Live data from Hacker News

The terms of the AGPL are pretty easy to comply with

drewdevault.com

151–160 of 341 posts

Re: The terms of the AGPL are pretty easy to comply with

#151
post #69

Earlier quoted context omitted.

The holy war could be avoided if Google simply paid authors of AGPL code they wanted to use instead of going on a tirade against the license. I think half the reason it exists is to make it deliberately risky for FAANGs etc. because they're exactly the ones who SHOULD be ponying up to support the open source ecosystem they rely upon.

Well, this is the heart of the issue. Chris DiBona has publicly stated that AGPL software just isn't valuable enough to care about. The authors of such software tend to overestimate its utility. https://www.theregister.com/2011/03/31/google_on_open_source...

If they don't want to use AGLP software anyway, then they have nothing to complain about.

Re: The terms of the AGPL are pretty easy to comply with

#152

After much consideration we finally released our core software ( https://github.com/kiprotect/kiprotect - a privacy & security engineering toolkit) under the AGPL. In the past we've released other software under more permissive licenses like the BSD-3 or MIT licenses, but we've decidedly picked the AGPL for our toolkit, for the following reasons: - We want to encourage people and organizations to use the software as…

> - We want to ensure that any extensions and modifications of the software (will make it back into the main software as open-source, so that everyone can benefit from them.

isn't that a contradiction with

> We offer dual-licensing by the way

since dual licensing requires every contributor to agree to a CLA and not merely contributing the code under the terms of the AGPL?

Re: The terms of the AGPL are pretty easy to comply with

#153
post #33

Earlier quoted context omitted.

I’ve taken AGPL through two FAANG reviews. Both arrived at the same very-much-not-FUD legal conclusion. Paragraph 1 of section 13 requires modifications to be disclosed and source code for them to be offered to remote users. The license uses the term of art Corresponding Source for this. Corresponding Source is defined in section 1 in a crystal clear way. Two separate teams of lawyers concluded that they could cohere…

Corresponding source has the exact same definition in GPLv3 and almost exactly the same in GPLv2, so all this "its completely untested" thing is completely disingenuous. Google uses Borg to control gplv3 code that they also distribute, so, exactly the same case and its complete BS you are spreading. Lawyers are actually pretty good at spreading FUD about GPL, they always have been.

AGPLv3 is exactly the same as GPLv3 except that it adds 1 paragraph. That paragraph has nothing to do with corresponding source or what a derivative is. Google ships distros with Gplv3 to customers GCP, so Borg and GCP stuff would be equally affected by the "risk to Borg" and other server side code, so, I don't believe that the claimed legal risk is real, just FUD.

Re: The terms of the AGPL are pretty easy to comply with

#154

Earlier quoted context omitted.

> because just looking looking at the performance stats from production services in R using an AGPL library could taint the source code of the service itself I think this is what is being referred to as "FUD". Anyone can go after you for some sort of supposed license issue, but at some point you need to consider that many of these are extremely far-fetched and serve only to quite literally add FUD around AGPL.

The true misrepresentation is: > Anyone can go after you for some sort of supposed license issue Suppose the software in question is MIT licensed. There are certain requirements, none of them involve users having to decide between releasing their source code or paying fees. Remedying most MIT project license violations usually involves adding a disclosure somewhere in the website. As a whole, for reasonably large com…

Well, that's simply because most MIT licensed projects don't choose to insist on the copyright infringement damages to which they're entitled with respect to past non-compliance. They could insist on statutory damages (assuming they've registered their copyright), or actual damages/profits of course, without offering the option to remedy past violations.

Most such rights holders simply don't do this as a practical matter given their own goals.

Re: The terms of the AGPL are pretty easy to comply with

#155

Hello, While I'm employed to develop an agpl software, and I fond of this license, it's clear that with the wrong actors it can be a threat to some businesses. I'll tell you a little story that happened around 10 years ago: I got a call from a representative of Oracle, he asked me if we where using MySQL, and if I could described him how, because he wanted to help us make Better use of this tool. We where pretty happ…

Your story is a good reminder that these license questions aren't just about some holy war or ideology campaign. These are real people with real problems. We need to be more sensitive about how to structure licenses such as the AGPL.

I find I don't want even to use the GPL at times. Why? Not because I want to give away free stuff to Google. Rather, because I don't want to force others to use the same license that I use. You can use MIT code from a GPL code base, for example. I want to be nice. If Google uses it without paying me, that's fine, too. Honestly I'd probably feel pretty proud of myself at that point.

