But likely this will just cause minor reputational damage among HN-types and have no real consequences.
But likely this will just cause minor reputational damage among HN-types and have no real consequences.
https://isl3893.sourceforge.net/
"17 apr 2004 - GPL testing in court by the Netfilter/Iptables team, due to refuse to give source code of the Sitecom WL-122 (isl3893 based!). In the same time, some source code has appeared on the webserver of Sitecom."
I think so too. Onyx has been in violation of the GPL for a few years now and nothing is happening. Their products are often recommended on HN so the reputational damage even here is likely to be minimal.
> https://www.reddit.com/r/Onyx_Boox/comments/hsn7kx/onyx_usin...
Naturally, they don't recognize FLOSS or commercial licenses originating from European Union or USA.
The catch here would be is to file grievances against major distributors (Amazon, Ebay) and to prevent shipment here until they comply and pay up.
And IMHO this is killing the license. Companies are doing the calculations and determining that by the time they get caught they can just negotiate at best and at worst just ignore it and drag things out until it realistically no longer matters. Without teeth no one will follow their obligations.
If it weren't a win for both sides, the side that feels like it got the short end of the stick would opt for court.
Some people say GPL is dying because nobody use it due to its terms.
Some people say GPL is dying because everyone use it but nobody follows its terms.
The truth is in somewhat in the middle. There is more GPL adoption out there than people think, but respecting terms is a nontrivial effort. Some infringements are done in good faith and resolved equitably once noted, but detection as a whole is undoubtedly difficult, and we only see the negative headlines when it happens. That doesn't mean the license is dying; in fact, it's doing the opposite: helping people out there building software in the open, and taking to task businesses that don't play fair. We just have to accept that success rate will just never be 100% compliance, because legal constructs never reach that.
This is true of almost all contracts. If respecting terms was easy, we'd have no needs for lawyers and courts.
- John Dev takes a bit of MIT/BSD licensed code. He drops an acknowledgment in the About screen (which nobody will ever read), and that's it. (yes, many still fail to do it...)
- Jane Dev takes a bit of (L)GPL licensed code. She has to add the license file to the installer, so the installer people start asking questions: "is this an eula? Should we display it on install?" Jane clarifies that we just need to ship it, but now Legal is in the loop. Legal goes "it says here that we have to provide stuff on request, does that mean all our private code?" Jane explains how she carefully used it in such a way to avoid that scenario; half of the explanation goes above the head of every lawyer in the room, so some of them trust her and some don't. Let's assume it gets greenlit, now we have to talk to the website folks to put a link somewhere - but Legal are still on the case: "ah, but we don't want to make it too easy, let's just have an email." Who's going to monitor that mailbox? Can you do it, Jane? Legal goes "no, Jane is technically not responsible for distributing, let's loop back in the release managers". Release managers don't want to hear it, they already have enough shit to shovel. By now half the people have gone on holiday one or more times, there are more urgent fires to put out, and the thread is forgotten. Product ships. Jane moves on to found her own startup. The product will likely be infringing for years, which may or may not ever be detected.
I love the GPL and I wish everyone used it and respected it, but it's not easy to live with it.
IANAL. Let's take VSCode as an example. At the very least, the license:
1. permits data collection on your machine.
2. restricts the user: no reverse engineering, no disassembly, no decompile. No alteration of any "notices" from MS (or others). No distribution (…ish, there are some exceptions? it's complicated?).
3. a $5 limit on damages, which is … interesting.
And to be fair to MS, I think this is one of the shorter and clearer proprietary licenses that I've found. But it is hardly "pay and you're set". (Hell, "pay" — the price is free^W your data, here.)
But a further part of the complication is the mere distinction of proprietary-ness of the license. The GPL is the GPL, and once I've read it, and made a decision on the terms of it, a piece of software can signal its license with "GPLv2" or such, and I can essentially get a cache-hit on my legal interpretation of the license. Every proprietary license is a cache-miss, and is thus immensely more time consuming to process.
Is it? Just give users the same source used to build the binaries.
The SFC's ongoing case against Vizio in California[1] appears to show that violators of the GNU GPL can be sued by users, not just copyright holders. If this case sets precedent elsewhere in the USA and even in other countries, then organisations like the FSF and SFC will have far more options in what violations they choose to litigate. However, this also opens up the risk of 'GPL trolls' who might not be motivated by the same principles[2].
https://sfconservancy.org/donate/
Their lawsuit against Vizio is especially interesting:
But not all businesses pay close attention to open-source licenses.
