Live data from Hacker News

License update

whispersystems.org

51–60 of 71 posts

Re: License update

#51
post #9

Earlier quoted context omitted.

The GPL is an amazing license to gag developers while looking like a good person in the process. Not saying that is happening here but I have seen this before where questionable motivations where the driving force behind the license choice.

The GPL is an amazing license to prevent devs from profiting off others' work without also providing access to their own. Some might call that a "gag" because they're prevented from using the code without opening their own code as well, so it's closed to them for all practical purposes. Is that the kind of gag that you're talking about, or did you mean something different?

Reminds me of a /. sig, with which I agreed very much (paraphrased):

  If you don't like my software licensed under the GPL write your own damn software.

Re: License update

#52

Earlier quoted context omitted.

"You know full well that it's illegal to use systems without authorisation. In the US, it's called the Computer Fraud and Abuse Act and they'd be committing a criminal offense, with severe penalties, if they did (and government could prosecute with or without OWS consent, as AaronSw experienced). There's also an open ended civil claim you'd now have against them. So whether express or implied, the project from then o…

I think this guy said it best: https://twitter.com/LauriLoveX/status/733137222539567106 i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. It's not like LibreSignal were doing anything particularly different to Desktop. L…

> i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms.

What in the world do you think our motivation is, then? We're not a business, it's not like we're doing all of this to capture revenue. We could all be making orders of magnitude more working elsewhere. We're doing this because we believe it's the most effective way to make private communication ubiquitous, and it's working.

> How many Signal users don't have GCM or Play Store? 1%? Hardly an extreme server load burden. More so, it would have attracted code contributions to further improve Signal. Equating THAT with assault as you have, is rather fkng melodramatic.

What code contributions? If this is something you want to see in Signal, sure, submit a clean well-written PR and stick around to maintain it. The only contributions we've seen from this particular community haven't even begun to pass code review.

> Oh, wait, people are taking liberties and entitlements? Well what the hell do you think you're doing by using the GPL in the first place? What was the spirit and intent of the authors who wrote it? Do you think THAT is being respected?

Exactly, we make our code available under the GPL. That entitles you to use the code for whatever you would like under the terms of the license. It does not entitle you to use our service for your product, or to use our name for your product.

> Quite simply, don't give people nasty lock-in surprises. If you intend to be a closed, tightly-controlled cathedral of non-optional dependencies on large swathes of commercial mystery meat blobs - then just say so in the first place. If you start off with non-commercial protocols like SMS, then switch to GCM, plus have federation clearly in your plan, until you're big enough you don't have to care and can rip it - then give people an out that doesn't involve losing their whole network.

I think I've been pretty consistent in my position from the beginning. I've been saying the same things over and over at least since #127, which was early 2013. It's true that we wanted to pursue federation, and we did. But when we tried it with Cyanogen, it was a total nightmare that probably set us back a year in development time. So we've learned from our mistakes, which I think is a good thing. We'd all be better off if projects like XMPP had also learned from their mistakes.

> Whether you like it or not, a big part of the reason Signal attained the critical mass of users necessary to take it to the next level, was the promotion and backing of the FOSS community.

I don't know what you consider "the FOSS community," but I think of them as being the same people who have been sending me a torrent of verbal abuse, legal threats, and even death threats pretty much non-stop over the past three years. At no point have I wanted any part of that.

> The attack on open protocols, cooperation, standards and community is hence the most disappointing part. We wouldn't even be having this conversation, if we weren't here standing on the shoulders of giants of open protocols from IETF, W3C, etc. Signal's contribution was respected as one of those, until it transformed (or revealed?) itself as a closed monopoly.

Plenty of people have used the Signal source to build their own projects (some even in "the FOSS community" like SMSSecure), so I don't know how you can say it's closed. Plenty of other people have also come to our project with an understanding of our development goals, and have helped to contribute to making Signal something better. A very small vocal minority of FOSS moralists have decided that we should have to do whatever they want if they scream loudly enough, and have contributed very little of anything but verbal abuse.

