Elektrine lite

← Feed

@simon_brooke@mastodon.scot

2026-09-19 08:11 UTC

@david_chisnall@infosec.exchange a good actor has no need to fear litigation, because what the #GPL requires is simple and clear and very easy to comply with. So a good actor, large or small, will not be deterred. You're right, of course, that a big bad actor won't be deterred in any case, but there is no substitute document — that I know of — that would be any greater deterrent.

Replies (1)

  • @simon_brooke@mastodon.scot a good actor has no need to fear litigation, because what the #GPL requires is simple and clear and very easy to comply with I can only assume from this that you have never talked to a corporate lawyer about the GPL. The requirements have a lot of corner cases where compliance is not obvious. Even most lawyers don’t claim that the GPL is simple so I’m struggling to understand how you’d reach that conclusion. Even for the LGPL, which permits more, I’ve heard from companies that they would not use them because of the recommendations from their lawyers. I’ve heard from others that they have internal fixes to LGPL’d project I worked on but that they don’t want to upstream them because their lawyers don’t want the liability (if you don’t distribute, the license doesn’t get triggered, so using a GPL’d or LGPL’d project internally is fine). That’s exactly the opposite of the incentives I want to create. The binary nature of the GPL also causes problems when it has to compose with other existing legal obligations. Again, to give a concrete example: When working with Arm on their CHERI extensions, they shared the architecture drafts under NDA with partners. More than one partner then did QEMU implementations internally. QEMU is GPL’d, so they could not distribute the result because they cannot attach an additional distribution restriction to the result, but the NDA forces them to. Out in the real world, companies (and even individuals) have a lot of situations like this where some existing agreement places restrictions that compose poorly with the GPL. In a healthy Free Software environment, modifying and distributing modified versions of a program is a normal thing to do, but that needs to be possible in a way that doesn’t cause other obligations to be violated. Most modern software has a strict boundary between documents and programs, which comes from the proprietary software model of selling the program and allowing users to create documents that don’t modify the program and distribute them. In a model designed around Free Software, this line is more blurry. If your office suite doesn’t have a feature that you need for some document, you just add it and distribute the version. But now your document is a derived work of the change, which is a derived work of the office suite. If your office suite is MIT licensed, this doesn’t matter at all. If it’s GPL’d, whether this matters or not depends on what other obligations come from the document (does it contain confidential medical data? Attorney-client privileged information? Sensitive financial information?). And now, as an end user, you need to talk to a lawyer to see what you can do. The GPL is only zero friction on the implicit assumption that end users rarely modify software. But, in any situation where that’s true, the end user sees no direct value of Free Software other than the price and so has no incentive to prefer Free Software to proprietary software. And that’s antithetical to the goal of Free Software displacing proprietary.

    Open ##4763335