Welcome!

Open Source Cloud Authors: Yeshim Deniz, Jason Bloomberg, Elizabeth White, Liz McMillan, Zakia Bouachraoui

Related Topics: Open Source Cloud

Open Source Cloud: Article

Demystifying Open Source

Many assume that the open source movement runs contrary to the concept of Intellectual Property (IP) rights

Open Source Journal on Ulitzer

In 2008, the open source community saw the year end with a headline-catching lawsuit, the Free Software Foundation files suit against Cisco for General Public License (GPL) violations. Not to be outdone, 2009 also ended with a bang. Best Buy, Samsung, JVC and 11 other consumer electronics companies were named in a copyright infringement lawsuit filed on December 14, 2009, by the Software Freedom Law Center (SFLC) on behalf of the Software Freedom Conservancy. The scope of this lawsuit is unprecedented as it includes 14 defendants.

The suit alleges that the defendants have distributed products containing the Software Freedom Conservancy's product BusyBox in violation of the terms of its GPL Version 2 license (the General Public License Version 2 superseded Version 1 in 1991, and is still widely used despite the creation of Version 3 in 2007). Specifically, the Software Freedom Conservancy alleges that the defendants have not made BusyBox's source code available to downstream users. BusyBox is a tool that combines many UNIX utilities into a single executable and is commonly incorporated into household electronic devices. The Software Freedom Conservancy is seeking damages, injunctive relief and legal fees. BusyBox has been at the center of several other high-profile GPL violations; the SFLC has in the past settled on behalf of BusyBox with Extreme Networks, Monsoon Multimedia, Xterasys Corporation, High-Gain Antennas and Verizon.

The Software Freedom Conservancy was not the only one to file a lawsuit for GPL violations as 2009 drew to a close. On December 2, 2009, Artifex Software Inc. filed a lawsuit against Palm, Inc., based on Palm's alleged unauthorized copying and distribution of Artifex's muPDF, a PDF interpreter that can be integrated with PDAs. The muPDF is licensed under the GPL or under Artifex's standard commercial license for companies that are unwilling or unable to comply with the terms of the GPL. Artifex alleges that Palm has neither obtained a commercial license nor complied with the terms of the GPL.

These enforcement actions drive home the importance of taking inventory of what open source software is included in each product, what licensing obligations apply to each component, and compliance with these obligations. Open source license compliance is particularly important given the growing ubiquity of embedded computer systems - the impugned products in the lawsuit against Best Buy et al include Insignia Blu-ray Disc players and Samsung LCD HDTVs.

If you're starting the New Year with clean IP in mind, this article endeavours to demystify open source by explaining how it works and providing a primer on some of the most frequently used open source licenses and their obligations.

What Is Open Source Software?
Open source software (OSS) refers to software in which, among other things, the source code is made available to the public. This is important because the open source community and various ecosystems can modify, improve, and incorporate the code into other works. Whereas with proprietary software, usually only the machine-readable compiled code is made available.

It is important to clarify the concept of "free." OSS is often referred to as free. While most OSS is indeed free of charge, it should be noted that "free" does not necessarily mean free of charge but rather refers to the freedom to use, modify, and redistribute the source code so long as certain conditions are met. Conversely, a product that is free of charge is not necessarily open source.

Many assume that the open source movement runs contrary to the concept of Intellectual Property (IP) rights. This, however, is a myth. The open source movement is actually made possible by IP rights. In most jurisdictions, such as the United States and Canada, software is automatically protected by copyright as soon as an original work has been created. Copyright law grants copyright owners the exclusive right to reproduce, prepare other works based on the protected work, distribute, and publicly display the work. In general, open source licenses use these exclusive rights to ensure that the code remains open and accessible so that successive developers can innovate around it. Anyone violating the conditions of the license may be held liable for copyright infringement.

There are many benefits to using OSS. Users can edit the code, fix programming bugs, and even tailor the program to fit their specific needs. OSS is also significantly less expensive than proprietary software. In Jacobsen v. Katzer, the United States Federal Court of Appeal even recognized the substantial benefits of distributing copyrighted works under public licenses. The Court noted that program creators may generate market share for their programs by providing certain components free of charge. Similarly, a programmer or company may increase its national or international reputation by incubating open source projects. The Court also noted that improvement to a product can occur rapidly and free of charge from an expert not even known to the copyright holder.

