62 ms·
Microsoft forked MIT licensed repo and changed the copyright [fixed]
- johnklos 5y agoThis is a perfect example of a huge company using the cover of bullshit to do whatever they want. "Oops. We f*d up? Well, you can't talk with a human unless you pay us lots of money. Oh - you don't have money for a lawyer? Tough. Good luck getting through our layers of trained monkeys."
- gjs278 5y ago
- iamleppert 5y ago
- rstuart4133 5y agoI was asked to run out Intune on Android [0], which is a Mobile Device Manager from Microsoft, (aka MDM) [1]. We needed an always-on VPN. Intune supports several, but all insist you run some proprietary server software. If you don't understand why that would make someone feel uncomfortable, PulseSecure [2] was one of those options. There is open source GPL software that replaces the proprietary back ends called OpenConnect [3], but that violates their client licensing. Then I discovered Microsoft has their own VPN called mstunnel. That's when I felt like I had fallen down the rabbit hole. I dismissed mstunnel initially because since it is a Microsoft Product, it would run only on Windows, right? Turns out it only runs on Linux. I thought you installed the mstunnel client on Android, because among other things it existed - but nope it was superceded by this thing called "Defender for EndPoint". The server came as a Docker install, but we didn't have the required version of Docker so I unpacked it and ran it in a chroot. That all worked in the end, but in the process of unpacking it I discovered what it was under the hood. It had two things - an "agent" written in dotnet whose sole function as far as I could tell was verify with Microsoft's servers you have paid for it and ... a copy of free as in beer OpenConnect. Nothing wrong with that really. In fact it's the reverse - it being OpenConnect under the hood gave me a lot of confidence I wasn't dealing with another PulseSecure. The only fly in the ointment is OpenConnect is GPL. They are completely free to use it the way they did - in fact I suspect the OpenConnect authors would be very happy to see the project used in that way. But you do have to comply with the licence. There was no attribution whatsoever, let alone instructions on a copy of the source as the licence requires. I'm sure it's just an oversight, just like the subject of this article. Maybe it's another mess for Jeff to fix. I don't know you from a bar of soap Jeff, but keep up the good work. [0] Intune provides a uniform MDM like experience across many platforms - including Windows. If you need to control Windows like that you probably don't have much choice, you have to use a Microsoft product. Maybe it works very well on Windows, but it's an ugly, buggy thing on Android, and the UI is a confusing mess. If you only need an MDM for Android I can heartily recommend headwind (https://h-mdm.com/ https://h-mdm.com/), which we rolled out before Intune because it took literally months to get the licences (in fact, we still don't have them). Headwind is open source, is cheaper than Intune and has free tier, and frankly was a joy to work with - once you discovered their doco was all in the FAQ's. [1] For the uninitiated, all Android devices (and iOS) allow a company to take control of a device by installing an MDM, something that can happen only immediately after a factory reset. Thereafter Android displays "your company can see everything you do on this device". [2] https://threatpost.com/pulse-secure-critical-zero-day-active-exploit/165523/ https://threatpost.com/pulse-secure-critical-zero-day-active... [3] https://www.infradead.org/openconnect/ https://www.infradead.org/openconnect/
- phendrenad2 5y agoSeems like it's probably a mistake, did you try to contact them? https://opensource.microsoft.com/ https://opensource.microsoft.com/ https://twitter.com/OpenAtMicrosoft https://twitter.com/OpenAtMicrosoft
- notquitehuman 5y agoContacting Microsoft is always a mistake. They don’t want to hear from anyone and their process reflects this.
- phendrenad2 5y ago1) What's your source for that assertion 2) Assuming it's even true, what should this person do instead? 3) What do you think the outcome would be if this person did contact Microsoft? Since it's a mistake, I assume something bad?
- kelnos 5y ago> Assuming it's even true, what should this person do instead? Since this is copyright infringement, the copyright holder could file a DMCA takedown notice.
- ognarb 5y agoA 'mistake' they are actually doing since a long time now. Here is the cups equivalent with a license change from apache to mit for the CUPS system. https://github.com/microsoft/cups/commit/ad69bcc78bdea3fea3f09fe56674daea821bb407 https://github.com/microsoft/cups/commit/ad69bcc78bdea3fea3f...
