Ubiquiti Networks is creatively violating the GPL
libertybsd.net
libertybsd.net
I imagine that some of the puzzle is because DMCA is cheap and effective against websites moreso than against hardware manufacturers. Even so, Ubiquity Networks provides web downloads of their firmwares [1] so surely DMCA notices could at least impair their update distribution, which would annoy customers and put pressure on them that way. Meanwhile there is plenty of "purely web" software license violations.
I know that many projects don't get the copyright registered, which puts them at some legal disadvantage. But it's cheap to do, it's something that developers can be educated about, and it is economical for lawyers to take those cases (if facts and registration are strong) on contingency.
So I don't understand why there's not a little cottage industry for it like there is for the photographers.
Which makes me wonder, perhaps in next iterations the GPL should include provisions stating that intentional infringement (perhaps defined as failure to comply after 1 year from date of the complaint) results in financial penalties, thus allowing a cottage industry to form.
It could be argued that this would have a chilling effect on the adoption rate of FOSS software in corporations, but I would argue we may have already reached a critical mass where it's more costly to develop your own solution and I would point out that this only applies to modifications that you make to the source code before distributing the result. Anyone can still download and use the software without worry.
To the extent that doesn't happen means that copyright holders (developers) don't do it. Either because they don't know how, they didn't register in a timely fashion, they don't want to bother, or they don't want money.
Here's the text of the relevant section of the GPLv3 (the GPLv2 only has an equivalent to the first paragraph):
You may not propagate or modify a covered work except as expressly provided under this License. Any attempt otherwise to propagate or modify it is void, and will automatically terminate your rights under this License (including any patent licenses granted under the third paragraph of section 11).
However, if you cease all violation of this License, then your license from a particular copyright holder is reinstated (a) provisionally, unless and until the copyright holder explicitly and finally terminates your license, and (b) permanently, if the copyright holder fails to notify you of the violation by some reasonable means prior to 60 days after the cessation.
Moreover, your license from a particular copyright holder is reinstated permanently if the copyright holder notifies you of the violation by some reasonable means, this is the first time you have received notice of violation of this License (for any work) from that copyright holder, and you cure the violation prior to 30 days after your receipt of the notice.
So, on a second violation of the GPLv3, or on a first violation if it takes longer than 30 days, the rightsholder can already say "You need to pay me if you want your rights reinstated."
Conservancy has been using a variant of this tactic: they get a friendly, clear rightsholder for something like Busybox (which has relatively few authors), inform a company that they're violating the GPL and revoking the Busybox license, and demand GPL compliance for all software, including stuff like Linux which has so many authors that getting a clear rightsholder involved is harder, before reinstating the Busybox license.
Here’s one attempt at a solution:
OTOH I've heard there is a small part of the software industry (I don't know that it is serviced by intermediaries) that uses the GPL to gain users and putative non-compliance to covert some of them to proprietary licensees.
The common difference is between those largely want compliance with their licenses (when they can be bothered at all) and those who largely want a payday, making their efforts must self-financing.
Folks who want to see more enforcement to bring into compliance should donate to http://sfconservancy.org/linux-compliance/ (disclaimer: I'm on their board)
Personally I would enjoy a cottage industry around self-financing (ie payday oriented) enforcement of free licenses. It'd either increase the apparent trend toward non-copyleft licenses (ie much less to comply with), particularly public domain, or increase the appeal of copyleft licenses, perhaps both.
Unfortunately we no longer offer support for our SDK, and I'm not able to divulge in the specific differences between airOS and openwrt. Also, we don't share u-boot GPL source. We used to in the past but not any more. This decision was taken keeping the security of the users in mind. I hope you understand.
However, you can find the GPL archive for our devices from here:
https://www.ubnt.com/download/
(Please refer the "GNU General Public License link" under the Firmware and Software section from the above link page provided).
If you have any other questions, please let us know.
Thanks!
xxxx Ubiquiti Networks
Funny, because this is the exact inverse of the situation. They introduce security bugs and then we are unable to fix them ourselves.
They are legally required to provide the sources they use for u-boot.
They use a lot of open source software and make firmware updates and controller software readily available, so how could they not know that
* The GPL's legal requirements come before your products needs, your users security or whatever. If you can't use GPL'd software, then don't.
* open source software has always proven to be more secure, because relatively serious and obvious security bugs linger in closed source software for a long time. How can we know that your closed source software is better than history suggests (unless you release the source...)
ridiculous. I kinda hope some of their engineers notice this on HN and can use evidence of "public" (engineer) sentiment to pressure the management
Given that they are clearly in the wrong, it is not surprising that they are hoping for copyright holders to be understanding!