What Are Open Source Licenses?
The Open Source Initiative (OSI) is a public benefit corporation that refers to itself as the stewards of the open source definition (OSD). The OSI is a community-recognized body for reviewing and approving licenses as OSD-conformant. A license must comply with the OSI's 10 distribution terms in order to be approved as open source. The three major requirements include royalty-free redistribution, available source code, and the license must allow for modifications and derived works. Derived works are essentially works based upon the licensed work. The OSI's website lists all of the approved open source licenses. You should also be aware that source code that is made available but is not approved by the OSI is still often referred to as open source. Merely making the source code available does not necessarily mean the licensor has permitted you to modify or redistribute the software. The OSI has criticized companies that have advertised their software as open source when the license was not approved by the OSI board. Such software might be more accurately described as source available software.

Open source licenses ensure that others are generally free to use, modify, and redistribute the OSS. More generally, license agreements are a type of contract. There are, however, subtle differences in the interpretation of licenses and contracts that can have harsh implications for a party that is caught offside the license.

A license gives a person permission to use another's IP in a way that would otherwise constitute infringement. A license will set out the conditions of use and if the user violates these conditions the license allows IP owners to exercise their property rights. This is an important distinction because it is easier to obtain an injunction when one's property rights have been violated, e.g., copyright infringement, than it is for a breach of contract. An injunction orders a party to refrain from the infringing activity and can halt business operations, whereas the ordinary remedy for a breach of contract is damages. In 2008, the United States Federal Court of Appeal in Jacobsen v. Katzer confirmed that if a license is limited in scope and the licensee acts outside the scope, the licensor can bring an action for copyright infringement.

Why Should I Care About Open Source Licenses?
In all likelihood your company has encountered OSS. OSS is becoming ubiquitous as companies that initially cast a wary eye on it have now realized its numerous benefits, including its ability to drive down development costs. It is now difficult to find commercial software that does not incorporate OSS in at least some areas.

While open source offers many benefits, it also heightens the probability of code contamination or unclean IP. Code contamination occurs when content is brought into a development project without regard for the licensing or copyright obligations.

The value of a company and its product often depend on the cleanliness of their IP and not solely on the protection of it. Disregarding license obligations can have surprising and costly consequences for many stakeholders. In any merger and acquisition or funding deal, uncertainty over clean IP can:

  • Generate risk and threaten successful closure
  • Increase product time-to-market
  • Affect software IP valuation and overall business valuation
  • Result in a litigation that can drag on for years, draining company resources
  • Produce negative press and public scrutiny

One of the most well-known examples of an open source surprise attack comes from Cisco and Linksys. Linksys routers used chipsets supplied by Broadcom, and Broadcom outsourced development of these chips to an overseas developer. In 2003, Cisco acquired Linksys for $500 million. After the acquisition, the Free Software Foundation (FSF), an organization that actively seeks companies that violate open source licenses, determined that the chips contained copyrighted code under the GPL and that Cisco was distributing the product in violation of the license. Cisco agreed to remediate the situation by releasing the source code. As a result, the software Cisco believed to be proprietary when it conducted its business and IP valuation of Linksys was now freely available to the public. In 2008, the FSF sued Cisco for copyright infringement claiming that Cisco never completed the compliance process. In 2009, Cisco paid an undisclosed amount to the FSF and settled.

What Are the Main Obligations of OSS Licenses?
Despite the many benefits of OSS, companies often shy away from it because they do not fully understand the obligations of various licenses. There is fear that using OSS will require a company to give away all of its software for free - this is not accurate. The matrix will explain the primary obligations of some of the most frequently used open source licenses. As you will see, open source licenses can be diverse and can range from quite permissive to quite restrictive. Some of the most frequently used open source licenses that will be reviewed are:

The matrix groups together six of the most frequently used open source licenses based on their salient obligations. Please note that this is not an exhaustive explanation and it should not be construed as legal advice. Please consult with an attorney.

