13 ms·
MongoDB's Server Side Public License Is Likely Unenforceable
- kstrauser 8y agoAbsolutely. This license change takes it completely out of the contention for anything I would have previously considered it for. Can you imagine if Nginx said you had to release any software you run behind it as FOSS?
- danieldk 8y agoAnd then what? The owner of the code is entitled to license the software as they want it [1]. If you dislike the license, then use a different program or fork the last version before the license change. I can fully understand the frustration of pro-copyleft developers and companies that want to use copyleft for a 'share or pay model'. Cloud computing makes existing licenses toothless by moving the software from the client to the server, thereby avoiding distribution. It can be argued that such use is not in the spirit of copyleft and is effectively a loophole from the perspective of copyleft licensing. It is not surprising that people try to make new copyleft licenses that fill that loophole. This may not be the best formulation, but it is definitely much better than the Commons Clause nonsense that was hyped a couple of weeks ago (which makes software proprietary). [1] Whether it is enforceable is another issue.
- kstrauser 8y agoOf course they’re entitled, but I’m also entitled to say I think this move was either idiotic or malevolent. I’m unsympathetic to the “oh no the cloud” mindset. I’ve worked at companies that have made on-premise patches to FOSS since the 90s. Can you imagine if Linux required you to make the source available of all software you ran on it? Or MySQL? Or Perl/PHP? I can vaguely see the point of the AGPL for things like web front end stuff where there’s a blurry line between you visitor merely visiting your site and you distributing the software to them. But that’s just madness for infrastructure code. And I’ll bet that the MongoDB team has used lots of FOSS that they didn’t financially support, so I see it as whining when they complain about others doing the same.
- simias 8y agoYou use their code for free and call them "idiotic or malevolent" when they make it harder for you to use their code for free. I can completely understand the frustration of their users if this move makes their life harder but it's still pretty entitled of you to insult them because they changed the license to something you don't like. It's perfectly understandable if you decide not to use their software because you find their license unacceptable but don't insult them for doing what they want with their own project. If a sizeable enough number of contributors are unhappy with the move they're still free to fork and continue the previous version of Mongo DB with the old license.
- kstrauser 8y agoThere is a decent chance that they’re using code I’ve written, and I haven’t seen a penny from them. Have you? Has anyone? I think it’s either: - Idiotic, because they meant well but managed to shoot themselves in the foot by making their software unviable, or - Malevolent, because they’re using this as a wedge to either force you into a pay-or-lose-it situation, while still trying to paint themselves as FOSS.
- toomuchtodo 8y agoBecause you don’t feel others are freeloading on you does not mean software consumers aren’t freeloading. You’re free to change your licenses (or not), just as other projects are (but should). It’s time the free ride and expectations of charity by for-profit users ends.
- kstrauser 8y agoWhat is freeloading? MongoDB is building a project off the works of others and selling it. So am I. If you're employed, so are you. And in return, hopefully we all contribute back to that ecosystem so that the next person can build off our new work. You say "freeloading". I say "participating in a rich culture of shared work". Maybe I don't contribute all my local work to Emacs upstream, but I push out a lot of Python stuff. Maybe you don't bother sharing all the Python tweaks you've made, but you're an active Vim contributor. Perhaps there's someone else that's a Vim "freeloader" but who cranks out a lot of kernel code that you and I both benefit from. I think that's a healthy, mutually-beneficial arrangement.
- nebulous1 8y ago> The owner of the code is entitled to license the software as they want it [1] > ... > [1]Whether it is enforceable is another issue. As per the article, apparently not. Copyright Misuse [1] will stop them setting terms beyond a certain scope. You could argue that that merely makes the licence unenforceable but by that definition the only thing worth talking about is enforceability, so that doesn't seem like a good definition as there are practical enforceability issues to separately consider [1] https://en.wikipedia.org/wiki/Copyright_misuse https://en.wikipedia.org/wiki/Copyright_misuse
- ptx 8y ago>> This license change takes it completely out of the contention for anything I would have previously considered it for. > If you dislike the license, then use a different program That's exactly what he said he would do, isn't it?
- deleted 8y ago[deleted]
- metheus 8y agoThe SSPL does not create that obligation.
