Showing posts with label free software. Show all posts
Showing posts with label free software. Show all posts

Tuesday, January 13, 2009

2008: The Risk Report

The Research Group has developed

tools that objectively track and report on operational risk associated with software applications, operating systems and hardware.

I have seen a number of “Most Risky” lists that seem to be subjective and crafted by nothing more than a few Google searches and a popularity contest. In response, here is a "Top 10" list, filtered for Applications, sorted by overall vulnerability per issue, weighted by age of issue.




Top 10 Applications
  1. Microsoft Internet Explorer
  2. Mozilla Firefox
  3. PHP
  4. Mozilla Seamonkey
  5. Mozilla Thunderbird
  6. Microsoft Office
  7. Apple Quicktime
  8. BEA Weblogic Server
  9. Apple Safari
  10. Joomla

Top 25 Overall

Why 25? It is easier to show that software risk is time sensitive, objective and accurate with a larger list. My current list as of this week tracks 14813 products from almost as many vendors.

Our risk metrics are collected automatically and sorted. Members of the team correct discrepancies introduced by bad data, and then the results are generated using statistical queries on MySQL.

http://nvd.nist.gov is the official datasource for the risk information.

The ordered output is generated by an algorithm that scores a weighted value for each CVE based on the risk and age of that CVE, and then totals all the weighted CVEs across the life of a product. Such total scores are then compared one to another. In this way, an application that has been out for a very short time could make the top of the list if it had more security issues of high criticality over its release life than most applications.

The complete report segments out software by type (hardware, application, OS, platform), license (commercial, FOSS) and is generated weekly. The results are then compared to NVD’s Workload Index calculation in order to give an IT manager an accurate understanding of resource requirements to manage software issues. The report is available for a reasonable fee. To subscribe to the complete report, send an email to risk_report@airius.com.


Top 25 Software

  1. Apple Mac OS X
  2. Microsoft Internet Explorer
  3. Linux Kernel
  4. Mozilla Firefox
  5. Sun Solaris
  6. Microsoft Windows 2000
  7. Apple Mac OS X Server
  8. Microsoft Windows XP
  9. PHP PHP
  10. IBM AIX
  11. Microsoft Windows Server 2003
  12. Mozilla SeaMonkey
  13. HP HP-UX
  14. Mozilla Thunderbird
  15. Microsoft Office
  16. SuSE SuSE Linux
  17. Microsoft Windows NT
  18. Apple Quicktime
  19. FreeBSD FreeBSD
  20. BEA Systems WebLogic Server
  21. Red Hat Linux
  22. Gentoo Linux
  23. Debian Debian Linux
  24. Apple Safari
  25. Joomla Joomla
UPDATE: For the FOSS (free and open source software) list, go to https://fossbazaar.org/content/2008-risk-report-foss.

What does this mean?
The lists review vulnerabilities reported historically to the National Vulnerability Database and sorts them. The reported vulnerabilities are weighted by their individual risk, then weighted by their historic age, where newer issues are more relevant than older issues, all else being the same.

The "percentage" is a relative metric, where the "most vulnerable" application for a report is scored 100%. All other software is scored relative to the 100%.

Is this software bad?
No. What you see is that open source and proprietary software both have issues. The risk seems to directly correlate with the complexity of the software type. Operating systems are inherently very complex, and always are very high on reported vulnerabilities. Notice that regardless of the license type, the level of relative risk is comparable by software type. What this seems to indicate is that complex software takes diligent effort to write, debug, and manage in an operational environment, regardless of the licensing that the software is distributed under. My team has tracked the resolution intervals relative to reported issues. What we saw as we started monitoring the publicly available data is that a well used and available forum drives awareness to issues, and indirectly facilitates rapid resolution for complex software, regardless of licensing.

