Showing posts with label clipperz. Show all posts
Showing posts with label clipperz. Show all posts

Saturday, June 14, 2008

GPL Project Watch List for Week of 06/13

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for June 7th through June 13th, 2008.

This Week:

  • Week Summary
  • New Projects
  • FOSS licenses based on US Copyright law
  • User Contributions

Two More Weeks...

Only two weeks until the anniversary of the GPL v3 license and the creation of this tracking project. We have come a far way and continue to bring relevant and accurate license information. We hope you have made use of our data and have enjoyed reading our blog.

This week our GPL v3 count is at 2592 GPL v3 projects, and increase of 59 GPL v3 projects. There was speculation as to whether the AGPL v3 would draw projects from the GPL v3 conversion rates, but this does not seem to be happening. The AGPL v3 count is up 7 projects bringing it to 109 AGPL v3 projects. The LGPL v3 number is at 251 LGPL v3 projects, up 9 projects from last week.






















New project conversions this week include:
  • EasyVote: EasyVote is a new easy to use, secure and transparent cryptographic online voting scheme for small elections (up to 500 voters).
  • ERP4U: ERP4U / ERP for You / Enterprise Resource Planning for You -- Enterprise Resource Planning web based platform implemented on top of Ruby on Rails.
  • Bluetooth Remote: Control your computer using a bluetooth enabled mobile phone. Move the mouse cursor send key strokes and control the most common applications such windows media player, internet explorer, firefox.

The Open Source "Market" Killed the Tools Market
Though open source tools can be sold, many are offered for free by developers. The open source market is an odd one since the price of the code is, for the most part, just the time to download the software. The fact the most open source code is offered for free makes competition extremely hard you can imagine, which is a gripe of some commercial developers.

In a recent article, John De Goes argued that
"The tools market is dead. Open source killed it." Open source has cut costs exponentially for developers, however they are restricted to the licensing terms of the code, which usually keeps it free and open. With so many open source tools now available for free, it restricts commercial companies from using price as a competitive tool since the open source alternative cost zero. So to be able to charge anything for a developer tool, the product would have to be significantly better than the open source alternative. Goes says that this also has a catch to this as well. The cost to learning a new IDE is quite high for most developers, since they are already use to the workings of their current one.

But is killing the tools market really such a bad thing. The death of the tools market was brought about from the birth of the open source market, and those in the open source market would argue that the benefits outweigh the loss. With open source, sharing code has eliminated countless hours rewriting code to do the same exact thing. And though this makes it nearly impossible to charge for your software, the creation of it is significantly easier.

Ohloh is a good site to put things into perspective. On their site, they show the projected cost of the project if it was done from scratch. Right away you can see that some projects would cost millions if not for open source. Subversion, for example, is projected to cost 5.2 million if a team was to write the code themselves. With these gains in cost efficiency, I would say the death of the tools market isn't so sad.

References:
http://www.ohloh.net/projects/subversion
http://tech.slashdot.org/article.pl?sid=08/06/10/0228220&from=rss

-Antony Tran


Thanks for the Continued Support and Contributions
Our database is partly maintained by our team of researchers as well by the contributions that are received from the community. Here is a submission we received last week through our web interface:

****************************************************************************
ApacheMap


Description:
The perl script parses a apache or apache2 combined access log for the IP addresses. It then looks up a Geo-Tag for those locations and if successful it adds them to a data file which the Google maps API then displays. So you get all your unique resolvable hits plotted on a map. From 0.3a onwards new style blue markers are used which contain information about the location when clicked on.


Newest Release:
apache-geo-map-0-6b.tar.gz

****************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Much Appreciated,

Palamida R&D Group


Notable Mention
Palamida actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to the almost 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.


The Research Group (rdgroup@palamida.com)
  • Ernest Park
  • Antony Tran
  • Kevin Howard

********************************************************************************************************
For more information, go to http://gpl3.blogspot.com.

To stop receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "unsubscribe".

