USB Implementers Forum Says No to Open Source
hackaday.com
hackaday.com
(Whoever gets "officially" issued that VID is going to whine when they notice it's already being used for hobbyist purposes anyway, which means that the technique of just picking one will guarantee uniqueness.)
Edit: On second thought (after I actually read it), this bit...
Please immediately cease and desist raising funds to purchase a
unique USB VID for the purpose of transferring, reselling or
sublicensing PIDs and delete all references to the USB-IF, VIDs and
PIDs for transfer, resale or sublicense from your website and other
marketing materials.
...rubs me the wrong way on so many levels, I'm tempted to say, the hell with the forum. This idea did not sit well with VTM Group, the people serving as the
management, PR, legal, and membership and licensing department of the
USB Implementers Forum
The hands, the mouth and collector of thoughts cannot be separated from a thing and still be called a whole. Besides even the title says, "USB Implementers Forum Says No to Open Source"I don't know about that. Publishing houses are certainly separate from authors, and record labels from musicians.
Don't underestimate the USB Implementers Forum. Despite its name, it is not an organization of USB users (big and small). They have a direct interest in this matter because:
a) Like every organization, they need to have some source of income. Technically, they're a non-profit organization, but they're also the one who issue the VID, and a company giving out PIDs to whoever wants them is eating their "lack of profit".
b) Its members who have an interest in consumer devices/end products (i.e. companies that don't sell chips, but devices using chips) tend to be large and slow-moving. The Kickstarter crowd is pecking at their business options. (True story).
Which explains why we (especially) react so strongly to it.
Imagine a world where this 'open' approach gains market share. For the consumer, the net result easily could be that USB, which now is highly plug and play, becomes more like the way ISA cards used to be plug and play: you can plug in any device, but to make it work, you need to do some voodoo (oops, there's more than one device with that PID/VID. Please tell me what you plugged in: X, Y, Z, or something I haven't heard of?")
Exaggeration? Yes, but not completely untrue, and that's the argument I would make.
Whatever you do, you need some entity that prevents multiple manufacturers from using clashing identifiers. That is one of the things the owners of the standard will fight for to maintain, because it is one of the things required to make USB work as well as it does.
Yes, it would be nice if they sold individual VID/PID pairs to hobbyists. But I do not see a legal reason why they would have to do so. Anti-competitive? Maybe, but they will argue that there are thousands of individual vendors in the market.
For the record, this already is pretty common. Lots of keyboards mimic Apple's VID/PID, and tons of controllers use absolutely nonsense VIDs/PIDs (GameStop's mobile controller line, for example).
"There are a number of ideas to get around VTM Group that include squatting on USB VID 0xF055"
0xDEAD
0xBEEF
0x1337
0xFACE
0xF00D
0xABCD
...and so on?Maybe, if they're reserved as unassignable (due to being an inappropriate value for professional, business puposes), then perhaps it's open season on those.
Though I'm not sure how accurate and complete this list is.
Edit the official list is here but they list their VIDs in dec.
So if you put the USB logo on your marketing and claim to have a "USB Mini" connector in your specifications then you could be in trouble on two fronts: (1) the usb folks can sue you for using their IP and (2) purchasers can claim the product is not "as described" which may given them certain rights dependent upon the location.
Not using the official logo shouldn't be a problem in hobby market. Everyone will recognise the connector. Not being allowed to identify it as USB2 or USB3 or whatever, that could be a problem. I'm sure there are creative ways around it though.
And about squatting on a VID.. Well, they should have thought about pollution of their namespace on their anti-hobbiest policies. They frankly deserve it.
The most prolific of those 3rd party companies was sued by Nintendo and lost.[1][2] Although that case is not directly applicable, and had different circumstances. I thought it was worth mentioning.
[1] http://digital-law-online.info/cases/24PQ2D1015.htm
[2] http://www.1up.com/do/feature?pager.offset=1&cId=3146206
http://www.lettersofnote.com/2012/03/butt-head-astronomer.ht...
"Connects to your computer at speeds up to five gigabits per second using industry standard USB cable," probably covers everything short of a the edge cases such as government procurement contracts.
V-USB for AVR gives you 2 VID/PID pairs for 500 Euro. http://www.obdev.at/products/vusb/license.html
There's also a 10EUR hobby package which gives you a pair for personal use only.
