Mailpile Chooses AGPL v3
mailpile.is
mailpile.is
RMS himself: "Both of these licenses qualify as free/libre; neither of them is unethical. Given a choice between two ethically valid options…"
some anti-GPL person: "The GPL irritates me -- mostly because of RMS's "this is the only answer" attitude"
I could go on about this, but just think about it for yourself. Don't be that foolish person making up straw men.
I'm sorry you missed our announcements - we did send an e-mail to everyone who donated $23 USD or more, inviting them to our community voting platform. We tweeted and blogged, it was mentioned on Facebook... we used all the channels we have and overall I've been very happy with community response.
There will be other votes in the future, so please follow us on Twitter or subscribe to our blog's RSS if you're interested. And thank you for your support! :-)
Regarding the election; as I mentioned in the post, I have been following the ratios since elections started. The ratios have been pretty stable the whole time; for every Apache vote there were roughly 1.05 AGPLv3 votes... I think it's unlikely that better outreach would have changed things. A broader and more lively debate might have, but given our limited resources we weren't able to stoke that particular fire any more than we did.
Out of curiosity, what is the percentage of all of your donors who donated $23 USD or more (and, thus, received the e-mail invitation)?
I'm simply curious if there's a correlation between the two.
That said, 16.5% voting participation is a bit on the low end. My guess is that it mostly reflect those who reads the Mailpile blog, are active in the development, or are active in places like HN/conferences where news about the vote has been announced several times.
(edited)
[1] https://github.com/MachinePublishers/jBrowserDriver/blob/mas...
[2] https://github.com/mattermost/platform/blob/master/LICENSE.t...
Perhaps we need a similar license for "AGPL with the Classpath exception".
Maybe call it LAGPL or something.
The classpath exception is intended to cause the target software to not have a license change just because it used a certain runtime library (classpath).
The LGPL has different aims entirely (around allowing library components for software).
Essentially, the classpath exception was written for programming language runtime libraries (and is thus the basis of what later became the gcc runtime library exception).
The LGPL was written for random library software, and started out much earlier than the classpath exception (by a decade or two).
I blogged about open sourcing the project and the license choice here: http://hbbio.tumblr.com/post/66287893522/open-sourcing-peps-... and HN discussion at the time: https://news.ycombinator.com/item?id=6690603
Several points and comments naturally also apply for Mailpile.
But why? If I would participate in the voting I would probably skim both, look at Wikipedia and some of these "license explained" projects, but I doubt it would be enough to be sure my vote is the right one whatever election result will be in the end. What it actually means for the project to take this or that stand?
I wonder, how many people who actually voted where thinking something like this? Maybe it would be better if anybody who knows for himself which decision is right would share his opinion explicitly. Who knows, maybe the voting result wouldn't look so "divided" after such a discussion.
He did.
> "Because I think it is the right license for this project".
That's the introduction sentence of that section. He then goes into more detail. Did you skip the last 3 paragraphs?
---------------
Mailpile is a project about freedom. It is not a popularity contest or a startup, it's not "industry infrastructure", nor does it aim to be. Mailpile is a political project which aims to improve the privacy and digital independence of individuals everywhere.
The Apache License is a wonderful thing, an open, generous, pragmatic, apolitical license. The AGPLv3 on the other hand, is a political and ethical line in the sand.
And so is Mailpile.
---------------
The whole point of Mailpile is to take your data off the cloud and control it yourself. It is explicitly and deliberately anti-cloud. If the license makes it nearly impossible for others to use Mailpile as part of a cloud-based platform, the developers probably consider it a feature, not a bug.
If there's any program for which AGPL is an appropriate license, Mailpile is it.
- you proved to me that AGPL is not usable in any professional system that runs in the cloud
- also proved that it does things forcefully so I am right not using it
Thank you!
That interpretation is wrong. The AGPL just prevents you from pursuing a business model that is based on leeching off the mailpile project without contributing back.
It's the decade old misunderstanding. The GPL is about user freedom. You talk about developer freedom. Mailpile tries to optimize for user freedom. The whole project is about preventing business models like the one you proposed. Choosing the AGPL is completely coherent with the stated project goals.
