3 ms·
Of course the corporate lawyers and enterprise settings are going to take this position, but I find your flippant dismissal of GPLs core uses and purposes seem
by gnuser 3y ago
Of course the corporate lawyers and enterprise settings are going to take this position, but I find your flippant dismissal of GPLs core uses and purposes seem to belie you are just in a group that prefers the non-user friendly licensing.
That’s ok, but you can’t hand wave away that GPL, especially v3+, is about protecting and defending the user (like tron), while MIT/BSD is not, by calling it “vague notions of fairness” as if GPL hasn’t already seen wins in the courts… on this point I think some research might be due for me though.
I’m just so very tired of the “hey me and my banker/lawyer/insurance friends all hate this - that means it’s useless and dangerous for everybody”
I say the GPL and copyleft and the four freedoms for the user are the tools we use to fight these types of corporations in the first place, and I truly believe not only is GPL not dead but that it will play a vital role in our near and long term future.
Choose your weapons wisely.
- crest 3y agoImo the question is do you want to protect passive users access to the code or developers freedom to use the code how they want it even if that does mean they take existing code, modify it slightly, put it in an embedded device, and enable temper protections on the MCU preventing anyone but them from signing new firmware images? If that embedded device is something harmless like a video player or gaming console most open source developers would probably like to use the license as a crowbar to force the device open, but what if it's a medical device, or a payment terminal the user is explicitly not trusted to modify?
- the8472 3y agoIf anything medical devices, especially implants, should be modifiable. Otherwise you're stuck with an unmaintainable device (possibly in your body) once the manufacturer goes out of business or the support window ends or whatever. Right to repair and all that. And this is a very real concern. https://spectrum.ieee.org/bionic-eye-obsolete https://spectrum.ieee.org/bionic-eye-obsolete For external devices breaking some big, visible "last inspected on XX/XX" seal to do so would be acceptable. For payment terminals you could do the secure boot thing where replacing the manufacturer keys and flashing custom firmware wipes the TPM storage.
- Nullabillity 3y agoFor payment terminals the core problem is that the trust model is ass-backwards. The user is the one at risk from a faulty authn device, so they should be the side "controlling" the authn flow. Merchants would be fine just carrying dumb plastic cards with an ID number. Though these days there's little reason not to just make both sides smart… it could even run on the phones they already have!
- kelnos 3y agoTo me it's not solely about modification. It's also about transparency. While I most likely would shy away from trying to modify the software of a medical device, I think it should be illegal to lock down those devices so that people can't at least see the code that's running it. If you're going to build something that's going to directly affect my health, I would much appreciate it if it were easy for researchers to find bugs and security issues with the software that controls it. But ultimately I don't care about the whole "legally locked down" thing, and think that concept is a net negative for society. If I can buy a medical device to use at home, then it should be on me if I decide to modify it and it injures or kills me. I expect the law hasn't really kept up with that notion; I wouldn't be surprised that in many cases the manufacturer might still be liable. But that's a legal problem (that should be fixed!), not an ideological one. > ... or a payment terminal the user is explicitly not trusted to modify This is the worst thing, IMO. I wholeheartedly reject the concept of software that I am given to use, but am not "trusted" to modify. Screw that. Unfortunately I do have to use software like that. But I think the entire concept is garbage.
- jillesvangurp 3y ago> That’s ok, but you can’t hand wave away that GPL, especially v3+, is about protecting and defending the user (like tron), while MIT/BSD is not, by calling it “vague notions of fairness” as if GPL hasn’t already seen wins in the courts… on this point I think some research might be due for me though. It sacrifices the user's freedoms for this. Which is exactly the concern corporate lawyers have with this. Fine if that's what you want but the net result tends to be the vast majority of big companies pretending your project does not exist. Can't look, can't touch, can't use, etc. If a blanket ban on your project across most commercial users is what you are after, AGPL does the job.
- whiterknight 3y ago> vast majority of big companies pretending your project does not exist. Good. Even so that point is wrong as GPL software is widely used in the industry (Linux, gcc, gnu make, etc).
- kelnos 3y agoTo me, frankly, that would be the goal. For some of the things I work on, I would much rather a company be allergic to it, than believe they can do whatever they want with it. But for other things, I don't really care.