So which application is the worst?
Software risk is a way of highlighting the management requirements imposed by software within an environment. Complex software may impose a greater management load than simple software. Tracking risk and vulnerabilities is a way that security and infrastructure managers can predict and deploy people and processes to actively manage the issues associated with certain types of software.

Risky software is not bad?
Tires wear out over time, asphault roads need to be repaved frequently, roofs need to be replaced, plumbing leaks once in a while. The requirement to maintain systems and to expect systems to require greater maintenance based on what these systems do is normal. Expecting software to be without issues is unreasonable and naive.

Risk is good?
Of course it is. If risk management is a process of ongoing maintenance, a healthy and interactive commnity participating in the discovery and reporting of risk issues improves the software. Failing to manage complex software, regardless of free or proprietary licensing, that is risky.

What do I do?
Complex software needs to have strong support and an active community. It is a greater risk to use a complex application that has no reported vulnerabilities than one that has many issues. Use the best software for the task. It may be risky, based on discovered issues. Understand that if your management process includes testing, validation of reported issues, and application of patches as available, your risk is incredibly low. If you can update your running software within 30 days of patch releases, your exposure is minimal, and you have an objective process to use complex and quality software within your environment.

Define Policies and Enforce Them
Software exists to facilitate the identification of software and services. Know what you are using, understand what the average work effort is to manage the installed software in your environment, and then set policies to monitor the active management of such software.

Summary
Sotware is asked to do many things. Complex software is asked to do many complex and critical things. More quality software is created by less people, in less time and with less resources. Is the software worse than it ever was? No. The power of the community works to expose these issues and drive resolutions quickly. Accept the fact that software is evolutionary, put a management process in place to take advantage of the input from the community (testing, validation, qualitative review, network and security policy, education), apply qualified patches.

Clear information about software issues reduces operational risk if such information is put to use. The applications for which no information exists pose the greatest threat to security. Without community oversight and review, unknown applications have the opportunity to mistakenly slide under the radar while being large potential threats.

The riskiest software is the software that you don't know about.










************************************************************

Notable Mention

The Research Group actively takes submissions from visitors regarding stories, FOSS issues and project announcements. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to over 150 core contributors who have devoted their time and resources at helping us provide up-to-date information. Send your stories and announcements to rdgroup@airius.com.

We are proud to have hosted over 80 interns in the last year from the leading schools in the United States. If you would like to be considered for an internship, please send a note to rdgroup@airius.com. You will receive instructions regarding how to apply.

************************************************************

Subscription

For more information, go to http://gpl3.blogspot.com/. To stop receiving these weekly mailings, please send a message to rdgroup@airius.com with the subject "unsubscribe:gpl3". To start receiving these weekly mailings, please send a message to rdgroup@airius.com with the subject "subscribe:gpl3".

The Research Group (rdgroup@airius.com)

Ernest Park


Credits:

http://nvd.nist.gov

http://en.wikipedia.org/wiki/Vulnerability_(computing)














What happened to the GPL Project Watch List

In October 2008, our research project was hit with the same economic crunch that has been affecting businesses throughout our country. The members of the Research Group are proud of what we delivered for more than a year, and we are glad that we were given the opportunity to deliver this significant information.


In April 2007, my team proposed the possibility of tracking the adoption and use of existing and new FOSS licensing. A month later, we started to build the database and write the web application for the search site. The team of researchers started crawling the internet manually and using specialized tools that we built to find indications of use of the new GPLv3 license. By July 2, as of our first post, we found 82 projects that announced GPLv3 releases as of June 29, 2007. While the start seemed lackluster, overall adoption has been consistent over observed time, averaging 200 new GPLv3 project releases monthly, with over 4000 current FOSS releases under GPLv3.

We started tracking GPLv3 information as of June 29, 2007, and continued to do so for 15 months. Our team included over 50 research interns from schools throughout our country, the project managers and me. We successfully provided clear and objective information regarding the acceptance and use of the new GPLv3 license, and extended the scope of our interest to report news and trends as well.