- phendrenad2 5y agoWhy the scare quotes around mistake? Are you implying that it's intentional? Or negligence? It seems like nobody noticed the CUPS license change until now, so it's irrelevant, right?
- hirundo 5y agoThey changed the copyright holder on this fork, but left the MIT license in place. How does this harm anyone?
- precommunicator 5y agoIt violates the license that specifically says (IANAL): > The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
- bayindirh 5y agoIt looks like Microsoft developed this all along. Yes, git keeps history, but it's unethical and ugly to begin with. Also, I'm not sure you can just change the copyright information, and change the history of the code like that. However, this is typical of Microsoft. Like DOS, like Windows App Store / Packaging ripoff (they asked the guy some questions, sherlocked his software, even didn't thank him later), etc.
- shp0ngle 5y agothat’s still breaking the license
- arbitrage 5y agoso take them to court.
- anonymousab 5y agoA supercorp will have far more resources to succeed in courts than an individual person, such that the courts are not a fair avenue for resolving disputes. The court of public opinion is, unfortunately, far more accessible to the individual.
- fault1 5y agoThat being said, if someone were to sue Microsoft over this (they would have to be the original copyright holder), I think it's more likely Microsoft would try and settle out of court.
- zach_garwood 5y agoI didn't think code was copyrightable in the first place.
- shp0ngle 5y agoThis might be true about trivial pieces of code, which this one is not
- dpratt 5y agoAny work, no matter how trivial, is eligible for copyright as long as it is an original artifact with a distinct identity.
- throwaway858 5y agoCopyright laws vary wildly across countries and jurisdictions
- tzs 5y ago...but aside from Eritrea, Ethiopia, Iran, Iraq, Marshall Islands, Nauru, Palau, Somalia, and South Sudan everyone is part of one or more (usually more) international treaties that cover copyright such as the Berne Convention or TRIPS or UCC, so you should expect in most places that most people on HN are likely to ever deal with have copyright law that isn't too different for the most common situations.
- emilfihlman 5y agoNot true, u64 add26562(u64 value) { return(value+26562); } is not copyrightable.
- anonymousab 5y agoIf that function always returned, say, the AACS key then it would likely be violating copyright in the US. Regardless of whether it was the result of a computation or statically defined.
- h2odragon 5y agoThe repo page still has: > This repo has been populated by an initial template to help get you started. Please make sure to update the content to build a great experience for community-building. Perhaps this is "updating content"?
- Hello71 5y agois it possible that microsoft bought the rights to the software
- mkdirp 5y agoThe original copyright holder claims on reddit[0] that it was forked, and there doesn't seem to be any implication of buying the rights to the software. [0] https://www.reddit.com/r/opensource/comments/roa9xz/microsoft_fork_changing_the_license/ https://www.reddit.com/r/opensource/comments/roa9xz/microsof...
- SloopJon 5y agoThat Reddit thread is a better source link for this submission.
- deleted 5y ago[deleted]
- kaladin-jasnah 5y agoThis comment shows they've done it to other pieces of software, including things like… CUPS: https://news.ycombinator.com/item?id=29684567 https://news.ycombinator.com/item?id=29684567 For some reason I doubt they've bought the copyright to CUPS.
- CyberShadow 5y agoThe account which did the change has this description: > This is the open source management service account used for performing key GitHub operations on behalf of Microsoft employees and users. Combined with the nonsense README change, this looks like a bot mis-use accident. Edit: to clarify, in no way am I saying that this is a "honest mistake" which does not deserve scrutiny.
- kenjackson 5y agoNo judgment from me since I suspect it is also an accident and I’ve made enough in my life that I don’t get super judgy in most cases. But what purpose is there for a bot that forks and makes changes like adding template files? Copyright aside, I don’t understand the value of this bot.
- CyberShadow 5y agoIf I were to guess, it would be that the action performed here (or the basis of the code implementing this action) was intended to be done on internal Microsoft repositories that should be open-sourced.
- matt123456789 5y agoOk, but this is still illegal, right?
