8 ms·
This really isn't news, folks. It happens every week. I was just grumpy this morning.
by seldo 8y ago
This really isn't news, folks. It happens every week. I was just grumpy this morning.
- tombert 8y agoHow much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.
- Mikeb85 8y agoIf their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.
- deleted 8y ago[deleted]
- kzrdude 8y agoHas it been tested in court? :)
- icebraining 8y agoYes, of course.
- Scoundreller 8y agoI’m not sure how universally true that is. When governments fail to redact documents, it’s on them. If you “accidentally” talk to a reporter about your solicitor-privileged comms, it’s not privileged anymore.
- JeremyBanks 8y agoThis isn't an open question. If you don't have a license from the copyright holder, you can't legally use it, except for fair use exemptions: perhaps you could write a blog post criticizing it.
- y4mi 8y agoThats only true for the US and the countries adhering to US copyright. It's not universally true
- JeremyBanks 8y agoIt's not "US copyright", it's several international copyright treaties, which 90% of all nations have agreed to: https://en.m.wikipedia.org/wiki/Berne_Convention https://en.m.wikipedia.org/wiki/Berne_Convention The few exceptions are where copyright essentially doesn't exist at all. Where it does, this is how it works.
- HenryBemis 8y agoAs someone above posted the wider "List of parties to international copyright agreements", this is one of the boxes that need to be ticked prior to signing any form of deal between countries. It's a kind of 'fundamental' in order to start doing business with that country (or for the country to be taken seriously).
- anticensor 8y agoDPRK only recognises foreign copyrights, and have no concept of IP for its own works (because everything is done to superior order, there is no creativity allowed). Micronesia does not have copyright, but has even stricter regime of creative works, amounting to a patent-like protection.
- zaphirplane 8y agoWas there a licence attached to the files? What if there wasn’t
- detaro 8y ago> If you don't have a license from the copyright holder, you can't legally use it, except for fair use exemptions: perhaps you could write a blog post criticizing it.
- devoply 8y agoAbsolutely not true. Anyone that lives in a country whose legal system does not respect their copyright can use it.
- icebraining 8y agoBasically every country has signed a treaty saying their legal system does respect them: https://en.wikipedia.org/wiki/List_of_parties_to_international_copyright_agreements https://en.wikipedia.org/wiki/List_of_parties_to_internation... If you're saying any country where they don't respect it in practice, then sure.
- MagicPropmaker 8y agoAnd if it's protected as a "trade secret" and not a copyright (or patent) then you probably can use it without question.
- ufo 8y agoSoftware is copyrighted "by default". You don't need to apply for copyright like you would need to do with a patent.
- MagicPropmaker 8y agohttps://www.uspto.gov/patents-getting-started/international-protection/trade-secrets-policy https://www.uspto.gov/patents-getting-started/international-... USPTO explanation of difference between a Patent, Copyright, and Trade Secret.
- detaro 8y agoThe software could contain a trade secret, and someone could discover it from reading the source (e.g. the banks magic evaluation function for credit ratings, or their trading strategy, or ...). That doesn't grant them any protected right on the software, which is protected by copyright.
- thaumasiotes 8y ago> If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site. Surely this depends on the terms under which they uploaded it. I would expect npm to have a legal structure in place under which code you upload for public use is also licensed for public use.
- crooked-v 8y ago> I would expect npm to have a legal structure in place under which code you upload for public use is also licensed for public use. Not how it works. For example, see the license field here: https://www.npmjs.com/package/unlicensed https://www.npmjs.com/package/unlicensed
- isostatic 8y agoThat would be the "terms under which they uploaded it" NPM doesn't appear to have a "default license" though, so that would be "no license", therefore normal copyright law would seem to apply, and you can't make a copy of it, and more than you can copy a picture on a billboard or a blog post or whatever.
- benj111 8y agoIANAL but if someone makes code publicly available (for 3 years). Then isn't there an argument to be made that its reasonable to make use of it? Probably not redistribute it, but use it at least. So I'm not even sure an explicit upload license would be required.
- tylersmith 8y agoIf you leave your keys in your car for 3 years it's still illegal for me to take a joy ride in it. I don't personally believe in/support the concept of IP but in a world that does (like the US) it doesn't make sense to me that people being able to see your property for 3 years gives them the right to use it.