Our reports explained licensing, copyright, best practices, and garnered a strong readership over the time that we managed this information. While there are methods to collect and manage this information using automated tools, we found enough errors and imprecision in the data to raise doubt and uncertainty in the quality of data that is not manually reviewed. We built tools to optimize our ability to review data, but we still qualified all data that made it into our database.

We are now self sponsored and accepting sponsorship and contributions. The site will start publishing on a regular basis as before, and we hope to deliver timely and topical information. If you would like to help, contact us at sponsor@airius.com .























************************************************************

Notable Mention

The Research Group actively takes submissions from visitors regarding stories, FOSS issues and project announcements. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to over 150 core contributors who have devoted their time and resources at helping us provide up-to-date information. Send your stories and announcements to rdgroup@airius.com.

We are proud to have hosted over 80 interns in the last year from the leading schools in the United States. If you would like to be considered for an internship, please send a note to rdgroup@airius.com. You will receive instructions regarding how to apply.

************************************************************

Subscription

For more information, go to http://gpl3.blogspot.com/. To stop receiving these weekly mailings, please send a message to list@airius.com with the subject "unsubscribe:gpl3". To start receiving these weekly mailings, please send a message to list@airius.com with the subject "subscribe:gpl3".


The Research Group (rdgroup@airius.com)

Ernest Park

Edwin Pahk

Antony Tran

Kevin Howard



Credits:
1929 Stock Market Crash
President George Bush and Barack Obama











Saturday, October 11, 2008

GPL Project Watch List for Week of 10/10

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for September 26th to October 3rd 2008.

This Week:
  • Week Summary
  • New Projects
  • Follow up: Jacobsen and US Copyright Law
  • User Contributions

Making Progress
If you haven't noticed already, we'd like to welcome back a member to our team, Antony Tran. After a brief hiatus, he has agreed to come back on board to help us manage the blog and GPL3 project. Welcome back.

This week our GPL v3 count is at 3237 GPL v3 projects, an increase of 22 GPL v3 projects. The AGPL v3 count is at 181 AGPL v3 projects. The LGPL v3 number is at 345 LGPL v3 projects, an increase of 51 LGPL v3 projects.

















New project conversions this week include:
  • Multigrid Contact Detection: libmgcd is a multigrid contact detection (MGCD) library

  • euFileUpload: A module to upload files. To be used in web-based applications. Written in PHP

  • luckybackup: A powerful, fast and reliable backup & sync tool.

********************************************************************************
I wrote about FOSS licenses and U.S. Copyright law back in June, prior to the case of Jacobsen v. Katzer coming out in mid-August:

http://gpl3.blogspot.com/2008/06/gpl-v3-watch-list-is-intended-to-give.html

To update that post a bit, the Jacobsen decision deserves mention. The case dealt with code licensed under the Artistic License 1.0 which was used in another project without complying with the terms of the license. See the link below on techlawjournal.com for more background. The central question of the case was whether the terms of the license were "conditions" that limited the scope of the copyright license, as opposed to "covenants" which define the terms for the use of the code. The court concluded the terms were "conditions."

While this may seem insignificant or merely a semantic non-issue, the remedies available for noncompliance with the "condition" of an open source license form the basis of the entire FOSS movement. The significance is that if a "condition" is broken or not followed, the person who broke or did not follow the particular condition is no longer entitled to use of the software under the license terms and such use is therefore copyright infringement. A remedy for copyright infringement is injunctive relief which means the violator can be prevented from further use of the software under the license or be required to follow the conditions if further use is desired.

If a "covenant" is broken or not followed, such violation is considered merely a violation of a contract term, which means the remedy is monetary and *not* injunctive. In that case the violator would still have a license to use the software and would merely have to pay contract damages.

Injunctive relief allows copyright holders who license their works under FOSS licenses to preserve the desired attribution, modification and distribution rights, which protects the openness of the code and preserves the rights of downstream users to have access to the code for research, learning or improvement. Having this decision on the books, with its clear discussion not only of the license in question, but also of the FOSS movement and its benefits, will only help the movement grow.

