Showing posts with label enforcement. Show all posts
Showing posts with label enforcement. Show all posts

Friday, April 16, 2010

Breaking the International Log Jam: Cloud Computing and Open Source

Possibly the biggest challenge to the continued maturation of the open source and cloud technology industries is inconsistency in the treatment of legal and other issues across international borders. Great progress has been made on this front in the open source context both through community efforts, and by greater legal certainty from court decisions, legislation and government policies. While the cloud will benefit from the growing international consensus on open source, it differs in ways that create important limitations. We need a new international legal consensus for these technologies to continue their rapid evolution.

A. Open Source

Examples of the emerging international consensus on the validity of open source principles are becoming more common. Till Jaeger, a German attorney affiliated with the gpl-violations.org project, recently published an article on Groklaw entitled, "Enforcement of the GNU GPL in Germany and Europe." What I found most striking is that both the types of issues arising in Germany, and the manner in which they are adjudicated and resolved in Germany have direct parallels with the United States. In fact, I recommend this article as an excellent educational tool or refresher on the specific aspects of GPL most likely to lead to compliance issues whether you are in the U.S., Europe or elsewhere.

The consensus is also evident in that governments are increasingly accepting, or even adding preferences for, open source as part of their procurement policies.  For example, in 2009, the United States State Department and President Obama's Administration made headlines in the IT world for making open source prominent parts of their IT objectives. Roberto Galoppini also recently reported on a ruling by the Italian Constitutional Court finding that an Italian state law preferring open source is acceptable under Italian law.  All these factors show that open source is becoming mainstream with remarkable consistency in treatment across international boundaries.

B. Cloud

At first glance, the growing international consensus on the legalities of open source and the tight link between the open source and cloud technologies would seem to indicate that the cloud will achieve similar consensus. Take the Affero GPL as an example: the license is both nearly identical to the familiar GPL, and is specifically targeted for the proliferation of technology in a cloud and networking context. Unfortunately, minor differences between the Affero GPL and the standard GPL require a significant rethinking of how terms like "conveyance," "distribution," "derivative work," "corresponding source code" and other should apply in a cloud context.

The cloud also lacks international consistency in other ways too. Summarizing a 451 Group analysis, Charles Babcock at InformationWeek notes that U.S. investors appear to invest more money in cloud computing than their European counterparts, and the technology infrastructure for the foundational elements of cloud computing are not as mature in Europe as in the U.S. These impose practical challenges to the growth of the cloud computing infrastructure in Europe.

Differences in the U.S. and Europe legal environments potentially present an even bigger barrier. The 451 Group analysis also notes that the U.S. and Europe fundamentally differ in how they regulate data protection. As but one example: the U.S. Patriot Act, emphasizes the government's ability to access information under certain circumstances; whereas, the European Union Data Protection Directive emphasizes the rights of individuals to privacy and protection of their personal information. While these purposes do not necessarily conflict, they clearly are not aligned enough to claim any kind of consensus on how to handle data in a cloud environment.

C. Possible Solutions

We are nearing the time when cloud computing will become so fundamental to our use of technology that we need a set of legal principles, not just technical standards, that ensure broad access to data across international boundaries while also ensuring protection of intellectual property in a manner that promotes innovation and investment regardless of jurisdiction. Possibly the best model from which to start is the Berne Convention for the Protection of Literary and Artistic Works. Though the scope of adoption of the many clauses of the Convention has varied over the more than 100 years since its inception, the Berne Convention represents a broad consensus and acceptance of a core set of basic principles in copyright protection, which are largely consistent between the more than 160 signatory countries.

The same type of international discussion should focus on principles of validity and enforcement of open source agreements like the Affero GPL, as well as address appropriate measures for data portability while preserving data protection standards. The U.S., Europe and other jurisdictions should strive to reach at least a basic consensus on these issues in much less time than the 100+ years for the Berne Convention to reach its current level of maturity. The pace of change in cloud technology and our reliance on the cloud will face meaningful limits sooner rather than later. The growing international consensus on how to apply basic legal principles to open source in a consistent manner should serve as a model for achieving consensus over cloud issues.

Sunday, January 3, 2010

Obligatory End of Year Post - 2009

Yes, I know it's already 2010, but this post is still my official "end of 2009" post. I've included some highlights from the posts on this blog along with my choice of top 5 open source stories and themes of the year. Please add your comments on what you think are the top stories for 2009.

