Live data from Hacker News

Ask HN: Huge enterprise customer wants to see our source code

news.ycombinator.com

241–250 of 293 posts

Re: Ask HN: Huge enterprise customer wants to see our source code

#241
post #90

Earlier quoted context omitted.

What exactly is the potential liability for a GPL violation? I've gone 12 rounds with IP lawyers over these theoretical violations (static vs dynamic links). But I found it odd that I could never find a single case of significant liability due to infringement. The nature of damages is unclear and the landscape of counter-parties (with an incentive to sue) is amorphous. It seemed like worst-case, a proven infringer ju…

Not trying to troll here... The biggest violation might simply be the size of the attorney bills related to using GPL licensed dependencies in your code. There's simply no great way that I've found to get attorneys to give you a checklist of how to comply with licenses that aren't on a short list of reasonably well understood licenses. Saying "no GPL" is easier in many cases for practical reasons that kind of stink.…

Fair point but doesn't this run directly counter to the trend of startups leveraging an increasing amount of open source code?

Re: Ask HN: Huge enterprise customer wants to see our source code

#242
1) yes but was more than algorithms 2) If you're not realistic and being stupid with yourself and look at the amount of money that the industry has there's ($50bn) no legitimate way if I were to see your code would not steal it because I have "UNLIMITED RESOURCES". I'll first try using scare tactics of pulling out of the contract then if it's not good and I really want it I'll try putting you in a binding contract and litigated out of court and there by the time you realize all the shit that's happened to you you'll be with your head stuck up in to you know where writing a pity blog post. Whining about how the deal of a lifetime got away. 3) If a lawyer tells you that they can find a way to bind them in the contract they must have actual software experience must be experienced for 10+ years and must know IP patent law. (Last I checked you're not KKR). "Yes I'm No I wont accept work" If you don't want to believe what I'm telling you just look at the cases Java oracle case comes to mind so does the android source code and so on. Plenty of others.

SOLUTION:

1) DON'T BE A CUCKMINDED i.e. not Antifragile.

2) There's five of you so some of you might agree some of you might not you have to be joint in your decision and equally around because if you're not that's a weak link. THE ANSWER MUST BE NO AND SAID ASTUTELY. "NO" COMING FROM ALL OF YOU IN DIFFERENT WAYS THAT YOU'RE ABLE TO COMMUNICATE. Where's case scenario if the industry has 50 billion I don't think you should have a hard time finding another potential even bigger customer in this field. (Speculation You're in the insurance business)

Other legal criteria: They may try coercing you as far as compliance and legal statutory, regulatory factors are concerned to say that they want to see the source code. THIS IS ALL BULLSHIT TACTICS IT REALLY DOESN'T MATTER IF THEY TELL YOU SOMETHING ABOUT RACE AND DEMOGRAPHICS THAT JUST MEANS YOU HAVE A REALLY DUMB LAWYER ALL THESE ACCUSATIONS ARE BEATABLE DEPENDING ON PLAUSIBLE DENIABILITY AND THE WAY THAT THE ALGORITHM HANDLE IT AT THE TIME BESIDES NO ONE UNDERSTANDS IT. (Remember if it's not inherently and deliberately made by you & the "can pewter" made the decision i.e. the algorithm Made that presumption. there's really not shit that they could do to you).

In that case you can find a third-party which you should do a lot of homework on unbiased arbitrator (NO BIG FIRM WHITE SHOEBOX PROFESSIONAL SERVICE THAT THEY WOULD QUERY WHATEVER CODE THEY NEED THAT'S JUST A FANCY WAY OF HAVING SOMEONE ELSE DO THE STEALING FOR THEM)

To have a look at.

By the way you should put this in the contract if it ever arises and by the size of the company that you're referring to it sounds like that would be something I would do.

If it's your crown jewel protect it simple.

OPEN SOURCE LICENSE OR NOT THE PROBLEM WITH A LOT OF START UPS NOWADAYS IS THEY TRY TO BALANCE MORALITY WITH BUSINESS WELCOME TO THE NEW WORLD. Just because they make you feel bad doesn't mean that it's really bad.

Historical relevance: Look at how the shell company was formed in order to compete with standard oil and how Rockefellers ROSE there was no sharing going on.

PS your welcome, pass it on.

And the only thing you need to know about the law is if I have enough resources the law doesn't matter and that's a fact in this country particularly when it comes to huge sums of money & tech. It's nascent and it's not really understood by a bunch of 80-year-old judges. Even the young ones don't.

With regards to the following comments please save that shit for your grandma I really don't care. I don't even want an opinion. And No I'm not gonna be answering to this comment.

GodSpeed

ProTip

All five must be on board with this decision

Re: Ask HN: Huge enterprise customer wants to see our source code

#243
post #56

I think this is a signal that you're probably underpriced by a factor of 2X to 10X. So this is a sales objection. With regards to that justification, I'd want to know a) who in the business is generating it and b) what they expect to feed your answer into. Is this just somebody who wanted to sound smart in a meeting? Then they don't need your source code; they need ~5 nice PowerPoint slides and you're done. I'd be po…

I’m a security engineer at a large financial organization and we audit all 3rd party products most of these audits include a code review. This is a compliance process and it’s controlled by the SEC. All of your suggestions would make the company that I at least work for to simply walk away from table. This has happened more than once and all of our contracts contain a clause that if the application does not get a pas…

There is no compliance rule put out by the SEC that requires (or even suggests) source code review.

