Bonum Certa Men Certa

Selling Services Without Selling Fear of Licences

Accusations against H-P and Palamida seem baseless

It wasn't long ago that McAfee and InformationWeek were both harshly (and rightly) accused for spreading GPL fear [1, 2, 3]. This was not appreciated. It is actually worth reminding ourselves of speculations and predictions of a McAfee-Novell tie-up because Novell too was caught using FUD to market itself.

“Empty allegations are used against Hewlett Packard (H-P) and Palamida and we wish to present them here in order to make some clarifications.”On the other hand, some baseless accusations are flying about at the moment. Having been in touch with some of the parties involved, we wish to debunk FUD (or just lies) about FUD that never was. Empty allegations are used against Hewlett Packard (H-P) and Palamida and we wish to present them here in order to make some clarifications.

Let us start with H-P. Just the other day, when H-P introduced a set of services and tools that assist tracking of software and licensing, Dana Blankenhorn accused rather than thanked.

The Hewlett-Packard open source strategy is becoming clear.

Fear the source.

I’m certain HP officials will disagree with that. But when your press release is headlined, ” HP Promotes Open Source Software Governance with New Initiative,” there is no other conclusion to draw.

Your big company can’t go into open source alone. It’s dangerous out there. Here, hold our hand.


PJ disagrees with this, as do I. "HP is trying to do something very good with Flossology. I totally support it," she says.

Why would anyone try to show just the negative side-effect (and yes, we're sometimes accused of doing this as well)? Maybe because it stands out from the crowd and because ZDNet bloggers can be rewarded for provocations. Regardless of the issue at hand, H-P did make either an observation or a complaint back in 2005 (maybe 2006) when it said there were too many open source licences. But coversely, In this newer case, there is an attempt to address the issue, not just raise it. We should be happy. We should be thankful. And here were have the latest report from Palamida (published on Friday) which heralds to the world that GPLv3 finds love. This is good news, not bad news. Project evolve successfully.

The GPL v3 growth for this week is consistent with our average growth rate. As of January 25th, the GPL v3 count is at 1579 GPL v3 projects, up 44 projects over the past week. The LGPL v3 list is growing slowly but steadily and is currently at 150 LGPL v3 projects, as compared to last weeks number of 148 LGPL v3 projects.


At least one person claimed to have found flaws in Palamida's work. Here is what one of our readers had to tell to us before we heard from Palamida (it's reverse-chronological):




[Anonymised:]

I have been visiting Palamida GPLv3 site and I think they are doing a great job at tracking the license adoption, and their statistics can be very useful to counter the established proprietary software oligopolies' and the mainstream tech media's FUD machine.

But today I have been warned by Pieter Hitjens about the following: I copy-paste the conversation about recent statements made in the palamida gplv3 site (gplv3.palamida.com -which redirects to --> gplv3.blogspot.com)

[Pieter:]

http://gpl3.blogspot.com/

This site looks like it's promoting GPLv3 but in fact it looks like subtle anti-GPLv3 FUD. E.g.:

"In the case of putting a GPL v3 project under a commercial license as well, there is high potential to violate the terms of the GPL v3. This is not to say that any of the aforementioned projects are or are not in violation of the license, since our analysis of the terms are not yet complete, but caution should be used if a project is under both the GPL v3 and a commercial license."

What they are saying, I think, is that GPL projects that do not have a clear copyright centralization cannot easily be re-licensed. However they don't state this clearly, and they are not publishing my comments on the blog.

-Pieter

[Anonymised:]

as somebody who has gotten note of Palamida very early after GPLv3 was released and I've got a bit of contact with actual GPLv2->v3 conversions, I can say this:

Palamida, the owner of this blog (it's advertized in the banner on the top of the blog) is a company who's business is software risk management, so it's the business of marketing at this company to show what risks may be there and that risk is increasing.

It is increasing, because GPLv3 makes things indeed a bit more complicated by the simple fact that it is a successor of GPLv2.

The only long-term solution to that which I see is to convince as many free software developers that licensing under "GPL v2 only" is a __very__ bad idea.

I think you guessed right that they may suggest that companies might want to buy services from Palamida, to improve legal security in software distribution.

What I see, rather looks like research which gives great information of the GPLv3 adoption, and no clear FUD.

[Anonymised:]

I see clear FUD, in this respect.

Dual-licensing is in fact a very strong argument for using GPLv3 but it depends on clear centralization of copyright. Projects like 0MQ - see www.zeromq.org - are careful to demand copyright assignments and/or MIT licensing from all contributors. For these projects, dual licensing is essential. This statement:

"This is not to say that any of the aforementioned projects are or are not in violation of the license, since our analysis of the terms are not yet complete, but caution should be used if a project is under both the GPL v3 and a commercial license."