-Kevin Howard

References:http://www.lessig.org/blog/2008/08/huge_and_important_news_free_l.html

****************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Link Partners
If you are willing to copy and tranlate the content weekly, please let me know - you will receive the content as soon as it is available, and you site will be listed as a translation. I can send you a bit of tracking code so that you get credit for your contribution to the readership of this site
Post your link on the bottom of the blog page.

Send me a note at rdgroup@airius.com that you are using some or all of the content
I will make sure that we host links to your sites, and we will be able to use your content within this site as well.

************************************************************

Notable Mention

The Research Group actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to over 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.

************************************************************

Subscription

For more information, go to http://gpl3.blogspot.com/.

To stop receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "unsubscribe:gpl3".

To start receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "subscribe:gpl3".

************************************************************

Our Sponsor, Palamida, Inc.

The GPL3 project, sponsored by Palamida, Inc (http://palamida.com/ ), is an effort to make reliable publicly available information regarding GPLv3 license usage and adoption in new projects.

The opinions expressed within the GPL3 Information Blog are exlusively those of Ernest Park, the subjects interviewed and the contributing authors, and are not intended to reflect the positions of Palamida, Inc and its employees.

This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License .

************************************************************

Palamida was launched in 2003 after its founders learned first-hand what happens when companies don't have full visibility into the code base of their software applications based on Open Source Software. Their experiences inspired them to create a solution to streamline the process of identifying, tracking and managing the mix of unknown and undocumented Open Source that comprises a growing percentage of today's software applications. Palamida is the industry's first application security solution targeting today's widespread use of Open Source Software. It uses component-level analysis to quickly identify and track undocumented code and associated security vulnerabilities as well as intellectual property and compliance issues and allows development organizations to cost-effectively manage and secure mission critical applications and products.

For more information about FOSS management solutions, go to http://palamida.com/, or send a note to sales@palamida.com.

Please mention the GPL3 site when you reach out to Palamida.


The Research Group (rdgroup@airius.com)

Ernest Park
Edwin Pahk
Antony Tran
Kevin Howard





Monday, September 15, 2008

GPL Project Watch List for Week of 09/12

The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for August 29th through September 12th, 2008.

This Week:
  • Week Summary
  • New Projects
  • FOSS issues and the 2008 U.S. Presidential Race
  • User Contributions
3000 Project Milestone

After over a year of tracking GPL3 adoption, we would like to announce that 3000 projects have adopted version 3 of the GNU GPL License. The strong adoption rate represented by this milestone shows the continued acceptance of this license by the Open Source and Free Software communities. We'd like to thank everyone that has been involved with this project. Without your hard work, none of this would've been possible.

This week our GPL v3 count is at
3000
GPL v3 projects, an increase of 69 GPL v3 projects. The AGPL v3 count is at 130 AGPL v3 projects. The LGPL v3 number is at 286 LGPL v3 projects, an increase of 13 LGPL v3 projects.













New project conversions this week include:
  • MLE - Mobile Learning Engine: MLE - The Mobile Learning Engine is a learning application for mobile phones written in Java (J2ME). It enables you to use your phone at anytime and at anyplace for computer-aided, multimedia-based learning. It is a content independent engine.

  • DataSync Suite: DataSync Suite is an open source platform for integrating tools like Zimbra, SugarCRM, Joomla, and KnowledgeTree. The tool is focused on a single sign-on, application data integration, and fast, flexible deployment.

  • EPG Record: This is a perl-gtk application to get a channel list from a dvb card, display it, and allow complex filtering of view. It also has extensive multi-channel recording capabilities based on the EPG display shown
*************
FOSS issues and the 2008 U.S. Presidential Race

There are many important issues in this presidential race. This is not a politically oriented blog, so we take no position and will leave the heated discussions for others, but we are interested in technology and software, so seeing as how technology is an "issue" in this political race, we thought we'd attempt to summarize where the candidates appear to stand on various technology issues related to software and code.