Re: License update

#53
post #47
post #20

Earlier quoted context omitted.

> Given OWS's worries about federation and shared standards standing in the way of progress, they might want to avoid third party access simply because it might stop them from changing the server interface. Totally. Client interoperability as well. For us, the problem is that when a 3rd party client breaks compatibility, that doesn't just affect the users of those 3rd party clients, but the normal Signal users who co…

> When normal Signal users try to call LibreSignal users, it just doesn't work. Wouldn't it be possible to give better feedback to the caller in this case, such as the name of the client the callee uses? I don't use Signal, so I may be missing something here.

Probably, but most people aren't going to understand that LibreSignal is different from Signal. We could try to make things work differently for users calling LibreSignal, but that sets us on a path of having to constantly account for all the various 3rd party clients and their various stages of development or support, which as a team of two developers we unfortunately don't have the resources for.

Re: License update

#54

Earlier quoted context omitted.

Come on @moxie, you didn't just say you'd prefer them not to, you expressly forbid it: "I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run." ( https://github.com/LibreSignal/LibreSignal/issues/37#issueco…

Regarding entitlement, it's not just an advertising company the 'product' is tied to. Google is of course one of the most aggressive global profit-shifters for tax 'minimisation'. I would prefer to call it avoidance, as I can't see any other reason for it, but I don't have pockets deep enough for the legal defense to use a word like that (or evasion).

I wonder who voted this down. I didn't know Google tax lawyers hung out on Hacker News. PR bot?

http://www.taxjustice.net/tag/google/

Re: License update

#55
post #39

Earlier quoted context omitted.

Where does Google state that? This meme keeps going around that the Android store is GPL compatible. But where is the actual license text that allows this, or at least how does the situation differ from that with iOS? I checked the current Google Play Terms of Service and the iTunes Terms and Conditions. The two were alike in several respects: - They had no blanket exception or deference I could find to third party a…

Google Play ToS: https://www.google.com/mobile/android/market-tos.html > 3.8: You agree that Google and/or third parties own all right [...]. You agree that you will not, and will not allow any third party to, (i) copy, sell, license, distribute, transfer, modify, adapt, translate, prepare derivative works from, decompile, reverse engineer, disassemble or otherwise attempt to derive source code from the Products, unl…

> Google Play ToS: https://www.google.com/mobile/android/market-tos.html

[..]

> And primarily 4.2, which you already found: In the event of a conflict between the Terms and any such licenses, the open source software licenses shall prevail with respect to those components.

No, I didn't find that, I found a similar clause in the overall Google ToS which, as I said, didn't seem like it would be applicable to third party applications. I see, this is what you were referring to. 4.2 would definitely qualify as the kind of blanket exemption I was looking for - if it is actually in effect.

Interesting. Your first link is not the Google Play ToS; it's your second link which calls itself the "Google Play Terms of Service", while your first link is the "Android Market Terms of Service", and does not contain the text "Google Play". But "Android Market" is a dead brand. And a relevant-looking page on android.com contains links to the Google Play ToS and other agreements, but not your Android Market ToS:

https://www.android.com/market/terms.html

Plus, the Android Market ToS says ©2011 at the bottom. Combining those indications, I think that despite being still up on www.google.com, it's outdated and no longer in effect.

I suppose that the failure of the new ToS to include similar language is probably a mistake, as is the fact that the Play ToS contains so many terms (like the stream ripping clause I quoted) that seem like they're intended for media rather than apps, but have no explicit limitation to the former. But that doesn't change the fact that the ToS is what it is, and has been for years, yet people still upload GPL stuff.

Also, if Google were to fix this it wouldn't just be a matter of adding the clause back. As I mentioned, from what I can tell (not an Android user myself), Google Play encrypts APKs at rest as a DRM measure; since modifying and redistributing them would require cracking the encryption, the Play ToS's anti-DRM-circumvention clause is presumably an "additional restriction" from the GPL's point of view. (If we ignore the who-contracts-with-whom question I raised, at any rate.) Giving the GPL priority prevents incompatibility, but Google presumably wouldn't want there to be a loophole where crackers could legally reverse engineer the DRM that applies to all apps by claiming to do it for the purpose of distributing a GPL app. This wasn't an issue in 2011 because the encryption feature hadn't been released yet; the Market ToS has an anti-circumvention clause too, but if there is no actual DRM to circumvent, there's no issue.