********************************************************************************************************

The GPL3 project, sponsored by Palamida, Inc (http://palamida.com ), is an effort to make reliable publicly available information regarding GPLv3 license usage and adoption in new projects. The work published on both sites listed below is licensed This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License .

********************************************************************************************************

Palamida was launched in 2003 after its founders learned first-hand what happens when companies don't have full visibility into the code base of their software applications based on Open Source Software. Their experiences inspired them to create a solution to streamline the process of identifying, tracking and managing the mix of unknown and undocumented Open Source that comprises a growing percentage of today's software applications. Palamida is the industry's first application security solution targeting today's widespread use of Open Source Software. It uses component-level analysis to quickly identify and track undocumented code and associated security vulnerabilities as well as intellectual property and compliance issues and allows development organizations to cost-effectively manage and secure mission critical applications and products.

For more information about FOSS management solutions, go to http://palamida.com, or send a note to sales@palamida.com. Please mention the GPL3 site when you reach out to Palamida.






Saturday, June 7, 2008

GPL Project Watch List for Week of 06/06

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for May 31st through June 6th, 2008.

This Week:

  • Week Summary
  • New Projects
  • FOSS licenses based on US Copyright law
  • User Contributions

Almost A Year Has Passed
The year has gone by quite quickly since the GPL v3 was first released. We have just entered into the month of the release, and it is only 23 days until a complete year has passed. It doesn't seem like we have been tracking the GPL v3 and its derivatives for a year, but it is more believable when you look at the count. Cumulatively, the GPL v3 and its derivatives have gained over 2800 adopters, which is an impressive number. Thousands of projects have, and now we can more confidently say thousands more will adopt the GPL v3, proving its significance in the open source community. The GPL v3 alone is now at 2533 GPL v3 projects, an increase of 62 GPL v3 projects. The AGPL v3 has gained 2 new projects, and is now at 102 AGPL v3 projects. And the LGPL v3 is now at 242 LGPL v3 projects. These numbers are considerably large and are still growing by the day. We will do a year summary to review all the key points over the past year for the anniversary of the GPL v3.






















New project conversions this week include:
  • kjscompress: Command line tool to compress and obfuscate Javascript code and compress CSS code. (Based on KJS -- Javascript library included in KHTML.)
  • IT-Inventory: IT Inventory is a web based system for inventorying computers and other IT based equipment. You can also track repair orders for computers.
  • MySXP Open Platform: Application SAP like for win32, based on MySQL,and mixed with the egroupware politics and database compatibility.

FOSS licenses based on US Copyright law

Since most, if not all, US-based FOSS licenses are based on US Copyright law as defined in the US Constitution, all have this same "life of the creator plus 70 years" term, so length alone is not an advantage. Also, a work or creation is considered to be "copyrighted," at least under US law, as soon as it is "fixed in a tangible medium," which can mean bits saved on a magnetic disk. So while something may be "copyrighted," it is more difficult to enforce a copyright without a written registration with the US Copyright Office. Compare proving in a court of law that you "own" electronically distributed code merely by saying that you created it with being able to have documented proof that you are the author and registered the work on a particular date. To be in technical compliance with US Copyright law, and to maintain a copyright registration, the creator of a software project would probably have to periodically re-register the work as it grew and progressed, since adding new code is adding new "creative elements" which are in themselves copyrightable, but also change the original work enough so that it is something entirely different, thus requiring a new copyright.

In my opinion, it is actually a disadvantage to not license a work and leave it up to US Copyright law. If you look at the rights granted under US Copyright law ( http://www.copyright.gov/circs/circ1.html#wci ) you can see that the first three of those rights (right to reproduce, right to prepare derivative works, and right to distribute copies) seem to be pretty easily applicable to software code, but were obviously not originally conceived with electronic bits traveling around the Internet in mind.

So, not only do they not quite fit, they are fairly restrictive in terms of only granting any of these rights to the original creator of the work. So, before anyone can perform any of the "rights" related to the "work" granted to the original copyright holder, the original copyright holder must give permission. Combine the clunkiness of this method of permission with the instantaneous worldwide distribution system of the Internet and you have an unmanageable mess of trying to coordinate and keep track of who has what rights. Remind you of anything? Digital music?