I have to assume that scale has something to do with it. Huge companies usually take that pretty seriously. Tiny companies... eh, they might not even be aware.
You're giving companies way too much credit. Unless a company has been sued for something, they often have no insight into or awareness of it. Most companies do not have strict policies around using GPL or OSS. The legal, audit and compliance teams are only aware of things when it's brought to their attention.
Our company is very good about accessibility and ease of use in our products, but only because someone used the ADA to sue the shit out of us a decade ago.
I would wager that most GPL violations are made by folks who are consciously aware of what they're doing, and the companies they work for are completely unaware that such decisions are even being made. There's no actuary running the numbers and saying "yeah go ahead and violate it, litigation is cheaper than compliance", that's tinfoil hat level thinking IMO.
That's a legal tactic regardless of initial intent or guilt. If you thinking waiting someone out is cheaper than losing or settling, then you stall. It puts a financial burden on them.
I'm not saying it's right, and it's also not an indicator of guilt, malice, or forethought.
Additionally people seem to think of legal contracts and licenses as being set in stone or non negotiable. In the legal world they are simple the starting point for any negotiation.
https://sfconservancy.org/copyleft-compliance/principles.htm...
"Our primary goal in GPL enforcement is to bring about GPL compliance. Copyleft's overarching policy goal is to make respect of users' freedoms the norm. The GNU GPL's text is designed towards this end. Copyleft enforcement done in this spirit focuses on stopping incorrect distribution, encouraging corrected distribution, and addressing damage done to the community and users by the past violation. Addressing past damage often includes steps to notify those who have already received the software how they can also obtain its source code, and to explain the scope of their related rights. No other ancillary goals should supersede full compliance with the GPL and respect for users' freedoms to copy, share, modify and redistribute the software."
Again, I'm not supporting or encouraging the behavior. This is just the reality of the legal system.
https://sfconservancy.org/copyleft-compliance/vizio.html
Sounds like John Deere might also need to come into compliance:
https://sfconservancy.org/blog/2023/mar/16/john-deere-gpl-vi...
A legally binding agreement (especially one to settle active litigation) is a very odd thing to describe as “non-legal means”.
Have any actually been decided by the court?
IIRC they redistribute the source to their users, so the GPL is respected. The GPL doesn't force you to make your modifications public or available to the original authors (that would be non-free), only that your users should have access to the modifications, also under GPL.
They surely do something like Red Hat that says in a contract you lose access to the GRSecurity patch¹ as a user if you publicly redistribute the source.
¹: (edit: lose access to further updates)
GPL 2.0
> 6. Each time you redistribute the Program (or any work based on the Program), the recipient automatically receives a license from the original licensor to copy, distribute or modify the Program subject to these terms and conditions. You may not impose any further restrictions on the recipients' exercise of the rights granted herein. You are not responsible for enforcing compliance by third parties to this License.
You may not impose any further restrictions on the recipients' exercise of the rights granted herein.
Red Hat prohibits you from redistributing their binary packages, and that's well within the rights of the GPL as it attached to the source with the only requirement on binaries being that the GPL'd source code be made available upon request. Before the CentOS rebase, they went a step further and you could just download SRPMs right off their FTP server without even being a paying customer.
In the case of GRSecurity, in their FAQ [https://grsecurity.net/faq] they even acknowledge that their customers have a right to share the patches.
Q: Does grsecurity have a free version for evaluation only?
A: Grsecurity fully complies with the license of the Linux kernel, the GPLv2. Since grsecurity is delivered as a source code patch, it is not possible under the terms of the GPL to offer a free version under an actual restriction that it be used only for evaluation purposes. Any customer receiving a grsecurity patch receives all the GPL-granted rights and responsibilities, including the right to redistribute patches in their possession or even to sell them to others.
What EULA do they require of end users?
I think this clause doesn't mean what you mean. This clause means that the GRSecurity project can't license their modifications under a more restrictive license than the GPL. Which the GRSecurity project respects, customers do have access to the modifications under the GPL license.
But this last Q&A states between the lines that no, they wouldn't provide a free version for evaluation only because if they did, you could freely redistribute the patch since they can't impose you to keep it secret because of this very paragraph of the GPL you quote, and they don't want this because that would break their business model.