(and more amusingly, had to turn off the very feature he got them for because of a wireless scale... https://plus.google.com/+LinusTorvalds/posts/WppMs5XEa3X)
Thank you for reinforcing my point (elsewhere) about how the "gratuitous negativity" rule will never be used to do anything but reinforce the HN zeitgeist. I knew I wouldn't have to wait long for an example I could point to.
To respond to your original point, I don't get it. If you choose to release under a license which doesn't require releasing source of any mods, that's a perfectly reasonable choice. Why should there be a "possibility of legal action" against something which is explicitly allowed by the license?
I can't (as an interlocutor), and I can see that nobody else has either. The prediction seems to have survived at least this one test.
"If you choose to release under a license which doesn't require releasing source of any mods"
...and there's nothing wrong with that. I'm not saying non-copyleft licenses are bad. I don't believe that. Even if I did, I don't have time for another round of that debate. I'm just pointing out what the practical difference is. People who care about the security aspect of Ubiquiti's behavior, or about the lost potential to install an alternate OS on their hardware, should be aware that permissive licenses give them zero leverage toward affecting a remedy. Those people might want to consider software licensing as part of their router purchase decision, even if they don't like GPL for their own code.
(I generally try to avoid meta-discussion, so this is all I'll say on this topic.)
Other licenses just don't make those sorts of demands.
Think of a license that limits you to X deployments per unit of time, and forbids any additional deployments.
If your automated deployment system performs X+Y deployments (where Y > 0) in a unit of time, then you're in violation of your contract and legally liable for your actions.
Is this contrived? A little. But, realistically:
1) The GPL isn't the only license that you can violate with sloppy dev practices.
2) In the overwhelming majority of GPL violation cases, the remedy is for the violator to simply comply with the code's license and ship the code covered by the GPL.
1) Sibling post mentioned forgetting to include notices in the documentation. Which is a valid counterpoint, but I would assume requires more of a one-time effort than a permanent change (improvement) in work procedures.
2) Assuming they can even find the right version.
You assume wrong. There is always another project, or another library.
But I would not try to guess how sloppy someone need to be to do it incorrectly.
For why I don't think is correct: if you violate a license, you are legally liable for copyright infringement, just as if there was no license on it in the first place. Every license other than CC-0, Unlicense, and other PD-equivalents requires something of you. If you use a piece of BSD-licensed software without attribution, you are liable for copyright infringement. (In at least the US, if the use was commercial, this is probably criminal copyright infringement.) The rightsholder can sue, and offer to settle out of court by having you release source instead of paying damages. It would be unusual but possible.
For why I'm confused by this comment: isn't it intentional, on the part of almost all other popular licenses, to permit commercial reuse without requiring the release of source? Wouldn't one only use the Apache License, the BSD license, etc. if one wanted Ubiquiti to be able to use it without being compelled to release source?
Is your claim that people are bad at understanding what licenses mean, and are unintentionally choosing weak copylefts when they want strong copylefts? I could believe that, but I haven't seen much evidence of that.
My anecdotal experience with this, having done many contracts providing commercial modifications of OSS, is that the companies that contribute their changes back is a tiny tip on the iceberg of use and modification.
That's not to say this is bad, if it's what one intends. But it's frustrating to watch people denigrate the GPL, sometimes, because of their wishful thinking about other licenses.
Frankly, the paperwork required to keep track of installed instances of -say- volume licensed MSFT software is a fair bit more burdensome than procedures to handle source code requests for GPL'd code.
Hell, you can automate both processes, but -in places that are like the dev shops that I've worked in- you're far more likely to automate the GPL compliance procedure. :)
I think I heard something a while back, about Microsoft changing how they did volume licensing. Because it really was too much of a PITA, and they wanted to simplify things.
I suppose one different would be what's required to get back into compliance one you inevitably stuff things up. In the one case, you have to probably pay (money is fungible) and/or remove things you have installed. In the other case, you have to find something you might not know where it is (if it even still exists) and provide it to the public (and be sure that doesn't violate an other licenses you have). ...I think I might be moving the goal posts a bit here, but that's what you get for being a rubber duck. ;)
If you follow what's generally considered good development practices (automated builds, everything in version control, etc), GPL compliance should be dead simple. So congrats, it sounds like you work for people who don't have their heads up their asses.
...hey, maybe that would be a good basis if we ever did turn into a proper profession: version tracking and automated builds.