FUP applies, but if you're breaking it then really you should go legit and pay the USB feds their protection money.
How are these guys getting round it?
So whether you can safely ignore this depends largely on how easy it is for this body to successfully throw the book at you, and others' success in this area doesn't really mean anything unless you're able to operate in the same circumstances, which I doubt most of us are.
Maybe we should just squat the VID, and then do a PID+(another field in the descriptor) as the discriminator for people who need special protocols (I do).
For now I've stolen my MCU maker VID and used 255 as PID, because I couldn't even find an "experimental" PID/VID in the spec to use during development.
It's a bug and urgent problem, I'm perfectly ok to fudge the rules, but we have to agree on something that doesn't break people's drivers.
development usb "vid" -video
First hit is someone asking about VID/PID in a motherboard forum.IIRC they're not the first, either. And there've also been organizations freely allocating unique ethernet addresses out of their OUI space.
The amount of trouble they receive from the USBIF/IEEE/whoever seems to vary a lot from case to case, though. I expect it depends on which individual person the situation comes to the attention of. In some cases the USBIF or IEEE has actually revoked the VID/OUI assignment, leaving everyone who tried to play by the rules effectively squatting on an unassigned ID anyway.
Some ancient history: https://forum.sparkfun.com/viewtopic.php?t=931
"Since other USB device vendors such as Microchip and FTDI give away USB PIDs for free"
Does that actually mean, they give them for free? If so, how can they do that? Why does VTM allow them to do it? And what is the actual problem at all if you can get them for free?
Bus 002 Device 013: ID 0a12:0001 Cambridge Silicon Radio, Ltd Bluetooth Dongle (HCI mode)
0a12 is the VID for CSR, and 0001 is CSR's PID for "Bluetooth Dongle (HCI mode)." You can find a list at:
http://www.linux-usb.org/usb.ids
Microchip has paid USB Forum for its VID 04d8. If you build a USB peripheral with one of their microcontrollers, you can ask Microchip to allocate you a PID (since they have 64K of these), and let you use their VID:
http://ww1.microchip.com/downloads/en/DeviceDoc/APPLICATION%...
FTDI own a bunch of VIDs which are associated with "FTDI" devices. If you ask FTDI they'll reserve a small block of PIDs for you to use for your own products that use the FTDI USB chips. 8 PIDs cut out of a 65536 block is not a significant cost.
I'm surprised that VTM still allows them to do it though, maybe it's a special case because you're using their IC.
The problem is that VTM maintains an "official" list of VID/PID owners, so that they can keep drivers on seperate IDs and prevent clashes for users. Most hobbyists just pick a random VID/PID for their personal projects and hope for the best, but for small scale hobby releases it's problematic since "technically" they are going against the terms of service for the USB protocol. Sometimes there will be clashes if people pick random numbers, and VTM hates that.
http://www.ftdichip.com/Support/Knowledgebase/index.html?can...
Whereas the hobbyists, if you don't intentionally try to screw them over like they're trying to do, would probably be ridiculously loyal and obedient in comparison.
Fundamentally despite the "hate opensource" and "revenue generating middlemen" story, some of which probably is true, the fundamental problem is likely the lack of a point of contact. They probably like knowing there's a directory of real world contact information such that identification number 0x123456 is clearly a product of such and such for debugging purposes and interoperability and lack of duplicate IDs and the like.
Something similar happens with ethernet MAC addresses. Legendarily it was HP (or was it sun?) who shipped a whole batch of ethernet cards accidentally in the 90s with the same MAC address, boy was that a nightmare to figure out the hard way.
Android has an API to query a unique device ID, which is generated from a field that's supposed to be populated with a serial number by the manufacturer. It is (or was previously) used to identify you as a particular user in some games, as well as for ad tracking and analytics.
One line of phones (I forget which manufacturer) managed to NOT update that serial number correctly, and as a result the entire model of phone came up with the same "unique ID". This was not fun to debug, as lots of users were ending up with other users' saved games, and one particular "user" was showing up in analytics as having used dozens of apps thousands of times a day...