I am not leaching on anything. You can twist words as much as you want but freedom is not defined by you or RMS or for that matter anybody else. It is pretty clearly defined in the dictionary and AGPL contradicts the foundation of freedom. If you dont want people use your software freely dont call it free software. Call it "limited use to a subset of non-profit oriented users who contribute everything back in return of using my software". That would greatly simplify the life for everybody and we could save the planet instead of haveing this thread about what is the definition of freedom and who does it apply to.
It's never as simple as this. That dictionary entry you refer to is meant for people who don't know the word and want to learn its meaning. Have a look at the theoretical spectrum here: https://en.wikipedia.org/wiki/Political_freedom#Views
(Mostly) independent of political leaning, it's more or less consensual that freedom is a social category. The concept only makes sense if we talk about human societies in one form or the other. That, by definition, involves other people, and other people's freedom. You always have a boundary where your desire to exercise your freedom conflicts with the desire of another person. We can't escape that. Theories of freedom all try to find an optimal way to lay out these boundaries while maximising freedom. But there is no objectivly archievable optimum, as every theory has to use certain axioms for defining the _details_ of that nebulous term.
You can lump together most schools into two categories: the institutionalist one and the consequentialist one. The US-American interpretation of freedom is strictly institutionalist. The Western European is mostly consquentialist. That's why both sides think the other part is less free :)
An example for instutionalist thinking: Both men and women are by law allowed to pursue every job they want. Therefore, both are equally free.
An example for consquentialist thinking: Observably, women choose jobs that earn them less money. In a capitalist society, that makes them less free. Therefore, we as a society have to intervene so they can get equally free.
The difference between AGPL and Apache etc. is exactly the same. Apache style licenses see freedom as theoritcal freedom of choice. That's the institutionalist way. AGPL goes the consquentialist way. It limits certain freedoms with the goal of maximising certain other freedoms. It defines the boundary between individual interests in a different way to enable higher observable freedom for those parties it deems more in need of protection: users, not entrepreneurs.
The foundation of freedom rest in the individual ability to create agency. Freedom is not the "liberty for everyone to do what he likes, to live as he pleases, and not to be tied by any laws", but "consists of being under no other lawmaking power except that established by consent".
It was a licensed chosen by a vote. As freedom goes, it more or less defines the ideal situation.
Do you want people to have an be able to exerciser that kind of freedom?
The AGPLv3 on the other hand, is a political and ethical line in the sand.
And so is Mailpile.
And a good way to completely scare away a good subset of potential users.
Perhaps the author feels like they are no-value users.
Due to the risks and complexity around these issues, and the high cost of "getting it wrong" either in one's analysis or in making a mistake, many firms choose to stay away from projects licensed with AGPLv3 even if they are actually intending to use the software in a way completely compliant with the license. Using it even the right way, safely, is viewed as too much of a risk.
The legal teams for many large companies recommend a company policy that prohibits using GPL and AGPL software outright - that's just using (running on company servers), not modifying, and not redistributing anything but the original version. Attaching a license like GPL or AGPL is a good way to kill enterprise use of a program even by companies that are conscientious about open source. See how Google views the AGPL, for example: http://www.theregister.co.uk/2011/03/31/google_on_open_sourc...
Perhaps it shouldn't be this way, and perhaps these legal teams are being overly cautious and someone should be push back, but that's how it is today at many companies. Attaching an AGPLv3 license means that I can't use it, while I can and do use Apache-licensed projects, and contribute improvements or fixes arising out of corporate usage.
However consider what they are building here: a mail client that purports to securely send and store email. Imagine you are working for a company that uses Mailpile. You think that your email is secure and encrypted because you are using Mailpile. Instead, you management has hacked in a back door to spy on your communications.
As you mentioned, perhaps someone should push back. I'm not involved in Mailpile, but it seems that this is exactly what they are doing. They are drawing a line in the sand and saying, "You must show your users any changes you have made to the system because otherwise how are they to trust it?"
It's clearly a tradeoff and also clearly not an easy decision. Do you give up a little bit of your goal of protecting users at the benefit of having wider exposure? Or do you refuse to compromise and suffer from potentially having less adoption? It doesn't seem that they took the decision lightly.
I don't think a license can solve this problem. I doubt someone who's willing to spy on people is afraid of breaking an open source license.
GPL on the other hand is about free and open source in product based software, and this do not conflict with Google's service based business model. This allow them to use GPL licensed copyrighted work which they have not authored, and distribute that to gain an competitive advantage in markets that supports their service based revenue source.