Neither candidate specifically mentions open source on his web page, but several prominent technology-related issues are common to both that can have an impact on software: Net neutrality, intellectual property protection and open standards with respect to online access to government services.

Net Neutrality
This issue deals with equal access to the Internet (no restrictions on types of devices or platforms) and equal opportunity to utilize the Internet once accessed. The availability of these two types of equality and openness provided by the original architecture the Internet is the primary reason so much innovation has occurred in technology and software over the last 30 to 40 years. Imagine if new, innovative devices had to be "approved" before being able to access the Internet, or if two software developers in a garage somewhere had a small web site that could never be found on the net because "prioritized" traffic bought by large media or existing commercial software companies drowns out the smaller players.

Both candidates appear to promote the idea of net neutrality, but take different approaches. John McCain does not support prescriptive regulation that would require net neutrality, preferring to allow a more "open marketplace" environment to provide a variety of choices to consumers. Barack Obama supports some type of legislation to protect the concepts embodied by net neutrality, namely to prevent network access providers from discriminating against those who won't or can't pay for "premium" access.

Intellectual Property Protection
This type of protection was originally intended to promote innovation and protect inventors and creators. It seems that more and more, our intellectual property laws are being used by content owners offensively to restrict others instead of to promote innovation and creative uses of existing ideas. However, some form of intellectual property protection is necessary to allow inventors and creators to profit from their work, so this is a delicate balance that must be managed.

Both candidates state they want to protect the IP rights of inventors and creators, both domestically and internationally. Both appear to recognize the balance between the extremes of content protection and the promotion of innovation, and that may be the extent of what we will hear about this issue.

Open Access to Government Services
This issue is pretty straightforward, but its implementation could say a lot about the attitude of each candidate toward technology. Most every government agency now has a web site that provides information to anyone who visits. Both candidates support this, and support expanding this type of access and increasing the participation of the citizenry in the process of government through increased access to broadband services.

Barack Obama's web site mentions the phrase "universally accessible formats" when it describes making government data available online. This is a critically important phrase, and is how open source can tie into this, as well as other technology issues. A "universally accessible format" is not necessarily an "open source" one, but by definition, open source formats should be universally accessible. The advantage of the open source philosophy here is that anyone can see the parameters and requirements of a particular format, and the particular format itself does not need to be tied to any particular entity, company or developer. A "format" that is "closed source" and proprietary is not available for scrutiny, customization or interpretation, and may be available only to developers within a single entity or company.

When handling the data of a government entity that will presumably continue operating for many generations to come, the ideal way to provide such data is in a format that is open and available to everyone. This includes backwards compatibility for older formats. Proprietary closed formats created by one entity or company create a disadvantage for those wishing to read data in a particular format that was discontinued years ago when the company that created the format went out of business.

Conclusion
While technology is one of the issues on the table for both candidates, other bigger issues will likely overshadow it this election. However, keep the ideas of equal access, the balancing of protection and innovation, and open standards in mind in the coming months when evaluating your candidate.

-Kevin Howard

References:
http://www.barackobama.com/issues/technology/
http://www.johnmccain.com/Informing/Issues/cbcd3a48-4b0e-4864-8be1-d04561c132ea.htm
http://en.wikipedia.org/wiki/Net_neutrality
http://news.cnet.com/8301-13578_3-9864581-38.html

****************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Link Partners
If you are willing to copy and tranlate the content weekly, please let me know - you will receive the content as soon as it is available, and you site will be listed as a translation. I can send you a bit of tracking code so that you get credit for your contribution to the readership of this site
Post your link on the bottom of the blog page.

Send me a note at rdgroup@airius.com that you are using some or all of the content
I will make sure that we host links to your sites, and we will be able to use your content within this site as well.