Is really bad. It suggests that we have to wait for Palamida to give the green light on whether it's safe to use 0MQ. That's very misleading and designed to create business for Palamida by exaggerating the complexity of the GPLv3 and ignoring the key role of copyright ownership.

If a company owns its code, how can it be in violation of the GPLv3 by dual-licensing its own code? That's pure FUD, and worse, it brings into question one of the key business models for new smart FOSS businesses.

[Anonymised:]

Care if I forward your message to Pamela Jones (groklaw) and Roy Schestowitz (boycottnovell) so they alert about the issue. Think the palamida guys, who are doing a great tracking of projects adopting the GPLv3 should be aware as well. And of course the FSF/FSFE

[Pieter:]

Forward away, of course. Tracking GPLv3 usage is fine. Throwing fear and uncertainty onto other businesses to try to create extra business is not fine.

-Pieter




Shared with implicit permission, the above is intended to at least show the arguments that were thrown into this debate, which we believe is resolved by several factors.

For starters, PJ says: "I don't agree they are doing that [spreading fear]". Further: "They want business, so they highlight problems without telling you the solution, because they want business, but that isn't, to me, exactly the same thing as FUD, although it can have a similar effect."

Our reader adds: "Up to now, their work at tracking GPLv3 project has proven nice and useful to counter quite a lot of FUD [...] I think Palamida at least should publish Pieter's comments. If they don€´t do it after a while, "someone" should be pointing at the problem. Of course making clear that the tracking of GPLv3 projects is nice and useful."

We received a response from Palamida quite quickly and it was very convincing. Judge for yourselves however:




I can say with 100% honesty that no, Palamida does not resort to FUD to sell our services. However, we do point out what can happen if you don't know what you've got in your code base, which is a reality, and it's what drives a lot of lawsuits and insecure apps. It's just something people want to avoid and we're here to help organizations figure it out so they can get it right. There is a subset of folks (including you) that know what the heck is going on and would vet and check you code, versions, and licenses ahead of time. Funny though that very large organizations often do not, or possibly can not, because of their size and geographically dispersed team of developers. These are the folks who have the Top 5 Most Overlooked OS vulnerabilities (and many more but let's stick with 5) and don't know it.

So in general, our message and mantra has always been "Know What's In Your Code." It's a message that shouldn't be considered FUD, because not knowing has very real consequences (can anyone say Busybox?).




Since H-P came under similar unjustified scrutiny we brought up this issue, which quite expectedly revealed sympathy:




In general, we like HP but here's something to think about. Back at the beginning of Palamida, folks used to ask us, "Why wouldn't I just use Google Code Search instead of paying for Palamida?" Our response was always that they certainly could use Google if they only wanted a skim the surface view of what was going on in one single segment (say, JBoss code). However, our expertise coupled with the depth and breadth of our code base (which weighs in at 3 Terabytes) could give you a little more (to put it mildly). So I personally feel the same about FOSSology. This is my singular opinion, it's a fantastic tool but it answers only one of the many, many questions people need to be asking (take a look at the blog we just posted Friday) about: what code are you using? What version? What license is it under? Is it secure?

How often is the FOSSbazaar updated? What does it include? What are its rates of false positives or irrelevant search matches? How comprehensive is it? Who has tested it? Would you bet your eBanking system security on it?

That sort of thing.




This hopefully resolves the issue, at least for those who were involved in a blame game. Censorship (aka "selective approval") of comment was probably the main reason for going this far. We never delete comments in this Web site and only a single abusive reader has his comments flagged (still truly visible) for repetitive abuses even against other readers. Transparency brings better answers than censorship, which we last complained about just an hours ago (ODF/OOXML).

Comments

Recent Techrights' Posts

Rust's "Memory Safety" Talking Point Ought to be Discarded in Light of Fil-C
new memory-safe C/C++ compiler
IBM May Well Be Laying Off Over 13,500 and Up to 27,000 Staff This Week When It Says "Single-Digit Percentage of Our Global Workforce"
It's not yet possible to know how many people IBM gets rid of
Early Unverified Figures About Scale of Latest IBM Layoffs
the real scale of the RAs will remain elusive
How Techrights Search Works
Hopefully bots won't use it
Techrights Became a Lot More Productive as a Result of Attacks on It
By default, it's safe to assume anything on the Web is garbage, especially in social control media
Unverified Rumours: IBM Cuts Will Continue Another ~10 Days, Managers Will Invite Those Impacted for 1-on-1 Meetings
Right now IBM likes diversity because with adoption of low-paid demographies it gets to pay workers less for the same work
 
