EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

03.25.20

Microsoft Continues to Attack and Steal From the Open Source/Free Software Communities

Posted in Deception, Free/Libre Software, Microsoft at 12:42 am by Dr. Roy Schestowitz

Law-breakers won’t change their ways; they only optimise their PR strategy (and bribe more of the media to play along)

Microsoft Loved Linux.

Summary: Microsoft cannot be trusted and there’s no “new Microsoft,” as another fairly new story serves to show

“Shocked, Roy!”

So said a reader of ours, who used to work for Microsoft.

“Microsoft copies/steals lerna,” our reader summarised, pointing to this archived copy/snapshot of a page that’s now gone (although the Web site is still there).

We are gratified to see that more people from inside Microsoft are starting to see just how evil the company really us. I know of several such people, some of whom I speak to regularly. They have inside information and leads/tips.

It will be good for Techrights to make a copy anyone can find by searching. The original was removed. Sometimes Microsoft bribes or threatens to make this happen (e.g. threatening through one’s boss/customers). We covered examples of that in past years.

With the original deleted we think it would only be fair to reproduce the full message (the emphasis below is ours for the “tl;dr” crowd):

I think it’s time I publicly shared about how Microsoft stole my code and then spit on it.

I’d been waiting for them to do something about it, but that is clearly never happening.

When we were working on Babel 6, one of the big changes was to split everything up in to nice little plugin packages. However, this created a need to manage dozens of packages. Thus @lernajs was born
I picked up Lerna a little while later and focused on making it work well for design systems. I rewrote it like 5 times to try and get the architecture right.
Lerna then started getting picked up by others who also contributed back and added features. I enjoyed watching it grow and so I started looking out for users.
One day I came across a new design system from a team at Microsoft. I saw that it was made up of lots of small packages. I was excited and wondered “ooh is MS using Lerna?”
It turns out, no they were not. They were using this other thing called “Rush”. I hadn’t heard of it, but I was interested in seeing how it differed from Lerna.
I found the repo and started exploring. The first thing I noticed was how familiar all the code was. I could navigate the file structure very easily. I realised that it was almost a mirror of Lerna’s code base.
Files and directories were named the same things, it had many of the same core functions with code that I distinctly remembered writing.
But no big deal right? It must be a fork. I was actually flattered at first. So I went back in the git history.
I got all the way back to the first commit, and looked at the date. Turns out Rush was created a couple weeks after Lerna was announced.
I continued working through the commit history and looked at commits that added features, it all felt so familiar and now I was getting suspicious.
Comparing dates of commits, it looked like Rush kept copying changes from Lerna days after they were made. Rewritten using this weird event system they added.
It left a bad taste in my mouth, I could tell this was my code. I looked at the license, no mention. I looked at the readme… Oh wait
In the readme they acknowledge the fact that there are “other solutions” and say that they are bad. No mention of the fact that Rush was taken directly from one of these bad other solutions.
You know if it were anyone else, I would have been mildly annoyed and ignored it. But Microsoft is a multi billion dollar corporation. If they are going to steal code without crediting the original author I’m gonna be pissed.
So I reached out to people I knew at Microsoft. This was probably a year ago now. They were shocked and apologized. But since then nothing has happened.
Oh wait yeah, something did happen. The commit history of Rush was messed with and a lot of the code was moved around, functions renamed, rewritten. It still feels familiar, but it’s more scrambled.
Instead of just updating a license or even just adding a footnote, they went through all that trouble.
Anyways, it’s really annoyed me to listen to all these people give Microsoft free good press about open source when clearly their product org is still happy to be dicks to open source communities
I don’t trust Microsoft (or Google or Facebook or Amazon) to be good shepherds of open source communities
.

Just because we’ve made it impossible to compete with their old closed source stacks doesn’t mean they’ll act in the best interest of open source
And just because there are great people at Microsoft who love open source and want to do the right thing does not mean that they’ll be able to stop Microsoft from doing shitty things when there’s money involved.
I know plenty of people at big corporations who want to change things but can’t because millions of dollars are in the way.
A few years back we were able to petition GitHub to start improving the tools the offered to open source maintainers.

later on at a @maintainerati event, GitHub acknowledged that this letter had a huge impact on how they worked with open source communities
Imagine a couple hundred people signing a letter to try and change things at Microsoft/Google/Facebook and it actually working. These companies deal with stuff like that on a daily basis and it doesn’t make them trip up for even a second
The consolidation of our infrastructure is dangerous. Having lots of small companies or even medium sized corporations forces them to work together without much effort which prevents any one of them from ever totally fucking us over
The tech industry has so many monopolies right now. Building more everyday. It’s only going to hurt consumers more and more. And when it comes to infrastructure, we’re going to be those fucked over consumers
If you trust a handful of corporations with your entire toolchain and expect them not to fuck you over I’ve got a bridge to sell you

As recently as this year we wrote about another such example. People, watch out. The warnings are there.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

Leave a Comment

You must be logged in to post a comment.

