10 ms·
Microsoft now credits maker of AppGet but offers no apology
- mikece 6y agoI am curious: why would I want to use AppGet or WinGet instead of Chocolatey? And is the assertion that Microsoft took code from AppGet as part of WinGet? The fact that the word "copied" is in quotes makes me wonder what the beef is... and did anyone ask the APT team if they feel ripped off by the existence of Windows package managers?
- ak39 6y ago>>I am curious: why would I want to use AppGet or WinGet instead of Chocolatey?<< https://keivan.io/appget-what-chocolatey-wasnt/ https://keivan.io/appget-what-chocolatey-wasnt/
- mikece 6y ago"AppGet uses YAML files instead of scripts; we call them manifests. Using data over scripts just seemed like a much better choice." So it's an opinion, one that the WinGet team decided to go with as well. Okay... not sure that's massively compelling just because the author says so but I'm willing to be convinced. I guess I need to go back and dig deeper on this scripting being referenced in Chocolatey: isn't it just powershell scripting?
- michaelhoffman 6y agoYeah and recently a lot of Chocolatey scripts are calls to a number of standard helpers for various types of installers. Not a whole lot of arbitrary commands being used. Having something like YAML seems cleaner than the Chocolatey approach, but there are almost 8,000 Chocolatey packages and it works pretty well. Implementation > architecture here.
- godtoldmetodoit 6y agoYeah it's very dubious to me that YAML is the better approach, at least from the perspective of the average enterprise looking for Windows package management tooling. There are still too many nasty installers out there, I'd be very worried about the ability to do what I need without a full scripting language at hand.
- michaelhoffman 6y agoYou can have an approach that is YAML with scripting where necessary. There are so many packages that fit into one of the standard Chocolatey package setups (exe, msi, msu, vsix, zip). https://chocolatey.org/docs/helpers-install-chocolatey-package https://chocolatey.org/docs/helpers-install-chocolatey-packa...
- munchbunny 6y agoIn general it's easier to verify the security of the installation (not the code itself) if the package is configured via manifest instead of script. That's because you've preemptively restricted what the installation could possibly do, at the cost of flexibility. There are also some other specifics that are easier to implement via manifest than asking maintainers to implement via script, like supporting private app repository hosting (common enterprise feature). I suspect that's why WinGet went with AppGet's approach instead of Chocolatey.
- JamesBarney 6y agoWinGet is written in c++ and a AppGet is written in c# so the code isn't copied. I think his complaint is they copied the functional interface.
- KayL 6y agohis point: Interview + YAML = Copied "We have already talked with a few of the well-known package manager teams...." https://devblogs.microsoft.com/commandline/windows-package-manager-preview/ https://devblogs.microsoft.com/commandline/windows-package-m... In my point of view, they do the comparisons and created their own product. The interface is too basic.
- thePunisher 6y agoThat's no crime. If developers wouldn't be allowed to do that we'd have a major crisis on our hands. The worst infringement as far as I'm concerned is that MS tricked him into giving up all his secrets before they implemented it themselves. If Microsoft ever came to talk to me about one of my projects the only thing I'd tell them is: "How much?" (are you willing to pay for it).
- 411111111111111 6y agoWhat secrets? The code is open source. They were probably planning to hire him as well, something just happened in the meantime before he started so it didn't work out. It's a shitty situation for him, but that's just life. Sometimes it sucks.
- onemoresoop 6y agoHis future plans that he disclosed at MS. They made the guy think MS would hire him then they didnt even bother to show him the finger.
- loufe 6y agoIf you read the Github thread it's mentioned that it's not just the interface, but the code structure, and design theory as well.
- tsumnia 6y ago> And is the assertion that Microsoft took code from AppGet as part of WinGet? The fact that the word "copied" is in quotes makes me wonder what the beef is... Agreed; reading the article makes it sound (to me) like they copied his "idea" rather than actual code.
- tzs 6y ago> I am curious: why would I want to use AppGet or WinGet instead of Chocolatey? Better names? As someone who does not install a lot of things on my Windows systems, if I got a package manager named Chocolatey to install something I'd have trouble remembering the name the next time I want a package manager six months later. I'd remember that I already installed a package manager, but not what it is called. AppGet I'd remember. I might look for it as app-get the second time, but would quickly remember it is spelled a little different than the Debian program. WinGet would be a little harder, but I think I would remember it. Seriously, I'm getting a bit tired of programs whose names have nothing even remotely apparently related to with what the programs do. While on a bit of a rant about names, what the heck is up with the naming of backup programs? There is Duplicacy, Duplicati, and Duplicity. Part of the reason I went with Arq was I kept getting those three confused with each other when reading reviews and comments. Sure, you might not immediately think "backup" when you hear the name "Arq", but at least there is not also an "Ark", "Arque", and "Ourk" backup too.