If a company do not have an identical business model, copying google will only cost the company. Either they will be overly cautious and the competition will produce cheaper and better way to produce revenue, or they will be overly receptive to legal actions. To make the car analogy, trying to drive exactly like someone else is going to make you crash into something. You need to make a analysis where your car is, and make decision based on the road and the traffic in relation to you.
Examples where AGPL makes little impact on a company revenues and commonly uses a webmail product: Internal use in a company, an ISP, or a dns/hosting provider.
The only thing this would prevent would be to offer a modified version of the software on a SaaS model without opening the code for its modifications.
Better to ban it from the organisation.
What does trigger that (which you somehow elided from your quote) is modifying the source. I must accept the license in order to modify the code as stated in section 9.
Having accepted the license I have a responsibility to offer the changes to all "users" interacting with it remotely. Very unfortunately, they don't provide a definition of "user". This may be intentional, though. There are legal definitions of the word "user" and it may not be possible/desirable to try to override the term in the license.
IANAL but in my experience, people who gain unauthorized access to software are not defined as a "user". I can't enter into a contract with an entity of whom I am unaware. There is a crucial difference between inviting people (even random people) to use the software and having a system that just happens to be accessible. There is a huge amount of case law on the topic, so if you are really curious I'm sure any lawyer can give you good advice.
And the licenses are 2 totally different animals anyhow... BSD license incidentally grants some freedom... but FSF's licenses are designed to protect it.
I measure freedom in the license context by how much I have to do using a certain licensed software.
MIT, BSDL, Apache, EPL -> nothing
AGPL -> I need to open up every single thing that touches the service that uses AGPL
Which one is more free? In my interpretation the former. Please convince me that AGPL is more free than the other licenses. On the top of all that jazz, I really dislike the GPL/Gnu agenda of defining freedom to me. Let me show you what is the definition of freedom:
"the power or right to act, speak, or think as one wants without hindrance or restraint."
Opening open source code that I have no intention to open up sounds pretty restraining to me and also it qualifies as hindrance...
And even then one can argue if the AGPL serves this best, because it also doesn't really help users if no-one offers services based on the software because they don't trust the legal situation.
- Yeah right, please explain this to my mom. She is a user of my software. Thank you in advance.
- Even if it was about my users you cannot re-define freedom for them aka same thing applies as I wrote above
- My users are also corporations and they banned AGPL
Checkmate. :)
I think you may be confusing your freedoms with your concrete possibilities (i.e what you can do).
Also, you need to distinguish the freedom of your users (X) from the freedom of the redistributors (Y). The (A)GPL licenses are about taking away some of Y to increase X.
AGPLv3 has license restrictions that are unacceptable to many or maybe even most companies, and secure company e-mail would be a great first growth application. Even for personal use easy 3rd-party deployment by hosting providers would be desirable, but AGPLv3 may be of concerns for these hosts for a fringe-application.
AGPLv3 also prohibits code-reuse in most contexts, so it makes surprising reuse of sub-components less likely. Stopping this reuse is a shame since it could have reduced the bar for implementing secure email support in more e-mail clients.
We use AGPL for the code we write ourselves in our project https://cloudfleet.io (sorry for the shameless plug), so Mailpile choosing AGPL fits in nicely.
But it would not have fit less so, had it chosen Apache.
But I agree that if they had decided to use a non-default method, it really should have been said before the vote rather than after. How to count votes is a common theme in manipulating vote results.
The AGPL itself makes a lot of sense, as any other licenses you mention would never have any teeth, as the software is - by nature - never distributed by the service provider.
Update: Tagged as Gunsmoke--TheLastApacheTag - https://github.com/mailpile/Mailpile/releases/tag/Gunsmoke--... ;-)
The remote network interaction clause makes no differentiation between internal and external users. They are all just users[1]
As such, you owe all them all source to modified versions.
Why does this matter?
A lot of companies have internal systems, and temps, vendors, and contractors who access those systems.
If those systems are (or are linked to) modified AGPL software (no matter how small the modification), they owe the temps, vendors, and contractors access to the source code to those systems.
That seems ... bad :)
[1] "if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network ... an opportunity to receive the Corresponding Source of your version ... at no charge ..."
