9 ms·
Ubiquiti Networks is creatively violating the GPL
- voltagex_ 12y agoSimilar shennanigans have happened with just about every router, AP and modem manufacturer. They just don't care. I'm not sure why u-boot always seems to be the sticking point but heaven forbid if you actually want to try bringing your board up from scratch.
- java-man 12y agoWho is going to take them to court? Who can take them to court?
- davexunit 12y agoThe page says that a u-boot copyright holder asked for source and got nothing. Perhaps they could bring this case to the Software Freedom Conservancy and file a lawsuit if necessary?
- java-man 12y agoMounting a legal offense is expensive. The current system favors battles between corporate giants. It's not often that a lone software engineer wins in court.
- pthreads 12y agoCan the copyright holder take them to small claims court? He/she ought to be able to file one without needing a lawyer and for minimal costs. At the very least the court may force them to release the source code.
- java-man 12y agoThis might actually work. Even though the potential monetary loss for the offender is munite, the fact of legal loss may cause the change in internal policy. Any public shaming would help as well.
- gnu8 12y agoYou could take their customers to small claims court one by one, they'd each be on the hook for the purchase price of their access points. This would go a long way toward generating publicity and forcing compliance.
- java-man 12y agoHas it worked in the past? Is this a valid approach? I don't think the customers are the guilty party here.
- gnu8 12y agoedit: all of the above is incorrect and I retract this. If Ubiquiti is in breach of the GPL then their customers cannot receive a license to the infringing work by Ubiquiti distributing it to them, so they're infringing too. I don't think this has been done before. It would definitely chill the acceptance of GPL software in general. edit: all of the above is incorrect and I retract this.
- trothamel 12y agoDo the customers need a license? I don't think so - the GPL covers distribution, not use.
- logn 12y agoBut you're getting copyrighted material in violation of the copyright. No different from downloading a song from bit-torrent.
- trothamel 12y agoPer GPL2, clause 4: 4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided under this License. Any attempt otherwise to copy, modify, sublicense or distribute the Program is void, and will automatically terminate your rights under this License. However, parties who have received copies, or rights, from you under this License will not have their licenses terminated so long as such parties remain in full compliance. As I read that, as long as you don't further redistribute, you should be good.
- btilly 12y agoI am not a lawyer, but I do know that in US law statutory damages are $750 to $30,000 at the discretion of the court. Per infringement. Willful infringement increases that maximum limit, up to a max of $150,000. Multiply by the number of infringements here, and the history of not complying with the license despite many opportunities to do so, and there is no way that this belongs in a court whose maximum potential penalty is $10,000.
- rbobby 12y agoDing ding ding... all the uboot copyright owner needs is a desire to to sue and a lawyer that would take the case on a contingency basis. The company does about 600 million in revenue... so there's a lot of money there.
- interdrift 12y agoThey seem to be awfully out of structure judging by the e-mails of the support team for a company that does 600M.
- rbobby 12y agoIt's a crazy amount of liability. If a company doesn't comply with the GPL them they don't have a license to the code, and without permission from the copyright owner they're at risk of being found to be infringing. And worse, this risk doesn't go away if the company corrects the behavior (i.e. the period of time where they weren't in compliance with the GPL doesn't just disappear because they are _now_ in compliance).
- martin1975 12y agoHe/she probably could. However this isn't some small claim - it's probably a very large claim, given UBNT's size. If they get wind of a single developer or a one man army lawyer launching these lawsuits, they will put up a fight and hope they will either settle or quit before they run out of money. Suing someone is expensive, even if your case is a winner from the outset. If there is one reason I'd ever consider becoming a lawyer w/my CS background, this would be it. I would set up some kind of a subscription model to which lone developers/copyright holders would pay my firm an ongoing subscription for as long as they wish, and in response get legal representation.