Estimating the Scale of IBM's Mass Layoffs This Week
there is no denying that the IBM layoffs are vast
Telling Our Story as Victims of Online Abuse
This post will not mention any names
Claim That EPO Quotas Brought Corruption and Mischief to Europe's Second-Largest Institution
Nowadays corruption is the norm at the EPO and there is even rampant substance abuse among the people who run the Office
Claim That IBM Has Another 8 Days to Lay Off 'Expensive' Staff
The consensus in comments we see is, IBM is a terrible place to work in, treatment of its workers is appalling, it's utterly foolish to relocate in an effort to retain a job at IBM, and it's foolish to join the company in the first place
Science Demands Facts, Not Dogma
Saying that restricted hardware is not secure hardware should be common sense
Site Anniversary is Tomorrow
The celebrations might delay our EPO series somewhat
Launching Techrights Search
New search interface and locally hosted back end
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 05, 2025
IRC logs for Wednesday, November 05, 2025
Slopwatch: linuxbsdos.com, Linux Journal, LinuxSecurity, Brian Fagioli, and WebProNews
Either Google doesn't care about the integrity of Google News or it deems slop to be acceptable
Gemini Links 05/11/2025: Affirmation, GnuPG, and While Loops
Links for the day
Links 05/11/2025: Economic Trouble in France and US Bombing All Over the World Without Declaration of War or Congress Approving
Links for the day
Red Hat Staff Also Impacted by Latest IBM Layoffs With Focus on North America and Software, Infrastructure
After the bluewashing never expect to see news about "Red Hat layoffs", just as "Tivoli layoffs" aren't to be expected
Coming Soon: Part 4 About the EPO's Substance Abuse (Breaking Laws to Fake 'Production' and Profiting From Unlawful Monopolies)
Notice how quiet the EPO's management has been lately
For the Record: We Never Named Staff of the Law Firm That's Attacking Us, Except the One the Firm is Named After!
Just to affirm and be sure, I've used our new search facility
Links 05/11/2025: Medicare Privatisation and "Breaker Box Economy"
Links for the day
Techrights Search Will Come Early
Maybe tomorrow
It Seems Like GNOME/IBM Don't Like Women and When Budget is Limited Only Women Take the Fall
Seems like a very patriarchal, GAFAM-controlled Foundation
"Last Day" as in "IBM Sacked Me" (Cruel Euphemisms)
"The entire design and research technical leadership at IBM was laid off in the past year, including this round"
analytics.usa.gov: Vista 11 Scarcely Used, GNU/Linux Increasingly Dominant (Microsoft Loses "Goodwill", Depletes Cash Equivalents, and Debt Soars)
"Total current assets" fell by more than 2 billion dollars in the past 3 months
Shadow Crew and Ads Disguised as Articles
That The Register MS runs articles that are paid-for fluff isn't unprecedented
Vista 11 "Market Share" Has Fallen This Month, Based on statCounter
The US government's own data shows the same thing this month
This is How Mainstream Media, Boosted or Parroted by Slopfarms, Spins IBM's Commercial Failure and Mass Layoffs as "AI"
Some say "software focus", but most just resort to buzzwords and blame-shifting hype
Resisting Misogynists
Rianne has already added close to 100,000 pages to this site
Starting November on a Strong Note
All in all, this month started well for us as we have good, accurate publications with considerable impact
Fake Retirements Help IBM Keep the Layoff Figures Down
Yesterday we read that it was quite cruel how IBM (or Red Hat) compelled staff to pretend to be happily leaving or "retiring" when the reality was, they had been pushed out with some "package"
Cocaine at the European Patent Office Now a Subject in YouTube, Media Will Revisit the Topic
"The Cocaine Patent Office" is no joking matter
Gemini Links 05/11/2025: "Wuthering Heights" and "Winter is Coming"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, November 04, 2025
IRC logs for Tuesday, November 04, 2025
2 Days Until Site Anniversary Party, Search Likely to Launch Same Day
We're now just two days away from the nineteenth anniversary of the site
Not Only Mass Layoffs at IBM But Complete Shutdowns "Amid A.I. Boom"
apparently about 10,000 layoffs, not counting those who got pushed out by PIPs and other means
Richard Stallman's 2005 Article on Why Patents on Software Should be Denied
If patent law had been applied to novels in the 1880s, great books would not have been written. If the EU applies it to software, every computer user will be restricted, says Richard Stallman
"Last Day" at IBM and Red Hat as "Stealth Layoffs" (They Force People to Pretend It's Wilful)
So the real extent of the layoffs is being kept 'undercover'
Slopwatch: The WebProNews Slopfarm and the Serial Slopper
