2026-09-15 08:40 UTC
Replies (1)
-
@david_chisnall@infosec.exchange 2026-09-15 09:08
@simon_brooke@mastodon.scot You are repeating the theory, which is laudable, but does not reflect the practice. I agree 100% with the goals of the GPL and 0% with it as an effective tool for achieving those goals. When lawyers for poorly-funded good actors (e.g. small companies wanting to be good citizens of the community) read the GPL, they see that complying is complex and exposes them to liability. This pushes them away from the GPL’d project because the risk of litigation (even if they win) is a significant liability that they cannot afford. When lawyers for well-funded bad actors (e.g. massive corporations wishing to exploit the community) look at the GPL, they see loopholes that they can convincingly argue in court and know that they can afford the long legal battle, whereas most other parties cannot. The axis of good community participant vs bad community participant is one dimension. The other dimension is large established powerful entity versus individual. This second dimension completely dominates when it comes to how the GPL influences behaviour: it makes less powerful entities change their behaviour (and, often, not in the desired direction: they create a proprietary in-house version of something, or take GPL’d code to use internally but avoid the liability from sending their bug fixes upstream) but it doesn’t change the behaviour of powerful entities. If your goal is to accelerate the concentration of power, the GPL is a very effective license and successors are even more effective in various ways. If you wish to change the behaviour of large entities, showing them the benefits of good engagement with the community is a key.