People screw up all sorts of compliance issues. All but a tiny handful of software licenses out there can be violated by sloppy practices or mistakes of one kind or another. The GPL is not unique in this regard.
You should try your attempts to paint a different picture in another forum: all but the greenest programmer has far too much experience to be convinced by your argument.
If you've ever used a Ubiquiti product you'd believe they're just stupid
Also their web interface has terrible memory leaks which causes loads of other issues.
Don't forget the management network interface that just stops being able to be pinged until you reboot. Have seen this on everything up to AirFibers.
If Ubiquiti is in breach of the GPL then their customers cannot receive a license to the infringing work by Ubiquiti distributing it to them, so they're infringing too.
I don't think this has been done before. It would definitely chill the acceptance of GPL software in general.
edit: all of the above is incorrect and I retract this.
4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided under this License. Any attempt otherwise to copy, modify, sublicense or distribute the Program is void, and will automatically terminate your rights under this License. However, parties who have received copies, or rights, from you under this License will not have their licenses terminated so long as such parties remain in full compliance.
As I read that, as long as you don't further redistribute, you should be good.
Think about the licensing issue as a licensing chain / tree with each version having a separate license (instance).
Firstly, the customers aren't distributing the software so I don't see how they could be liable. Secondly, the customers are the ones who are actually being wronged here, because they've purchased devices based on GPL software--for which they are entitled to the actual source code.
If anything, the customers should be the ones bringing suit.
Multiply by the number of infringements here, and the history of not complying with the license despite many opportunities to do so, and there is no way that this belongs in a court whose maximum potential penalty is $10,000.
If there is one reason I'd ever consider becoming a lawyer w/my CS background, this would be it. I would set up some kind of a subscription model to which lone developers/copyright holders would pay my firm an ongoing subscription for as long as they wish, and in response get legal representation.
I am both and I have investigated this, and discussed partnering with firms etc. - I have looked at this seriously, and from many angles. There is no way this can be made viable. How much will an OS/single developer pay for this? 10$/month, max, the most motivated ones? OK great, after one year, they've paid for 30 mins hour of legal representation, not enough to read the first 2 emails that lay out the first issue they have (and those who pay 10$/month will find issues, they'll make a sport out of finding anything that remotely looks like they could get their money's worth).
Furthermore, the added value of a CS background in the legal profession is tiny - as in 'worthless for all practical purposes'. At best, you'll be the Word and Excel wizard in the office - which is basically a career-limiter, rather than propellant. I can count on the fingers of one hand (even if I would have had a serious wood-chopping accident involving that hand) the top people in the legal profession (in my market) who get a real value from their technical background (the one I do know has been blogging for going on 20 years on the intersection of law and technology, so even there the advantage is indirect).
Just saying - don't bother :)
Hence, if you had a ubiquity contract, and demanded GPL compliance, you could sue for quite a bit of money for selling you pirated software (GPL license is revoked when source is not provided), and they would settle, rather than violate national security.
Phillips too, with their smart TVs running Linux and other FOSS.
They just provide some vanilla random .tar.gz of "gpl source CODE" and thats it, not really the version thats running on the device or that was distributed by them.
The actual binary, firmware, is encrypted too.
0 fucking freedom for a normal user in age of FOS software all around us.
It would have been better with proprietary software. Then I wouldnt have gotten pissed.
Sierra Wireless 803s - running Linux as far as I can tell (nmap -O, update files, GPL license text in manual). Once again there's not even really a website for the device, nevermind some token source tar. Haven't yet broken into this device, I'm assuming there's a JTAG on its 60 pin debug connector, but I need to try the easier route of hacking an update first.
The theory goes that manufacturers should realize that obscuring their systems gives them no benefit (especially since they're able to put different copyrights on the parts they actually write eg the webuis), while opening them should give goodwill, but this has not played out in practice. Manufacturers clearly care about some aspects of licensing, given that they'll include license texts/notices/etc in the manual. We need a way of making the two line up.
But the unfortunate reality is that we're on shaky ground. The rise of embedded devices with baked-in binaries has shifted the landscape. In this environment, BSD-style licenses fail Freedom 1 (https://www.gnu.org/philosophy/free-sw.html).
The Linux kernel is the main item that is infringed upon (presumably because its too complex for eg Google to reimplement as BSD like they did with the Android userland). And its developers have stubbornly stuck with the broken GPL2, making it so that even with perfect enforcement (which they also don't seem interested in), make && make install is not an achievable goal.