11 ms·
My insulin pump controller uses the Linux kernel. It also violates the GPL
- raverbashing 9mo agoGood luck trying to enforce the GPL against a Chinese company
- caminanteblanco 9mo agoWell it looks like insulet is the primary offender here, and Nuu (the Chinese company) is just the hardware manafacturer
- themafia 9mo agoAn actual good use case for tariffs.
- viccis 9mo agoNot really.
- themafia 9mo agoYou can tariff a single company.
- immibis 9mo agoThe normal response to a company importing illegal products is to seize them at the border, destroy them, and, optionally, send the importer a big fine. This is already an established process.
- themafia 9mo ago> importing illegal products What's "illegal" about these products? > send the importer a big fine. And that gets paid? > This is already an established process. And has it ever been used for /civil/ software GPL violations?
- viccis 9mo agoOr you could just prevent the goods from being sold, rather than making the American tax payer foot the bill for that company's crime.
- mijoharas 9mo agoOut of interest is there a process to petition the FSF to take up something like this? How do they triage and decide what to pursue?
- LukeShu 9mo agoTL;DR: Not the FSF, but SFC; email compliance@sfconservancy.org The dominant legal theory is that the GPL can only be enforced by the party holding the copyright. SFC's lawsuit against Vizio is strategically trying to establish precedent changing that; establishing that end-users are "third party beneficiaries" under the GPL, so others can enforce the GPL; but for now the copyright holder is the only one who can enforce it. So the FSF could only take it up if the violation is on projects that do copyright-assignment to the FSF (i.e.: most GNU stuff). If you do find a violation of GNU stuff, the process is "email license-violation@gnu.org". I do not know what process Craig and Krzysztof use when triaging reports and deciding what to pursue. Many Linux-kernel contributors (also, SFC member projects such as OpenWrt, Git, Qemu) have assigned their copyright to SFC or named SFC as their legal representative (also, SFC member projects; so SFC can take up something like this. Similarly, you can report violations to them by emailing compliance@sfconservancy.org (see https://sfconservancy.org/copyleft-compliance/help.html https://sfconservancy.org/copyleft-compliance/help.html for more info). Now, SFC is aware of more violations than they could ever possibly pursue, so they're strategic about pursuing ones that are high-impact. I'm not sure how they decide that. But I can say that medical devices are near-and-dear to them, between executive-director Karen Sandler's implanted defibrillator and policy-fellow Bradley Kühn's blood glucose monitor.
- Tomte 9mo ago> Bradley Kühn's I saw that spelling for the first time last week, I think. Did he change his name? Has he always been Kühn, but went with Kuhn, because Umlaute are hard for Americans?
- ralph84 9mo agoHe changed his name. https://fedi.copyleft.org/@bkuhn/115461658201124515 https://fedi.copyleft.org/@bkuhn/115461658201124515
- anigbrowl 9mo agoAs always, the solution is to contact their legal department, preferably via a lawyer. Engineers and support staff are not going to risk their jobs making legal decisions about giving away company property. The FSF could help a lot here by publishing demand letter templates outlining the statutory and precedential basis for license enforcement and recovery of damages.
- whatshisface 9mo agoIt is not company property.
- Aurornis 9mo agoSupport staff or even engineers are not in a position to be making that call. It’s a legal department decision, even if it seems obvious to you.
- ozim 9mo agoThis should be the most upvoted answer. Yeah there are are startups where head guys don’t know that and developers jump the gun because they feel like they’re ones that have the best understanding of the issue at hand. But of course that’s legal territory.
- opello 9mo agoI agree that a front-line CSR or even engineer is not likely the right person, but surely then the responsible action is to redirect the request to the responsible department or person?
- SpicyLemonZest 9mo agoAbsolutely, and companies that routinely get requests like this train customer service agents on specific trigger words like "license" or "GDPR" that must be redirected. Without that training, it's not obvious why "it's GPLv2 licensed" is more compelling than the last customer's argument that the device warranty obligates you to drop everything and immediately fix the minor UI bug they reported.
