4 ms·
The BSL and SSPL licenses were created with an explicit goal of protecting the revenue of SV startups. Frankly, I'm tired of portraying those startups as some
by peppermint_gum 3y ago
The BSL and SSPL licenses were created with an explicit goal of protecting the revenue of SV startups.
Frankly, I'm tired of portraying those startups as some kind of underdog freedom fighters. They are billion-dollar corporations upset that other billion-dollar corporations are profiting using their software.
It's perfectly fine to build your business on Linux or Apache, but if someone wants to use an SV startup's project, like Elasticsearch, suddenly it's immoral and we must turn the whole world of FOSS licensing upside down to fight it.
- jchw 3y agoExactly. PostgreSQL has been here this whole time with RDS and Managed SQL and I haven't heard a damn thing. Somehow this only seems to come up with companies in the red-hot SaaS space where people are making lots of money, and basically nowhere else. Hundreds to thousands of classic open source projects are important to billion dollar businesses, but we only ever hear about VC-funded NoSQL databases and that kind of crap, and many of them probably weren't going to get an Amazon managed service to begin with. This is the closest I've ever felt to like I'm seeing some kind of psyop crap going on. Yes, we get it. You want to attract developers, gain mind share, get some good press. So you go open source. Then later you have developers, mind share, and good press, and now you'd really like it if you had exclusivity over the rights to host a SaaS for your open source product. And you know what, if you want to do that rug-pull, go for it. You presumably used some horrible CLA that gives you carte blanche to crap all over the community you fostered, so go ahead. But for the love of God, please stop talking about "open source sustainability." Google and Amazon may be terrible companies, but they contribute far more to open source than 99% of SV companies ever will. They're great for open source, they're just bad for your business model. It is genuinely a shame that some projects die because the company that sustains them are unable to manage to find a business model, but you knew what you were getting into the moment you went for funding, or if you didn't, then you failed to act responsibly. The reason why people are mad is because you're acting like you're trying to fix a "bug" in open source, but it's not a bug, it's a feature. The freedom that actually free and open source projects give you is exactly what attracts people. You're relinquishing some level of control by releasing things permissively like this. There's a reason why there's an open source movement and not a shared source movement. I want to say that what people are learning is why it used to be the default to not open source things, but actually I'm pretty sure a lot of these people knew from the get go. If you really didn't know what you were up to, you probably wouldn't have, super early on, selected a CLA that explicitly gives you the legal right to go for a rug-pull later on. (Supposedly the Apache CLA is better in this regard, but I haven't had a chance to read it.) And of course, the open source movement has a solution for the loophole anyway. It's called AGPL and as far as I know big corporations treat it like toxic waste. So go for the AGPL dual license if you want to still be considered "open source" and also not have Amazon compete with you. Sure, it may be a bad license from some standpoints even disregarding the FUD, but it is child's play compared to the legitimate nuclear waste that is the SSPL. I'll just quote the SSPL itself: > If you make the functionality of the Program, or a modified version available to third parties as a service, you must make the Service Source Code available via network download to everyone at no charge, under the terms of this License. Making the functionality of the Program or modified version available to third parties as a service includes, without limitation, enabling third parties to interact with the functionality of the Program or modified version remotely through a computer network, offering a service the value of which entirely or primarily derives from the value of the Program or modified version, or offering a service that accomplishes for users the primary purpose of the Software or modified version. > “Service Source Code” means the Corresponding Source for the Program or the modified version, and the Corresponding Source for all programs that you use to make the Program or modified version available as a service, including, without limitation, management software, user interfaces, application program interfaces, automation software, monitoring software, backup software, storage software and hosting software, all such that a user could run an instance of the service using the Service Source Code you make available. This license is supposed to save open source. lol
- stavros 3y agoWhat's wrong with those quotes? My reading is that they force you to publicize source code if you're hosting modified versions of the services.
- jasode 3y ago>My reading is that they force you to publicize source code if you're hosting modified versions of the services. Your phrase "modified versions of the services" is glossing over some major details. If we use MongoDB as an example to discuss (since they authored the SSPL license)... One part that some open source advocates disagree with is and interpret as overly-broad overreach is this fragment that extends the source code exposure to other internal projects that are not MongoDB : - ", including, without limitation, management software, user interfaces, application program interfaces, automation software, monitoring software, backup software, storage software and hosting software," That type of "expose your entire tech stack source code and not just the modified MongoDB source" wording in the SSPL goes beyond the more limited scope of AGPL. In a past thread, you can read about people disagreeing with SSPL's wording : https://news.ycombinator.com/item?id=18301116 https://news.ycombinator.com/item?id=18301116 That thread also has MongoDB employee metheus responding to various criticisms. If you don't want to read the whole thread, you can do Ctrl+F search for "metheus" to just read his responses.
- stavros 3y agoThanks, this is informative.
- jchw 3y agoOn top of that, this clause is set to trigger upon granting network access to the program, not on modifying it. IANAL but my understanding is that AGPL still desperately wants to be an additive copyright license and not a contract/EULA so it only applies to copying and modifying source. In practice this seems more than a little unintuitive in its implications, But, OTOH, it does seem to help ensure that AGPL is less of a legal threat: if you are just casually deploying unmodified AGPL software, as far as I know, you don't really need to treat it differently from GPL. I'm definitely not going to argue it's a good license, but I think the strong distaste for it is a little unjustified, and seems like corporate lawyer FUD.
- jeswin 3y agoI would have no problem if a license restricted its commerical use by teracorps, while leaving smaller companies alone. The Llama licence is a step in the right direction.
- theamk 3y agoTo take an example of Elastic Search, Elastic's offering is 1.5x-2x more expensive than AWS one. You can say "AWS is a teracorp" but if Elastic had its way, it would be small startups paying much more that they pay now.
- KingMob 3y agoPerhaps that reflects the true cost, if Elastic is the one funding development, while AWS is a free-rider.
- marcosdumay 3y agoAlso, Elastic on AWS looks a lot like a loss-leader.
- amadeuspagel 3y agoIt's perfectly fine to use the GPL or the Apache License, and it's also perfectly to use some other license. No one is turning anything upside down. People are choosing licenses for their own projects according to their own preferences.