- judge2020 5y agoSince MIT has this line: > The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. MS would be in the wrong to redistribute this code without the notice that includes '(c) 2020 LesnyRumcajs' - however, just changing the line doesn't constitute copyright infringement or fraud if MS reverses the change and/or simply appends the original MIT license above their MIT license (since MS does indeed have '5 commits ahead' of the origin repo, all of those changes are copyright MS but still MIT licensed). They could even simply have a file called 'LICENSE2' with the original notice, if they can't easily exclude this repo from the bot.
- fiatjaf 5y agoSo you can't do that? I do it all the time when I fork something.
- jeremyjh 5y agoMaybe read the license before agreeing to its terms.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- ignoramous 5y agoOne can add their copyrights, relicense in some cases, but absolutely cannot remove existing copyrights. I don't think any FOSS license (save for the "public domain" ones) allow for that.
- zenexer 5y agoCorrect. You don’t own the code just because you forked it. The original copyright holders retain ownership, and you must abide by their license. You can’t swap out the license unless they explicitly allow you to do so.
- gortok 5y agoThat’s not true. You can change the license if the license allows you to. It’s copyright you can’t change unless the author assigns the copyright to you.
- soheil 5y agoThis comment highlights the ignorance of a lot of people in this thread jumping to conclusion and view MS instantly as an aggressor and themselves as victims of the obvious and horrible crime of copyright infringement. A) Do you know it was not an honest mistake? B) Why a complete understanding of esoteric legal copyright laws created by non-programmers all of a sudden so important to a mainly programmer HN audience?
- akyoan 5y ago
- zenexer 5y agoIt doesn’t matter that it was an accident; it’s still a serious issue that needs to be corrected and deserves an upvote. It’s also quite curious, and I appreciate hearing about the incident. Incidents don’t need to be malicious to be newsworthy or intriguing.
- akyoan 5y ago
- luckylion 5y agoHow often did the bot make the same mistake? In how many of those cases does Microsoft now assume they have copyright and make their army of lawyers enforce it? Are you willing to go up against Microsoft in a court, rolling the dice?
- Crosseye_Jack 5y agoProblem is in a world of moderation actions being taken by bots and not humans often the only way to get a human to review its decision is to raise awareness on social media like HN. How often have we seen closed accounts getting resolved after complaining about it on HN/Twitter/Etc. I’m not saying tha to how it should be, just what it’s become.
- AdrianB1 5y agoHow about stop blaming the bots and take responsibility? The bots have none, the humans behind the bots have full responsibility.
- frob 5y agoBots don't steal licenses; people who program bots steal licenses. It's the latter action that's being addressed here.
- ghjklpoiuy 5y ago
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- brisad 5y agoSince they also removed a full stop at the end... What is the point of using all caps? For me it makes legal texts like these really annoying to read. I'm not a native English speaker, is that really correct English writing? Aren't there clear rules when to use capitalization? Like, at the beginning of sentences. Feels like they are abusing the language. Can they just lower case the paragraphs, to make things more convenient to read? Or does that change the legal meaning? For me it would feel like they would stop screaming :-)
- brianwawok 5y agohttps://www.termsfeed.com/blog/all-caps-legal-agreements/amp/ https://www.termsfeed.com/blog/all-caps-legal-agreements/amp... It’s legally important
- feanaro 5y agoYour text says it's not. What's legally important is to make certain parts of the text conspicuous. Using all-caps is one way of achieving this, but there are other options, such as using a different typeface, font size or colour.
- Ensorceled 5y agoHow do you use a different typeface in a plain text file?