The Web is ill
Links 04/11/2025: Tensions Around Belarus Grow, Turkey’s Hype-inflation Continues
Links for the day
Corporate Media That Fails to Report Cocaine at EPO is Totally Failing to Report Mass Layoffs at IBM
How come nobody anywhere writes about this week's RAs?
Search @ Techrights: Almost There Now (Maybe an Anniversary Gift)
Just to be very clear, search would not be unprecedented at Techrights
At IBM, Layoffs Start at 1AM (at Night)
not a single English-speaking site covers the news about the layoffs
Links 04/11/2025: Google Cloud Account Engages in Censorship of the Innocent, arXiv Spammed by LLM Slop
Links for the day
EPO Cocaine Chronicles: Our Aim Will be to Ensure This Becomes a Mainstream Media Topic, Not a Suppressed Scandal (Which the German State Deems Embarrassing and Detrimental to Its Pan-European Patent Franchise)
At the EPO, and perhaps in German media as well, people "fall upwards" (they get rewarded for bad things)
Envy Makes People Do Self-Harming Things (and Harm to Others)
Online communities that can be deemed successful are built around trust, mutual respect, and collective accomplishment
Static Site Generators (SSGs) Made Techrights Better, Faster, Easier to Manage
Consider adopting SSGs if you still use a CMS such as WordPress
But he Was Born in Manchester! (Origin Stories)
Borussia Dortmund does not exist!
What Julian Darley Wrote About the Stallman Talk Regarding "AI" in Oxford (2025)
From LinkedIn (Microsoft)
GNU/Linux is American, Not Finnish
It started in Boston, not in Helsinki
'Hacker' 'News' Makes Dumb Assertions Against Smart People
A logical fallacy
We Turned Down Every Settlement Offer Because Truths Aren't Determined in Bank Accounts
Without free press, there won't be free society
"All truths are easy to understand once they are discovered; the point is to discover them." -Galileo Galilei
This site is educational
Why I'm Always Proud of the Site I've Devoted My Life to
As a graffiti around the corner from our home says, "be a better person"
Standing Up or Standing for What's True But Inconvenient
Bad actors need to be called out
Many People Have Said That They "Leave" IBM in Recent Days (Ahead of Mass Layoffs)
So the real extent of layoffs is greater than what's publicly stated (there are silent layoffs) [...] Whatever IBM says about the scope, scale, or magnitude of the "RAs", it doesn't tell the full story
Media Coverage Regarding IBM is Vapourware and LLM Slop
With slop images, too
statCounter Says GNU/Linux Rose to 4% in the Russian Federation
Adoption of Vista 11 has been embarrassingly weak
Corruption is Not a Joke
we'll try to limit our use of humour to avoid misunderstandings or misinterpretations
The Slopfarm WebProNews is Overwhelming "linux" Results in Google News
Google News is slop
The Fall of IBM: What Happened?
Just like the EPO continues riding some old reputation acquired in the 1970s IBM relies on old myths like, "nobody gets fired for buying IBM."
IBM's CEO Already Has the Excuse for the Latest Wave of Mass Layoffs
Only days ago the CEO told a bunch of nonsense
Links 04/11/2025: Conflicts, Politics, and IPv6 at Home
Links for the day
Gemini Links 04/11/2025: Entering WiFi Passwords and Programming Rambles
Links for the day
Arch Linux Seems Like the New Debian
Arch users (btw!) are growing in relative and absolute share
Analytics From US Government Affirm a Trend: Microsoft's "Market Share" in Search is Falling
the data set is large
Holding Institutions Such as the EPO Accountable Through Public Information
Speaking truth to power is never easy
Techrights Will Contact German Media About the EPO's Substance Abuse
This scandal won't "go to waste"
EPO Staff Losing Holidays, as Usual, as the Office Increases Profits by Illegally Granting Invalid Patents While Reducing Salaries
How much more can the staff endure and generally tolerate?
Free Software Does Not Always Speak for Itself, It Needs Advocates
Legal matters that relate to sharing of code will be discussed
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, November 03, 2025
IRC logs for Monday, November 03, 2025
The Register MS Continues Looking for Money in Promotion of the "AI" Ponzi Scheme
That The Register MS participates in this deceit rather than tackle/debunk it says a lot about The Register MS
IBM Layoffs in "Software", This Likely Impacts Red Hat as Well
Many people say "software" people are impacted
Escaping Proprietary Software, Not Just Escaping Microsoft
To take control of your life adopt GNU/Linux
A Lot of Fake News About Microsoft Headcount (Also: Microsoft's Debt Rose by About 24 Billion Dollars in Past 12 Months)
If you see some headline about Microsoft's CEO making claims about hirings, look away
Techrights Turns 19 in Three Days
It would be nice to meet for a chat