************************************************************

Notable Mention

The Research Group actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to over 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.

************************************************************

Subscription

For more information, go to http://gpl3.blogspot.com/.

To stop receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "unsubscribe:gpl3".

To start receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "subscribe:gpl3".

************************************************************

Our Sponsor, Palamida, Inc.

The GPL3 project, sponsored by Palamida, Inc (http://palamida.com/ ), is an effort to make reliable publicly available information regarding GPLv3 license usage and adoption in new projects.

The opinions expressed within the GPL3 Information Blog are exlusively those of Ernest Park, the subjects interviewed and the contributing authors, and are not intended to reflect the positions of Palamida, Inc and its employees.

This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License .

************************************************************

Palamida was launched in 2003 after its founders learned first-hand what happens when companies don't have full visibility into the code base of their software applications based on Open Source Software. Their experiences inspired them to create a solution to streamline the process of identifying, tracking and managing the mix of unknown and undocumented Open Source that comprises a growing percentage of today's software applications. Palamida is the industry's first application security solution targeting today's widespread use of Open Source Software. It uses component-level analysis to quickly identify and track undocumented code and associated security vulnerabilities as well as intellectual property and compliance issues and allows development organizations to cost-effectively manage and secure mission critical applications and products.

For more information about FOSS management solutions, go to http://palamida.com/, or send a note to sales@palamida.com.

Please mention the GPL3 site when you reach out to Palamida.


The Research Group (rdgroup@airius.com)

Ernest Park
Edwin Pahk
Kevin Howard

Tuesday, August 26, 2008

GPL Project Watch List for Week of 08/22


The GPL v3 Watch List is intended to give you a snapshot of the GPLv3/LGPLv3 adoption for July 25th through August 22nd, 2008.

This Week:
  • Week Summary
  • New Projects
  • Are Software Patents Incompatible With Open Source And Free Software Ideals?
  • License Proliferation: Less is more, one is best
  • User Contributions
The GPLv3 team

We would like to thank everyone for their continued support of the GPL3 project. Currently, we are transitioning not only managers, but the GPLv3 collection team as well. Along with former manager Antony Tran and current manager Edwin Pahk, the GPLv3 project has been maintained and supported by a number of interns checking hundreds of projects daily to provide the OSS community a reliable source for GPLv3 adoption. As we move forward, we will be restaffing our team and reviewing our approach. We thank you for your patience during this time.

This week our GPL v3 count is at 2931
GPL v3 projects, and increase of 56 GPL v3 projects. The AGPL v3 count is at 130 AGPL v3 projects. The LGPL v3 number is at 273 LGPL v3 projects.
















New project conversions this week include:
  • Voice Keyboard: Voice keyboard/dictation. Aims to be a total substitute for a keyboard. Spell out words letter by letter (using code: alpha, bravo, ..). Arrow keys, modifiers work. Speak whole words (but whole word accuracy is not good). Attach commands to some words.

  • OpenModeller: openModeller is a static spatial distribution modelling tool originally conceived to predict species distribution (fundamental niche).

  • Sudoku Savant: A simple GUI-driven application to solve and generate sudoku puzzles through logical means. Also supports manual solving, with pencil marks and cell colouring. Should be able to solve any standard sudoku from a newspaper or magazine.
*************
Are Software Patents Incompatible With Open Source And Free Software Ideals?

The following discussion includes descriptions of legal concepts. This is not intended, and should not be interpreted as, legal advice. If readers have questions about software law, copyright or patents, please consult an appropriate attorney.

In the context of open source and free software, copyright is quite possibly a necessity as many, if not all, open source and free software licenses are based on United States copyright law or copyright concepts. Copyright protects original creative works, which includes software code. Copyright protects a particular form of expression. Defining and protecting such creative works allows the author to receive appropriate attribution for the work as well as a certain level of profit, if that is what the author desires. The terms of a copyright license can be used to "enforce," or protect certain rights as well as restrict rights, and this is one of the main purposes of open source and free software licensing.