FOSS licenses are written specifically for software code and define, to varying degrees, what can be done with that code and by whom. FOSS licenses are used by the holder of an original copyright in a creative software "work" to grant the permission ("license") mentioned above to others for others' use. FOSS licenses actually improve the efficiency of the open source movement. Keep in mind that the same rights granted under US Copyright law that are the foundation of FOSS licenses are the same rights that are the foundation of closed-source and proprietary licenses, so you can see that the structure of any given license can lead to dramatically different outcomes for what happens to software code depending on how various rights are granted or restricted.

-Kevin Howard


Thanks for the Continued Support and Contributions
Our database is partly maintained by our team of researchers as well by the contributions that are received from the community. Here is a submission we received last week through our web interface:

****************************************************************************
Gloss


Description:
Gloss is intended to be a drop-in replacement for the existing MythTV frontend. It is written in Python however uses the Clutter OpenGL framework with the intent of producing a visually richer interface than the existing MythTV frontend.

Newest Release:
gloss-0.1-rc1.tar.gz
****************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Much Appreciated,

Palamida R&D Group


Notable Mention
Palamida actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to the almost 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.


The Research Group (rdgroup@palamida.com)
  • Ernest Park
  • Antony Tran
  • Kevin Howard





Monday, June 2, 2008

GPL Project Watch List for Week of 05/30

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for May 24th through May 30th, 2008.

This Week:

  • New Projects
  • Clipperz Follow Up
  • AGPL v3 Hits 100 Projects
  • User Contributions

Congrats to the Grads
For those of you in school or have children that are, graduation has just passed for some or is soon approaching. We would like to congratulate all the graduates and wish you the best of luck in you career, especially if it involves open source *wink*.

This week our GPL v3 projects has grown to 2471 GPL v3 projects, which is in increase of 44 new GPL v3 projects. Our AGPL v3 count has just hit its first benchmark of 100 AGPL v3 projects, with the 5 new AGPL v3 projects that were added over the past week. And lastly, the LGPL v3 count is now at 236 LGPL v3 projects, in increase of 16 new LGPL v3 projects.



















New project conversions this week include:
  • pion-platform: a development platform for Complex Event Processing (CEP)
  • freyrms: Based on OdinMS, FreyrMS strives to improve the functionality of the OdinMS Project.
  • domac: text edit/macro language, similiar to awk,sed, or m4. It can be embedded in other languages and allows comments anywhere, even inside instructions.

Follow up:
What is "zero-knowledge", and what does it mean to the growth of web services and information security?
From Marco Barulli, Clipperz

Dear Ernest, I'm happy to inform you that Richard Stallman finally agreed with the

"call for action" that I published on the Clipperz blog today.

It's a three step plan that combines free software (AGPL)

and the
zero-knowledge architecture.

http://www.clipperz.com/users/marco/blog/2008/05/30/freedom_and_privacy_cloud_call_action
I am glad to say that you saw it here first.