- rdpintqogeogsaa 5y agoDisclaimer: I am not a lawyer. The following is not legal advice and, in particular, has not been tested in court to the best of my knowledge. You can't use a different typeface, font size or color in a plain text document. That does not mean you have no options. The criterion is that it is “written, displayed, or presented that a reasonable person [...] ought to have noticed it.” Consider the following: Nihil harum autem impedit commodi ut occaecati. Nihil quisquam ab molestiae veritatis consectetur. Quis molestias sunt facere tempore est. Eum quia quisquam veritatis illo minus sint atque ipsa. Omnis optio ducimus minus nemo non deleniti voluptas. Blanditiis nisi eum eum beatae fugit delectus. Optio neque sed nostrum veniam eos. Culpa ut no‐ bis rem est dignissimos est eum sed. Occaecati dignissimos eveniet odit aut est ipsum minus nisi. !! IMPORTANT !! DISCLAIMER OF WARRANTY The software is provided "as is", without warran‐ ty of any kind, express or implied, including but not limited to the warranties of merchantability, fitness for a particular purpose and noninfringe‐ ment. In no event shall the authors or copyright holders be liable for any claim, damages or other liability, whether in an action of contract, tort or otherwise, arising from, out of or in connec‐ tion with the software or the use or other deal‐ ings in the software. Unde sint ab qui ut. Debitis qui deserunt fugiat aut nihil impedit vel saepe. Et ad voluptas quia. Omnis libero ni‐ hil perferendis aut ab. Illo et neque voluptatibus. Et animi consequatur enim eius aut at veritatis. Modi error a ratione tempore velit inventore. Accusantium accusantium et quam quis nemo id. This seems rather noticeable to me, gets to the point, and is considerably more readable. By using the all-caps sparingly, we've made way to draw attention to the heading, then offset the passage with large amounts of whitespace to draw attention to the passage itself. At the same time, this keeps readability of the actual text that you want people to read.
- stillicidious 5y agoSomeone has pushed a button and it's run the equivalent of cookiecutter on the repo. Original author could send a DMCA, or they could simply enjoy Christmas and assume a ticket will undo this sometime in January.
- radicalbyte 5y agoThis, the reason why we have the DMCA is to protect copyright holders, now the copyright holders should exercise their right.
- uda 5y agoWhat? no, this goes entirely against the idea of laws. Copyright laws have one major purpose: protect the right holders. It does so by giving them tools to mitigate their loses by deterring people from infringing. If a right holder has to invest more time in complaining on people about infringement than actually having time to do other stuff, like creating, then we've got it all wrong.
- 37ef_ced3 5y agoThe larger issue is that anyone using GitHub is donating their work for re-use without attribution through Copilot. In return, you receive hosting from GitHub. The writing is on the wall. You MUST host your own code on a stand-alone website. Here is an example. This Go program (a compiler) generates and serves its own website: https://NN-512.com https://NN-512.com It runs on a Linode shared CPU cloud instance that costs $5 per month: https://www.linode.com/pricing https://www.linode.com/pricing Another example, look at what Fabrice Bellard does: https://bellard.org https://bellard.org
- wellthisisgreat 5y agoIs the copilot thing true for paid accounts as well?
- judge2020 5y agoIf you treat copilot like a human, and you ask it a question ( like "#find median of list") that human either (A) will put together all the things they've learned over thousands of hours of simply looking at code in the programming language and how the syntax works, then provide a new code block, or (B) remember "oh, I remember this extract string of text and what comes after it. Here's the next 10 lines from that snippet". In that B scenario, would the human be infringing on the original's copyright? Arguably yes; but is situation (A) also copyright infringement, or is it like getting code help from a friend? In these situations, whether it be originating from a human or robot, the knowledge comes from looking at public code on GitHub and it's always been a risk that your public code might not be used with proper attribution at some point. Think about how many OSS projects have core code and algorithms copied daily by companies with no public name and keep all of their source code private - it's surely caused more damage than CoPilot ever will.
- rdpintqogeogsaa 5y agoI observe some confused comments on this page that seem to argue that the MIT license doesn't come with a requirement to keep the copyright line intact (which is demonstrably false, you don't get two paragraphs into the license without finding the attribution requirement). The part that caught my interest is: How many people consciously picked the MIT license when they actually meant a non-attribution license?
- throwaway2037 5y agoI like your last question. Can you give an example of a "non-attribution license"?