What Else is New


  1. Upcoming Articles and Research Areas

    Although we've failed to write as much as usual, we're still preparing some in-depth articles and maintaining Daily Links (in spite of unforeseen ordeals like a forced laptop migration)



  2. Links 2/4/2020: ProtonMail Bridge for Linux, GTK 3.98.2 and Red Hat DNF 4.2.21

    Links for the day



  3. Links 1/4/2020: Linux 5.7 Merges, Qt 5.14.2, GhostBSD 20.03, Linux Mint 20 Ulyana Plans, WordPress 5.4 “Adderley”

    Links for the day



  4. IRC Proceedings: Tuesday, March 31, 2020

    IRC logs for Tuesday, March 31, 2020



  5. Techrights to Delete Articles From All Past Years to Save Disk Space

    What if we deleted over 25,000 posts?



  6. IRC Proceedings: Monday, March 30, 2020

    IRC logs for Monday, March 30, 2020



  7. Links 30/3/2020: GNU Linux-libre 5.6, WireGuard 1.0.0

    Links for the day



  8. IRC Proceedings: Sunday, March 29, 2020

    IRC logs for Sunday, March 29, 2020



  9. Links 30/3/2020: Linux 5.6, Nitrux 1.2.7, Sparky 2020.03.1

    Links for the day



  10. The Fall of the UPC - Part IX: Campinos Opens His Mouth One Week Later (and It's That Hilarious Delusion Again)

    Team Campinos said nothing whatsoever about the decision of the FCC until one week later, whereupon Campinos leveraged some words from Christine Lambrecht to mislead everybody in the EPO's official "news" section



  11. Pretending EPO Corruption Stopped Under António Campinos When It is in Fact a Lot Worse in Several Respects/Aspects (Than It Was Under Benoît Battistelli)

    Germany's eagerness to keep Europe's central patent office in Munich (and to a lesser degree in Berlin) means that politicians in the capital and in Bavaria turn a blind eye to abuses, corruption and even serious crimes; this won't help Germany's image in the long run



  12. IRC Proceedings: Saturday, March 28, 2020

    IRC logs for Saturday, March 28, 2020



  13. Links 28/3/2020: Wine 5.5 Released, EasyPup 2.2.14, WordPress 5.4 RC5 and End of Truthdig

    Links for the day



  14. IRC Proceedings: Friday, March 27, 2020

    IRC logs for Friday, March 27, 2020



  15. The Fall of the UPC - Part VIII: Team UPC Celebrates Death, Not Life

    Team UPC plays psychological games now; it is trying to twist or spin its defeat as good news and something to be almost celebrated; it is really as illogical (and pathetic) as that sounds



  16. Links 27/3/2020: GNU/Linux Versus COVID-19 and Release of GNU Guile 3.0.2

    Links for the day



  17. When Your 'Business' is Just 'Patent Portfolio'

    Hoarding loads of patents may seem impressive, but eating them to survive is impossible if not impermissible



  18. LOT Network is a One-Man (Millionaire's) Operation and Why This Should Alarm You

    The ugly story of Open Invention Network (OIN) and LOT; today we take a closer look at LOT and highlight a pattern of 'cross-pollination' (people in both OIN and LOT, even at the same time)



  19. Faking Production With Fake Patents on Software

    The EPO with its illegal guidelines (in violation of the EPC) can carry on churning out millions of fake patents that European courts would only waste time on and small companies be blackmailed with (they cannot afford legal battles)



  20. With the Unified Patent Court (UPC) Out of the Way Focus Will Return to EPO Corruption

    Expect the European Patent Office (EPO) to receive more negative attention now that the ’cause’ of UPC is lost and there’s no point pretending things are rosy



  21. IRC Proceedings: Thursday, March 26, 2020

    IRC logs for Thursday, March 26, 2020



  22. Links 27/3/2020: qBittorrent 4.2.2, Krita 4.2.9, pfSense 2.4, Bodhi Linux 5

    Links for the day



  23. IRC Proceedings: Wednesday, March 25, 2020

    IRC logs for Wednesday, March 25, 2020



  24. Still Work in Progress: Getting Those 2,851 Pages of Police Report About Arrest for Pedophilia in Home of Bill Gates

    It’s extremely difficult to get those police records, which were requested exactly one day before the media started attacking Richard Stallman (associating him with pedophiles based on a deliberate distortion)



  25. Links 26/3/2020: Plasma Bigscreen, New Kubernetes, Fedora's New Identity and Bodhi Linux 5.1.0

    Links for the day



  26. Guest Article: Window Managers, Github and Software Disobedience

    "Walking away from monopolies is the essence of freedom"



  27. Links 25/3/2020: LLVM 10.0.0 and UCS 4.4-4 Released, WordPress 5.4 RC4

    Links for the day



  28. 'Team UPC' Last Week

    The looks on Team UPC's faces 5 days ago (before and after the 9:30AM announcement)



  29. The Fall of the UPC - Part VII: Lies and Revisionism About the Reasons for the UPC's Ultimate Demise (to Leave the Door Open for More Failed Attempts)

    The media was lying in a hurry, in a coordinated effort to distort the meaning of the FCC's decision or belittle the impact of this decision; Techrights will carefully watch and respond to these lies



  30. IRC Proceedings: Tuesday, March 24, 2020

    IRC logs for Tuesday, March 24, 2020


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts