5 ms·
Just because Routebuilder was never called out for violating the ToS doesn't mean it wasn't. Nor is there a "statute of limitations" for violations. What's even
by basseq 11y ago
Just because Routebuilder was never called out for violating the ToS doesn't mean it wasn't. Nor is there a "statute of limitations" for violations. What's even more insidious is that the "duplicating GM functionality" is a) vague and b) a moving target. Just because Routebuilder wasn't violating a decade ago doesn't mean it's not violating now.
This is the risk you take building something on top of an API—access can be cut off at any time.
- JustSomeNobody 11y ago>> This is the risk you take building something on top of an API—access can be cut off at any time. This simply cannot be stressed enough.
- basseq 11y agoIt's worth expanding that this is a very broad spectrum of software. No one's worried about assembly code for Intel chips, but the next generation could be locked down. No one's worried about writing C++ for Windows, but technically you're using their APIs and hooks that could be dropped in the next release. There's iOS, where you're also subject to review and approval. There's well-known web joints like Google, where this can happen. Then there's the fly-by-night shops that could just dissolve tomorrow. The safest thing is to build your own computer from silicon, write your own OS, your own compilers, your own languages, your own software, and your own APIs. Of course, by the time you do that, we'll all be dead. So it's a balancing act. But it's worth illustrating that you're taking for granted that things will remain the same forever, when in reality there's a sliding scale of risk.
- cookiecaper 11y agoFree software ameliorates this problem. The code is free to live on independent of its authors or parent organization. Sun may or may not have killed its business by making all of its software open and free, but the community benefited from that immensely when Oracle took over. We don't have to start from scratch, just have to use free software. Your post also seems to assume that everyone will upgrade to the "next release". On platforms where you get to control your upgrade cycle, people won't upgrade if the upgrade breaks the programs they want to use, and this acts as a check on gratuitous API/ABI breakage. Microsoft takes this extremely seriously and has hardly any API breakage over the last 20 years because they know that there's a real threat that a competitor could emerge with WINE pre-bundled and take away some market share if they break a lot of programs.
- kuschku 11y ago> No one's worried about writing C++ for Windows, but technically you're using their APIs and hooks that could be dropped in the next release. Well, Valve was, justified, worried about that, and built SteamOS.
- jrumbut 11y agoI think this shows when you should be particularly worried about vendor (supplier?) lock-in: if it would hurt you more than it would others, including the vendor. My shareware Snood clone company is not very worried about Microsoft changing the Windows API, but I'm sure with every release major Windows software suppliers, particularly those reliant on a certain niche feature, certainly are.
- nqzero 11y agoi think the point of the article, or at least our interest in it, is that this is a terrible business arrangement. if you can't look at past tolerance as evidence of acceptable use, then you effectively can't ever afford to invest in building a business unless you're lawyered-up and that's bad for tech, and bad for america
- cookiecaper 11y agoYes. The current legal situation with access to online resources is an absolute, unmitigated disaster. My advice to anyone building anything significant off an API or scraped access: do it anonymously. Never reveal your real identity. Never use your real IP. Don't process credit cards. Don't register an identifiable LLC. Run it out of China or Russia where American companies will have a hell of a time trying to get to you. If you depend on one entity's API, that entity is not going acquire you. At best, your product will be ripped off and they'll make you irrelevant. This happens to popular mobile applications all the time. At worst, you'll get sued civilly, get your wages and bank accounts garnished, lose all of your possessions, and get criminally prosecuted under the CFAA, end up doing some time, and eventually get released with the stipulation that you never touch a computer or access the internet again for the rest of your life. Unless you can ramp up to doing tens of millions of revenue per year (or have investors willing to pony that up) before the company you depend on notices/decides they don't like you anymore and sends out their law firm, you're dead meat, no matter what the details of your case are and no matter how wrong they are. These are not problems you want. It's easier to put your service in the onion and run it from there, access all external data via proxy, only accept Bitcoin for payment, and never tell anyone the link to your real-world identity. Granted it takes good opsec to continue this for a long time, which is really hard to pull off, but it may be doable depending on your level of commitment.
- chinathrow 11y agoMy advice is: Obey robots.txt and provide a real user agent. End of story. Seriously.
- pjc50 11y agoThis is a little paranoid if you're at least trying to stay within the TOS and not overtly get in a fight with the big entity whose API you're using. (And having the LLC gives you great protection against lawsuits!)