- itsspring 6y agoIs there a way to protest this? Perhaps devs should upload every package with a readme that includes a reminder for developers, something like: "This package is dedicated to Keivan Beigi. Read more about what Microsoft did to Kevin here: thankyoukevin.com" Any better ideas?
- zxter 6y agoSubmitting PR to WinGet's repo for changing the name to AppGet, also crediting original author.
- Kenji 6y agoYes. Stop using Windows. Contribute to FOSS alternatives. License your code GPL3. Don't ask someone else to change. Be the change.
- gowld 6y agoEconomy of scale means freeloaders are too expensive a burden, preventing keeping up with closed source, for projects of unbounded complexity, like OS ecosystems. Sad but true.
- benatkin 6y agoIt sounds like an apology to me. What's missing, just the words "I'm sorry?"
- ak39 6y agoSounds like an apology. That's ok, I suppose. But I'd personally also love to see Microsoft pay Keivan for his contribution. It needn't be huge sums but something. No, not because it's the moral thing to do, but for the sake of Microsoft's GitHub and their open source community strategy itself. Keivan's project is exactly the type of projects Microsoft wants to encourage from their GitHub & open source endeavours for the eventual benefit of Microsoft. Paying Keivan something for his contribution to WinGet will really incentivise others to want to contribute to the ecosystem.
- jka 6y agoAlthough I'm sure you have good intentions, handing money to people after you make a mistake isn't always the best way to make amends (or to incentivize people).
- bzb3 6y agoThen Google should pay Oracle for using the Java API :')
- josefx 6y agoDid Google ask over Oracle engineers for job interviews just to pick their brains on Java?
- ocdtrekkie 6y agoIndeed. It's pretty funny when people pick their sides based on what companies are involved. They basically loosely implemented AppGet's API. AppGet, being permissively-licensed and open source, could've simply been forked or what-have-you anyways. There's nothing Keivan was actually holding back they had to interview him to get. That being said, I think it's likely a loss for Microsoft: Keivan obviously had thoughts they considered of value, and he probably would've been a solid hire. The PR hit from this probably costs them more than a year's salary for an engineer, so they probably should've considered the risk here. The fact that Microsoft engaged in a "dick move" is obvious, and for what? Something that feels like a tack-on side project by a couple of Microsoft engineers, that'll probably never graduate to mainstream adoption?
- tasogare 6y agoLicense is Apache 2.0 which does not require acknowledgment. I’m always surprised when open source project creators are complaining about a legal move made by a company related to their project: they allowed it in the first place. If they wanted more, like citation or financial advantage, they had the choice to force interested parties to comply by choosing another license. Betting on companies goodwill is risky...
- ghaff 6y agoThere's a matter of politeness/good practice that goes beyond license terms. And in some contexts (e.g. academia) there's absolutely an expectation that you cite others' work whether or not you're legally required to do so. That said, I basically agree with you. If you have specific expectations of whoever uses your code, you should absolutely pick a license that requires the behaviors you want. (With the understanding that fewer people may use your code as a result.)
- tasogare 6y agoOf course there are implicit expectations and etiquette. What I’m saying is that corporations are less likely than individuals to follow them so if one doesn’t want to be screwed they have the opportunity to do it with the license. You speak of academic code, and precisely some projects require (or at least ask for) citations in their license file if use in a research context.
- viraptor 6y agoThere's a difference between ethical and legal. You can do a lot of things that don't break any law but make you a terrible human being. Of course you can copy someone's design and not acknowledge it unless it's patented. You're going to be a dick then, not a criminal.
- jdmichal 6y agoIs it really being a dick when someone explicitly, through choice of a license, allows it? What is this post from Microsoft except an explicit and public thank you? Which seems like it should certainly appease the "not a dick" criteria to me...
- heavymark 6y agoThere message sounds like a clear apology, unless the poster is hoping to hear the actual words "I'm sorry". They screw uped and came clean, even though like in most cases takes trending on Hacker News to get that resolution.
- crones 6y agoI thought the message itself was okay and posted the article as it shows at least some action since the previous Hacker News discussion. I didn't want to edit the article's title though, beyond cutting the words "for Windows 10" to make it fit.
- awinder 6y agoYou did the right thing, the source article just has a dreadful title.
- KayL 6y agoI think the AppGet wanted his name on the repo.