- teddyh 9mo ago> I then decided to contact Insulet to get the kernel source code for it, being GPLv2 licensed, they're obligated to provide it. This is technically not true. It is an oversimplification of the common case, but what actually normally should happen is that: 1. The GPL requires the company to send the user a written offer of source code. 2. The user uses this offer to request the source code from the company. 3. If the user does not receive the source code, the user can sue the company for not honoring its promises, i.e. the offer of source code. This is not a GPL violation; it is a straight contract violation; the contract in this case being the explicit offer of source code, and not the GPL. Note that all this is completely off the rails if the user does not receive a written offer of source code in the first place. In this case, the user has no right to source code, since the user did not receive an offer for source code. However, the copyright holders can immediately sue the company for violating the GPL, since the company did not send a written offer of source code to the user. It does not matter if the company does or does not send the source code to the user; the fact that the company did not send a written offer to the user in the first place is by itself a GPL violation. (IANAL)
- jstanley 9mo agoAre you saying that in the general case if you send someone a written offer for something and then don't honour it, you are in breach of contract? That doesn't sound right to me. A written offer is not the same thing as a contract.
- deleted 9mo ago[deleted]
- dspillett 9mo agoThe written offer is part of the licence, as is the need to respond to that offer with the source code offered. It is all part of the same agreement. A written offer on its own would not normally be directly enforceable in many (most?) jurisdictions, for the same sort of reason that retailers can't be held to incorrectly published prices (in the UK at least, a displayed price is an “invitation to tender”, not a contract or other promise) except where other laws/regulations (anti bait&switch rules for instance), or the desire to avoid fighting in the court of public opinion, come into effect. But in this instance, the written offer and the response to that offer are part of the wider licence that has been agreed to.
- Group_B 9mo agoOh well. The whole thing has already been reverse engineered. Look up Loop or Trio or OpenAPS. Diabetic companies like Insulet have been very lax when it’s come to the hacking of their devices. This isn’t really that big a deal. What we need right now is help REing the Omnipod 5
- duban 9mo agoI’m aware of a few people working on REing the Omnipod 5. The furthest issue that I have seen is that when a PDM/Omnipod 5 app signs into your insulet id, it gets a private key from the API which is stored in the keychain (and uses SSL pinning to prevent MiTM retrieval of the private key). When pairing with the pod they exchange public keys and then a derived key from the devices private key+pods public keys, but haven’t been able to get a copy of a private key yet to make further progress.
- Group_B 9mo agoAnyway to follow the progress? I attended the Nightscout conference and asked around regarding this but no one really knew of any group to follow. Or really knew of the latest developments on this effort.
- kakoni 9mo agoWas going to ask the something. And also, so the omnipod app is not using android attestation but stores private key it got from omnipod server?
- duban 9mo agoIt seems to use the play integrity API when communicating with Insulet's servers which provide a private key to the PDM/app once it was registered with the user's account. However since the Pod doesn't have access to the internet, it has no way to check the play integrity signature AFAIK, so instead it checks that the certificate that the PDM/app presents to it is issued from the cert chain that it trusts.
- 9mo ago
- Aurornis 9mo agoBe sure to read the top comment where someone who claims to have worked for the company provides some inside information. In my experience, this is quite common when the development of hardware is viewed as a cost center and is outsourced to various providers and teams. Those providers and teams churn a lot and nobody who worked on that is likely still involved with the company via contracts or direct employment. Front line support people aren’t equipped to respond to these requests. If you’re lucky they’ll get bounced around internally while project managers play hot potato with the e-mail until it gets forgotten. You might get lucky if you go the corporate legal route, but more likely is that the lawyers will do the math on the likelihood of you causing them actual legal trouble for anything and decide it’s best to ignore it. When I worked at a company that had a history of GPL drama one of the first things I did was enforce a rule that every release had a GPL tarball that was archived and backed up. We educated support people on where to forward requests. I handled them myself. 7 out 10 times, the person on the other end was angry because they assumed the GPL entitled them to all of our source code and they were disappointed when they only found GPL code in the tarball. It really opened my eyes to some of the craziness you get exposed to with these requests (though clearly not the polite and informed request in this Reddit thread) which is probably another reason why support staff are uneasy about engaging with these requests.
- teddyh 9mo ago> 7 out 10 times, the person on the other end was angry because they assumed the GPL entitled them to all of our source code and they were disappointed when they only found GPL code in the tarball. Well, if your non-GPL code was directly linked to, or closely interoperated with, any GPL code, those users would have been right.
- juped 9mo agoRichard Stallman is wrong about linking.
- teddyh 9mo agoAs far as I understand it, Richard Stallman has gotten his view about linking from FSF’s lawyers, who has advised the FSF about what does and does not count as a “derived work”, in the sense of US copyright law. If you want to argue that the FSF’s lawyers are wrong, please provide more detailed, and hopefully referenced, arguments (as opposed to plain assertions).