- Hello71 8y agoNo, because it's even worse than that. "management software, user interfaces, application program interfaces, automation software, monitoring software, backup software, storage software and hosting software" encompasses everything behind the server, everything in front of the server, and basically everything beside the server.
- metheus 8y agoSee my main thread post addressing this misconception. The SSPL's obligation to release those components only applies in the case that the user is offering the licensed software itself as a service.
- mbreese 8y agoEven if it wasn’t intended to do that, the sheer amount of uncertainty this creates is untenable for many projects.
- GiorgioG 8y agoUse Postgres, problem solved.
- MaxBarraclough 8y agoSolves many more problems than just the licence, too.
- haggy 8y agoPlease take your unhelpful comments elsewhere
- GiorgioG 8y agoUnhelpful how? I'm providing an alternative NoSQL option (Postgres supports JSON - https://www.postgresql.org/docs/10/static/datatype-json.html https://www.postgresql.org/docs/10/static/datatype-json.html) and you don't have to deal with this MongoDB licensing nonsense.
- Thaxll 8y agoNoSQL usually have built in constructs for horizontal Scalling / HA, pg have none of that.
- dang 8y agoPlease review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and follow the rules when posting here, regardless of how unhelpful another comment is (or feels). Uncivil swipes in particular are not ok.
- _verandaguy 8y agoWhile I like relational data and I _love_ Postgres specifically, there are some tasks and contexts for which non-relational stores are better suited.
- GiorgioG 8y ago
- appleflaxen 8y agoI don't understand the line of reasoning. Can anyone give me a lay explanation? My understanding of the license change is basically "if you use MongoDB to support any site, all software higher in the stack needs to be released as well". Is that accurate? If so, why can't an author make this part of the license?
- geofft 8y agoNot quite—if you offer MongoDB itself as a service, then yes. If you just use it on the backend, no. (Read the license and consult your lawyer for details, of course.)
- tyingq 8y ago"offering a service the value of which entirely or primarily derives from the value of the Program" That sounds pretty squishy and likely to be broader than just the use case of offering Mongo as a service.
- fatbird 8y agoIt doesn't seem squishy to me insofar as you can't offer Mongo as a service and then swap Mongo out for a different product, while leaving your offering unchanged. Any app using Mongo simply as a datastore on the backend can swap it out without altering their offering.
- tyingq 8y agoYes, it clearly targets Mongo as a Service. I'm not clear, though, on whether that's where it stops.
- amarant 8y agoit also really doesn't sound like "if you use MongoDB in your streamingplatform/blog/whatever you need to opensource everything, which seems to be the gripe many a commenter is having.
- ilikechairs 8y agoI never understood all the hate mongo gets. Like any tool, if people simply took the time to understand it and use it correctly, maybe they wouldn't run into issues.
- macintux 8y agoMongoDB made some very sketchy, undocumented (or poorly documented) technical decisions in its early years that placed data at great risk. It's better now, but very few things worry technical people more than a database that loses data. It's hard to get past that early impression.
- icedchai 8y agoThen again, so did MySQL. Do you remember the MySQL 3.x "MyISAM" days? No transactions, automatic truncation and type conversions, etc...
- vesak 8y ago...and a significant portion of IT people still distrust MySQL.
- merb 8y ago... or they love it, like uber
- int_19h 8y agoMySQL was very upfront about it, though. They always said that if you wanted that stuff, there are real RDBMS for that.
- pritambaral 8y agoMySQL still has some unsafe behaviours. Even if it were to fix them all, I still wouldn't use it or recommend it, on account of finding it difficult-to-impossible to trust the design and engineering behind it.
- 8y ago
- trasz 8y agoIsn't it just so that the Mongo's SSPL is a natural extension of AGPL, modified to make it cover things that wouldn't otherwise be considered a derived work (which is exactly what FSFs interpretation of GPL does for more typical, 'single-host' situations), and inheriting the AGPL's problems?
- DannyBee 8y agoI'm not sure what the question is, but the AGPL is very carefully drafted to avoid the problems Van is talking about.
- trasz 8y agoWell, according to the article the second problem is directly inherited from AGPL.
- VanL 8y agoNot quite. There are administrative problems with the AGPL, which are inherited here. But it is the scope of this license that pulls in these new defenses.
- zzzcpan 8y agoI'm sure they will address your concerns in SSPL v2. But make no mistake, you can't win here.