- rdpintqogeogsaa 5y agoIf you're attached to your copyright: 0-clause BSD is a thing that exists[0]. Toybox uses it. If you want to throw your copyright out the window: The commonly accepted solution seems to be CC-0[1], which tries very hard to disclaim rights and limit liability in as many jurisdictions as possible, complete with a fallback license grant for failed public domain dedications. Because CC-0 makes some people uncomfortable despite the lengths it goes to reach its goals, some projects work with dual-licensing to cover the other side, such as Monocypher. Neither of them address patents. If patents are something you want to/need to address, you could perhaps paste the patent clause from BSD-2-Clause-Patent onto 0-clause BSD. See also the discussion on [2,3]. [0] https://spdx.org/licenses/0BSD.html https://spdx.org/licenses/0BSD.html [1] https://spdx.org/licenses/CC0-1.0.html https://spdx.org/licenses/CC0-1.0.html [2] https://en.wikipedia.org/wiki/Public-domain-equivalent_license https://en.wikipedia.org/wiki/Public-domain-equivalent_licen... [3] http://landley.net/toybox/license.html http://landley.net/toybox/license.html
- redthrow 5y agoI wondered why more FOSS projects aren't using CC0 instead of "permissive" licenses like MIT, considering a lot of folks who work in FOSS are against copyright/software patents system in general, and most of them don't really seem to care about attribution. People who release code under MIT not only won't/can't take legal action but they probably won't even bother writing an email to the person who they believe violated the attribution part.
- ramsundhar20 5y agoIs this the commitment, Microsoft shows towards Open source. Things never change.
- noodlesUK 5y agoThis is a clear violation of the MIT License. MSFT can and should get in hot water over this. The copyright doesn’t belong to them, just a license to use the software.
- alkonaut 5y agoThey’ll be in hot water on social media because of a the automation mishap. Then it’ll be corrected. There will be no legal hot water.
- noodlesUK 5y agoThe relevant Reddit thread also points out that MSFT has illegally relicensed Apache licensed Apple software in the same way. Apple is very litigious… https://github.com/microsoft/cups https://github.com/microsoft/cups
- ognarb 5y agoI created an issue in the original cups repo: https://github.com/OpenPrinting/cups/issues/315 https://github.com/OpenPrinting/cups/issues/315
- bayindirh 5y agoI was contemplating a PR with original license, but your course of action is much better.
- 88j88 5y agoI guess this is grounds for a valid DMCA take down? They are obviously breaking license agreement, effectively stealing copyrighted software.
- noodlesUK 5y agoIt looks like Jeff Wilcox who seems to be in a decision making position about this has addressed this (on Christmas no less), and I think whilst this is bad and definitely violating, I don’t think there was any ill intent, and I hope we can all put the pitchforks down for a while.
- mradmin 5y agoSeems like a mistake to me. Microsoft recently adopted one of my Open Source projects and part of the agreement was they would keep the original license. This was a request on their part, I had no choice in the matter. They know what they're doing, I don't think they would do this deliberately. (Licence here: https://github.com/microsoft/vscode-gradle/blob/main/LICENSE.md https://github.com/microsoft/vscode-gradle/blob/main/LICENSE...)
- motoboi 5y agoMicrosoft is not a person. And, by its size, is not a single entity with homogeneous values and procedures. You interacted with one part of Microsoft, maybe we are seeing the works of another part.
- mradmin 5y agoSure, could be. I guess i'd expect Microsoft to have company-wide processes and practises when working with OSS though. Could be wishful thinking.
- 3np 5y agoSo sure, this is far from a good look. But the verdict is still out on if it is an unfortunate mistake or malicious. It's far from the first time I see this kind of reaction and, IMO, rather than everyone spending time on piling on the flamewar, how about opening the door for MS to set this straight and do the right thing? Assume good faith even if you personally don't sincerely believe it? Give them an easy way to save face and present a plausible narrative rather than having everyone dig their trenches deeper? If you'd prefer MS not to screw people over, it helps no one to solidify them in doing just that. Already so many people shouting "YOU ARE THE DEVIL", not one going "hey, looks like this is a mistake, let's sort it out". IMO the latter is more constructive. It's almost as if people want Microsoft to do bad things. Remember it's a huge organization with all kinds of people and ideologies internally. It's too early to tell which way the individual behind this particular change is leaning. It took me all of 1-2 minutes to make this PR[0], probably less than any of the meme pictures in that commit thread. Let's see how it goes. Last time it went through[1]. [0]: https://github.com/microsoft/grpc_bench/pull/1 https://github.com/microsoft/grpc_bench/pull/1 [1]: https://github.com/dotnet/sdk/pull/22262 https://github.com/dotnet/sdk/pull/22262 EDIT: ...And, it's merged. I'm assuming the rest of the affected repos will be fixed as well and an apologetic blog post issued by Monday. Anyone who feels that's too long time can always open corresponding PRs instead of wasting their time by replying to this with how that's not our job. Happy holidays.
