6 ms·
Is the service even public yet? The license says that users of the service are entitled to the code but if the service isn't open to users I fail to see the vio
by kfprt 5y ago
Is the service even public yet? The license says that users of the service are entitled to the code but if the service isn't open to users I fail to see the violation.
- aaron695 5y agoCorrect. They also are not entitled to the code unless it's been modified. But this is the license and reality, not what HN makes up in their heads, two very different things. (It is entirely possible they have modified the code and are allowing uses to access this code, but I haven't seen it shown)
- humanistbot 5y agoFrom TFA: Truth Social hasn’t officially launched. But users could access a test version of the platform, where many of them created prank accounts that flooded the service with false company announcements and even fake Donald Trump posts. (The platform has since been replaced by a waitlist.) The SFC demands that TMTG offer all these users access to the Truth Social source code. “If they fail to do this within 30 days, their rights and permissions in the software are automatically and permanently terminated,” Kuhn says.
- Xylakant 5y agoAccording to the article, a beta version was available and the claim is that users that had access to the beta are entitled to the source.
- kfprt 5y agoIt didn't say that the beta was public. If you run AGPL code on a home server for personal use and someone hacks in I don't think you should owe them code.
- humanistbot 5y agoIf you deploy a "test" version of an app to a public server/domain and send an invite to a closed mailing list for users to beta test it, then that still triggers the AGPL.
- kfprt 5y agoYou are absolutely correct. As far as I'm aware they never sent any invites though. edit: Only the users of the AGPL service are owed the code, it doesn't need to be posted publicly.
- qkqk 5y agoIt did say the beta was public "Truth Social hasn’t officially launched. But users could access a test version of the platform" > if you run AGPL code on a home server for personal use and someone hacks in No one hacked in [1] "we could find no evidence that someone illegally broke into the website [...] the site was simply deployed live early as a test, and without proper configuration [...] people merely used the site legitimately to register accounts and use its features" https://sfconservancy.org/blog/2021/oct/21/trump-groups-violates-affero-gpl/ https://sfconservancy.org/blog/2021/oct/21/trump-groups-viol...
- kazinator 5y agoI think if you run AGPL code on a public server and someone breaks into it, you also don't owe them the source code because unauthorized access isn't legitimate use.
- kazinator 5y agoWhat is the definition of a "user"? Is every visiting rando from the Internet a user? If a person has five sock-puppet accounts, is that five users or one? If a software robot creates an account, is that a user? Do we owe the source code to the robot? Or to the author of the robot? Are users of the service entitled to free-of-charge access to the source code? Or could you comply by stating, "for a processing fee of $17,750 USD, we will mail a thumb drive to a real person's residential address"?
- wccrawford 5y ago>Is every visiting rando from the Internet a user? Yes. > If a person has five sock-puppet accounts, is that five users or one? Each of those sock-puppet accounts can request the source, so 5. No wait, it's still a single human being, so 1. Either way, it doesn't matter. They can request the source, and they should get it. Are users of the service entitled to free-of-charge access to the source code? No, with limits. https://softwarefreedom.org/resources/2008/compliance-guide.html https://softwarefreedom.org/resources/2008/compliance-guide.... >GPLv2 permits “a charge no more than your cost of physically performing source distribution”. This fee must be reasonable.
- colejohnson66 5y ago> Each of those sock-puppet accounts can request the source, so 5. No wait, it's still a single human being, so 1. Either way, it doesn't matter. They can request the source, and they should get it. The answer is complicated. If I hack into a company and steal a binary for an internal tool (that uses GPL licensed stuff), I can’t demand the source code because I was not authorized to use said binary. If its a beta not designed to be used by the public, it’s not clear how it will go. The users weren’t authorized to use it but it was easily accessible. See also: the horrific CFAA Act
- kazinator 5y agoOK. Now, further, suppose you're the member of some copyleft outrage group and have heard that someone broke into a company and obtained an internal tool based on GPL-ed code. You jump up and down and scream that the person be given the source code in 30 days, or you will somehow terminate their license to use that code. Does that fit what we are looking at here?