Is this important? Sure it is. Marco Barulli is taking the risk of blazing the trail for web services developers to come. Is AGPLv3 the right license? Who knows. Is "zero-knowledge" the right architecture? Maybe yes, maybe no.
  • Zero-knowledge architecture is a web services framework in which secure information is distributed only to the endpoint, the service, through a secure and reliable framework that does not allow disclosure or residual existence of any user specific information.
  • In a service framework, providers enabling the connection from a user to the target service may have access to secure and potentially user specific data.
  • The zero knowledge architecture is one in which programmatic architecture and tools are put in place to hide and encrypt data in a format only usable by the intended service.
  • The AGPLv3 assures that the architecture and the source code is transparent and available for scrutiny, thereby insuring a clear implementation of secure practice that can be monitored and verified by the community.
  • While we as users get in the practice of complacency and trust, the idea of "zero-knowledge" allows the user to validate the secure and reliable implementation of security and data protection practices.
An interesting key point is the browser, our gateway to an OS neutral world of services.
  • The browser would need to let the user control how web service code, in this case, Javascript, is loaded, validated and run. While I can go into more detail here, Mr. Barulli does an excellent job of explaining here.
What is new here?
Clipperz is trying to provide an architectural guideline for how to develop and deploy web services that have an inherent high security, and a set of tools as a valuable starting point. Additionally, the idea that a user does not have to trust the developer or service provider for the protection of private data is smart. Is this novel? No. Is it needed? Of course. "Zero-knowledge" architecture is based on old ideas applied to a new web services paradigm. Trust nobody, encrypt, and double check everything. Clippers and the zero-knowledge concept is an old idea finding a proper place to start talking about transparent architecture which puts the responsibility of information security in the hands of the users. Is it perfect? Maybe yes, maybe no. It is licensed under AGPLv3, so Marco Barulli is inviting the community to grow what he started. Simple idea, great initiative. Well done.


AGPL v3 Hits 100 Projects
As stated in our project summary, the AGPL v3 has hit 100 projects by our count as of this week. This is an important benchmark for the license, seeing as it was uncertain if projects would want to adopt this derivative of the GPL3. 100 projects is by no means a large support group, out of the hundreds of thousands of projects, but it is a first step. This benchmark shows that the extra clause in the AGPL v3 that closes the ASP loophole, which requires "software as a services" to also release its code modifications is an important issue. Hitting this benchmark along with Clipperz proposed AGPL suite might just act as a catalyst to make the AGPL v3 a significant license in the open source community.


Thanks for the Continued Support and Contributions
Our database is partly maintained by our team of researchers as well by the contributions that are received from the community. Here is a submission we received last week through our web interface:

****************************************************************************
Sinatra


Description:
Sinatra is a free karaoke game for GNU/Linux. Sinatra puts your voice on top of the note sheet and gives you score for matching it good. Beat your own scores or battle in a duet, trio or quartet with friends and several microphones and sound cards. Sinatra was released February 16.

Newest Release:
Sinatra 1.0
****************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Much Appreciated,

Palamida R&D Group


Notable Mention
Palamida actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to the almost 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.


The Research Group (rdgroup@palamida.com)
  • Ernest Park
  • Antony Tran
  • Kevin Howard

The GPL3 project, sponsored by Palamida, Inc (http://palamida.com ), is an effort to make reliable publicly available information regarding GPLv3 license usage and adoption in new projects. The work published on both sites listed below is licensed This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License .

For more information, go to http://gpl3.blogspot.com.
To stop receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "unsubscribe".



Friday, May 23, 2008

GPL Project Watch List for Week of 05/23, Special Interview With Marco Barulli From Clipperz

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for May 17th through May 23rd, 2008.

This Week:

  • Interview With Marco Barulli on Their New AGPL Suite
  • GPL v3 Numbers
  • New Projects

Interview With Marco Barulli on Their New AGPL Suite
This week we had the privilege of having a special interview with Marco Barulli, co-founder of Clipperz (
http://www.clipperz.com/
), who is working on a suite of web applications that are all under the AGPL. Clipperz, for those of you who are unfamiliar with the project, is a free and anonymous online password manager, and now they are working on a new open source project, and we have the first scoop. The Clipperz Community Edition was one of the first, if not the first, large project to adopt the Affero GNU General Public License and their group is a leading proponent of the license. In our interview, we gained insight to Clipperz stance on the AGPL, and we found out more information on their new suite.

Q: Why did Clipperz choose AGPL?

A: Clipperz source code has always been available under a reference
license in order to perform security reviews of our [online password
manager][1]. (Nobody should consider using a cryptography based
software solution that does not provide the source code! See the
[Kerckhoffs' principle][2].)

But then we felt that it was more appropriate to adopt an open source
license for several reasons:

1) coherence with our approach of complete transparency on any front:
code, money, strategies, ...