- 3np 5y agoAnother aspect of this: Rejecting such a change, or indefinitely leaving it hanging as open, is a much worse look than simply ignoring all the complaints (which is already bad enough but has more plausible deniability). Providing a ready-to-merge PR is effectively pushing them to take a public stance.
- phkahler 5y ago
- niros_valtos 5y agoCan it be identified only in a PR or is there any tool that can search through all forks? Maybe it’s too small problem to solve though.
- Tepix 5y agoI don't think that just because some "bot" did this Microsoft is to be excused. Someone decided that using a piece of software to automatically alter license files. This is a genuinely stupid idea. And they already fucked up in the same way with the CUPS project. Will they learn without someone taking them to court over this? I don't think so.
- misnome 5y agoI think people should be as forgiving as Microsoft would be if someone “accidentally” changed the licence of Microsoft software and started distributing it.
- doubled112 5y agoMy copy of Daz's Windows Loader accidentally activated my Windows pre-upgrade. It was just accidentally run in a script. No worries right?
- nexuist 5y agoI don't know what point you're trying to prove here, since I don't think I've ever heard of Microsoft suing individuals for illegal Windows keys and certainly not in the past 10 years. If you start an LLC and attempt to commercialize on piracy then you'll probably get sued, but regardless they are a lot more lax than, say, Oracle on this issue.
- IgorPartola 5y agoFWIW it does look like a bug in a bit and not company policy to me. But having said that the equivalent situation would be some larger than Microsoft copying their work. For example the US Federal government distributing Windows under the MIT license.
- Dylan16807 5y agoThe license on something that was already open source?
- helsinkiandrew 5y agoHow did it used to go? Embrace, Extend, and Extinguish But now not even bothering with the extend. I’d guess this is a mistake of some kind.
- deleted 5y ago[deleted]
- implements 5y agoDismiss, Embrace, Extend and Extinguish - if I remember the early histories of Netscape and Java accurately.
- implements 5y agoCrikey - surprised by the downvotes. I mentioned “Dismiss” because I remembered it as being a significant part of the process - attempting to “Take the wind out of the sails” of something innovative, to slow market adoption and to buy time to plan the Embrace, and decide how to best Extend to eventually win the competition.
- osolo 5y agoThe attitude in these threads always boggles my mind. When YOU, your teammates or someone else you know makes a mistake, then it’s just a mistake. But when someone at Microsoft makes a mistake it’s because Microsoft is evil and by extension so is the person who offended. “It’s a big company”, you say. They should have a process! And I’m sad to say, they do/will have a process exactly because of this attitude. Then, everyone wonders why it takes forever to fix that bug they’re furious about or why features are slow to come. Full disclosure: I work for MS, though have nothing to do with this. It’s a huge company. I know hundreds of people and most of them are upstanding and try to do the right thing.
- beervirus 5y agoY’all are not entitled to the benefit of the doubt any more than obviously-evil companies like Facebook are.
- voakbasda 5y agoFor those of us that remember the “old” Microsoft, they are still obviously evil. Nothing they have done will change that view. Incidents like this prove that this zebra cannot change its stripes. Never. Trust. Microsoft.
- beervirus 5y agoI mean yeah. But for a few years there, they were at least not as obviously horrible as they used to be, or as some other companies were.
- Dylan16807 5y ago> Never. Trust. Microsoft. Good advice. > Incidents like this prove that this zebra cannot change its stripes. Nope! This was a simple mistake that would have gained them nothing.
- dang 5y agoWe've banned this account for repeatedly breaking the site guidelines and ignoring our requests to stop (most recently https://news.ycombinator.com/item?id=29501677 https://news.ycombinator.com/item?id=29501677). If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future. They're here: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html. We particularly don't want the online callout/shaming culture here. nhttps://hn.algolia.com/?sort=byDate&type=comment&dateRange=all&page=0&prefix=true&query=online%20shaming%20by%3Adang https://hn.algolia.com/?sort=byDate&type=comment&dateRange=a...
- darepublic 5y agoDid the original author agree to give their project over to Microsoft?