- anticensor 8y agoI will then create Anticensor's Public License, stating everything interacting with said work must be licensed under the same license.
- akvadrako 8y agoIs this similar to the GPL3 in intent to force website backends to become open source?
- detaro 8y agoHow does the GPL3 have that intent? AGPL does, but GPL?
- jimktrains2 8y agoMy understanding is that AGPL does only for that piece of software, not all layers above it?
- deleted 8y ago[deleted]
- zzzcpan 8y agoYes, but explicitly includes all the stuff needed to make and run the service.
- kevin_thibedeau 8y agoGPL3 doesn't do that. You're thinking of AGPL.
- mindcrime 8y agoYeah, I'm not necessarily opposed to the general spirit of what they're trying to do here, but this license just doesn't make sense in practice. Now that I've had more time to look at it, I'd really recommend that everybody stay the f%!# away from MongoDB. This bit in particular really hits the nail on the head: Let's assume that it is ok somehow to pass forward other open source software, solving that problem. What about my continuous integration software (e.g. CircleCI), or my business backup software (e.g. Jungle Disk) or my code hosting service (e.g. Github)? There is no logical bound to this license. Taken on its face, I would theoretically be bound to release the internal source code of services from third parties that I included in or relied upon to deliver my service. Copyleft is one thing, but this is so invasive and byzantine that it beggars belief that anybody actually thought this license made sense.
- deleted 8y ago[deleted]
- djsumdog 8y agoHmm ... Would this technically be the ultimate Stallman dream?
- SEJeff 8y agoNo. RMS has stated more than once that he is entirely ok with the "service provider loophole" in the GPL. They made the AGPL for those not ok with the loophole, but he never had any issue with it in the original GPL at all.
- mritun 8y agoNo, technically, Stallman is firmly rooted in copyright law. GPL says you take this software and make derived works, as copyright law says what they are, as long as you make derivative works available under the same terms as you received the original software. GPL steers clear of non-derived work. If you use VMWare on Linux, VMWare is not a derived work as far as copyright law is concerned and there is no relation between them as far as GPL is concerned. This SSPL, is another story.
- 8y ago
- tlrobinson 8y ago> accused infringer would then, quite rightly, plead impracticability I’m not a lawyer, but I wouldn’t expect that to be a valid defense. If you can’t comply, don’t use it.
- DannyBee 8y agoVan is an IP lawyer, and has taken these things to court before. I generally would trust his view on whether he thinks he could make out a defense or not.
- Bartweiss 8y agoI wish the article had taken this question more seriously. Impracticability is a defense under contract, but a fundamental requirement in the US test is: > "an occurrence of a condition, the nonoccurrence of which was a basic assumption of the contract" Impracticability is not a defense against signing stupid or damaging contracts; it specifically releases a party when circumstances change such that a contract is no longer reasonable. Standard examples are things like the outbreak of war or a supply chain collapse, which don't render a contract literally impossible to fulfill but do place fulfillment outside the domain of any reasonable effort. Defending against conditions which were already in place when a contract was signed is far harder, and even impossibility is not necessarily a defense if the impossibility is obvious at the time of signing. The only common defense I know of against conditions present at the time of signing is illegality, which of course comes up quite often with things like noncompete clauses. The misuse complaint at least looks plausible, but I'm pretty baffled by the appeal to impracticability.
- VanL 8y agoHere is the analysis: Let's think about the context where this would come up: A party ("Service") takes the SSPL'd MongoDB and implements a service. Service releases some code based on a good faith interpretation of the scope of the release necessary. There is a dispute between MongoDB and Service as to the scope of the necessary code release. In the ensuing lawsuit, Service raises misuse and argues that the scope is ambiguous. Leaving aside the misuse argument, a court could either a) find for Service, thus restricting the scope of the code to be delivered, or b) find for MongoDB, thus giving rise to an immediate defense of frustration/impracticability, which would undo the contract.
- jason46 8y agoDoesn't Unifi use this?
- specto 8y agonot as a service, but yes as a backend
- nicole_express 8y agoAs a non-lawyer who's tried to understand copyright law, this analysis confuses me; my understanding was that in the realm of source code "by default" you only have rights to use that source code through a license or contract, so it seems odd that any restriction on the terms would be misuse or detrimental to competition, when the option always exists to not use MongoDB. This isn't me trying to argue against the article; I'm trying to understand the law as it applies to my profession.