- roel_v 12y ago"If there is one reason I'd ever consider becoming a lawyer w/my CS background, this would be it." I am both and I have investigated this, and discussed partnering with firms etc. - I have looked at this seriously, and from many angles. There is no way this can be made viable. How much will an OS/single developer pay for this? 10$/month, max, the most motivated ones? OK great, after one year, they've paid for 30 mins hour of legal representation, not enough to read the first 2 emails that lay out the first issue they have (and those who pay 10$/month will find issues, they'll make a sport out of finding anything that remotely looks like they could get their money's worth). Furthermore, the added value of a CS background in the legal profession is tiny - as in 'worthless for all practical purposes'. At best, you'll be the Word and Excel wizard in the office - which is basically a career-limiter, rather than propellant. I can count on the fingers of one hand (even if I would have had a serious wood-chopping accident involving that hand) the top people in the legal profession (in my market) who get a real value from their technical background (the one I do know has been blogging for going on 20 years on the intersection of law and technology, so even there the advantage is indirect). Just saying - don't bother :)
- lazylizard 12y agowhy small claims or claims at all? why not just tell them to stop using u-boot? like..'your license is thusly revoked' or something?
- EvanAnderson 12y agoThis is disturbing. I've been recommending their gear for the last couple years. Now I'm wondering if that's such a great idea.
- jimrandomh 12y agoThe problem is almost certainly internal disorganization: the person who put together the shipping firmware either isn't hearing about the requests for source code, or has moved on to another company.
- JoshTriplett 12y agoThat's not an excuse; that's something you figure out before you ship a product.
- tbrownaw 12y agoIt's extra paperwork that is not needed unless you use GPL code. Idiosyncratic requirements are annoying.
- simoncion 12y agoI'm not sure what you're angling for with your anti-GPL comments in this thread, but all software licenses have requirements that are burdensome to one degree or another. Frankly, the paperwork required to keep track of installed instances of -say- volume licensed MSFT software is a fair bit more burdensome than procedures to handle source code requests for GPL'd code. Hell, you can automate both processes, but -in places that are like the dev shops that I've worked in- you're far more likely to automate the GPL compliance procedure. :)
- tbrownaw 12y agoMostly just thinking out loud (congratulations, you're a rubber duck). I think I heard something a while back, about Microsoft changing how they did volume licensing. Because it really was too much of a PITA, and they wanted to simplify things. I suppose one different would be what's required to get back into compliance one you inevitably stuff things up. In the one case, you have to probably pay (money is fungible) and/or remove things you have installed. In the other case, you have to find something you might not know where it is (if it even still exists) and provide it to the public (and be sure that doesn't violate an other licenses you have). ...I think I might be moving the goal posts a bit here, but that's what you get for being a rubber duck. ;) If you follow what's generally considered good development practices (automated builds, everything in version control, etc), GPL compliance should be dead simple. So congrats, it sounds like you work for people who don't have their heads up their asses. ...hey, maybe that would be a good basis if we ever did turn into a proper profession: version tracking and automated builds.
- notacoward 12y agoWorth remembering: under many other popular licenses, there would be no possibility whatsoever of legal action that leads to Ubiquiti releasing the full/proper source for what runs on their devices.
- kelnos 12y agoWell, duh... most popular licenses don't require modifiers to release full source. Which is fine if that's the author's choice.
- notacoward 12y ago"Well, duh." Thank you for reinforcing my point (elsewhere) about how the "gratuitous negativity" rule will never be used to do anything but reinforce the HN zeitgeist. I knew I wouldn't have to wait long for an example I could point to.
- zaroth 12y agoI personally consider the new rule an exhortation to down-vote more aggressively whatever gratneg we come across. As I like to say, there's a button for that! To respond to your original point, I don't get it. If you choose to release under a license which doesn't require releasing source of any mods, that's a perfectly reasonable choice. Why should there be a "possibility of legal action" against something which is explicitly allowed by the license?
- notacoward 12y ago"down-vote more aggressively " I can't (as an interlocutor), and I can see that nobody else has either. The prediction seems to have survived at least this one test. "If you choose to release under a license which doesn't require releasing source of any mods" ...and there's nothing wrong with that. I'm not saying non-copyleft licenses are bad. I don't believe that. Even if I did, I don't have time for another round of that debate. I'm just pointing out what the practical difference is. People who care about the security aspect of Ubiquiti's behavior, or about the lost potential to install an alternate OS on their hardware, should be aware that permissive licenses give them zero leverage toward affecting a remedy. Those people might want to consider software licensing as part of their router purchase decision, even if they don't like GPL for their own code.
- zobzu 12y agoSuch a classic. Unfortunately. And they probably have nothing to fear.