- jacquesm 9mo agoLet me guess. Omnipod. They've had some pretty bad recalls too. Never in a lifetime would I trust my well-being to their p.o.s. hardware / software combo. Apologies that person in this thread that worked there, but I hope you are working for a better company now.
- abigail95 9mo agoI get mad triggered by software license violation discussions. Please for the love of all that the FSF thinks is holy - just file a damn lawsuit if you are telling me they are violating the law. State your claim and have a court sort it out. It costs hundreds of dollars. For a medical device? Seems like a good deal.
- robomartin 9mo agoIn what planet does a lawsuit cost hundreds of dollars?
- abigail95 9mo agoThis one. That's what the filing fees are for a lawsuit like this. There's no rule saying you have to pay a lawyer to write a statement of claim. Edit: Courts deal with contract law disputes all the time. It's their bread and butter, everyday, nothing special stuff. Edit2: To you below, citation needed
- lucb1e 9mo agoIs that also what it costs when you lose and the court makes you pay their lawyer time?
- abigail95 9mo agoUse the CCB then? Edit: I'm somewhat mad that there's all these tools out there to solve the screeching about GPL violations and nobody seems to want to use them.
- apublicfrog 9mo agoFor reference for non Americans/non legal people: > The Copyright Claims Board (CCB) is available to resolve copyright disputes of a relatively low economic value and provides an efficient, less expensive alternative to federal court. https://ccb.gov/ https://ccb.gov/
- jimrandomh 9mo agoIf the only GPLed component used is the Linux kernel, you probably aren't entitled to any noteworthy source code. It's well established that using the kernel doesn't create a GPL requirement userspace software running on the same device, and the most likely arrangement here is a completely-uncustomized kernel paired with an open-source userspace program that does all the interesting bits.
- kkjjjjw 9mo agoThen it should be trivial for them to provide the source code.
- Nextgrid 9mo agoIt's trivial in terms that it will cost them nothing, because it's very likely there are no changes to the kernel, or nothing of value nor commercially-sensitive anyway. It's not trivial in terms of big company bureaucracy - this request will have to go through so many levels of red tape that they (correctly) decided not complying to random people's requests is more profitable. I'm sure if you actually sue them then they will comply right away, because at that point paying for some engineer's time to tar up the source tree and send it to you now becomes cheaper than lawyer time. But their analysis is correct in that nobody will waste time/money suing to get what is effectively a stock kernel they can get from the official source anyway. Which is why these complaints are also a bit stupid - they're not asking for anything of value or using the GPL to advance software freedom by freeing up some valuable code, they're just wasting both theirs and others' time asking for something they can already download directly.
- f1shy 9mo ago> because it's very likely there are no changes to the kernel That is a gratuitous assumption. My experience is, as long as there is the smallest custom hardware, you will have to make some tweaks here and there. > they're not asking for anything of value or using the GPL to advance software freedom by freeing up some valuable code, they're just wasting both theirs and others' time asking for something they can already download directly. I'm sorry that the company which is making lots of money by using a copyrighted SW has to "waste" 200 dollars in some bureaucracy, printing and postage. But is the license of the SW they are using, and should abide by it.
- lacoolj 9mo agoSo can someone tell me - a non-insulin-dependent individual - why would an insulin pump need to be (controlled by?) a phone (in this case, the Nuu phone referenced)? Surely there is a way to cheaply obtain bluetooth and a controller without saying "we'll just use this already existing hardware - that happens to be a whole-ass phone - because it's $5 from China"? Kinda feels like that just screams data-stealing, regardless of where it was made.
- mlsu 9mo agoUntil recently, if you offered a pump that _could_ be controlled by another device (such as a phone) you would have to offer your own "controller" device, even if 99.9% of your customers have a phone already. So, this companion device is kind of a thing that Insulet had to release. You'll see this with CGM's too -- there's a small companion device sold with the Dexcom G7 (the "controller"), even though everyone just uses their phone. This is kind of a regulatory quirk; basically from the FDA's point of view you had to have a complete standalone system, that did not include the phone, in order to be able to prescribe it. I think they do not require companion devices any more, it's OK to release something that requires the user to have a phone.
- martin_bech 9mo agoIts also for security.. outside the US, you still cant use a regular phone with the omnipod.
- lacoolj 9mo agoSo essentially, it's like this? "we plan on users having a phone to connect to it and use primarily. FDA requires a primary/backup. well it's already phone-controlled, go find a phone that works with it. needs to be cheap, cuz no one will really use it anyway" That makes a little more sense. I was imagining the development process involving both devices, rather than one device first, then determining what the second would be later. Thanks for the insight!