- jillesvangurp 8y agoThis uncertainty and confusion is by design and the whole point of this license. It's designed to make people who are not lawyers consider getting a commercial license just to avoid the potential for legal headaches that may or not materialize. I doubt it will work since many people will indeed not want to deal with companies that are dangling legal threats over their own users like this. IMHO there's no other way to interpret this than as exactly that: a user hostile move. Whether this thing is enforceable or not is beside the point.
- toyg 8y agoIt is actually silly, because being “the only unpaid open source nosql” is a pretty good position to be in. It’s how MySQL became huge: by being “the only unpaid open source relational db” good enough for real work. It’s not with licensing shenanigans that they’ll fix a monetization failure; in fact, it will likely backfire. It’s hard enough to push (A)GPL software in enterprise contexts, by making it even more awkward they are basically begging users to go away.
- metheus 8y agoDisclosure: I work for MongoDB. Forcing droves of community users to buy commercial licenses is not the intention of the SSPL -- indeed, it cannot serve that function, as it does not obligate them to do anything at all unless they are making the licensed software itself available to the public as a service.
- 8y ago
- vitalus 8y agoI'd be interested in seeing a license that better accomplishes the goals cited as motivation for moving to this license, that would hopefully also avoid the flaws mentioned in this article and throughout the comments. Is there an example of such a license? Could this type of license even be created in an enforceable way?
- Latteland 8y agoSo has there been a startup yet that forked mongodb's pre-license change form? Get cracking, VC folks.
- greglindahl 8y agoA viable VC-backed startup business model for a GPLv3 or AGPL MongoDB isn't necessarily possible.
- Illniyar 8y agoThis is more likely to come from big companies, not VC funded startups
- amyjess 8y agoI honestly don't see how this can pass OSI or DFSG approval. It's a blatant violation of rule 9, which prohibits restrictions on distribution of other software.
- zzzcpan 8y agoOnly if you think that related software necessary to make and run the service is "other software" and not an improvement over the primitive default service.
- metheus 8y agoThere is no restriction, only the requirement that the systems that make your service run be made available under the SSPL.
- amyjess 8y agoIf your license places any requirements on software that is not a derivative work of software you own the copyright to, the license is nonfree by the standards of the OFSI and the DFSG and probably others.
- PeterZaitsev 8y agoMongoDB of course has right to change their license to anything they want. One day they might decide to go proprietary with no notice too... According to our poll many users will seek alternatives for MongoDB because of the license change https://www.percona.com/blog/2018/10/24/poll-mongodb-license-change/ https://www.percona.com/blog/2018/10/24/poll-mongodb-license... MongoDB probably feels they have reached critical mass so it does not matter any more...
- asien 8y ago>MongoDB probably feels they have reached critical mass so it does not matter any more... They have become a new standard and they are aware of it. Just look at any bootcamps for devs this days , it’s basically always JS + MongoDB. Not Postgres or MySQL , Mongo. Mongo has become the new MySQL for a lot of devs these days. It’s often the only DBMS they know... These move is somewhat coherent with what others are doing in the industry ( Redis Enterprise Modules new licence , Docker preventing download without creating an account etc...) Open Source is now Venture Backed , as a result it needs to make profit.
- com2kid 8y ago> Just look at any bootcamps for devs this days , it’s basically always JS + MongoDB. Not Postgres or MySQL , Mongo. The online classes love Firebase. :-D But yeah, I had to explain to a bootcamp dev a few weeks ago what Postgres was. I felt rather sad.
- apl002 8y agoI am a bootcamp dev (still in it) and I can confirm that its all node + mongo. I know what postgres is but obviously dont know anything about it technically. I am struggling to understand what this license change means for someone like myself who is building a web app with mongo...
- village-idiot 8y agoPostgres is orders of magnitude safer, sometimes a bit slower, but requires a bit more forethought when it comes to planning a schema to match your models. You typically appreciate this more in maintenance and later development more than you appreciate it up front. The general risk with any for profit open source company is either them pulling all the good features into the paid version, or suddenly changing your license so that closed source projects have to either stay on the old versions or pay for a commercial license.