- lallysingh 6y ago'He went for an interview at Microsoft's Redmond headquarters in December, which apparently "went well", but Andrew didn't inform him he would not get the job at Microsoft until six months later – on the day before the WinGet preview would be unveiled at Build 2020. ' This is bullshit. Keep him quiet with the hope of a job (embrace) until they release their version (extend, extinguish). Changing CEOs doesn't change everyone who works there.
- macspoofing 6y agoThat's not how "embrace, extend, extinguish" works. That practice is in the context of standards, and not products. Microsoft was perfectly in its right to build a package manager. They based it on an open-source version that allowed copying and forking. So no issue there either. They did string the developer along, but I'm not sure it was anything nefarious. I think the people at MS who were looking to acquihire Keivan ran into roadblocks at MS from higher-ups for whatever reason and it just fell apart. It probably wasn't a nefarious strategy to string Keivan along in order to boost their WinGet announcement - but just general inconsideration and rudeness in not communicating.
- Voloskaya 6y agoCan we please stop trying to slide in an EEE reference everytime something comes up about MS? You have clearly embraced EEE, but now you are extending it way past what it actually means, and if people like you continue you will extinguish it because it will not mean anything anymore. Please don't EEE EEE.
- dustinmoris 6y ago> Can we please stop trying to slide in an EEE reference everytime something comes up about MS? Agreed and also this AppGet story wasn't EEE anyways. It was just a plain good old "Fuck you". There was no embrace or extend at any point :)
- Lammy 6y agoWe can stop talking about EEE when Microsoft stop practicing it. This time is just with regard to a community instead of a particular software product. WinGet is the “Extend” step where they overtake AppGet in usage and probably in package registrations until AppGet withers and eventually Extinguishes itself.
- nojs 6y agoActual link to the statement: https://devblogs.microsoft.com/commandline/winget-install-learning/ https://devblogs.microsoft.com/commandline/winget-install-le...
- deleted 6y ago[deleted]
- forgingahead 6y agoCross-posted from another thread that is now buried:[0] The "Andrew" in question who courted Keivan (AppGet's dev) is Andrew Clinick. He wrote a blog post in response to this a few days ago: https://devblogs.microsoft.com/commandline/winget-install-learning/ https://devblogs.microsoft.com/commandline/winget-install-le... Still seems pretty tone-deaf to me - obviously MS seems to be in the legal clear, but the moral high ground and lots of dev goodwill has been lost. It also damages the ability for devs to informally meet and chat with PMs at larger companies everywhere - adds a lot of mistrust to the eco-system. This is not that MS came up with their own package manager. It's the entire song-and-dance routine that was conducted about potentially hiring Keivan, and then ghosting the engineer whose open-source product you were simultaneously cloning. Of course, people will forget, but many will still remember. This is still a net-negative all-around when it didn't need to be. Edit, this ZDNet article adds no new information and nothing has changed since the other articles have come out, but I guess it's good that more places are covering it to signal boost this properly. [0]https://news.ycombinator.com/item?id=23375624 https://news.ycombinator.com/item?id=23375624
- franciscop 6y agoFWIW this has been discussed here (please HN do not spam it) where both Andrew and Keivan have started talking, and it seems then they took it to a private convo: https://github.com/microsoft/winget-cli/issues/353 https://github.com/microsoft/winget-cli/issues/353 Disclaimer: I opened that issue
- username3 6y agoKeivan doesn’t want an apology. Keivan only wants credit.
- wayneftw 6y agoDid Keivan credit Microsoft for every free or open source tool, service or framework of theirs that he used during his career? And credit for what? Unoriginal ideas that have been around forever? They didn't even build WinGet in the same language as AppGet! You can see the rest of my response to the top comment here - https://news.ycombinator.com/item?id=23377936 https://news.ycombinator.com/item?id=23377936
- dotjosh 6y agoIt's unfortunate to hear all of this from Beige's perspective. But the optimist in me thinks this is probably just a big company focusing on a release and putting everything else on the back-burner. That doesn't make it right, but I want to think this isn't an example of how Microsoft wants to treat the community moving forward. I think AppGet, an officially supported package manager, should be a core feature. It needed to happen one way or another. But the lack of UI to browse/search I think is too lacking so I put this up a few days ago: https://wingetit.com https://wingetit.com -- I imagine Microsoft is going to copy/replace this soon, but I won't mind.
- ru552 6y agoTaking the dude's work that he licensed them to take (via Apache 2.0) is one thing. Giving him false hope about a future job prospect is another.
- stormdennis 6y agoYes that was really low scam artist type behaviour. Still, on the bright side, the more profitable MS are, the more money for Bill and Melinda's good causes
- tarsinge 6y agoYeah if someone scam you $10 but give $0.001 to charity I guess it's a brighter side than if they kept everything.
