3 ms·
Let's say a piece of software licensed like this becomes popular and is non-trivial to replicate. At some point, a significant enough portion will be two years
by scj 3y ago
Let's say a piece of software licensed like this becomes popular and is non-trivial to replicate.
At some point, a significant enough portion will be two years old and changed to the escrowed license. A fully open source fork will become tempting for pragmatic and ideological reasons.
If forked, what are the odds the copyright holder will re-license their source code for the sake of control & profit?
Every semi-open license/core tactic is just a rug-pull waiting to happen.
- bentlegen 3y agoI’m not a lawyer, but AFAIK, they can’t relicense any permissive versions that are already out there. They could choose to relicense future versions (i.e. they could stop future versions from becoming permissive, after 2 years). And if they did that, future changes wouldn’t propagate down (but it’d take 2 years to feel it). > Every semi-open license/core tactic is just a rug-pull waiting to happen. Note that everything you’re concerned about can also occur with permissive licensed OSS.
- scj 3y agoYou're right that Apache 2.0 is irrevocable. But MIT isn't. An open source project that starts to "scratch an itch" is far less likely to revoke a license than one that is motivated by money. Motivation aside, if it's a non-trivial organic project, they've likely taken many patches from others and effectively cannot revoke the license of the code base. But I shouldn't say "motivation aside" as motivation is the point when it comes to trust.
- zeeg 3y agoCan you actually revoke it in practice? I’m not deeply familiar with MIT (and personally always opt for Apache as it’s more well understood), but I didn’t think that was possible.
- scj 3y agoIn the scenario I've constructed, yes. The trick is that you don't need to threaten everybody, just any fork that gains traction and might be a viable open source project. Otherwise stated, you don't go after every user, just the competition.
- zeeg 3y agoI believe you’re suggesting revocation means something else. Once the software is released under a license you’ve created a legal contract granting those terms. You can’t (at least in the referenced licenses) rewind and take away the license grant. Sure you can fork it and license new code in a different way, but that’s not the same thing.
- tonyarkles 3y ago> Once the software is released under a license you’ve created a legal contract granting those terms. I’m not a lawyer but I’ve followed the “is it a license or is it a contract” thing for 25 years now. One important part of the confusion here is that a contract requires mutual consideration; unilateral “contracts” aren’t contracts at all. The long-term argument is that the source code is subject to copyright which implicitly would not allow distribution; the license is what grants additional permissions on top of what copyright does and doesn’t allow, and thus probably could be revoked.
- the_mitsuhiko 3y agoWe as an industry and community have settled on the irrevocably of Open Source licenses. I doubt that any court would rule against this notion today. Too much would be at stake.
- Diggsey 3y agoWhy do you think the MIT license is "revokable"? It's not - the version that was MIT licensed can always be used under that license.
- scj 3y agohttps://writing.kemitchell.com/2023/09/23/Two-Kinds-Relicensing https://writing.kemitchell.com/2023/09/23/Two-Kinds-Relicens... Makes it seem like it would be a legal grey zone in the US. And a reminder, not all of us are American and the ambiguity might be even less favourable in other jurisdictions.
- kemitchell 3y agoI wrote that post. I generally advise developers, and believe most of my US colleagues also advise developers, to treat past releases under MIT and BSD terms as irrevocable, even though they don't explicitly say they are. But that conclusion comes as much from practicalities as legalities. If the MIT license lets people make and share copies willy-nilly, online and off, how do you go about notifying every potential recipient that you've taken that license back? Even if you send a notice to just one user you want to block, who wants to see that on the Internet within hours? Who wants to be the company potentially arguing in court to undermine the reliability of MIT license grants generally? On the legal side, sketching very roughly: The general rule seems to be that non-exclusive licenses without terms remain revocable by default. But in what circumstances won't a court find a contract or quasi-contract, applying those rules instead? So much better to get ahead of all this head scratching by saying in the terms that those giving can't take them back. Alas, literally nobody's got commit bit on what we call "MIT", "BSD", &c. anymore. But we made very sure to do it the Blue Oak Model License: https://blueoakcouncil.org/license/1.0.0#reliability https://blueoakcouncil.org/license/1.0.0#reliability Other, more recent forms, notably Apache 2.0, say it, as well. If you're reading this and thinking about a particular bit of software, don't rely on what I've written here. Talk through it with a lawyer who's up to speed on the latest, will ask you for specifics, and will stand professionally responsible for their guidance. I won't.
- bentlegen 3y agoThe license for that version is irrevocable. It doesn’t mean I couldn’t publish a newer version with a different license, if I am the copyright holder. The existence of a newer version with a different license does not revoke your ability to use, modify, etc. the prior-released version. That’s what irrevocable means here, AFAIK.
- kemitchell 3y agoMIT certainly doesn't say it can't be revoked. But do you really think it's inherently revocable at will, in all or even many practical circumstances? From the US law perspective, I understand that some courts have decided that non-exclusive licenses without stated terms can be revoked at any time. But I wonder about situations when a court looking at a permissive grant for open software wouldn't also bring contract and quasi-contract concepts to bear. There's clearly an expectation of reliance, MIT and BSD themselves contain contract-type disclaimers and exclusions, and what a licensor might get in return doesn't have to be money.
- scj 3y agoIf I had to bet, I'd bet on it not being revocable. Betting a mere $20 on a case currently in court could be fun. But my time is worth a lot more than that. So if I'm thinking about starting a viable open source fork off this thing, I'm effectively betting a lot more. That kind of begs the question, who am I betting against? I'm suggesting on the other end is an entity that chose a licence that attempts to minimize competition. Please, re-read the last sentence as I can't stress it enough. What happens if that competition-adverse entity's business model is existentially threatened by my fork? Maybe they're willing to try their luck and try the MIT license in court. Whether or not I'd win doesn't matter to me. A long lawsuit is going to be expensive either way. The question I'd pose is if the case would be quickly dismissed? I'm not a lawyer, I have no way of answering that. But I've donated money to more than one programmer's legal fund against an absurd case that was clearly meant to just kill the project [0]. I don't want to be that programmer. I'd rather work on something else. Which gets to the actual point I've been trying to make all along. I personally wouldn't want to fork this, and I suspect a percentage of the open source community feels the same way. And forking is one of the most important aspects of open source. [0] https://lwn.net/Articles/181261/ https://lwn.net/Articles/181261/ - The programmer actually emailed me back with a thank you note, expressing some surprise that a non-American would care about a legal system they were not subject to.
- mdaniel 3y ago> Every semi-open license/core tactic is just a rug-pull waiting to happen. I believe that's only true with CLA, which is something I have started to check for in any new "Show HN" announcements