7 ms·
What on earth is that license?
by Somasis 11y ago
What on earth is that license?
- sqs 11y agoSourcegraph CEO here. :) We released Sourcegraph under the Fair Source License (https://fair.io/ https://fair.io/), which we worked with a well-known open-source lawyer to draft. TLDR is that it lets us create the best product for developers by having a sustainable business. Full info at https://fair.io https://fair.io: > Fair Source allows companies to both share a product’s source code and charge for that product. Releasing a product’s source code makes it more valuable to customers by enhancing extensibility and building trust. With open source, releasing the full source code and charging for the product is virtually impossible. Fair Source makes doing both possible.
- Somasis 11y agoYou would be better off selling services akin to what GitLab does for sustenance.
- nickpsecurity 11y agoAll evidence is to the contrary. The companies making the most profit on software are licensing it somehow while others that are at least successful are using plenty venture capital with SaaS. So, both are the best choices and the use of a proprietary license preserving FOSS-style freedoms is interesting. Strange how much negativity proprietary OSS gets on HN vs cool, proprietary, closed tech.
- dragonwriter 11y ago> Strange how much negativity proprietary OSS "Proprietary OSS" is an oxymoron, like "four-sided triangle".
- nickpsecurity 11y agoI retract my statement for any given commenter that was purely concerned with my misuse of the OSS phrase, which I'm fixing in future comments. However, there's often an overly-negative reaction to anything that involves payment and shared source w/ OSS-like benefits. If they were reacting to that, then it still stands if they don't do similar for cool, closed-source stuff here. Just seems hypocritical to me. That's where I was going with that comment.
- dragonwriter 11y ago> However, there's often an overly-negative reaction to anything that involves payment and shared source w/ OSS-like benefits. I think you miss that the biggest and most important benefits of open source are tied to the freedom to fork, which is both the source of the greatest security against divergence in interest between the original copyright holder and the user community and the enabler of community-driven innovation. Put simply, shared-source does not have "OSS-like benefits". > If they were reacting to that, then it still stands if they don't do similar for cool, closed-source stuff here. Unlike shared-source stuff like the Fair Source License here, simple closed-source proprietary software generally doesn't try to pretend to be Open Source-like (and, when it does, it is attacked in the same way.)
- nickpsecurity 11y ago"I think you miss that the biggest and most important benefits of open source are tied to the freedom to fork, which is both the source of the greatest security against divergence in interest between the original copyright holder and the user community and the enabler of community-driven innovation." I agree that's a major benefit. It's why a form of it is on my list. :P A non-profit maintaining a shared-source software requiring a mere $1 a year wherever it was used would have enough for a full-time developer plus the website by time it hit 20-20k users whether in original or forked form. Plus could take contributions from others while giving them credit and/or a pass on the money. Whereas many OSS projects get used all over the place with about nothing in return and depend on goodwill of occasional volunteers or sponsored developers. So, there's definitely a benefit here with similar innovation, even community driven if a membership fee model. "Unlike shared-source stuff like the Fair Source License here, simple closed-source proprietary software generally doesn't try to pretend to be Open Source-like (and, when it does, it is attacked in the same way.)" Nah, shared-source stuff gets attacked more than proprietary or even shoddy OSS when it shows up. I was happy to see some exceptions considering the license a nice evolution in OSS direction from a proprietary angle or just better than most proprietary licenses.
- sulam 11y agoCompletely disagree. Services models seem to very much limit what companies like this can achieve. It also creates a perverse incentive for the company to make a product that needs service contracts to manage. They tend to produce more closed-source "addons" as well.
- nickpsecurity 11y agoExactly. Empirical research I saw showed that most companies in that market don't do so well in either profits or longevity. The majority of them we see here also intend to sell out.
- bradrydzewski 11y agoGitlab graduated from Ycombinator and raised a 4MM series A round. While these are both tremendous accomplishments and important milestones for any startup, it may be a bit premature to declare their business model a success.
- nickpsecurity 11y agoAs I said in another comment, many of the companies pushing this model are VC-funded with intent to sell out and their operation disappears into a big company (or disappears). We should distinguish between business models that are just to get an acquisition and that support long-term growth. Cheap addons with OSS/FOSS seems mainly to work in the former.
- bradrydzewski 11y agoI agree. I was responding to the parent comment suggesting Sourcegraph should adopt a similar business model to GitLab and I was pointing out that perhaps GitLab's business model has not been proven successful yet
- nickpsecurity 11y agoExactly. Way too early.
- koko775 11y ago> If I modify the source code, can I redistribute my modified version under the MIT License? Separate but related question about the Fair Source License: If I modify the source code, can I redistribute my modifications under the MIT License? The difference being, of course, that one would redistribute the original code under the FSL and so the work as a whole would remain licensed under it.