Re: The terms of the AGPL are pretty easy to comply with

#156
post #50

Earlier quoted context omitted.

MacOS uses BSD code for free. Apple, most profitable company in the world, contributes nothing back. Sad story.

Nit: Apple open sources the majority of their BSD modifications, it's just that nobody upstream wants them apart from the few ex-Apple employees who try macOS bits out in those OSes for fun.

Do they still? I thought they drastically cut the amount of stuff publicly released after they shut down macosforge.

Re: The terms of the AGPL are pretty easy to comply with

#157
post #156

Earlier quoted context omitted.

Nit: Apple open sources the majority of their BSD modifications, it's just that nobody upstream wants them apart from the few ex-Apple employees who try macOS bits out in those OSes for fun.

Do they still? I thought they drastically cut the amount of stuff publicly released after they shut down macosforge.

They do, slowly.

Re: The terms of the AGPL are pretty easy to comply with

#158
post #33

Earlier quoted context omitted.

I’ve taken AGPL through two FAANG reviews. Both arrived at the same very-much-not-FUD legal conclusion. Paragraph 1 of section 13 requires modifications to be disclosed and source code for them to be offered to remote users. The license uses the term of art Corresponding Source for this. Corresponding Source is defined in section 1 in a crystal clear way. Two separate teams of lawyers concluded that they could cohere…

> AGPL is unchallenged in court. The risk to being wrong about it as huge. It’s risk aversion, not ideology, and it’s important to remember that identifying an argument as part of legal review does not call it the correct one. Anyone who’s ever worked with legal matters knows there is no such thing as “correct,” there are rulings. The existence of the argument condemns the license for FAANG, not its validity. Having…

> All these contracts are "unchallenged in court", by definition, because they are entirely custom.

They do, however, very often use existing language, and custom language is minimized.

> Another type of custom and complex contract is employment.

Where contracts are often almost entirely standard per-company, and often standard between companies. And very rarely is the company in danger from the non-boilerplate clauses.

If you want an example of such a clause, consider Google's own IP clause in its contracts, which contend that Google owns basically all of your IP while you work at Google, unless you take steps to declare ownership of it in advance (and Google approves).

Will this clause entirely hold up in court? Probably not. Do you want to be the one to test it with your multi-billion dollar startup on the line?

The risk of using AGPL software is significantly higher than not, and the benefits are relatively small.

Re: The terms of the AGPL are pretty easy to comply with

#159
post #96

Earlier quoted context omitted.

The error is using a pejorative term of FUD to identify uncertainties that are routine in every legal review ever performed. What you’re saying is you have a different risk assessment for your business and you’d take the advice and proceed anyway. That’s your prerogative. That does not extend to “different assessments from my own are objectively wrong,” which is what calling them FUD implies. Engineers seek hard trut…

When working for eBay I've asked our legal department "So if we do this, are when then safe?" - The answer was always "The court decides, before that noone knows."

Right. That's really the issue -- it's not that the risk isn't there, it's that the risk is always there, so it's an isolated demand for rigor.

For example, here's the Windows 10 license:

> c. Restrictions. The device manufacturer or installer and Microsoft reserve all rights (such as rights under intellectual property laws) not expressly granted in this agreement. For example, this license does not give you any right to, and you may not:

...

> (v) use the software as server software, for commercial hosting, make the software available for simultaneous use by multiple users over a network, install the software on a server and allow users to access it remotely, or install the software on a device for use only by remote users;

With people staying home because of COVID-19, a lot of companies with Windows desktops (with all their line of business software on them) have been having their employees access them from home, exclusively remotely with no local users. Are they now in violation of the license? Do you want to have to find out in court?

It's an excuse which is present anywhere for any non-trivial terms and used as FUD in contexts where someone wants to scare others away from something.

Re: The terms of the AGPL are pretty easy to comply with

#160
post #98

Earlier quoted context omitted.

The definition of FUD is that you are spreading fear, uncertainty and doubt as a tactic not that you yourself are afraid, uncertain or have any doubts.

I think the “spreading” aspect is overstated. These are clearly Google’s internal docs that just happen to be accessible to the public.

The article:

> Ask yourself: why is documentation of internal-facing decisions like what software licenses to use being published in a public place? The answer is straightforward: to influence the public.

Post reply on HN