Sun used to use the same MAC address on each port of their QFE (quad fast Ethernet) cards. It was easy to fix with ifconfig, but always made me wonder two things: a) if I number these ports sequentially (:a, :b, ...) am I going to collide with some other QFE card from the same batch, possibly from this same order of a dozen cards? And b) who thought this was a good idea? Was Sun just conserving MAC addresses on the theory that most QFE cards are 75% underutilized??
The problem I ran into was that when two same-MAC ports were connected to different segments/VLANs on the same layer 2 or 3 network device, that device wouldn't know what to do with the packets. Or it might send them down the wrong wire, which was a problem for me -- these were firewall boxes. :)
Eventually Sun added a boot param (or a kernel config? Set from OBP or from a shell) that would automatically number the QFE interfaces sequentially on boot. That fixed the problem for me.
Much later, they added the front-panel accessible smart cards that contained MAC, hostid, etc. I think that was the Netra series, intended for carrier grade RAIC installations.
I have a knock-off xbox controller that is an exact copy of the Xbox controller S, but claims USB ID ffff:ffff. It turns out there is also some unrelated cheap IR receiver that does the same and if you are unlucky this driver gets loaded instead, leaving you wondering why the gamepad doesn't work.
If they can't responsibly offer their product without revoking it for simply using it as intended, they are racketeers. The Open Source community has not broken any legal agreements in simply publicizing the idea of a shared VID. The USB Forum are completely in the wrong for their behavior.
http://www.mcselec.com/index.php?page=shop.product_details&f...
MCS is in Holland, where both their jurisdiction and the fact that they licensed their VID from USB-IF a long time ago make it impossible to enforce the prohibition against reselling PIDs. For EU 10 each, it's worth it just to kick sand in the face of the asshats at USB-IF.
I use lots of hobby stuff with USB ports. I have to lookup the vendor ID to make it read write in linux by default.
Presumably getting a proper ID makes this pain point go away from consumers somehow?
What's the gain I don't understand it?
Using your own VID/PID allows you to write and distribute a driver that can be tied to your gadget rather than using a generic driver. Widely distributing products (even if they are "hobby stuff") that re-use the microcontroller's default VID/PID is also usually against the license agreement with the chip vendor and can lead to problems down the road.
The USB-IF can go fuck themselves either way. There is no place for them in this world, and I hope they disappear as soon as reasonably possible.
Also, a lot of this could very well be trying to avoid the pain of the Bad Old Days of pre-plug and play DOS, where you had to manually set things like interrupts and I/O ports, and hope and pray that your new device didn't conflict with something important. For example, many an oldschool game had dire warnings about not running the sound card autodetect if you had things like scsi cards, because the conflicts were near inevitable and pretty catastrophic.
It will happen, that's a near certainty. Some day, somebody will think that's a good idea, and since it's easy, the scheme will get widely used.
Whether this is actually better probably depends on your point of view. But loading (somehow OS-neutral?) drivers from a fixed store on the device seems like a great way to be stuck with out-of-date binary blobs forever.
Moreover, in my current forey into USB, I discovered that kernel device drivers are completely unnecessary. And a google chrome API (or the underlying libusb) is completely good enough for proprietary devices.
[1]: http://www.draisberghof.de/usb_modeswitch/ [2]: http://www.hp.com/global/us/en/laserjet/hub/printer-installa...
Oh, come now. Any competently-designed USB penetrator will have your system owned seconds after you plug it in, with no further interaction from you. Running drivers from the device poses no additional risk beyond what you've already taken.
Where can I donate to Arachnid Labs?
Also, if an open source is popular enough to the point a unique VID is needed for proper driver support, I will say this project will easily get fundings to go commercial (just like RedHat).
Following a link on the internet it look like they actually have a prototype VID/PID, but you have to contact the forum and sign some boilerplate (saying you won't release your product with the proto numbers) to get it.
The fee is $5k if I recall. As others have mentioned, if you are planning on making a real product, it's something you can roll into the cost. Although I completely understand the difficulty of someone just looking to sell ~100 devices.
I wonder if there's a way to allow a "Bring-your-own" VID? As in maybe switches or something to set the VID by the purchaser?
And also, to find the device from the OS API, you sometimes have to submit the VID/PID of the device you are looking for. Example: http://developer.chrome.com/apps/usb.html#method-findDevices So changing it on the fly might be a problem (not sure, maybe once open they won't seek it again).