- Tyriar 5y agoMS dev here. I contacted the internal repo owners to bring this to their attention, people may be out for the holidays but I expect it to get fixed up soon.
- bennyp101 5y agoCould be it got caught by mistake? I know I can run "Update Copyright" on my projects in JetBrains - could just be an innocent mistake that hit the wrong folder. I know everyone jumps on the big corp as everything they do is intentional, but it's the holidays, someone was doing a bit of work, maybe not fully concentrating and hit push. Seeing how quickly this was plastered everywhere, and the responses to it, do you really, like REALLY think that this is a deliberate play?
- abhishekjha 5y agoHey, why are the comments repeating on the page? Is this a UI bug?
- throwaway984393 5y agoIt seems people are outraged because they don't like it, but they don't seem to be talking about whether it's actually legal. IANAL, but the MIT license specifically does not say you have to redistribute with the same copyright owner notice. It says the copyright notice and terms must remain, and that you can sublicense it. It doesn't say you can't change the copyright notice.
- deleted 5y ago[deleted]
- uda 5y ago
- dls2016 5y agoEmbrace, extend, extinguish. https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...
- rvz 5y agoI did warn everyone that Microsoft has gotten smarter and is 'using' open-source and Linux for EEE. We know how they embrace and extend. Extinguish basically now means: 'We fork the best open-source tools and they sit on our cloud and are more secure and scale better than if you self-hosted it, and is completely free to use.' Paid competitors can't compete or will struggle to compete with free, given that it is open-source and more secure and is sitting on the cloud and scales. Lastly, nobody got fired for buying products with Microsoft® stamps.
- dang 5y agoIt seems to have very plainly been a mistake, and your comment broke the site guidelines. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
- rangoon626 5y ago
- naves 5y agoYeah, everyone has a second chance but Microsoft has had n-th chances. Make no mistake, gravity will always pull MS towards their default behavior. Just wait for VS Code becoming a subscription-based product. Yes, there will always be a community maintained project. But it will not be MS Certified…
- readbeard 5y agoThere is a rampant practice where companies and organizations flippantly and often fraudulently stamp copyright notices on everything they touch—including public domain materials such as the U.S. Constitution, works of William Shakespeare, prints of the Mona Lisa, copies of the 9/11 Commission Report, and compositions of J.S. Bach. [0] It seems Microsoft has now automated this practice. [0] http://www.copyfraud.com http://www.copyfraud.com Edit: It's easy to jump the gun and start accusing Microsoft of something nefarious here. To be clear, I'm personally giving Microsoft the benefit of the doubt and assuming that this was an honest mistake, and that the folks at Microsoft who had something to do with setting this up were well-meaning. My point is that we're living in a culture that, as a standard practice, sprinkles "(c) [year] [company]" on things like salt, that such claims are frequently invalid or misleading, and that this broader issue may be partly to blame for incidents like the one we are discussing today.
- exdsq 5y agoIt’s fixed https://github.com/microsoft/grpc_bench/pull/1/commits/305618da96fe4a6e518540010ffefa2f9e92cb48 https://github.com/microsoft/grpc_bench/pull/1/commits/30561...
- sandworm101 5y ago
- deleted 5y ago[deleted]
- aoetalks 5y agoA PR reverting this is already approved and merged: https://github.com/microsoft/grpc_bench/pull/1 https://github.com/microsoft/grpc_bench/pull/1 Thanks, 3np
- jhawk28 5y agoProbably just a setting in someone's IDE or a bot that they didn't understand what it was doing.