Of course, there is a solution: Google could just allow developers to turn off DRM on a per-app basis. But they'd have to care enough to implement that.

Which is essentially the same problem as with Apple. I said that Google's and Apple's ToSes were alike in enforcing random usage rules on apps with no exceptions, but there's a difference in quantity: since Apple's has separate sections for iTunes proper and the App Store, it doesn't have the same kinds of probably-not-intended-to-apply rules as Google's. In fact, aside from DRM clauses, the only restrictions in Apple's ToS that apply to third-party apps distributed with their own ToS are four paragraphs of "APP STORE AND APP STORE FOR APPLE TV PRODUCT USAGE RULES", of which two are a prohibition on using the same iTunes account on multiple commercial or multi-user devices, and the other two are essentially a description of DRM limitations. If Apple wanted to properly support GPL on the store, it would have to add an option for developers to disable DRM on their apps, same as Google, but then legally speaking it wouldn't need to add any dangerous-seeming blanket exception clause; it would just need to add an exception to those four paragraphs. Again, a matter of caring.

Historically, Google has cared a lot more about open source and particularly the GPL while Apple has kind of turned up its nose - but then, historically, Apple was under different management than it is today. Maybe I should try filing a Radar.

Re: License update

#56
post #28

Earlier quoted context omitted.

> Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Olm/Megolm is not Signal Protocol. It is an entirely different protocol that has made different choices, and those choices have received less study and scrutiny. It hasn't been deployed anywhere that I know of. It's fine if you want to explore those choices, but I would caution against c…

Come on @moxie, you didn't just say you'd prefer them not to, you expressly forbid it: "I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run." ( https://github.com/LibreSignal/LibreSignal/issues/37#issueco…

> "I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run."

Yes, that is what I said, after they explicitly asked "Let's ask @moxie0 if he is OK with LibreSignal using OWS servers."

They asked, "are you OK with this," and I responded "I'm not OK with this." I never took any action at all, just gave them my opinion when they asked for it.

If you think it's reasonable to go around telling people that I "threatened legal action" to LibreSignal based on that exchange, I don't know how you expect me to take anything you say seriously.

Re: License update

#57
post #8

Earlier quoted context omitted.

Tough crowd! That's what we used to do, but some extremely vocal people weren't satisfied, so we've done this to integrate our intentions into the license itself.

Was this lawyered? Because the clause reads to me like Programmer Law. > Provided that you are otherwise in compliance with the GPLv3... [we] also grants you the additional permission to convey through the Apple App Store non-source executable versions of the Program as incorporated into each applicable covered work as Executable Versions only under the Mozilla Public License version 2.0 1. The phrase "only under the…

Yes, of course, we had a lawyer write this.

Re: License update

#58
post #52

Earlier quoted context omitted.

I think this guy said it best: https://twitter.com/LauriLoveX/status/733137222539567106 i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. It's not like LibreSignal were doing anything particularly different to Desktop. L…

> i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. What in the world do you think our motivation is, then? We're not a business, it's not like we're doing all of this to capture revenue. We could all be making orders of…

> What in the world do you think our motivation is, then?

I didn't have much doubt before. But once you double-down on technical strategies that entrench concentrated power of Google, Apple, etc and leave users without open source options, I have to start to wonder.

> What code contributions?

I guess we'll never know. I think more could have been done to bring them back in though. There was obviously significant interest in LibreSignal for a reason and the community sure looked big enough to curate a PR between them. I'm pretty sure that the only reason they'd have given a different name to the fork (which might have evolved into a solid PR), was that they'd been told blanket that FDroid was never going to happen and hard Google dependencies would continue to be baked in.

> It does not entitle you to use our service for your product, or to use our name for your product.