- tptacek 8y agoWhy isn't a straightforward solution to the "impracticability" problem just a "to the extent possible" or "authorized"-type predicate?
- VanL 8y agoThis would significantly ameliorate the problem.
- tptacek 8y agoSo then, really, a big part of the critique here is that the SSPL is simply not written very well?
- DannyBee 8y agoi mean to be fair that's the big problem with most licenses as "not written very well" covers almost all problems with contracts :) Like the LGPL is confusing because it is not written well in some sense. But that goes to "confusing" instead of "unenforceable". But yes, better written the problem with this license would just be "They are trying to claim things they know they can't claim" instead of "they are actually claiming things they know they can't claim". The next question that would pop into my head would then be "At what point does attempting to claim rights to things you know you can't, as a way of scaring people into paying you, cross into unfair and deceptive trade practices"
- tptacek 8y agoSorry, I just meant: "a more conscientious lawyer could have straightforwardly drafted that contract to avoid some of its major problems". Like, the subtext of the question is, if I was MongoDB, and stipulating that I didn't create unreasonable work conditions like "get it done in a day", should I be pissed at my lawyer? Additional question: if you can fix that problem with the contract with a "to the extent possible" predicate, is that really not the default? Like, if a clause can be interpreted as requiring the impossible, even if a straightforward alternate interpretation doesn't, that clause is broken?
- ianamartin 8y agoIt's hilarious to me that out of all the problems with the way MongoDB works it's the license, of all things, that gets a strong reaction from the HN crowd that says, "I'm never using that!"
- gtycomb 8y agoOnly a data point here -- after I read about this license change on HN, it took me about 2 hours to struggle over the issue, discuss with my team, and switch from MongoDB to PostgreSql. We are very lucky in that we were into this project for only two months, prototyping and learning the ropes with MongoDB schema. With PostgreSql now, everyone feels secure in a familiar territory. Yes, we have to make changes and its not rocket science to move over. The issue is not about having to buy a license here. The problem is the uncertainty with a product whose license agreement is being switched over mid-stream. It makes me weary of what else might happen with their license structure further down the road.
- chrisweekly 8y agoweary (tired) -> wary (concerned) not nit-picking, just attempting to help other readers who aren't native English speakers
- SOLAR_FIELDS 8y agoFor those that don’t know, they are sometimes pronounced the exact same, which is why they are often mixed up (see also affect and effect). Where I’m from weary is pronounced WEER-y though.
- yutghgh 8y agoNot true (at least in the US): weary (at least the adjective) is pronounced with a "we" at the beginning, while wary is pronounced with a "wear" at the beginning.
- macintux 8y agoI hear "weary" spoken so very rarely that I have no idea how it's pronounced here (Indiana). I can't even make up my mind how I pronounce it, but I'd wager it's almost, but not quite, indistinguishable from wary.
- ars 8y ago
- princekolt 8y agoOkay so after reading the article, and thinking about this for a while, I get the following out of this debacle: The issue here is that SaaS providers are building tools on top of MongoDB that effectively add functionality, instead of modifying MongoDB (which would force them to share those changes publicly). This is a valid concern and I understand the motivation behind the license change. However, how is this different from any other FOSS? Just as a random example, think of a proprietary blog/site provider like Tumblr and Weebly. They are effectively a SaaS provider that introduces tools on top of open-source web servers (like nginx or apache) to make hosting a website much easier. Instead of building the entire model/code of your website, you simply add customizations using a frontend. Maybe the comparison is not ideal, but my understanding is that all FOSS suffers from this concern, and the industry seems to be doing well enough.
- Illniyar 8y agoThe difference is that those projects (apache, nginx) are ASL or MIT licensed.
- rlaanemets 8y agoI understand the difference is that Nginx Inc. as a company is not in the business of providing a blogging platform or e-commerce hosting while MongoDB Inc. is actually providing SaaS (MongoDB Atlas) which I believe is their major revenue source.
- metheus 8y agoDisclosure: I work for MongoDB. You're in the right ballpark, for sure, but the SSPL addresses the difference explicitly. I'll use your example of Tumblr to clarify. Tumblr is built on some component technologies, like a database, an app framework, operating systems, backup systems, load balancing, etc. But Tumblr itself is not any of those things. Nor does it make any of its component technologies available to the public as a service. You cannot pay Tumblr to backup your servers, or to rent you VMs running an OS, or to do load balancing for your infrastructure. Even if every single one of those components were licensed under the SSPL, Tumblr would not have to release a single line of their code under the SSPL, because they provide something else -- a publishing platform.