- AceJohnny2 12y agoIronic, considering Torvalds himself uses their zero-handoff wifi access points: https://plus.google.com/+LinusTorvalds/posts/HQF92MY5y8o https://plus.google.com/+LinusTorvalds/posts/HQF92MY5y8o (and more amusingly, had to turn off the very feature he got them for because of a wireless scale... https://plus.google.com/+LinusTorvalds/posts/WppMs5XEa3X https://plus.google.com/+LinusTorvalds/posts/WppMs5XEa3X)
- drewcrawford 12y agoI'm puzzled that there is apparently a whole cottage industry that can protect the rights of indie photographers [0] but we cannot do the same for free software. The closest we come is like the SFLC, and they are really quite soft on infringers in most cases. I imagine that some of the puzzle is because DMCA is cheap and effective against websites moreso than against hardware manufacturers. Even so, Ubiquity Networks provides web downloads of their firmwares [1] so surely DMCA notices could at least impair their update distribution, which would annoy customers and put pressure on them that way. Meanwhile there is plenty of "purely web" software license violations. I know that many projects don't get the copyright registered, which puts them at some legal disadvantage. But it's cheap to do, it's something that developers can be educated about, and it is economical for lawyers to take those cases (if facts and registration are strong) on contingency. So I don't understand why there's not a little cottage industry for it like there is for the photographers. [0] https://www.imagerights.com https://www.imagerights.com [1] https://www.ubnt.com/download/ https://www.ubnt.com/download/
- lambda 12y agoIn part because the "cottage industry" for photographers rights is based on getting people to pay, while most free software authors aren't actually interested in being paid for it, they are just interested in keeping it free. When the focus is on getting paid, a cottage industry can form that is based off the revenue from extracting royalties, but getting injunctions that apply until someone comes in compliance with a license is expensive due to lawyers fees and court costs, without any revenue to offset it.
- drewcrawford 12y agoBut those are not mutually exclusive; they are complementary. It is not very effective to say "Um, stop being a violator pls." It is much more effective to say "Here is your invoice for being a violator, and don't let me catch you again."
- click170 12y agoNailed it. Which makes me wonder, perhaps in next iterations the GPL should include provisions stating that intentional infringement (perhaps defined as failure to comply after 1 year from date of the complaint) results in financial penalties, thus allowing a cottage industry to form. It could be argued that this would have a chilling effect on the adoption rate of FOSS software in corporations, but I would argue we may have already reached a critical mass where it's more costly to develop your own solution and I would point out that this only applies to modifications that you make to the source code before distributing the result. Anyone can still download and use the software without worry.
- feld 12y agoNever attribute to malice that which is adequately explained by stupidity. If you've ever used a Ubiquiti product you'd believe they're just stupid
- GabrielF00 12y agoReally? I haven't used Ubiquiti hardware in a few years, but my recollection was that their stuff was inexpensive, easy to set up, and very powerful. We used their Bullet and Nanostation line of products.
- feld 12y agoThe rule we developed at a previous job for doing upgrades on their products is to reboot twice to avoid bricking it. Yes, twice. Sometimes once isn't enough for an unknown reason. Also their web interface has terrible memory leaks which causes loads of other issues. Don't forget the management network interface that just stops being able to be pinged until you reboot. Have seen this on everything up to AirFibers.
- fapjacks 12y agoYeah, I like the hardware well enough, but the software is atrocious. It is ugly, slow, counterintuitive with settings in all sorts of strange places, and makes me feel insecure about my own wireless network. The hardware is alright, but it feels like really shoddy software engineering work whenever you need to interact with it.
- stsp 12y agoThey certainly do have quality issues. A friend of mine had to mod an M2 to make it work with PoE over long cables. http://hofmeyr.de/PoE%20power%20fix%20for%20NanoStationM2/ http://hofmeyr.de/PoE%20power%20fix%20for%20NanoStationM2/ The manufacturer obviously didn't test the hardware with 100m cable length.
- hwh 12y ago
- mightyhops 12y agoI contacted support@ubnt.com and info@ubnt.com about the issue and received a quick reply: Unfortunately we no longer offer support for our SDK, and I'm not able to divulge in the specific differences between airOS and openwrt. Also, we don't share u-boot GPL source. We used to in the past but not any more. This decision was taken keeping the security of the users in mind. I hope you understand. However, you can find the GPL archive for our devices from here: https://www.ubnt.com/download/ https://www.ubnt.com/download/ (Please refer the "GNU General Public License link" under the Firmware and Software section from the above link page provided). If you have any other questions, please let us know. Thanks! xxxx Ubiquiti Networks
- btilly 12y agoI hope you understand. Given that they are clearly in the wrong, it is not surprising that they are hoping for copyright holders to be understanding!