The intent is to provide access to the source code for no more than what you charged for access to the service itself. It doesn't mean that you necessarily will be out of pocket.
Putting your changes on GitHub or the equivalent and providing a link would satisfy the requirement completely. This is not exactly an onerous requirement unless your intent is to keep your changes secret.
The "That seems ... bad" part, really depends on your point of view, I guess. Letting all my temps, vendors, and contractors have access to this code means that any of them can inspect it for problems, learn from it, fix bugs, improve it for themselves and help others improve it.
That seems ... good ... to me, anyway.
At worst, they'll do nothing and I won't be any worse off. Of course, if I'm relying on secret source code to obfuscate my security holes, then perhaps I'll be in trouble, but I'm not about to do that. At best, I've turned my users into collaborators.
Perhaps you can enlighten me as to why you think this is bad.
You can't see why a Google lawyer would think it 'bad' for a temporary member of staff to be able to receive the full source (with licence to use and redistribute) for Google search, adwords, gmail etc etc?
Why would it be? Employees having access to modifications to open-source software the company made surely wouldn't materially affect any aspect of the business. It doesn't mean they can change the code running on your servers, or peer into other people's accounts.
Sounds like a non-issue.
Seems rather clear cut to me how contractors are handled. Since we are talking about legal risk and risk is measured in likeliness of an event happening, and as a lawyer you were expected during training to find and provide legal precedence as proof for legal reasoning, how high risk is there that this would not cover internal systems, temps, vendors, and contractors who access those systems? Has there been any cases involving that kind of employee status, having access to source code with similar licensed agreement, and the court finding a decision which support your conclusion? If you worked for a insurance company, how much money per month would you advice them to charge for this "risk", and would you then in good-faith advice companies that it is a good deal rather than shouldering the risk themselves?
This is a fairly nasty difference from the standard GPLv3 that I don't think enough people appreciate. As you point out, companies that modify GPL code for internal use don't have to release the source code and aren't affected by most of its provisions, and this is intentionally one of the freedoms it gives users. This isn't true of the AGPLv3.
DannyBee said the word "access", and technically that would then be "read only" access. While I could conceive a situation in which a disgruntled contractor plus the original author could in theory make a case, read-only access is a odd thing to create a court case around and a judge decision could really go anywhere. I don't think anyone would be willing to test it or feel that the court costs would be worth paying for the privilege.
Most legit AGPL projects I've seen by the way don't really try to trap you like that anyhow... for instance, you can re-theme mediagoblin etc. And if you're going to hack on the core... would it really be so bad to upstream the code?
Is that tested in court? Because that was one of the scenarios described as potentially problematic before to me by a lawyer (Applying a corporate theme to an AGPL system, breaching the contract with the designer of the theme that doesn't allow you to re-license the design, only to use it)
Outside software, there doesn't seem to be a clear legal precedence either. I commonly see news paper include CC-share-alike images in articles without adding the CC license to the article, website or the news paper itself. The question about copyright almost exclusively end up being about distribution rights of the work in isolation, or the right of the author to have the work associated in a specific context.
Which is exactly the point. Don't modify the source code or use a different product if you don't want to accept the license.
http://gcn.com/Articles/2007/07/23/GNU-version-of-GPL-gives-...
I'd be more OK with the Apache license if it did not contain very dangerous language in it for contributors:
https://www.taoeffect.com/blog/2013/09/the-apache-contributo...
For those looking for an Apache-like license without such language, consider the MPL 2.0.
http://b.pagekite.me/blog/2015-06-15_Community_License_Feedb...
>>>
Temporarily Unavailable
The website http://b.pagekite.me/ is unreachable at the moment. Possible explanations:
The computer may have been turned off
The computer may be disconnected from the Internet
The PageKite program may not be running
Please try again later.
What kind of site is this?
This website connects to the World Wide Web using PageKite, a Free Software solution for exposing "localhost" servers to the public Web.
<<<<
Not a good show of PageKite's value.
https://www.mailpile.is/blog/2015-06-15_Community_License_Fe...
My work-flow is to draft posts and other changes on my laptop and then use PageKite to show things to a friend or two to get feedback on spelling and content. In this case I mistakenly copy-pasted a link verbatim from the draft site into the post itself.
PageKite was working 100% as intended, this was just a typical copy-paste error. If I hadn't been using PageKite, you'd have seen a localhost link instead.