Reflections on This Blog

The readership of this blog grew substantial in 2009 and I am very thankful for that. Visitors from 30 states, 29 countries and 6 continents came to this blog with the top 3 countries being the United States, Brazil and the United Kingdom. I have to admit, the prominence of Brazil surprised me. Visitors seemed to be attracted to a wide variety of subjects, but management of open source within a company and GPL enforcement seemed to be the favorites. Here are top 5 most visited posts of the year, beginning with the most popular:

1. In-House Counsel - Managing Open Source
2. FSF Motives in the Cisco Case
3. Obligatory End of Year Blog Post (2008) (emphasis on the FSF-Cisco case)
4. Highlights of the Open Source Business Conference - Day 1
5. Show Me the Money at OSCON - Venture Capital and Open Source

Top 5 Open Source Stories

Shifting to the industry as a whole, the top stories of 2009 also illustrated the importance of in-house open source management and GPL enforcement among many other themes. Below, I have provided my list of the top 5 stories and themes of the year:

1. Oracle Acquisition of Sun Microsystems - As a Sun employee, I have a deep personal interest in this deal, but it is also a significant event for the business of open source (not to mention the software and hardware business too), particularly the EU's competition investigation of the MySQL business. The deal could be characterized as a definitive affirmation of the importance of open source in that even companies whose success is perceived to rely on the traditional proprietary software model (such as Oracle), see open source as an important strategic element. Questions on the MySQL aspect of the deal even prompted industry heavyweights like Eben Moglen, founding Director of the Software Freedom Law Center, to explore the impact of the GPL.

2. GPL Enforcement Actions - The relative popularity of my blog posts on the Cisco-Free Software Foundation litigation (which has since settled) is one indication that GPL enforcement is a hot topic. This trend gained momentum throughout 2009 and will likely continue to do so in 2010. Examples include the Software Freedom Law Center's December announcement of litigation against Best Buy, Samsung, Westinghouse and 11 other entities on behalf of the owners of BusyBox, and a French court case in which users of GPL software got a ruling affirming their right to receive the source code to that software and modifications.

3. Microsoft Release of GPL Code - Few companies raise the ire of the open source community more than Microsoft. That's why open source proponents were pleased, and surprised, to see hear Microsoft announce that it would contribute driver code to the Linux kernel. It is not clear whether Microsoft's decision was based on necessity in the face of a potential GPL violation, or a strategic move to enhance compatibility with Linux. Regardless of the motive, Microsoft's actions indicate that even the most sophisticated of companies must pay close attention to their use of open source and honor the provisions of open source licenses. This is especially true in light of the recent enforcement activities discussed in the previous paragraph.

4. US Government Commitment to Open Source - The principles of technology neutrality have long been recognized in the European Union to the benefit of open source software usage by European governments. The United States federal government has not been as accommodating of open source, but at least two events in 2009 indicate a possible change in US attitudes. The US Department of Defense revised its guidelines on use of open source software in October to essentially give it a procurement preference over proprietary software when all else is equal. In addition, it appears that the Obama Administration is actively looking for ways to bring the benefits of open source to government operations.

5. Red Hat's 10 Year IPO Anniversary - Red Hat is commonly viewed as the most successful pure open source company with its status as a Fortune 500 company with a market cap of almost $6 billion and generating over $700 million in revenue in 2009. As such, it's longevity and success are significant barometers on the health of the open source business as a whole. With a lingering cloud over the economy, and the relatively slow growth trajectory of most open source companies, it seem unlikely that we will see any open source IPOs in 2010.

Please post your thoughts on the most important open source events of 2009. I wish the best of success to all of us in this corner of the world we call "open source."

[Note: The "Top 5" portion of this post was updated after the original post to make non-substantive changes for purposes of clarification and adding more reference links.]

Tuesday, June 30, 2009

Expanding Open Source Enforcement Strategies

What comes to mind when you hear "open source enforcement"? Probably the names "Busybox" and "Software Freedom Law Center". These organizations are good examples of the "cease and desist" style of enforcement in the open source context. But an enforcement strategy should go beyond "cease and desist" to also include other considerations such as alignment with business strategy, product development and business model considerations, and promotion of open source education.

A. Aligning Enforcement Strategy With Business Strategy

Enforcing intellectual property rights always sounds like a good idea. Unfortunately, the typical cease and desist and litigation strategy has significant pitfalls including requiring vast resources and risking the loss of goodwill with customers, partners and the community. Aligning enforcement strategy with business strategy clarifies which enforcement activities will have maximum impact while minimizing risks. The question is, how do you align these strategies?

Looking at the size and goals of a company is one place to start. Many open source vendors today are relatively small and privately held. These companies prioritize rapid growth, building adoption and proliferating products over converting customers to cash. These companies could reasonably choose to avoid tricky enforcement issues under the theory that any customer, paying or free, in or out of compliance with a license, is one more customer that can be converted to cash sometime in the future.