- finchisko 8y agoJust thinking. Can you make a fork of MongoDb before license change and keep merging upstream changes under former license? Not asking because I want to hurt Mongo, just curious.
- icebraining 8y agoYes, you can fork, but no, you can't merge new changes, those come with a different license (except maybe for third-party contributions, you could ask them to double license them under the old one too).
- rlpb 8y ago> keep merging upstream changes under former license? Upstream changes made by the project sponsor would be expected to be copyright and released only under the new license. Unless the copyright holder permitted it (perhaps via the new license), it'd be copyright infringement for anyone to distribute those upstream changes under different terms.
- asien 8y agoRemind me of that one time when they went berserk on every tooling vendor using the name « Mongo » in their product name : RoboMongo,MongoGUI etc... they all received a legal notice to remove the name mongo from their product. This was probably one of the most evil thing have seen in the open source industry . Most of those vendors were open source with paid premium features or donation. After receiving their legal notice most of those vendors deprecated or sold their project to a company feeling betrayed by Mongo. As a result Mongo Compass became the de facto GUI for MongoDB and is advertise as sold with MongoDB Enterprise.
- segmondy 8y agoMongoDB is a profit company riding hard on the opensource bandwagon. This company is a publicly traded company, make no mistake about it. Profit over community. Every 3 months, they gotta report to Wall Street.
- rhacker 8y agoI had no idea that's why it was renamed to Robo3T so confusing. Man what a way to bruise people trying to help.
- msla 8y agoI have absolutely no problem with trademarks as long as they're used as consumer protection. For example, there's the whole uBlock vs uBlock Origin thing, where uBlock Origin is the good one run by the original maintainer, and uBlock is run by people who had nothing to do with the original project. https://en.wikipedia.org/wiki/UBlock_Origin https://en.wikipedia.org/wiki/UBlock_Origin Trademarks can be used offensively, and few cases were more offensive than the Linux trademark dispute back in the 1990s, when William R. Della Croce, Jr., someone with nothing to do with the Linux kernel or anything else of value, acquired the trademark to "Linux" in September 1995 and began to demand royalties from the people who did useful things with their time. It took a court case to dislodge him. https://en.wikipedia.org/wiki/Linux_Mark_Institute https://en.wikipedia.org/wiki/Linux_Mark_Institute https://www.linuxjournal.com/article/2559 https://www.linuxjournal.com/article/2559 What Mongo did was meaningfully better than what Della Croce did, and closer to the spirit of "prevent people from confusing products and thinking stuff is from the original development team when it isn't", but I can see how it would be an unpleasant shock in the Open Source world which, sadly, usually doesn't know or do a damned thing about trademarks until some asshole forces the issue.
- ianamartin 8y agoFor people defending this, you're being naive. It's way too easy to argue that the value of any app resides mostly in the data it collects. That data is stored in MongoDB, therefore the value of the app "primarily derives from the Program." Of course their sales people are saying "No. We won't use it that way." Sales people gonna sell. I'm sure the people currently running MongoDB would not do that. What happens when they get acquired by, say, Oracle? Or some other company that absolutely would do that? The bottom line that you have to assume from a legal point of view is that any part of an agreement that can be abused, will be abused. This not only can be and will be, but it will be really easy. If they are doing this to prevent people from competing with their own service--which they absolutely are--then they need to rewrite it and make that explicit. This is way too squishy for anyone with an ounce of brains to use in a commercial product.
- polynomial 8y agoSincere question: who is actually using MongoDB these days?
- sytse 8y agoAt GitLab we still use it for Gitter. It wasn't a priority to convert it to PostgreSQL. After the WiredTiger updates I think Mongo got a lot more reliable. But I would start any new project with PostgreSQL.