Lessons Learned
GPL violations and other open source license violations occur on a regular basis even if unbeknownst to the offender. The lawsuits in 2009 demonstrate that licensees cannot simply ignore their open source licensing obligations. As seen in this article, licensors are willing to enforce the terms of the licenses in a court of law. The lawsuit against Best Buy et al highlights the importance of understanding what OSS is, taking inventory of what OSS is included in each product, what licensing obligations apply, and compliance with these obligations. This process can be facilitated by IP audits, now made easier with automated source code scanning tools that analyze and identify the presence of open source code, IP ownership, and what type of license applies.

It's become common in many industries for products to contain hundreds and thousands of software components, so companies will increasingly seek assurances of clean IP. The Cisco-FSF saga described earlier, serves as a cautionary tale to acquirers, targets and other stakeholders in the software food chain that IP audits should be conducted not only during the due diligence phase preceding a closing, but also throughout the product life cycle from conception.

More Stories By Katherine Chin Quee

Katherine Chin Quee is a legal consultant at Protecode, a provider of software IP audit services and solutions for software governance and Intellectual Property (IP) management. She has a Bachelor of Commerce degree with a concentration in Information Technology Management, a Juris Doctor from the University of Toronto, and a Master of Laws in Intellectual Property Law from Benjamin N. Cardozo School of Law.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
DXWorldEXPO LLC announced today that Big Data Federation to Exhibit at the 22nd International CloudEXPO, colocated with DevOpsSUMMIT and DXWorldEXPO, November 12-13, 2018 in New York City. Big Data Federation, Inc. develops and applies artificial intelligence to predict financial and economic events that matter. The company uncovers patterns and precise drivers of performance and outcomes with the aid of machine-learning algorithms, big data, and fundamental analysis. Their products are deployed...
Dynatrace is an application performance management software company with products for the information technology departments and digital business owners of medium and large businesses. Building the Future of Monitoring with Artificial Intelligence. Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more busine...
All in Mobile is a place where we continually maximize their impact by fostering understanding, empathy, insights, creativity and joy. They believe that a truly useful and desirable mobile app doesn't need the brightest idea or the most advanced technology. A great product begins with understanding people. It's easy to think that customers will love your app, but can you justify it? They make sure your final app is something that users truly want and need. The only way to do this is by ...
CloudEXPO | DevOpsSUMMIT | DXWorldEXPO are the world's most influential, independent events where Cloud Computing was coined and where technology buyers and vendors meet to experience and discuss the big picture of Digital Transformation and all of the strategies, tactics, and tools they need to realize their goals. Sponsors of DXWorldEXPO | CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities.
Digital Transformation and Disruption, Amazon Style - What You Can Learn. Chris Kocher is a co-founder of Grey Heron, a management and strategic marketing consulting firm. He has 25+ years in both strategic and hands-on operating experience helping executives and investors build revenues and shareholder value. He has consulted with over 130 companies on innovating with new business models, product strategies and monetization. Chris has held management positions at HP and Symantec in addition to ...
The challenges of aggregating data from consumer-oriented devices, such as wearable technologies and smart thermostats, are fairly well-understood. However, there are a new set of challenges for IoT devices that generate megabytes or gigabytes of data per second. Certainly, the infrastructure will have to change, as those volumes of data will likely overwhelm the available bandwidth for aggregating the data into a central repository. Ochandarena discusses a whole new way to think about your next...
Cell networks have the advantage of long-range communications, reaching an estimated 90% of the world. But cell networks such as 2G, 3G and LTE consume lots of power and were designed for connecting people. They are not optimized for low- or battery-powered devices or for IoT applications with infrequently transmitted data. Cell IoT modules that support narrow-band IoT and 4G cell networks will enable cell connectivity, device management, and app enablement for low-power wide-area network IoT. B...
The hierarchical architecture that distributes "compute" within the network specially at the edge can enable new services by harnessing emerging technologies. But Edge-Compute comes at increased cost that needs to be managed and potentially augmented by creative architecture solutions as there will always a catching-up with the capacity demands. Processing power in smartphones has enhanced YoY and there is increasingly spare compute capacity that can be potentially pooled. Uber has successfully ...
SYS-CON Events announced today that CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5–7, 2018, at the Javits Center in New York City, NY. CrowdReviews.com is a transparent online platform for determining which products and services are the best based on the opinion of the crowd. The crowd consists of Internet users that have experienced products and services first-hand and have an interest in letting other potential buye...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...