- jeffwilcox 5y agoI lead the Microsoft Open Source Programs Office team. I'm sorry this happened. We have merged a pull request that restored the correct LICENSE file and copyright, and are in touch with the upstream author Leśny Rumcajs who emailed us this morning. We'll look to revert the entire commit that our bot made, too, since it updated the README with a boilerplate getting started guide. The bug was caused by a bot that was designed to commit template files in new repositories. It's code that I wrote to try to prevent other problems we have had with releasing projects in the past. It's not supposed to run on forks. I'm going to make sure that we sit down and audit all of our forked repositories and revert similar changes to any other projects. We have a lot of process around forking, and have had to put controls in place to make sure that people are aware of that guidance. Starting a few years ago, we even "lock" forks to enforce our process. We prefer that people fork projects into their individual GitHub accounts, instead of our organization, to encourage that they participate with the upstream project. In this situation, a team got approval to fork the repository, but hasn't yet gotten started. To be as open as I can, I'd like to point to the bug: - The templates we apply on new repositories live at https://github.com/microsoft/repo-templates https://github.com/microsoft/repo-templates - The bug seems to be at this line of the new repository workflow: https://github.com/microsoft/opensource-management-portal/blob/main/routes/org/repoWorkflowEngine.ts#L373 https://github.com/microsoft/opensource-management-portal/bl... - The system we have in place even tries to educate our engineers with this log message (https://github.com/microsoft/opensource-management-portal/blob/main/routes/org/repoWorkflowEngine.ts#L375 https://github.com/microsoft/opensource-management-portal/bl...): "this.log.push({ message: `Repository ${subMessage}, template files will not be committed. Please check the LICENSE and other files to understand existing obligations.` });"
- deleted 5y ago[deleted]
- gautamcgoel 5y agoA lot of commenters are sharpening their pitchforks, but this comment, in my opinion, makes it very likely that it was an honest mistake. Amazing what taking personal responsibility and earnestly apologizing can do to restore trust and credibility!
- TedShiller 5y agoMicrosoft
- goodpoint 5y agoReminder: if you want to protect your software or your community from similar issues you can use [A]GPL and let Free Software Conservancy handle any legal battle on your behalf: https://sfconservancy.org/copyleft-compliance/ https://sfconservancy.org/copyleft-compliance/
- franky_g 5y agoOk Jeff We forgive you... ;)
- ThinkBeat 5y agoMakes me wonder if Microsoft GitHub should not make it a more specific action to relicense a repo. That would solve any ambiguities around the script Microsoft wrote. "Are you sure you want to change the license?" Yes / No. Perhaps a specific API call when you are doing it with a script.
- bmitc 5y agoWhat's surprising to me about all the negative reactions Microsoft receives, especially on here, is that from my point of view, they are currently the most open out of all the big companies (Google, Facebook, Apple, etc). I cannot remember a time Apple has admitted to anything or made any effort to have anything that could be considered open, but they do no wrong in most people's eyes, where even a simple mistake by Microsoft gets turned into some nefarious narrative.
- throwaway82931 5y ago
- Kye 5y agoReleases of all open source things Apple uses, by OS: https://opensource.apple.com/releases/ https://opensource.apple.com/releases/ These mostly link to repositories under one of their GitHub organizations: https://github.com/apple-oss-distributions/ https://github.com/apple-oss-distributions/ Apple's open source projects: https://opensource.apple.com/projects/ https://opensource.apple.com/projects/ Which mostly link to repositories under their main GitHub organization: https://github.com/orgs/apple/repositories https://github.com/orgs/apple/repositories
- glandium 5y agoNote these are thrown-over-the-wall source dumps, with no valuable VCS history, nothing more recent than at least 2 releases ago, and sending a PR will likely only receive crickets (said as someone who recently found an easily patchable bug in dyld, contemplated the idea of opening a PR and was told by an ex-colleague who now works at Apple that my best shot would be through feedbackassistant.apple.com). BTW, those repos don't take issues.
- dapids 5y agoI just got a security bug fixed last month in dyld in one release cycle. Didn't strike me as difficult. I emailed them, and they fixed it. Not much more to add then that. Have you actually tried? Also dyld isn't just some thrown-over the wall code. It's completely designed and built by Apple and is the cornerstone to making the user-space runtime functional.
- jesprenj 5y agoOops, a bot just removed bandwidth limits for Windows source code on a bittorrent seedbox.
- axiosgunnar 5y agoSure this might be an innocent mistake, but if you were to infringe a nanometer on Microsoft intellectual property, never in hell would they be like „oh an innocent mistake, we don‘t sue you into oblivion then!“
- rolph 5y ago
- jwsteigerwalt 5y ago
- drumhead 5y agoTo quote Thomas Jefferson, "eternal vigilance is the price we pay for liberty".
- de6u99er 5y agoSomeone did this at an university. They replaced my name in the MIT license with the name of the institute. After I let them know that this is not OK, they reverted it.