- Illniyar 8y agoI can understand the sentiment and realize the need to monetize, it's hard when others take your code and make more money out of it then you (which I am assuming is the case). But even if they are right, this doesn't seem smart, it feels like a knee jerk reaction. I imagine that they hope that by doing this they'll cause people who are using mongo on other providers to move to mongolabs, since there is 0 chance of these providers open sourcing their infra. But that's not whats going to happen, either cloud providers will remain with old versions and people will gradually move to different dbs or they'll just fork it, they certainly have the manpower for it, this will give them incentive. Frankly though I think this is well within the agpl, cloud providers aren't modifying the code they are building things around it.
- 51lver 8y ago> it's hard when others take your code and make more money out of it then you Just my opinion, of course, but I think this is only true for sales and management types who are profit driven. For engineers and artists, it's not really an issue. We want to see our best work appreciated, primarily.
- Arcsech 8y agoAll the engineers I know still want a paycheck every two weeks. Engineers aren’t (and shouldn’t be!) all Above All This - sure, it’s great to make something and give it away just to help the community, but you still gotta eat. That said, I think MongoDB REALLY screwed up the execution here, even though I can definitely sympathize with what they were aiming to accomplish.
- toomuchtodo 8y ago> For engineers and artists, it's not really an issue. We want to see our best work appreciated, primarily. I want to be paid first. Everything else comes second. That doesn't not make me an engineer. It makes me a wise engineer. Money buys options and freedom. Prestige and other abstract concepts are used to steal your time and value.
- 8y ago
- metheus 8y agoDisclosure: I work for MongoDB. If you look at these two threads you'll find my comments in them, addressing similar concerns to those raised in this one. https://news.ycombinator.com/item?id=18229452 https://news.ycombinator.com/item?id=18229452 https://news.ycombinator.com/item?id=18229013 https://news.ycombinator.com/item?id=18229013 To reiterate those comments, the SSPL only affects people who are offering the licensed software to the public as a service. This does not include any software that uses MongoDB as a component, even if it's a commercial SaaS offering itself. The FAQ we put out here makes that clear: https://www.mongodb.com/licensing/server-side-public-license/faq https://www.mongodb.com/licensing/server-side-public-license.... 99.999% of MongoDB users are not affected by this license change. People have expressed concerns that the 1) the FAQ is not the license, and 2) the language of the license does not make the intended responsibility clear enough. But it was drafted with that intention (and reviewed by outside counsel, with an eye towards being explicit without giving bad actors loopholes to exploit). Nonetheless, addressing those concerns is extremely important to us. This exact issue is being discussed on the OSI license approval mailing list, and we are considering very seriously all of the feedback. The article anchoring this thread contains a lengthy discussion of copyright misuse and of impracticability. Those are also the subjects of discussion on the OSI mailing list, where Heather Meeker, writing on MongoDB's behalf, refutes claims that are similar to those made in the article. In particular, the SSPL is not trying to make people release substrate infrastructure, or adjacent tooling, under the SSPL. Consider the last line of section 13: "...all such that a user could run an instance of the service using the Service Source Code you make available." This means that as long as the Service Source Code you release is enough for anyone to run the service, you've fulfilled your obligation. As an example, you would not have to somehow be able to offer CircleCI under the SSPL (an impossibility), as long as your tooling that orchestrates its use is public, because anyone can use CircleCI. It's our hope that these discussions will lead to an accepted understanding of the actual obligations of the SSPL. The only people we want to be in any way affected by it are those who are literally offering the licensed software as a service, and we want those people to release their management stack under the SSPL. Thanks for helping us with that.
- ballenf 8y agoDoes MongoDB also release their stack or are they exempt from the disclosure requirement? Apologies if this has been asked a million times -- didn't see it in a skim of your linked discussions nor the FAQ.
- pitaj 8y agoIntellectual "property" is cancerous repression. It's time for copyright to die.
- benatkin 8y agoMongoDB doesn't deserve all the credit (or blame) for what they've created. The client libraries are true open source projects, and a lot of the good parts of the design have probably come from them. I think they've also accepted a lot of contributions to mongod without compensation, and had the copyright assigned to them. Having the copyright assigned to them is reasonable, but it facilitates them closing an open source project that's received many community contributions, which is unethical IMHO.
- codemaverick123 8y agoThey use plenty of other open source components as well. As I pointed out in other parts of the discussion they use PostGres beneath the scenarios for their reporting solution and charge customers for it. What do they contribute back to the PostGres community?
