Live data from Hacker News

The terms of the AGPL are pretty easy to comply with

drewdevault.com

161–170 of 341 posts

Re: The terms of the AGPL are pretty easy to comply with

#161
post #60

> Obligatory: I’m not a lawyer; this is for informational purposes only That's the main point, though. You aren't, in fact, a lawyer. And this is not, in fact legal advice. You are presumably expert in a non-legal field, and you are giving expert opinion on something you are not an expert on. The GPL is tested. The LGPL less so, but lawyers seem to be more comfortable with it. There's the extra complexity that Google…

> You're calling Google liars. There's an alternative interpretation of events where a whole legal department, with great lawyers, and backed by great engineers to clarify the technical aspects for the lawyers, come to a different conclusion than yours. Google claims that they care about your privacy. Entire teams of engineers and lawyers will say the same thing. But when you look at it, you can plainly see that they…

So your legal interpretation as a lawyer (I assume) is an ad hominem on Google for unrelated reasons?

Re: The terms of the AGPL are pretty easy to comply with

#162

Earlier quoted context omitted.

The true misrepresentation is: > Anyone can go after you for some sort of supposed license issue Suppose the software in question is MIT licensed. There are certain requirements, none of them involve users having to decide between releasing their source code or paying fees. Remedying most MIT project license violations usually involves adding a disclosure somewhere in the website. As a whole, for reasonably large com…

Well, that's simply because most MIT licensed projects don't choose to insist on the copyright infringement damages to which they're entitled with respect to past non-compliance. They could insist on statutory damages (assuming they've registered their copyright), or actual damages/profits of course, without offering the option to remedy past violations. Most such rights holders simply don't do this as a practical ma…

Both license violations can involve a fee. The point is that on a going-forward basis it is sufficient to appropriately disclose use of MIT licensed software. On a going-forward basis, an AGPL violation will require either a release of the entire source tree or a replacement of the AGPL software with an alternative

Re: The terms of the AGPL are pretty easy to comply with

#163
post #60

> Obligatory: I’m not a lawyer; this is for informational purposes only That's the main point, though. You aren't, in fact, a lawyer. And this is not, in fact legal advice. You are presumably expert in a non-legal field, and you are giving expert opinion on something you are not an expert on. The GPL is tested. The LGPL less so, but lawyers seem to be more comfortable with it. There's the extra complexity that Google…

And Microsoft said all GPL was a cancer and unamerican and viral and disallowed it from about 50k engineer's computers due to "legal risk of GPL virality", and this was when they were by far the biggest software company. Wait, they lied? It was all FUD and really about threatening their business model. They changed their policies and actually said publicly they were wrong. Is it so hard to believe?

Right. So because MS used the wrong strategy that is evidence that Google's lawyers are deriving incorrect legal conclusions?

Is that your argument?

So because MS was wrong once, Google is wrong other times of your choosing?

Re: The terms of the AGPL are pretty easy to comply with

#164

"The Google page about the AGPL details inaccurate (but common1) misconceptions about the obligations of the AGPL that don’t follow from the text." "The reason they spread these misconceptions is straightforward: they want to discourage people from using the AGPL, because they cannot productize such software effectively." "Ask yourself: why is documentation of internal-facing decisions like what software licenses to…

Not the article author, but:

> - Google internally knows they can comply with the AGPL without trouble

No, and I don't know where you got that. The article is talking about how start-ups can typically comply with AGPL without trouble. cic48 claims that all software running on Borg needs to be extensively modified and then can only be compiled using Google's proprietary tool-chain. If that's true, then they can't run AGPL on Borg without releasing the code for the tool-chain.

> - Has consciously chosen to write policies prohibiting it based on misleading reasons

No. Has written policies prohibiting it for rational self-interest (GPL, MIT, etc licenses allow them to sell access via the Internet without any cost to them, AGPL does not). After writing these policies, they've provided an alternative justification.

> - Google adheres to that policy

Outside of Google Legal, who would know whether or not they adhere to their own internal policies? If they used AGPL software internally, they would have no legal obligation to disclose that (because they'd be fully in compliance).

> - Most importantly: they are doing this because they believe that the influence this would have in discouraging use of the AGPL is valuable enough to substantially benefit Google

Why "substantially"? I would imagine the cost of saying "don't use AGPL" and then publishing an article about it was very low. A couple person-weeks of work at the most? It's hard to imagine what wouldn't be worth that investment.

But I think you didn't understand the article, because the main thrust of it was to encourage businesses to not be afraid of the AGPL, not to determine whether Google is acting maliciously or not.

Re: The terms of the AGPL are pretty easy to comply with

#165
post #33

Earlier quoted context omitted.

I’ve taken AGPL through two FAANG reviews. Both arrived at the same very-much-not-FUD legal conclusion. Paragraph 1 of section 13 requires modifications to be disclosed and source code for them to be offered to remote users. The license uses the term of art Corresponding Source for this. Corresponding Source is defined in section 1 in a crystal clear way. Two separate teams of lawyers concluded that they could cohere…

> AGPL is unchallenged in court. The risk to being wrong about it as huge. It’s risk aversion, not ideology, and it’s important to remember that identifying an argument as part of legal review does not call it the correct one. Anyone who’s ever worked with legal matters knows there is no such thing as “correct,” there are rulings. The existence of the argument condemns the license for FAANG, not its validity. Having…

The remedy for a violation is also in play. Private contract between two companies, cutting a 10 figure check makes it all better. Being wrong about AGPL, you have to release a lot of code that you really don't want to release, that is very important to your core business.