- 8y ago
- tombert 8y agoI know that, but is the issue that companies are using the code or that NPM, Cloudflare, and Amazon are hosting the repo?
- shawnz 8y agoWhat if the public site states in their terms that they must be granted those rights on the uploaded material, and the actual copyright holder is the one who does the uploading (but accidentally)?
- walrus01 8y agoStreisand effect.
- deleted 8y ago[deleted]
- omouse 8y agoIf this happens often, perhaps the user interface for npm publish needs to change? I mean, that's the only thing I can see mitigating this, with like a nice dialog that says "hey, are you REALLY REALLY sure and have you consulted lawyers on this???" Or something to that effect. Or maybe companies can just pony up for NPM Enterprise which fits their use case.
- vvoyer 8y agoNo alert box ever will save you from doing the biggest mistakes, most people don’t read them.
- ivan_gammel 8y agoJust compare this to publication to Maven Central - you’ll never publish there by accident exactly because there are significant barriers. Public NPM repo should not be that easily accessible for upload.
- kbenson 8y agoAt some points in a language and its package management system's lifetime, reducing barriers to publishing are one of the best things that can be done to increase packages and fill out the ecosystem, and drive utility and adoption. Later, once you have most needs filled by packages, and a good number of enterprise users, more control is beneficial. Companies appreciate it, and single users are willing to jump through an extra hoop or two much of the time because the rest of the ecosystem is so useful that it's not worth switching languages. I think it's unlikely that a system will move from one style to another without an event causing them to reevaluate their prior choices. More likely, multiple events. This has already happened with NPM for other choices they made in the past, such as letting package namespaces be claimed by new people after someone gives it up, and whether releases are immutable, IIRC.
- ljm 8y agoThis is going to be cynical, but as far as I understand it people are looking for usability through vanity. Why not install `com.facebook.react’? Reverse domain notation is remarkably elegant given our internet. You are not typing ‘npm i com.facebook.react’ so often that it’s a pain. You probably use ‘create-react-app’ which is even worse. Instead, every language creates a new cash grab for common names. And made it worse. New namespaces, new squatting. I can publish ‘react-racket’ and do whatever I want behind the scenes with it. Case in point: do you add coffeescript or coffee-script. Why optimise for keystrokes in your term instead of stability for your client? Jesus fuck.
- seniorsassycat 8y agoAdding 'private: true' to the package.json prevents publishing to _any_ registry, including a corporate proxy. Adding a string or regex option for private that would only publish to matching registries may prevent issues like this. I ask for regex only because our corp proxy binds to a random port reach time it runs so a static string wouldn't be flexible enough.
- ljm 8y agoWhy isn’t this a source URL? Took a while for Ruby to get it but for the last 5 years you have default config for self-hosted sources whenever you make a new gem. Of course, npm is unique in being privately funded. It doesn’t want you doing that. Benefit of the doubt says that they thought they were publishing privately. Going back to Ruby, you will fail a bunch of CI steps just by leaving defaults in place.
- krainboltgreene 8y agoHey, contributor to rubygems here, there's no source url for ruby gems specification. You can read more here: https://guides.rubygems.org/specification-reference/ https://guides.rubygems.org/specification-reference/ You're likely thinking of bundler's source, but even then that doesn't apply to publishing a gem.
- bigiain 8y ago> Benefit of the doubt says that they thought they were publishing privately. In what world is pushing your source code to a venture backed (therefore viral growth oriented) company who promote themselves with "npm Inc supports the JavaScript community by providing the registry where developers publish and share packaged open-source modules" possibly consistent with a view that "they thought they were publishing privately"??? Sorry, but I just don't buy that. Somebody at the bank fucked up. It cannot possibly be npm Inc's responsibility to detect and somehow police that.
- Nuzzerino 8y agoStill made my day ;-)
- jldugger 8y agoSo true. How many takedown requests per week do you think Apache.org gets from megacorps of the form "Our employee asked for help, and their debugging logs published our internal URLs. please delete this post and all replies" ?
- lucb1e 8y agoCan't you recycle some old lawyer letters then? Or a little more radical, why even bother with the lawyers? You can explain to them how it is, and if they won't listen, they can sue you. Then you spend some lawyer costs, they lose because the whole thing is ridiculous, and you get a 'cost conviction' or 'cost order' as we call it (kostenveroordeling, where you pay the winning party's costs to prevent abuse of the system) so they pay your lawyer.