- rectang 6y agoBut he didn't license them to take code without attribution. If they had forked the codebase, maintained the copyright notices and adhered to the conditions of the Apache License 2.0, that would have constituted "credit". The Apache License 2.0 requires attribtion!
- kolanos 6y agoAnyone know why Microsoft implemented their package manager in C++ and not C#?
- walkingolof 6y agoI would guess fewer dependencies with a native image.
- vips7L 6y agoProbably because of startup time and size. Powershell faces these same problems.
- Matthias247 6y agoI would rather guess because "that was the team/persons favorite tool to do the job". In most areas tool choices are less about objective benefits and more based on familiarity/popularity/etc.
- snuxoll 6y agoMicrosoft is publishing this as part of a UWP package, writing it in C++ means it could publish the libraries as a framework package allowing other applications to consume it as WinRT components regardless of their implementation language (C++, Rust, C#, JS, etc). Whether this is planned or not I don’t know, but as they are putting this in the App Installer package right now which also has a public API I would not be surprised.
- atarian 6y agoBased on what I read, I'm guessing Andrew initially thought Keivan was someone worth working with because of AppGet. But then something during the interview started rubbing Andrew the wrong way. Maybe it was the way Keivan talked or how he dressed. So he started ghosting Keivan and things got more awkward. Maybe this worked for Andrew in the office, but that's not how things work between a company and its community.
- bluedino 6y agoThey could at least send him a new Surface Pro
- saos 6y agoI thought they offered me Azure credit? Maybe he preferred that.
- yesbabyyes 6y agoThey offered, but they didn't even come through on that: https://news.ycombinator.com/item?id=23333070 https://news.ycombinator.com/item?id=23333070
- saos 6y agoOhh that’s not cool.
- chooseaname 6y agoMaybe I'm old school, but I think an apology should use the word apologize in it. This is a "thank you", not an apology. But, at least it is better that what they did last week.
- squarefoot 6y agoNot sure if it applies here, but I've read before that is common practice for companies to never admit errors or apologizing because it could be used against them in court as if they were admitting some wrongdoing.
- gowld 6y agoThat's like saying people who steal for five it back because that's an admission of stealing. Of course it is. So what? Not apologizing doesn't make them less wrong. It just means they are covering up whatever they did wrong.
- bediger4000 6y agoThat may or may not be true, but why excuse a corporation for what would be insulting, pathologically rude behavior in an individual? Wealthy entities (including even moderately rich humans) can't admit error for legal reasons. That seems like a recipe for continued abuses, frankly. I'd like to see that changed.
- ken 6y agoIANAL. I found an interesting article [1], "Legal Consequences of Apologizing", which says: > Usually, apologies are admissible into evidence. Admissability into evidence does not necessarily mean useful as evidence of guilt. Since an apology usually can be admitted into evidence, and because some plaintiffs choose to understand an apology as an admission of guilt, it seems safest not to apologize. Case law suggests, however, that courts do not see it this way. Judges and juries seem to like apologies and treat them favorably. Often, an apology does nothing to satisfy the plaintiff's burden of proof. In some proceedings, an apology can be a mitigating factor, and the lack of an apology can be an aggravating factor. and concludes: > This article illustrates that judges and juries understand that expression of sympathy, regret, remorse and apology are not necessarily admissions of responsibility or liability. This serves the public interest because such expressions have the potential to reduce the number of lawsuits, rather than attract litigation. When someone goes to court armed only with an apology, they may find that it does nothing to satisfy the elements of the case they need to prove. Additional evidence is required, almost as if the apology did not exist. Cool. [1]: https://scholarship.law.missouri.edu/cgi/viewcontent.cgi?article=1313&context=jdr https://scholarship.law.missouri.edu/cgi/viewcontent.cgi?art...
- logicalmind 6y ago"We will be open sourcing our service code into our our WinGet repository on GitHub so that we can work together with Keivan and others to enable a better WinGet repository listing service." People who decide to "work together" should carefully read and understand the terms under which they're doing so: https://opensource.microsoft.com/pdf/microsoft-contribution-license-agreement.pdf https://opensource.microsoft.com/pdf/microsoft-contribution-...
- hajile 6y agoYes, "work together" means you work for free for Microsoft. Nothing more. Because you sign your code over to them, they are free to CLOSE SOURCE future versions at ANY TIME. Sure, you could attempt to fork, but the platform is proprietary and can lock you out (very likely in this case for "user security"). They are the biggest company in the world (by market cap) and those deep pockets mean they can outspend you until you go under or fall too far behind. It wouldn't be the first time.