That's the other side, uncertainty with acceptable error bars vs uncertainty with unacceptable error bars.

Re: The terms of the AGPL are pretty easy to comply with

#166

Earlier quoted context omitted.

> AGPL is unchallenged in court. The risk to being wrong about it as huge. It’s risk aversion, not ideology, and it’s important to remember that identifying an argument as part of legal review does not call it the correct one. Anyone who’s ever worked with legal matters knows there is no such thing as “correct,” there are rulings. The existence of the argument condemns the license for FAANG, not its validity. Having…

> All these contracts are "unchallenged in court", by definition, because they are entirely custom. They do, however, very often use existing language, and custom language is minimized. > Another type of custom and complex contract is employment. Where contracts are often almost entirely standard per-company, and often standard between companies. And very rarely is the company in danger from the non-boilerplate claus…

> They do, however, very often use existing language, and custom language is minimized.

Guess what, AGPL does that too. Its only 1 paragraph different than GPL.

> Where contracts are often almost entirely standard per-company

"standard per-company", means custom and used used throughout the company. That doesn't make it less risky, and its not like these things don't constantly change and are hugely complicated, just look at privacy policies. AGPL is standard for all companies.

> And very rarely is the company in danger from the non-boilerplate clauses.

Citation needed.

Re: The terms of the AGPL are pretty easy to comply with

#167
post #91

> Obligatory: I’m not a lawyer; this is for informational purposes only. and > Google states that if, for example, Google Maps used PostGIS as its data store, and PostGIS used the AGPL, Google would be required to release the Google Maps code. This is not true. They would be required to release their PostGIS patches in this situation. AGPL does not extend the GPL in that it makes the Internet count as a form of linki…

I've seen the same phobia to a lesser degree around the plain old GPL. Lawyers think, and not unreasonably, in terms of risk. Is there a risk you might be dragged into court? If so, that's a very expensive risk. Is the library or application worth this risk? If not, then ditch it. It's not an unreasonable fear either given past events like the SCO/Linux lawsuit. IBM had deep enough pockets to fight it and win. Anyone…

Lawyers run businesses, and drafting custom contracts/licence are a big part of their business.

GPL and standardized licences destroy this part of their business.

Also who pays a lawyers to read the thousands of page of licences for say Microsoft software (all the version of all the software deployed)? Where I work no one is able to know what Microsoft licence we need to buy, even when we ask licence sellers they mostly don't answer, and it changes all the time.

IIRC early Microsoft Visual C++ licences did not authorize the diffusion of debug compiled executables (don't know if it's still the case). How many violation of this?

Re: The terms of the AGPL are pretty easy to comply with

#168
post #135

Earlier quoted context omitted.

It is almost literally GPLv3 with the interactive remote network source obligation added in. If you diff GPLv3 and AGPLv3, the differences are (ignoring differences that are just in the name of the license): 1. The preamble has a few differences where they describe why they wrote each license and what ills they are trying to address. 2. In the actual terms and conditions, the first 13 sections and last 4 sections are…

Then I guess I am confused by this statement: > The user source entitlement only applies to users remotely interacting with the software through a computer network. It applies to all users under the GPLv3 as well, is certainly more than just those interacting with it over a computer network, right?

GPLv3 does not have a source entitlement for users of the software. Its source entitlement is for people the work has been conveyed to. It defines "convey" thusly:

> To "convey" a work means any kind of propagation that enables other parties to make or receive copies. Mere interaction with a user through a computer network, with no transfer of a copy, is not conveying

and propagate is:

> To "propagate" a work means to do anything with it that, without permission, would make you directly or secondarily liable for infringement under applicable copyright law, except executing it on a computer or modifying a private copy. Propagation includes copying, distribution (with or without modification), making available to the public, and in some countries other activities as well

Using software does not necessarily involve conveying the software to the user.

A good example is given in the GPL FAQ [1]:

> Does GPLv3 require that voters be able to modify the software running in a voting machine?

> No. Companies distributing devices that include software under GPLv3 are at most required to provide the source and Installation Information for the software to people who possess a copy of the object code. The voter who uses a voting machine (like any other kiosk) doesn't get possession of it, not even temporarily, so the voter also does not get possession of the binary software in it.

This is what makes AGPL so different from previous licenses. As far as I know it is the only free software license that has a source entitlement that triggers on mere use. The others trigger on distribution or possession of copies.

[1] https://www.gnu.org/licenses/gpl-faq.en.html#v3VotingMachine

Re: The terms of the AGPL are pretty easy to comply with

#170

It reminds me of the story I heard around a campfire once, about a programmer who decided to fix a bug in a single AGPL module, and they were forced to make their entire code open source. Even today, long after the bankruptcy, they say you can still hear the screams in the shuttered, decaying boardroom. And the bug somehow got unfixed. It’s out there now, waiting ... for its next victim.

Is this a story lawyers tell around the campfire to scare new law school grads?
Post reply on HN