- martin_bech 9mo agoSecurity… The PDM is walled off completely, it cant install apps, its not on wifi, you cant change any settings. The issue is that a PDM technically could easily kill you, by giving you a lethal dose of insulin. Funny thing is that the newer Omnipod 5 from the same company works with regular phones now, but only in th US.
- pvtmert 9mo agoIf they built the kernel directly from tree, just pointing out the correct https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin... should be enough...
- cxr 9mo agoSince a company building it themselves hasn't gotten it in the form of a binary from someone else that they're just passing along to you and their use is commercial, they don't satisfy either condition of GPLv2 3(c), but they'd need to satisfy both in order to be able to exercise that option.
- HackerThemAll 9mo ago[flagged]
- RobotToaster 9mo agoSome of us just prefer the old version, so when we copy the link from our URL bar it's to the old version.
- GaryBluto 9mo agoWhy would you come to that conclusion instead of the obvious one being that the kind of people to use Hacker News are the same kind to prefer old Reddit?
- viccis 9mo agoNo
- billforsternz 9mo agoI recall idly looking through the manual of our Bosch dishwasher when it was delivered and seeing that they offered to share GPL'ed source code from the machine's embedded guts. I thought to myself, "that's kind of interesting, I'll take them up on that". So I emailed the address they provided for this purpose. I got an auto email back saying, effectively, "No. You're not an authorised person, we don't recognise your email address, we don't know who you are, we're not going to talk to you." Oh well. Big Corp doing what Big Corps do. Paying lip service to legal requirements, but reluctantly and with barriers that would no doubt take a lot of time and money to even try and break down.
- billforsternz 9mo agoI was troubled by my own comment. How exactly did Bosch handle this? I went back and checked and in fact the rejection email came from their email server, it was an "access denied" type email that I originally misinterpreted as a "you don't have access" type message leaving me annoyed but really I took away and remembered a wrong impression. Looking more carefully, the message doesn't mean anything subtle, it just means the email address (oss-request@bshg.com for the record) doesn't exist. Which is bad, but not nearly as bad as I portrayed it above. Apologies (for the record) to Bosch.
- piekvorst 9mo ago> This honestly disgusts me. GPL violations are already bad on their own, but on a medical device? That me, and thousands of people rely on to stay alive? Disgusting is not respecting the producers who put together the device that wouldn’t exist otherwise, leaving thousands of people in pain or death.
- f1shy 9mo agoIt shocks me how much comments, here in HACKER news, are something like: "Why do you want the source code?! leave it alone! Don't touch it, is unsafe! Big Pharma companies know much better than you what they do!" REALLY?! REALLY?! I'm not saying, go changing the SW like crazy. Is clear it can kill you. But this "anybody who is not a mega pharma company is absolutely unable to do anything right, you will absolutely kill yourself if you look at the code" that is just... idk... so low. It may be named hacker news, but boy, many people here are not remotely near what I would call a hacker...
- Dilettante_ 9mo ago"Agency is dangerous, please take away my(and by extension, everyone's) agency to hurt myself!" is a sentiment that's somehow gained a lot of traction everywhere. The People yearn for the accountability sink.
- voidpointer 9mo agoWhy is this relevant for understanding how the IP works or even tweaking it? Whatever is relevant for that matter will most certainly not be a modification to the Linux kernel that the android system is running. It will not fall under the GPL that the kernel is licensed under. Can someone explain why this dispute is worth having beyond a theoretical legal debate on whether they should hand out the particular source tree from which their kernel was built (if they even built it)?
- abigail95 9mo agoI'm sorry you didn't get a response yet. I'm not a lawyer and have no legal training but it seems to boil down to this: It's part of the debate of whether (1) GPL is a contract, (2) GPL can be enforced by non-parties, (3) How Fair Use applies, (4) Methods to bully/shame companies to give up source code ...? (5) Who the actual parties involved are if the actual rights holder (Linux Kernel) tries to sue someone. (First Sale doctrine might apply).
- esoterae 9mo agoWhat a remarkable stalking horse to try and kneecap right-to-repair by arguing "Please, think of the chil^H^H^H^Hhackers!" You wouldn't download a CAR, would you? You wouldn't hack your own INSULIN pump, would you? Face it: If it's GPL and vulnerable to interference, responsibility is squarely on the manufacturer and the fastest death-free way to prove it. If it's GPL and modified by the owner, fuck off.
- randyrand 9mo agoCopyright is only as good as your enforcement of it. Seems like this company already understands enforcement is crap.