- nickpsecurity 11y agoThat's an interesting license and the first I've seen of what I call open-source proprietary outside the dual-license model. I've been encouraging developments in this area given the problems of proprietary and OSS licenses in isolation. Additionally, people seem to have a false dichotomy where proprietary has to be closed/bad and OSS open/free/good. Wrote here, with security focus, that this wasn't the case: https://www.schneier.com/blog/archives/2014/05/friday_squid_bl_424.html#c6051639 https://www.schneier.com/blog/archives/2014/05/friday_squid_... Elaborated briefly on my goal here with an old example: https://news.ycombinator.com/item?id=10501615 https://news.ycombinator.com/item?id=10501615 Your license appears to meet many of those requirements. Curious about several things, though, that I figure you could give some straight, English answers to. ;) How did you come to letting it depend on a user count rather than some other criteria? That's unusual and even reminds me of commercial licenses. Does the license create a specific amount at that point or allow extortion where locked-in clients are hit with large amounts later? Is the author able to terminate the project in a way where users are left with a dependency they no longer have access to? I know you accept modifications under a CLA or something. Let's say, though, you didn't want to distribute some substantial changes. Basically, a fork is in order. How does that work? Do they just assign the whole fork to you where you can optionally offer it to others? Do they keep it onsite? Does it not happen at all? Prior discussions taught me forking is something that should have definitive answers in new OSS licenses. The ability to make things disappear, get overpriced, or turn to shit arbitrarily are among the largest risks in proprietary OSS projects. So, interested in seeing your company's take on those.
- digikata 11y agoWhen you go to the source link at https://src.sourcegraph.com/sourcegraph https://src.sourcegraph.com/sourcegraph and look at the LICENSE file, it says: "Use Limitation: 15 users" That implies that the project there is the full Enterprise version? Is there a separate link or some dividing line to the Core source? Or how does one build or access just the core features to abide by the licensing terms if you're a team larger than 15 and want to evaluate Core Sourcegraph?
- 3ot 11y agoAfter comparing the features of Core and Enterprise, it looks like the Core package is not self-hosted à la non-enterprise github. And the source at https://src.sourcegraph.com/sourcegraph https://src.sourcegraph.com/sourcegraph seems to be the Enterprise version – minus 24/7 technical support and automatic backups I'd say.
- beliu 11y agoSourcegraph CTO here. Sourcegraph Core is self-hosted and the source code for it lives at https://src.sourcegraph.com/sourcegraph https://src.sourcegraph.com/sourcegraph. Sourcegraph Enterprise includes the additional features mentioned in the pricing section on https://sourcegraph.com https://sourcegraph.com that are specific to very large companies. Sorry about the confusion. Anything we can do to make that clearer?
- digikata 11y agoWell if the intent is that Sourcegraph Core is "for teams of any size", and the code at https://src.sourcegraph.com/sourcegraph https://src.sourcegraph.com/sourcegraph is the Core, then it seems like the LICENCE file in the source should be updated to reflect the intent and not say it's limited. Inside https://src.sourcegraph.com/sourcegraph@master/.tree/LICENSE https://src.sourcegraph.com/sourcegraph@master/.tree/LICENSE it has a line that says: "Use Limitation: 15 users"
- sqs 11y ago
- vitno 11y agohttps://fair.io/ https://fair.io/ It's made by them as well. It most certainly is not libre/free software. I'm guessing it has minimal legal ability to stand up in court. It is a bastardization of what open source is about... really it's more of a disclosed source setup.
- nickpsecurity 11y agoOpen source is about the source being open plus certain benefits. Free and open source software, a la Richard Stallman, is a totally different thing with a philosophy akin to how a virus operates. A glance at fair.io shows an interesting attempt to provide OSS under a proprietary model. Many businesses are fine with whatever gets the job done with main benefits of OSS being reviewing, extending, or just fixing things. A proprietary license allowing that has real value. Curious, do you write comments like this whenever Google, Amazon, deep learning, etc closed-source tech with benefits are mentioned on HN? How they're insanity and not worth further discussion because the whole stack isn't FOSS?
- vitno 11y ago> Curious, do you write comments like this whenever... Uh.. I actually often do. I would more, but it generally isn't appreciated and is off topic of the main thread. Here, the software license is a key component of the release seeing as it is a unique component of it. >Open source is about the source being open plus certain benefits. It's more than that. The key intent of OSS is the right to study, change, and distribute the software to anyone and for any purpose. The source code is just a prereq for that ability. I did initially use stallman-esque language, since it's terminology most people are familiar with in this field, but I'll approach it from a different point since I personally have problems with strong copy-left licenses. The primary thing this license doesn't do is allow distribution in the OSS spirit. This is really just a pervasive license, actually in some ways similar to the Stallman-esque virality except with a corporate intent. It simply masquerades as OSS.
- nickpsecurity 11y ago"The key intent of OSS is the right to study, change, and distribute the software to anyone and for any purpose. The source code is just a prereq for that ability." No, the key intent of open-sourcing software is to let one see the source. That's it. Additional intents are added with licensing terms. This goes back to academic and even proprietary (eg Burrough's 1960's MCP) examples that did this. Many models of it formed with examples ranging from permissive BSD to proprietary OSS like LISP machines (esp Genera) letting customers use the source of OS & supporting libs in applications. So, OSS is a broader thing than you are describing which supports many models. There is no "spirit" so much as many different ideologies competing and pushing their own licensing schemes with various perceived benefits. Now there's one more.