2) increase the chances to attract developers interested in writing
"zero-knowledge web apps" and improving the underlying crypto
libraries.

And eventually the advent of AGPL v3 provided the long awaited legal
framework for the protection of our code. Thanks FSF!

[1]:
http://www.clipperz.com/
[2]: http://en.wikipedia.org/wiki/Kerckhoffs%27_principle

Q: Why are you launching a project that aims to build a suite of AGPL
licensed web applications?

A: Because today I can easily make my choices between Photoshop and Gimp,
Internet Explorer and Firefox, between free and proprietary software.
But the programs I use are steadily and quickly moving from my
computer to the web. In this transition I gain a lot (ubiquitous
access, seamless upgrades, reliable storage, ...), but I lose the
freedom to study, modify and discuss the source code behind my
programs.

Using web applications with an AGPL license, the above freedom is preserved.

You can think of this project as a GNU Project for the web, a set of
web applications that provides tools for the most common needs.
The suite should include: word processor, web chat, password manager,
wiki, address book, to do list, calendar, bookmark manager, ... But
each web apps must be released under an AGPL license! So forget
Google, del.icio.us, Plaxo, Meebo, ... at least unless they switch to
AGPL.

While the GNU Project was targeted mainly to software developers and
advanced computer users, the "AGPL suite" could bring free software to
the average user.

I'm aware it's a bold and probably not well thought out initiative,
but ... I like it!

Q: What is the link between this new project focused on AGPL and the
zero-knowledge architecture introduced by Clipperz?

A: The "AGPL suite" is only the first step on a path to bring more
freedom and privacy to the world of web applications.

At Clipperz we envisioned a new architecture paradigm called
"zero-knowledge web apps" (here a more [detailed description][3]) that
combines the idea of browser-based cryptography with a set of rules
focused on the "learn nothing" mantra.

[3]:
http://www.clipperz.com/users/marco/blog/2007/08/24/anatomy_zero_knowledge_web_application

The name was both an homage to cryptography (a "zero-knowledge proof"
is a standard cryptographic protocol) and a promise of a specific
relation between the application provider and the users. The server
hosting the web app would know nothing of its users, not even their
usernames!

Clipperz built its [online password manager][1] as the first
zero-knowledge web app and it worked quite well. Therefore it would be
wonderful to apply zero-knowledge techniques to each component of the
above "AGPL suite".

Converting an existing web applications to the zero-knowledge
architecture is not easy, but at Clipperz we have a considerable
experience on the subject and we will be happy to share our knowledge
and code base.

We grew accustomed to trust web applications with our data (bookmarks,
text documents, chats, financial info, ... and now [health
records][4]). Now it's time to to regain complete and exclusive
control of our programs and our data.
AGPL plus zero-knowledge architecture could do this!

[4]:
http://googleblog.blogspot.com/2008/02/google-health-first-look.html


On to Our Numbers

We hope you enjoyed the interview with Marco Barulli. Maybe this early exposure to their new suite will bring more attention and projects to the AGPL to help them compile their suite. Speaking of which, our database now contains 95 AGPL v3 projects, up 9 AGPL v3 projects from last week and approaching its first benchmark of 100 AGPL v3 projects. The GPL v3 count is now at 2427 GPL v3 projects, an increase of 56 GPL v3 projects. And lastly, our LGPL v3 count is at 220 LGPL v3 projects.






















New project conversions this week include:
  • cvtool / CVL: CVL is a library for image and data processing using graphics processing units (GPUs). Cvtool is a general-purpose computer vision tool that is based on the CVL library.
  • Celerity: Celerity is a JRuby library for easy and fast automation of web application testing.
  • OpenVista: OpenVista is the open-source version of VistA, which is an enterprise grade health care information system developed by the U.S. Department of Veterans Affairs (VA) and deployed at nearly 1,500 facilities worldwide.

Notable Mention
Palamida actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to the almost 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.



The Research Group (rdgroup@palamida.com)
  • Ernest Park
  • Antony Tran
  • Kevin Howard