ramifications. (and even there not much-- defendants aren't businesses, they're volunteer developers many (most?) of whom have already quit participating)
Nice multi-billion dollar business you got there, be a real shame if somebody started introducing subtly-breaking bugs into that critical library you use, wouldn't it?
https://en.wikipedia.org/wiki/Heartbleed
https://www.schneier.com/blog/archives/2008/05/random_number...
I can keep going. The notion that big tech has the time or inclination to rigorously audit all the free software they're using is absolutely laughable.
In all seriousness, it appears as if I'm the first to mention the GPL in this thread and I find that very odd. There's your starting point.
… if the MIT license's warranty disclaimer doesn't hold up in this regard, what makes you think the GPL's would, or for that matter, any FOSS license's such section?
The result allegedly reached here is absurd. No amount of legalese can defend against absurd conclusions.
At the end of the day, there will still be conflicts over responsibility, no matter what the law or licenses say. Making authors of open source software immune from all responsibility in any and all circumstances doesn't strike me as a good idea, because it will also enable abuse by bad faith actors.
Not that establishing intent to do harm would be easy, or that the law is effective or efficient. But if you're looking for a watermark to shoot for...
Or: the MIT license has essentially worked as intended for almost 40 years. Now one bad-faith troll abuses the court system. Do we really need to start panicking? Courts exist to settle disputes, and sooner or later some bozo will come by with a faux-dispute. It's kind of inevitable, and unless there's a structural problem – which doesn't seem to be the case – it doesn't strike me as something that needs new legislation.
And being a volunteer doesn't guarantee immunity from lawsuits, nor should it IMO.
Maybe it's a one off fluke. Or maybe it isn't. I think that makes it worth discussing.
I think it's not difficult to imagine alternative terms that would have been likely to have a stronger effect.
After reading the appeal ruling, the case seems to have far more merit than is presented. If you want to develop money-like software then you have to accept money-like responsibility. Where this responsibility starts or ends is currently unclear. I don't really have an answer what responsibility there should be, but a full rejection would be an absurdity: Bitcoin developers could legally push malicious updates which steal Bitcoins for example.
In short: there is a legitimate dispute here. The legal system seems to be working as intended.
> I think it's not difficult to imagine alternative terms that would have been likely to have a stronger effect.
The MIT license has a very strong "no liability" statement. I don't really see how it can be improved.
In many jurisdictions law takes precedent over contract. In the UK specifically liability cannot be signed away unconditionally and is always subject to reasonableness. This is the case for most jurisdiction, with the US being the notable exception I believe (although this may also differ per state).
However, it seems to me the entire thing is only tangentially related to "MIT license" or "open source" at all.
That's incorrect and addressed explicitly in the trial court decision: a fiduciary duty isn't needed to prevent someone from behaving fraudulently.
And what he demands is an affirmative duty to act, which isn't even necessarily found in a fiduciary context, and is almost never found otherwise. E.g. you could be falling off a cliff right in front of a police officer who need only toss you a rope to save your life, and the rope is already in his hand-- he has absolutely no obligation to do so (in the UK or in the US, as a matter of settled law).
This is because duties to act are in conflict with duties to not act. If both can exist then there may be no safe move. In the US and UK we've decided that inaction is the safe move, so it's you to get sued for actions that cause harm and very hard to get sued for inaction that fail to prevent harm. Situations where it's reversed are special exceptions.
In this case the true owners of the assets would obviously have not only a reason to sue but to seek criminal charges if the defendants aided the plaintiff (it's his case that the defendants are already in breach of their obligation to rescue him, even though he did nothing to convince them that the loss was real or the coins were his before suing). Moreover, essentially every user of Bitcoin bought into a system with certain well described properties, including the impossibility of directly recovering lost coins-- a fact that was explained quite clearly by Satoshi (who the plaintiff fraudulently claims to be!). If it were possible for the defendants to change that and they did, every user harmed by undermining the system in that way would have a clear cause of action against them.
This kind of impossible bind is why our legal systems are extremely conservative in handing out these kinds of duties (both in the US and the UK, though the underlying case law is different obviously). It shouldn't be possible to accidentally and unknowingly end up being a fiduciary to total strangers who have no particular reason to trust you.
> If you want to develop money-like software then you have to accept money-like responsibility
Except no such duty has ever been found for commercial banks or central banks. If you claim to have lost your dollars you don't get to sue your bank or the fed to replace them for you.
Moreover, many of the defendants (most I think now?) are no longer developers and many weren't long before this supposed loss.
> I don't really see how it can be improved.
An obvious change which has become common in commercial terms of recent years is to require explicit indemnification. It also could have more expressly set out the non-relationship between the user and the authors.
One of the big problems here is that there will never be any compensation for the costs to us here. It's not like after we win all the costs will be covered and we'll receive a reasonable rate for the time spent defending it.
We gave our labor away for what we hoped was the betterment of the world, with no direct benefit to ourselves for doing so, and in return this is what we get: It's a really bad deal, and so Wladimir saying he regrets it is no shock.
The abuse and lack of gratitude from a few users that many high profile open source developers get is one thing... being dragged into a foreign court over something which isn't even argued to be your own fault is something else entirely. It's not like he argues that the results are on account of error or negligence on the part of the defendants-- much less malice!