The concept of patent is similar to copyright, but based on a different rationale. Patents have historically been granted to inventions in the form of a physical device or a particular process that performs some specific task in a new and useful way. As opposed to copyright, which protects a particular expression of an idea, patent protects the process, the machine or operating object itself that performs the useful task. The concept of patent protection has been extended to include software code. While code has no physical manifestation, when written, arranged and executed in a specific way it certainly creates a process that can accomplish a useful task, so the argument has been made that software is patentable.

Both copyright and patent holders can grant licenses for their various works and inventions, so why the controversy over software patents? The granting of a patent gives the patent holder a complete monopoly on whatever process the patent covers. This leads to one aspect of patents that is very different from copyright, which is there is no "fair use" of patented processes. Without a license, one simply cannot use a patented process or arguably anything substantially similar to the patented process. This in itself goes against the desire to encourage the sharing of code and ideas among programmers that is at the heart of the open source and free software movements.

Patents can have an anticompetitive effect also. The system for obtaining a patent as it currently exists is extremely expensive, often requiring an attorney who has specialized knowledge of the subject area covered by the proposed patent as well as years of time to obtain approval of the patent. In this regard, the system favors corporations with large budgets. Virtually no small developers have the ability to go through this process from a financial perspective, to say nothing of having to wait years before being able to actually put out a final, patented product. Another argument against software patents is that they can be used "offensively" by larger companies via patent lawsuits to impede developers of competing products. Not only is the time and expense required to defend a patent lawsuit enormous, the penalties for infringing a patent can be equally daunting.

Some OSS developers have begun creatively using their own software patents in a "defensive" manner by dedicating the patents to a "patent commons" to protect the code from being patented by others and enforced offensively against OSS developers, while protecting its use by the community. Others in the OSS community have taken it upon themselves to police software patents by looking for ways to invalidate some patents, such as by finding and publicizing "prior art," which is an example of the existence of the patented process or method prior to the granting of a particular patent. The existence of prior art puts the "inventiveness" of the patent into question, and can lead to revocation of the patent.

The ease of obtaining a copyright, as well as the ability to protect the rights granted to downstream developers via OSS licensing terms, makes it the best method for preserving OSS ideals. Patents appear to have too many costs, both practically and financially, to be useful in encouraging the sharing and development of software code. This is a complicated issue with many polarized viewpoints. See below for links to just some of these.

References and further information:http://perens.com/Articles/Patents.html
http://www.advogato.org/article/7.html
http://w2.eff.org/patent/wp.php-Kevin Howard


****************************************************************************

License Proliferation - less is more, one is best

Chris DiBona from Google suffered the slings and arrows of the OSS community when he rejected the AGPLv3 license for Google Code repository, citing license proliferation as one of hte reasons. Looking back, Chris challenged the wisdom of OSI years ago when he was on their board, still at the time fighting against yet another license.

An open source software license is specifically a copyright focused on types of use permitted for electronic media.

By introducing yet another license, it create more complexity to explain, understand, and enforce the use of software governed by these licenses.

The reality is that lack of clarity and confusing, or internally contradictory terms, makes the license potentially limited in worth, as the cost to actually enforce that license increases.

If we look at any open source software license, we realize that they all are governing copyright specific to the use of software.

Use type -
1. Copying: This is the term popularized by Free Software Foundation to describe the act of moving the software from a point of distribution to a local computer, solely for the purpose of personally using the software.

2. Distribution: Once software has been collected from a distribution point, the act of making it available, either by itself, repackaging, bundling, modifying configuration files specific to a platform, and then making the resulting software available for others to "copy".

3. Modification: When a user takes code that has been copied, and implements changes to the source code, such that the program is changed, and then makes the code available through a distribution channel for others to "copy".