- gowld 6y agoThis is nuts. Why not send the guy a $10-50K check (or to a nonprofit of his choosing) as a bounty/thank-you/we-love-open-spource-PR thing? It would be one thing if there were trying to to hide it with closed source, but this was stupidly evil out in the open.
- ocdtrekkie 6y agoMy assumption is a program manager can relatively easily write a letter thanking someone for their insight and work, but that a significant amount of paperwork is entailed in sending someone a big check. It really depends what level this issue has made it up to for Microsoft. Did Satya hear about this? If the answer's no, money probably is hard to just disburse.
- dustinmoris 6y agoFor me the worst thing about this entire fiasco is really Microsoft's brazen unapologetic predator behaviour. They've invited Keivan to their headquarters with a bait, giving him the wrong impression that they wanted to help him with the project when really they wanted to extract valuable information from his experience. He's been working on AppGet for a while, ran into issues, thought about problems which users are having, dealt with certain challenges and iterated until he got to a certain understanding/vision of his product. This is all very very valuable information not published anywhere in an open source thoughts database. It's just the experience and knowledge that only lives in Keivan's head and Microsoft knew that they had to bait him with some false promises and hopes in order to get access to that information which he might otherwise not have shared with a competitor. Also they didn't forget about Keivan. They knew what they were doing. At the beginning of the process someone put in their calendar to contact him the day before BUILD 2020 to send him this email, which is why he got the email the day before the announcement of WinGet. This was no coincidence. That is fraud in my opinion. Who cares about his source code, they stole much more valuable stuff from him. Anyone who doesn't see that is ignorant or blind. Keivan should take legal action.
- hajile 6y agoI'd love to see what turned up in discovery as his lawyers sifted through MS records.
- scott_s 6y agoWhat legal action, though? That is, what did Microsoft do that violates the law? I don't see anything. The code is open source, so I believe they're in the clear there. And I don't think they had a contract with Keivan, so I don't see any breach of contract disputes. To be clear, I think Microsoft acted unethically. But I don't see any obvious violation of the law.
- Lammy 6y agoI don’t need a legal basis to be able to find Microsoft’s actions reprehensible here.
- hysan 6y agoOriginal source was posted to HN a few days ago:https://news.ycombinator.com/item?id=23367153 https://news.ycombinator.com/item?id=23367153 It likely got no views because the title is worded in such a way as to avoid the actual topic at hand. Given how it's written, my gut is that it was titled to avoid being picked up, so I'm glad a news source caught wind and is calling them out with an appropriate title.
- jeffrallen 6y agoAny apology would pretty much be "we're sorry we got caught".
- jtdev 6y agoWhy anyone works with or supports Microsoft beyond corporate IT at this point is completely beyond me.
- rdgthree 6y agoThis seems more in the realm of poorly managed expectations and less intentional and malicious copying. After reading his original blog post[0] I felt like they were originally interested in acquiring his software, but decided to go in a different direction with it and just weren't transparent about that decision at the time. It's not like they had to talk to him, the code is literally open sourced. There's definitely things to gain from talking to the author of the project, but seems a bit reaching to suggest they wouldn't have been able to do what they did without talking to him. And it seems like a particularly pessimistic read to assume they were just lying to him outright to pull from his experience. Very little to gain from being a shark in this scenario, tons to (potentially) gain from acquiring an existing package manager. Gotta follow the incentives. It's also worth mentioning that he mentioned the name similarity in his post in this way: > When I showed it to my wife, the first thing she said was, “They Called it WinGet? are you serious!?” I didn’t even have to explain to her how the core mechanics, terminology, the manifest format and structure, even the package repository’s folder structure, are very inspired by AppGet. He did not go on to mention that his own name was (nearly certainly) inspired by apt-get (stylized as AptGet on Ubuntu[1]). Implying he was the originator of the name [X]Get for a package manager seems aggressively dishonest, to the point that it throws his entire side of the argument into question for me. I haven't looked thoroughly into the code, but this feels like someone who was expecting something to come out of his hard work and is (understandably) bummed it will now likely amount to nothing. I have trouble putting much blame on Microsoft for that. [0]https://keivan.io/the-day-appget-died/ https://keivan.io/the-day-appget-died/ [1]https://help.ubuntu.com/community/AptGet https://help.ubuntu.com/community/AptGet
- onemoresoop 6y agoIt may also serve as a warning to other developers to beware the big MS’s practices
- hardsoftnfloppy 6y ago“We contribute to open source now, everything is fair game”
- lstroud 6y agoEmbrace, extend, extinguish?