- striking 12y ago>This decision was taken keeping the security of the users in mind. I hope you understand. Funny, because this is the exact inverse of the situation. They introduce security bugs and then we are unable to fix them ourselves. They are legally required to provide the sources they use for u-boot.
- ploxiln 12y agoIt is funny... I get the feeling that they still give this response, because everyone who's gotten it doesn't know how to respond, it's so obviously wrong. They use a lot of open source software and make firmware updates and controller software readily available, so how could they not know that * The GPL's legal requirements come before your products needs, your users security or whatever. If you can't use GPL'd software, then don't. * open source software has always proven to be more secure, because relatively serious and obvious security bugs linger in closed source software for a long time. How can we know that your closed source software is better than history suggests (unless you release the source...) ridiculous. I kinda hope some of their engineers notice this on HN and can use evidence of "public" (engineer) sentiment to pressure the management
- naringas 12y agomaybe they have some compelling (and secret) reasons to introduce security vulneravitilites and close the source code...
- fapjacks 12y agoThis is what I'm thinking, as well. My spidey sense is tingling on this one.
- mrbig4545 12y agoit's more than I ever got out out Coolpad or Mediatek. i can't even find a valid email address for Coolpad to ask for android kernel source :(
- antocv 12y agoHuawei does the same. Phillips too, with their smart TVs running Linux and other FOSS. They just provide some vanilla random .tar.gz of "gpl source CODE" and thats it, not really the version thats running on the device or that was distributed by them. The actual binary, firmware, is encrypted too. 0 fucking freedom for a normal user in age of FOS software all around us. It would have been better with proprietary software. Then I wouldnt have gotten pissed.
- mindslight 12y agoFranklin Wireless U770. Running a telnet daemon, I managed to get root through modding an update. FWIW, the default root password is 'frk770' and it appears to listen on the WAN interface in the default config. No idea what modifications the kernel has - I'm not too interested in customizing software running on pwnt Qualcomm chips, I just wanted a prompt. Sierra Wireless 803s - running Linux as far as I can tell (nmap -O, update files, GPL license text in manual). Once again there's not even really a website for the device, nevermind some token source tar. Haven't yet broken into this device, I'm assuming there's a JTAG on its 60 pin debug connector, but I need to try the easier route of hacking an update first. The theory goes that manufacturers should realize that obscuring their systems gives them no benefit (especially since they're able to put different copyrights on the parts they actually write eg the webuis), while opening them should give goodwill, but this has not played out in practice. Manufacturers clearly care about some aspects of licensing, given that they'll include license texts/notices/etc in the manual. We need a way of making the two line up. But the unfortunate reality is that we're on shaky ground. The rise of embedded devices with baked-in binaries has shifted the landscape. In this environment, BSD-style licenses fail Freedom 1 (https://www.gnu.org/philosophy/free-sw.html https://www.gnu.org/philosophy/free-sw.html). The Linux kernel is the main item that is infringed upon (presumably because its too complex for eg Google to reimplement as BSD like they did with the Android userland). And its developers have stubbornly stuck with the broken GPL2, making it so that even with perfect enforcement (which they also don't seem interested in), make && make install is not an achievable goal.
- mindslight 11y agoTypo: the U770 default root password is 'frk700' (in case anybody ends up here searching).
- william20111 12y agourghhh really. This has annoyed me, I have an edgerouter lite and its really good! But this is really shady stuff...
- tjakab 12y agoThe article doesn't mention if they've contacted the FSF about the violation. Looks like they may be able to provide some assistance, particularly if any of the code is directly copyrighted to the FSF. http://www.fsf.org/licensing/compliance http://www.fsf.org/licensing/compliance https://www.gnu.org/licenses/gpl-violation.html https://www.gnu.org/licenses/gpl-violation.html
- anonbanker 12y agoI'm of the opinion their firmware is real swiss-cheese'd, and they're not allowed to disclose the firmware and source modifications under EO12333 or other nonsense. Hence, if you had a ubiquity contract, and demanded GPL compliance, you could sue for quite a bit of money for selling you pirated software (GPL license is revoked when source is not provided), and they would settle, rather than violate national security.