By contrast, other open source companies are either publicly held, or privately held and on the verge of generating a return on investment. Accumulating customers is not the focus of these companies, but the traditional cease and desist and litigation approaches to enforcement of unauthorized copies could be seen as a quick way to make money for investors.

B. Building Enforcement Success Into Your Product

Enforcement begins with the choices you make as to features to include, the license that applies and the business model. For example, DRM (digital rights management) is a dirty word in the open source community, but it can be a valuable tool in enforcement. Companies with a subscription model can use DRM tools, such as a digital fingerprint, to track subscription periods and to confirm whether particular installations are eligible for support and services.

Licenses make a difference in enforcement too. The popularity of GPLv2 is due in large part to its viral terms, which make the mere threat of enforcement enough to drive compliance, particularly with traditional proprietary software companies. GPLv3 offers an even more intriguing range of enforcement options because it allows licensors to easily apply their own conditions for enforcement opportunities.

A company's chosen open source business model makes a difference too. As mentioned above, companies with a subscription model often worry about enforcement because they want to ensure the services and tools they provide are only available to licensed servers. By contrast, companies with an open core model might not be as concerned with unauthorized availability of the software because they make their money by enabling additional features or functionality.

C. Safety in Numbers

One of the most successful enforcement strategies adopted by proprietary software companies could be a model for open source enforcement strategies too. Many of the leading software companies are members of the Business Software Alliance (BSA), an organization that not only organizes anti-piracy and license compliance programs, but also promotes public policy initiatives including intellectual property and development policies. Possibly the greatest advantage of the BSA is that it allows licensors to pursue enforcement strategies collectively, thus allowing enforcement resources to be pooled while avoiding the risk of individual members losing goodwill. The uniformity in approach also creates predictability in license rights and when enforcement is appropriate.

Open source companies could come together to form their own Open Source Software Alliance (OSSA) and realize the same benefits. Ideally, the proposed OSSA could also partner with the Free Software Foundation to add credibility to the positions it takes and bridge the gap between the open source and free software movements. Unfortunately, the gap between open source and free software is likely too big for the FSF to endorse an organization like the OSSA.

These are just a handful of ideas that I hope will help open source companies break out of the "cease and desist" box to realize that enforcement means so much more than adversarial confrontations and litigation.

Thursday, June 26, 2008

GPL Enforcement, Frogs & Funny Hats

The GPL has become the most popular of open source licenses in large part because of its "copyleft" status. Not only does it virally attach to software code, but it automatically terminates if its source code distribution obligations are not honored. The severe consequences of breach, along with community pressure for compliance are strong deterrents to violations that would require enforcement measures. Even so, every open source company using GPL will be faced with GPL violations and must carefully consider both when enforcement is appropriate and what factors should be weighed as part of that decision.

To those open source companies that assume GPL enforcement is always the quickest, best strategy, I quote the great open source guru Homer J. Simpson: "you're living in a world of make-believe! With flowers and bells and leprechauns and magic frogs with funny little hats." Yes, it's true that enforcement serves a critical function. Not only does it prevent abuse of open source code on a case by case basis, but it also upholds the legitimacy of the GPL as a license vehicle and meets the community's expectations of its fellow members.

On the other hand, enforcement is not a panacea. The community might view inconsistent enforcement as arbitrary and self-serving, or it might have different views on what a company's enforcement priorities should be. In addition, enforcement actions might actually slow the adoption of open source in proprietary companies. A great recent example of this type of unintended consequence is the discussion arising from the recent string of settlements related to the Busybox GPL enforcement cases. Though widely criticized by a number of open source commentators, intellectual property attorney Edmund Walsh wrote an article in which he analyzed these cases and concluded that "for-profit companies [have] new reasons to re-evaluate the ways in which they use open source software as well as the extent to which they use it."

Open source companies should also consider strategic non-enforcement as an option, or take a further step and grant limited exceptions to open source licensing (assuming the company controls adequate IP rights). Among the benefits of these approaches is the ability to encourage specific types of partner and end user activities that would have been difficult to otherwise achieve without radically altering a dual license strategy. However, these approaches should be used with caution because they can easily backfire. The community might view this type of manipulation of open source strategy as counter to open source philosophy. It also could lead to end users using the software in unanticipated ways that negate the perceived or realized benefits of the approaches.

The moral of the story is ... as you consider your options with respect to enforcing the inevitable GPL violations that all open source companies face, avoid the frogs with funny little hats!