- jiveturkey 8y agoHuh. So, the rush to release and announce the license before OSI vetted it, was in fact VERY VERY intentional. Not some poorly planned "rush the news out" mismanagement. And the recent stink on HN where OSI claimed MongoDB was not Open Source because the license had not yet been reviewed, with many claiming (correctly) that OSI is not the determiner of what is open source, appears to have been out of order. I think there was a base assumption that the license would in fact be fine, and OSI claiming it wasn't because they hadn't stamped it ... yet ... was overreaching. Anyway my understanding is that the single largest user (and commercial licensee) of MongoDB hates it and can't wait to get away from it. With that in mind, this licensing nonsense smells like a desperate grab. Maybe it's time to short $MDB?
- golubbe 8y agoCloud computing is becoming the dominant model, and the current combination of OSS licenses and public cloud players/incentives make it nearly impossible for OSS companies to monetize in the cloud. While there are no perfect answers, we either need to come up with new licenses (difficult) or pursue a new approach to cloud (decentralization) that supports OSS monetization.
- brobdingnagians 8y agoThe umbrella issue is monetization of software. Perhaps the philosophy of OSS as a monetization strategy is fatally flawed for certain types of software. I love OSS and it is very useful, but in the world we see that some things are better suited for selling online (not usually pet food), etc. Perhaps it is simply an issue of a particular problem that cannot be well solved by OSS. If that is the case, then perhaps we fall back to the idea of "software monetization" and go proprietary for certain things which work best that way, while pushing OSS for things where it works very well.
- jkaplowitz 8y agoWhy does the article think MongoDB is located in the jurisdiction of the 9th Circuit? I mean sure they operate nationally in some senses, but their HQ is in NYC (2nd Circuit). And if they're incorporated in Delaware as most funded tech startups are, that isn't 9th Circuit either. Am I missing something or is the author? Also, what stance has the 2nd Circuit taken on copyright misuse, if any?
- manigandham 8y agoInteresting that none of the clouds even offer hosted mongodb in the first place, and from everything I know there were 0 plans for any of them to start. They all have their own proprietary databases to promote instead. Meanwhile MongoDB Atlas seems to be doing well so the entire impetus for this license change seems rather unwarranted.
- mr_toad 8y agoArguing that the license is invalid as a defense in court seems to be a risky legal strategy. ‘Your honour, my argument is that I was copying this copyrighted software, for profit, without any legal license to do so. Oh wait...’
- bigiain 8y agoStartup idea: A MongoDB as a Service company with the entire hosting/management platform written from scratch in Befunge or Brainfuck... (VCs please form an orderly queue. Priority given to investors willing to pay in Bitcoin or Monero. Contact deets in profile...)
- matt4077 8y agoI think both this discussion, as well as last year's Facebook/React Patent License brouwhaha (and Redis, more recently) would all be far better if people assumed good faith, and tried to actually get at the core of the problem. It's clear that there's a gap in existing licences that some regard as unfair. It also seems plausible that many projects could have dramatically better resources if the companies they are attached to could find a way to capture a fraction of their product's worth to their largest users. Just offering service with their competitive advantage being only the result of name recognition seems to work only for a very select group of huge projects. And even there, the likes of Canonical or SUSE show how hard it is. Yet it is obviously challenging to write a license that adequately captures these facts. I think everyone would have something to gain from finding a way to make these situations work. A required part of that solution may be for the community to interpret licenses not with the current they-are-trying-to-screw-us mindset but with, say, the "reasonable person" standard often used by the courts in contract/license disputes. That's not going to be easy, considering "expect the worst and don't risk anything" always looks like sound advice, given that you will never know what you missed on the path not taken. But the GPL's success should be inspiring here: it was initially met with scepticism, especially among corporate lawyers. Their essential pessimism never changed (it's how they became corporate lawyers in the firs place). But as it happened, it was enough for just few to take the risk, and subsequently creating precedents in court affirming the GPL, that made the concept cross the chasm to being palatable even to initial sceptics. Once courts fill in the questions of interpretation currently clouding these (necessarily somewhat abstract) licence, some doubts may dissipate.
- luddy 8y agoApple's SDK has an EULA that says it cannot be deployed on a server and made available as a service. Why can't mongo just create a license that says such a deployment requires a commercial license from them?