Re: Ask HN: Huge enterprise customer wants to see our source code

#244
post #56

I think this is a signal that you're probably underpriced by a factor of 2X to 10X. So this is a sales objection. With regards to that justification, I'd want to know a) who in the business is generating it and b) what they expect to feed your answer into. Is this just somebody who wanted to sound smart in a meeting? Then they don't need your source code; they need ~5 nice PowerPoint slides and you're done. I'd be po…

I’m a security engineer at a large financial organization and we audit all 3rd party products most of these audits include a code review. This is a compliance process and it’s controlled by the SEC. All of your suggestions would make the company that I at least work for to simply walk away from table. This has happened more than once and all of our contracts contain a clause that if the application does not get a pas…

[deleted]

Re: Ask HN: Huge enterprise customer wants to see our source code

#245

Earlier quoted context omitted.

That is completely different. You don't go to jail for a license violation.

Honest question: Is a license violation not equivalent to unlicensed use of code? I mean, if you don't meet the terms of a license, you're not eligible to use the code under that license. That means you have no license to the code, and therefore are in breach of copyright, no? How is that different from just using someone else's code outright - you're breaching copyright and you're not licensed, no?

Well, the difference in that case is that it isn't license violation at all. This case is a trade secret violation. Since Goldman Sachs never released the source code, it is by definition a trade secret which Sergey Aleynikov was not allowed to release or utilize outside of his job at Goldman Sachs.

If Goldman Sachs ever officially released the software it could be a copyright or license violation but this isn't the case.

Re: Ask HN: Huge enterprise customer wants to see our source code

#246

I have run into requests like these twice. First time the big gorilla company liked our product and they wanted it for a core process of their business. They knew we were a small startup and they wanted to be sure we were doing things properly. So they asked us for a full audit of the code by a third party company. This external company was a big consultancy and auditing company and they run something like a 'due dil…

> this company did not want to play fair and it was clear that they wanted to copy Were there other signs they wanted to copy besides "asked for the source code and they wanted it all the time they needed to study it by themselves"? I'm curious about the red flags to look out for when negotiating such deals

First company was very clear about its concerns and came with a list of what they wanted to know. Something they wanted to see with their own eyes it was no violation of any license, specially GPL.

The second company (Telco) was the opposite. The requirements were vague and its R&D team felt attacked because a local division of the company in UK chose us versus them. So I listed what they could see of our code and how (white room, our computers, no network, partnering with us all the time...) and I asked for a scoring method based on their requirements to know if we passed or not the test. They rejected all our conditions. They wanted the code to give us the “blessing”.

The funny thing about this Telco is the UK branch signed the deal no matter what R&D said. As I said R&D tried to hire our Team. They failed. Then they spent 2 years developing a copycat of our solution to replace us in UK. And when they finally were ready, the cost and impact of transition to their solution was too high, and the copycat solution was abandoned.

How to know if are good or bad guys? It’s hard. When both parts want to sign a deal everybody gets involved and pushes towards the goal. Also, connect to companies that did that before to tell you their story. For example, the Telco had an “extractive” reputation and people warned me.

Re: Ask HN: Huge enterprise customer wants to see our source code

#247

Earlier quoted context omitted.

How specifically did it signal to you that they're underpriced? Because the poster is surprised by this requirement and doesn't have standardized answers to it yet. In poker, there is this thing called "assigning a range" to someone based on their actions. You can't see their cards, but their actions might give you signal where you could say "Hmm, playing like they have a middle pocket pair and not totally air nor a…

At the flea market they call it "looking at the customer's shoes."

Priceless!

Re: Ask HN: Huge enterprise customer wants to see our source code

#248
post #3

This is a complete no-no. There really is no justification for this whatsoever. What does "cover their bases" mean? As them to explain what they are trying to achieve and find other ways to assuage their concerns. The only legitimate thing is to have something in case you fail and they have "banked" on you. There is a legit way to solve that. basically if they want that tell them they should pay for an Escrow service…

I work for an enterprise company and we demand the source code for machine learning models from vendors all the time. This isn't like asking for the code to Excel. It's a model derived from our data that has likely no use for anyone but us and is highly susceptible to misunderstandings of the data. We absolutely need to verify your work. Models are the output of the process. It's like going to graphic designer for wo…

I think you make an interesting point, ml models and algorithms are two different things.

I also think it's reasonable to ask for a model so you can test and validate it yourself.

Re: Ask HN: Huge enterprise customer wants to see our source code

#249
post #85

Earlier quoted context omitted.

I've done this too. The question is usually a matter of compliance more than anything else. They want to check the licenses of any included packages, makes sure there's no encryption stuff that can't leave the USA, etc. Doing what OP described is great: it lets their folks do the audit with no risk of you loosing "ownership". It shows you are both a good partner and value what you do.

License compliance is incredibly important and unfortunately overlooked by many smaller firms. The potential liability to a GPL or other violation is just not worth it. Anecdote: We have released code under the Apache 2 License (our biggest project by far is https://github.com/sheetjs/js-xlsx ) and we've been roped into negotiations because some companies tried to take shortcuts by copying our code without proper att…

I don't understand how license compliance matters here. Why does the big customer care about whether the seller has violated licenses? The seller would be the one in trouble, not the customer.

Re: Ask HN: Huge enterprise customer wants to see our source code

#250
post #241

Earlier quoted context omitted.

Not trying to troll here... The biggest violation might simply be the size of the attorney bills related to using GPL licensed dependencies in your code. There's simply no great way that I've found to get attorneys to give you a checklist of how to comply with licenses that aren't on a short list of reasonably well understood licenses. Saying "no GPL" is easier in many cases for practical reasons that kind of stink.…

Fair point but doesn't this run directly counter to the trend of startups leveraging an increasing amount of open source code?

In my experience, having a good ratio of responsible, experienced developers on the team (one of those may do it, for a small startup) is often enough to keep an eye on it, and a lot of startups get quite far while avoiding the most risky (for them) licenses. If this is reasonably gated while starting a project, or whenever you want to add new dependencies, it's well possible to stay on course.
Post reply on HN