That's not proof they actually tell their customers they will stop providing them further updates if they redistribute the patch, but this only reinforces my belief they do. This is exactly how they manage to keep there code non-public.
The GPL doesn't and can't force the GRSecurity project to provide updates to their customers under any circumstances.
This faq does not lie and is technically correct, it just "forgets" to mention that customers are tied to such a contract.
I completely understand why FLOSS people wouldn't want to go after individuals misunderstanding a license. And that's also not at all what I'm talking about. LEGO et al have been around for decades, piles of lawyers, heavy handed trademark letters from their lawyers.... but end up doing fuckall with FLOSS folks.
Think if the tables were turned - and you accurately modeled every LEGO brick and allowed sending to 3d printers to make custom bricks. Just how FAST would they shut that down?
Oh, and this is hypocritical as ever: https://www.lego.com/en-us/legal/notices-and-policies/fair-p...
LEGO brick patents have already expired years ago and there exists plenty of alternate producers of LEGO compatible bricks. but yes, LEGO is trying every trick in the book to stop alternate brands from selling their products.
i disagree however that suing for maximum damage is helpful to GPL software. it only instills fear in companies wanting to use it because it increases the risk.
i believe a good will approach to help companies with compliance is better, only suing when companies refuse to comply.
And for some reason, a company with questionable EULAs, illegal in many jurisdiction's terms, and hundreds of pages of dense legalese doesn't seem to scare any of these companies away.
And many FLOSS licenses are written in plain language to easily understand what you can and cant do. These companies aren't doing an accident - its intentional, ongoing, and continual malfeasance BECAUSE there is no real punishment. At best, they'll have to "comply". (And you know, FLOSS is always bemoaning no money.... well, here's a way to fund it)
> i believe a good will approach to help companies with compliance is better, only suing when companies refuse to comply.
You can disagree with me all you want. All I ask is "how does it look when the tables are turned"?
And we have a rather nice answer - https://www.bsa.org/ and https://www.siia.net/
The business software alliance and Software & Information Industry Association are utterly dictatorial about intentional copyright violations, and also very harsh about accidental violations.
You can do further research on case studies of places that were called out for pirated software, and how many millions of dollars they had to pay in fines and "fixing proper licenses".
Until FLOSS starts doing tit-for-tat (the best game theory decision in these kinds of things), we're going to keep seeeing companies treating FLOSS as their own personal loot-crate with little to no punishment for intentionally doing wrong.
for every company that is doing that there are two others the use FOSS with good intentions, and some of those will make mistakes in their compliance which they will fix when politely approached.
if we start pursuing every violation with an immediate lawsuit then those well intended companies will stop using FOSS because they don't want to risk getting sued.
i will have to stop using FOSS in my products. because my small company can't afford a lawsuit just because i accidentally forgot to give notice or include a link to the source somewhere.
so if we do that FOSS will loose market share.
we can and should pursue malicious users aggressively, but only after we have confirmed that they are not going to comply willingly.
I doubt the statistics here. I surely hope most companies are not this sloppy with their contracts, that they "forget" to follow their requirements.
> if we start pursuing every violation with an immediate lawsuit then those well intended companies will stop using FOSS because they don't want to risk getting sued.
> i will have to stop using FOSS in my products. because my small company can't afford a lawsuit just because i accidentally forgot to give notice or include a link to the source somewhere.
And what will you use instead? How will you follow the requirements of those licences? That's what I never understand in these arguments. The alternatives have typically much stricter requirements and are enforced by large corporations.
> so if we do that FOSS will loose market share.
Why should I care about the market share of FOSS if a significant portion of that share doesn't distribute their code?
> we can and should pursue malicious users aggressively, but only after we have confirmed that they are not going to comply willingly.
i said "some of those will make mistakes", which means, most won't. there is no contradiction.
And what will you use instead?
BSD stuff i suppose, or write my own, or pay for a commercial license which is usually a lot easier to follow than the GPL, because it doesn't require me to give anything to my users. i just pay and then i can use the code however i want as long as i don't resell the source.
Why should I care about the market share of FOSS
that's up to you. i care because FOSS, and the GPL in particular give me and other FOSS users more freedom in how they use the software. in want this freedom to spread. making it risky for businesses to use FOSS is not the way to do that.