Heck if you wanted to claim that it was due to a design flaw in Bitcoin--- well the plaintiff claims to be the person who created it! (...who spent the early days of Bitcoin explaining that there was no way to recover lost coins and for good reason, because any mechanism to do so would require third party trust which the system was designed to avoid).
> If you claim to have lost your dollars you don't get to sue your bank or the fed to replace them for you.
If I claim it's the fault of the bank? Of course you can.
The judge decided there wasn't one, it was the appeals court that differed. :)
> and that courts are the system we have to resolve that sort off thing.
If not for some fortunate historical luck it could only decide this wrongly, since but for some fortuitous turns we'd be forced to lose due to being unable to afford the defense. You can easily replay this situation with different defendants or a different situation and get that outcome.
If not for the impossibility of the requested remedy (and the fact that plaintiffs was never to be win)-- I don't see why it wouldn't just be rational for us to collude with the plaintiff and throw the case in exchange for, say, half the windfall. Fortunately for Bitcoin users the system is designed in a way to preclude that possibility, but not so fortunately for us.
> If I claim it's the fault of the bank? Of course you can.
At no point has the plaintiff alleged that the loss is our fault.
I have a set of licenses ([1]) set to be approved by a lawyer. Because of your suggestions, I've now added an indemnification clause and a clause disclaiming any relationship between user and contributor.
> time to enshrine open-source software ... merely relying on an old copyright hack
the copyright hack you're referring to is the copyleft hack, associated primarily with GPL, whose hacker author (Stallman, and not that kind of author) chose to call "free software". (This is the idea that if you take a copy of copyleft software and use it to create a product, users of that product are permitted to see the source code if they want, just as you got to see the source code that you used to create it. If you don't want to agree to that, don't use that free software in your product)
the people who chose to distinguish themselves (ESR Eric Raymond) from "copyleft free software" chose to call their movement "open source", and their disagreement was precisely with the requirement that you share and share alike what was shared with you; and their disagreement was not in regard to whether it was a copyright hack or a signed contract, it was the meaning or intent of the express user permission to see the source (which they like to portray as a restriction on their right to hide the source)
so it doesn't make sense for you to conflate "open source" with the old copyright/copyleft hack, which more importantly has nothing at all to do with with warranties.
seems to me the issue OP has brought up has more to do with "click/shrink wrap" licensing. I don't know where the UK stands on click&shrink wraps, but seems to me you'd attack entire ediface rather than specific terms within (although I am aware that european regulators (and to a lesser extent american consumer rights advocates) obsess over customer rights to warranties)
The issue in this case is that for any software which is released by anyone, for free, no matter the licence attached to it, the UK courts are contemplating doing do may create a fiduciary duty between the author and the user based on the user's actions entirely.
The fact that FLOSS types both view this as an absurdity that couldn't possibly affect them, and in some cases that since Bitcoin is unfashionable in certain circles it is somehow just punishment in the form of psychopaths with money trying to ruin the Bitcoin developers and their families, while talking openly of shooting them all in the backs of their heads, on video, while fondling an illegal weapon that the cops in the UK are doing absolutely nothing about—well, this kind of blind eye they're turning to the developments in this case are astounding to me since there's no logical/sensible way to disintangle the notion that a user's actions are what create the fiduciary duty, from literally every other project on the planet.
lol
We need a #FreedomToPublish amendment:
Section 1. Article I, Section 8, Clause 8 of this Constitution is hereby repealed.
Section 2. Congress shall make no law abridging the right of the people to publish or peaceably implement ideas.Doesn't it? Has anybody been succesfully sued for anything from a non-customer using his open source MIT-licensed software?
Though, as I understood from reading comments here, the UK legal system is so fucked up and medieval that they don't have to win to succeed at their goal.
So much for Magna Carta
The UK "loser pays" model seems like it would be a benefit, but since the norm that they only pay 70% and that your share can be diminished by presenting a comprehensive case (diminished by every argument you lose) the incentives are complicated and its far from clear to me that it doesn't make it worse.
What you're suggesting also might be at rather large risk of being ignored by the court as pretext, or esp to the extent that it's not pretext, would be viewed by developers as compromising their independence, which is quite important to them.
There is no shortage of alternative structures that you could imagine putting in place if you knew in advance that this would happen ... but if every time you went to contribute to a piece of open source you needed to first form a non-profit it's pretty clear that there wouldn't be any open source! :)
The fiduciary responsibility here isn't even arising from the software itself, but through the control of the Bitcoin network via control of the "official" software repository.
Software licensing isn't even relevant here.
111k is like half a percent of btc? Them changing the code to hand over 111k would have severe adverse effect on the value lost to the rest of the btc holders. The trust lost should wipe out all value of all btc.
So the main claim that users best interest has to be upheld is bunk. He is not the only user.
Personally I am quite torn.
From the OSS side this trial is obviously tragic and a shame.
Then again it would be hilarious it btc would finally die because something like this.
I have seen a large number of products (from SaaS to desktop apps) which don't properly ask for license acceptance to reduce sign up friction. They might be affected in the same way (I am not a lawyer).
Would be a real shame.