Mate, you've been spending too much time with corporate lawyers. Take a breath. It's not a "product". In the days that GPL was written, operating as a closed service wasn't something the founders had even contemplated. It just wasn't the done thing.

> We'd all be better off if projects like XMPP had also learned from their mistakes.

The core issue with XMPP was that MSN Messenger, ICQ, etc. had deeper pockets. It wasn't fundamental technical flaws in open protocols. Sure, protocols don't always get it right the first time. I don't think HTTP would be better today though if we had to use 10 different browsers from 10 different vendors with pages that won't link together. Yes, XMPP had some issues (chief of which for mobile, was battery drain resolved by push). Let's hope Matrix gets traction.

> I don't know what you consider "the FOSS community," but I think of them as being the same people who have been sending me a torrent of verbal abuse, legal threats, and even death threats pretty much non-stop over the past three years. At no point have I wanted any part of that.

Well that's pretty sad. The BSD kernel of your iPhone, the Linux kernel of your Google devices and the GNU user space you enjoy on Linux are what the FOSS community have built. It just sounds like you're painting the whole community as abusive now.

Death threats etc should be reported to police. Likewise the community shouldn't be tolerating abuse. My condolences that you've had to go through that @moxie. It's bullshit and behaviours like that help no one.

No doubt, it's been traumatic and stressful, so I want to cut you a lot of slack. This in no way excuses their behaviour and I've never seen you engage in abuse, but mate (and recognising we're all human), your tone hasn't always come across as encouraging either.

> Plenty of people have used the Signal source to build their own projects (some even in "the FOSS community" like SMSSecure), so I don't know how you can say it's closed. Plenty of other people have also come to our project with an understanding of our development goals, and have helped to contribute to making Signal something better. A very small vocal minority of FOSS moralists have decided that we should have to do whatever they want if they scream loudly enough, and have contributed very little of anything but verbal abuse.

It sounds like it's always just going to be a protocol issue. Signal is a closed service and a closed network, unless you're using Signal's App. The GPL for the app in that context seems fairly meaningless in practical terms.

To anyone looking on, from the outside, it looks like OWS has taken a giant flip from their previous position: https://twitter.com/lyon01_david/status/733096322304249856. Maybe you need to work on your PR. When people see companies like Facebook given rights, but open source are not, it naturally raises eyebrows. Good on you for opening the iOS libraries now, but maybe it should just have been clearly stated (or repeated when necessary) that it was your intention all along, otherwise it really does give the impression it was only due to 'complaints'.

The fact that you keep painting other projects as "products" and legitimate security concerns as mere 'FOSS moralism', does make people really ponder what the development goals are.

Re: License update

#59
post #52

Earlier quoted context omitted.

I think this guy said it best: https://twitter.com/LauriLoveX/status/733137222539567106 i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. It's not like LibreSignal were doing anything particularly different to Desktop. L…

> i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. What in the world do you think our motivation is, then? We're not a business, it's not like we're doing all of this to capture revenue. We could all be making orders of…

p.s. 'FOSS moralism' is the only reason that you have other development targets than just Blackberry & Windows CE to work with today.

Re: License update

#60

Earlier quoted context omitted.

"You know full well that it's illegal to use systems without authorisation. In the US, it's called the Computer Fraud and Abuse Act and they'd be committing a criminal offense, with severe penalties, if they did (and government could prosecute with or without OWS consent, as AaronSw experienced). There's also an open ended civil claim you'd now have against them. So whether express or implied, the project from then o…

I think this guy said it best: https://twitter.com/LauriLoveX/status/733137222539567106 i.e. Don't pretend to be "Open", altruistic, acting only in users security interests, selling benefits of open source, taking public interest donations, contributions, etc - and then prevent users from actually exercising simple neighborly freedoms. It's not like LibreSignal were doing anything particularly different to Desktop. L…

I never equated anything with assault. I in fact presented using the term "assault" as being melodramatic and an overreaction, just like calling upon the Computer Fraud and Abuse Act in this case is being melodramatic and an overreaction, and which Moxie has never done.
Post reply on HN