4. Other: This refers to license clauses that set restrictions on actions of software uses for actions outside of the direct use, as described above, of the software. Typical "other" language defines restrictions of special restrictive language specific to the use of the original developer's name and branding in marketing done by a distributor/modifier of software copied.

Restrictions -
1. Limitations of liabilities, as is clauses
2. Advertising restrictions
3. Licensing fees, shared revenue, restriction of revenue activities
4. Export restrictions
5. and so on
6. Downstream licensing on modified code

"Restrictions" govern "use" type. Many restrictions also only exist for specific use type.
Revenue restrictions, downstream licensing requirements, and triggered by modification, and or distribution, as example.

Therefrore, if you are copying and distributing, many restrictions don't even apply.

In summary, open source software licensing has become needlessly complex, FUD evolves around rumors of compatibility and interoperability without consideration and understanding of use types and specific restrictions. Open source licensing is a copyright with specific use considerations, restrictions and terms defined within the license, rahter than by copyright law. The thousands of licenses that exist have complicated the issue of using open source software far too much than the issue requires. Practically, we need only one license that specifies the use types and associated governance. Anything beyong one simple license that we can clearly explain the use and restrictions around open source software fails the future use and growth of the adoption of such software.

Ernest Park
http://the-opensource.blogspot.com
http://gpl3.blogspot.com

*************************************************************************
We appreciate all the contributions that have been made, either through our form on our web page or by email, and we also like to hear why you are changing your project's license as in the email above. It gives us more insight into which direction license trends are moving. We will continue to post up user contributions to our blog each week, and we may quote parts of your emails. If you wish the email to remain private, just mention so and we will not disclose any part of it.

Link Partners
If you are willing to copy and tranlate the content weekly, please let me know - you will receive the content as soon as it is available, and you site will be listed as a translation. I can send you a bit of tracking code so that you get credit for your contribution to the readership of this site
Post your link on the bottom of the blog page.

Send me a note at rdgroup@airius.com that you are using some or all of the content
I will make sure that we host links to your sites, and we will be able to use your content within this site as well.

************************************************************

Notable Mention

The Research Group actively takes submissions from visitors on updates on new GPL v3/LGPL 3 projects. We are amazed at the number of submissions we have gotten to date, but even more so, we are incredibly grateful to over 100 core contributors who have devoted their time and resources at helping us provide up-to-date information.

************************************************************

Subscription

For more information, go to http://gpl3.blogspot.com/.

To stop receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "unsubscribe:gpl3".

To start receiving these weekly mailings, please send a message to rdgroup@palamida.com with the subject "subscribe:gpl3".

************************************************************

Our Sponsor, Palamida, Inc.

The GPL3 project, sponsored by Palamida, Inc (http://palamida.com/ ), is an effort to make reliable publicly available information regarding GPLv3 license usage and adoption in new projects.

The opinions expressed within the GPL3 Information Blog are exlusively those of Ernest Park, the subjects interviewed and the contributing authors, and are not intended to reflect the positions of Palamida, Inc and its employees.

This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 United States License .

************************************************************

Palamida was launched in 2003 after its founders learned first-hand what happens when companies don't have full visibility into the code base of their software applications based on Open Source Software. Their experiences inspired them to create a solution to streamline the process of identifying, tracking and managing the mix of unknown and undocumented Open Source that comprises a growing percentage of today's software applications. Palamida is the industry's first application security solution targeting today's widespread use of Open Source Software. It uses component-level analysis to quickly identify and track undocumented code and associated security vulnerabilities as well as intellectual property and compliance issues and allows development organizations to cost-effectively manage and secure mission critical applications and products.

For more information about FOSS management solutions, go to http://palamida.com/, or send a note to sales@palamida.com.

Please mention the GPL3 site when you reach out to Palamida.


The Research Group (rdgroup@airius.com)

Ernest Park
Edwin Pahk
Kevin Howard