Misfired e-mail was never viewed by Gmail user
news.cnet.com
news.cnet.com
I've yet to find a compelling argument against this. Or at least one that's persuasive to our legal department.
What -- in particular -- does the legal department have against Open Source software? Is FireFox somehow a legal-risk as opposed to Opera? Even though it's been vetted by a larger installed user-base? Or is it just because there is no 'single entity' that they can sue/point fingers at when/if something goes wrong? There are plenty of anonymously authored non-opensource pieces of software out there.
I think that it would make more sense to have either: 1) have to register all software on the list or 2) have to register all 'non-popular' software (i.e. Firefox/Opera ok, random OSS/proprietary software needs to be registered though).
We also have a number of customers requiring that we provide indemnification against any open source software infringement claims, which has sent our counsel down the path of wanting a full registry and approval process for all open source software on developer workstations.
The positions I've taken -- the workload, the fact that the registry doesn't adequately protect us from the surreptitious introduction of copyleft code snippets, etc. have all fallen on deaf ears. I'm trying to figure out what other arguments I might be able to bring to the table.
You might remind them that not all proprietary software comes from large corporations and many of the smaller guys might be more willing to pursue the legal 'issues' to the fullest extent of the law.
> The positions I've taken -- the workload, the fact that the registry doesn't adequately protect us from the surreptitious introduction of copyleft code snippets, etc. have all fallen on deaf ears. I'm trying to figure out what other arguments I might be able to bring to the table.
I would point them in the direction of people that have purposely included open source code in proprietary projects (e.g. the recent ScummVM on Wii issue) to try and instill the fact that registering all open source tools that are being used will not protect them from a developer that is trying to 'cut corners.'
If I have Firefox installed on my computer that DOES NOT mean that I have the source code 'at my fingertips' as well. The same could be said of Vim or Emacs. And unless your employer is building developer tools, I doubt that any of your developers is going to try and include code from the Vim or Emacs codebase. It just doesn't make sense.
Or perhaps it just feels that way to me, because I really detest environments where one must start paperwork fights with bureaucrats just to get things done.
Note that the answer to the latter can not be "you know what we mean".
Note that there's potential liability for proprietary software if you get this wrong while there's no liability for free software if you make a mistake. (The only liability for free software is if it turns out that it's actually proprietary.)
no customer data of any sort has been viewed or used by any inappropriate user during this data lapse
Since the email was apparently sent "in the clear" they cannot say this with certainty. A copy could have been siphoned off any intermediate network or smtp server.
https://addons.mozilla.org/en-US/firefox/addon/9549
Also posted to HN here (upvote if you want others to know about it):
So basically they got unbelievably lucky. It doesn't change the fact that Google was prepared to bust down this guy's virtual door because someone said they accidentally slipped some data in his mail-slot.
It's still all very troubling.
First, one company has access to tons of my personal data. I trust this company, they seem well intentioned and they have a very reasonable privacy policy. It's also extremely useful to me to have all of my data (email, personal contacts, calendar) in one place and accessible via a web-interface.
However, when you throw in the second variable, namely, the mixed-bag which is the US judicial system it can all be torpedoed with the flick of a wrist.
I really would have preferred to have seen the judge tell the bank "tough shit" and have someone (either the email recipient or EFF) put up more of a legal resistance to this court order.
I found the Liskula Cohen blogger case much more troublesome, and the ongoing TCI Journal case is especially disturbing.
But in the end, they did the reasonable thing: delete the email and move on.
This is how it's done in most disk encryption software, for example, FileVault.
I love this world.