Bonum Certa Men Certa

Selling Services Without Selling Fear of Licences

Accusations against H-P and Palamida seem baseless

It wasn't long ago that McAfee and InformationWeek were both harshly (and rightly) accused for spreading GPL fear [1, 2, 3]. This was not appreciated. It is actually worth reminding ourselves of speculations and predictions of a McAfee-Novell tie-up because Novell too was caught using FUD to market itself.

“Empty allegations are used against Hewlett Packard (H-P) and Palamida and we wish to present them here in order to make some clarifications.”On the other hand, some baseless accusations are flying about at the moment. Having been in touch with some of the parties involved, we wish to debunk FUD (or just lies) about FUD that never was. Empty allegations are used against Hewlett Packard (H-P) and Palamida and we wish to present them here in order to make some clarifications.

Let us start with H-P. Just the other day, when H-P introduced a set of services and tools that assist tracking of software and licensing, Dana Blankenhorn accused rather than thanked.

The Hewlett-Packard open source strategy is becoming clear.

Fear the source.

I’m certain HP officials will disagree with that. But when your press release is headlined, ” HP Promotes Open Source Software Governance with New Initiative,” there is no other conclusion to draw.

Your big company can’t go into open source alone. It’s dangerous out there. Here, hold our hand.


PJ disagrees with this, as do I. "HP is trying to do something very good with Flossology. I totally support it," she says.

Why would anyone try to show just the negative side-effect (and yes, we're sometimes accused of doing this as well)? Maybe because it stands out from the crowd and because ZDNet bloggers can be rewarded for provocations. Regardless of the issue at hand, H-P did make either an observation or a complaint back in 2005 (maybe 2006) when it said there were too many open source licences. But coversely, In this newer case, there is an attempt to address the issue, not just raise it. We should be happy. We should be thankful. And here were have the latest report from Palamida (published on Friday) which heralds to the world that GPLv3 finds love. This is good news, not bad news. Project evolve successfully.

The GPL v3 growth for this week is consistent with our average growth rate. As of January 25th, the GPL v3 count is at 1579 GPL v3 projects, up 44 projects over the past week. The LGPL v3 list is growing slowly but steadily and is currently at 150 LGPL v3 projects, as compared to last weeks number of 148 LGPL v3 projects.


At least one person claimed to have found flaws in Palamida's work. Here is what one of our readers had to tell to us before we heard from Palamida (it's reverse-chronological):




[Anonymised:]

I have been visiting Palamida GPLv3 site and I think they are doing a great job at tracking the license adoption, and their statistics can be very useful to counter the established proprietary software oligopolies' and the mainstream tech media's FUD machine.

But today I have been warned by Pieter Hitjens about the following: I copy-paste the conversation about recent statements made in the palamida gplv3 site (gplv3.palamida.com -which redirects to --> gplv3.blogspot.com)

[Pieter:]

http://gpl3.blogspot.com/

This site looks like it's promoting GPLv3 but in fact it looks like subtle anti-GPLv3 FUD. E.g.:

"In the case of putting a GPL v3 project under a commercial license as well, there is high potential to violate the terms of the GPL v3. This is not to say that any of the aforementioned projects are or are not in violation of the license, since our analysis of the terms are not yet complete, but caution should be used if a project is under both the GPL v3 and a commercial license."

What they are saying, I think, is that GPL projects that do not have a clear copyright centralization cannot easily be re-licensed. However they don't state this clearly, and they are not publishing my comments on the blog.

-Pieter

[Anonymised:]

as somebody who has gotten note of Palamida very early after GPLv3 was released and I've got a bit of contact with actual GPLv2->v3 conversions, I can say this:

Palamida, the owner of this blog (it's advertized in the banner on the top of the blog) is a company who's business is software risk management, so it's the business of marketing at this company to show what risks may be there and that risk is increasing.

It is increasing, because GPLv3 makes things indeed a bit more complicated by the simple fact that it is a successor of GPLv2.

The only long-term solution to that which I see is to convince as many free software developers that licensing under "GPL v2 only" is a __very__ bad idea.

I think you guessed right that they may suggest that companies might want to buy services from Palamida, to improve legal security in software distribution.

What I see, rather looks like research which gives great information of the GPLv3 adoption, and no clear FUD.

[Anonymised:]

I see clear FUD, in this respect.

Dual-licensing is in fact a very strong argument for using GPLv3 but it depends on clear centralization of copyright. Projects like 0MQ - see www.zeromq.org - are careful to demand copyright assignments and/or MIT licensing from all contributors. For these projects, dual licensing is essential. This statement:

"This is not to say that any of the aforementioned projects are or are not in violation of the license, since our analysis of the terms are not yet complete, but caution should be used if a project is under both the GPL v3 and a commercial license."

Is really bad. It suggests that we have to wait for Palamida to give the green light on whether it's safe to use 0MQ. That's very misleading and designed to create business for Palamida by exaggerating the complexity of the GPLv3 and ignoring the key role of copyright ownership.

If a company owns its code, how can it be in violation of the GPLv3 by dual-licensing its own code? That's pure FUD, and worse, it brings into question one of the key business models for new smart FOSS businesses.

[Anonymised:]

Care if I forward your message to Pamela Jones (groklaw) and Roy Schestowitz (boycottnovell) so they alert about the issue. Think the palamida guys, who are doing a great tracking of projects adopting the GPLv3 should be aware as well. And of course the FSF/FSFE

[Pieter:]

Forward away, of course. Tracking GPLv3 usage is fine. Throwing fear and uncertainty onto other businesses to try to create extra business is not fine.

-Pieter




Shared with implicit permission, the above is intended to at least show the arguments that were thrown into this debate, which we believe is resolved by several factors.

For starters, PJ says: "I don't agree they are doing that [spreading fear]". Further: "They want business, so they highlight problems without telling you the solution, because they want business, but that isn't, to me, exactly the same thing as FUD, although it can have a similar effect."

Our reader adds: "Up to now, their work at tracking GPLv3 project has proven nice and useful to counter quite a lot of FUD [...] I think Palamida at least should publish Pieter's comments. If they don€´t do it after a while, "someone" should be pointing at the problem. Of course making clear that the tracking of GPLv3 projects is nice and useful."

We received a response from Palamida quite quickly and it was very convincing. Judge for yourselves however:




I can say with 100% honesty that no, Palamida does not resort to FUD to sell our services. However, we do point out what can happen if you don't know what you've got in your code base, which is a reality, and it's what drives a lot of lawsuits and insecure apps. It's just something people want to avoid and we're here to help organizations figure it out so they can get it right. There is a subset of folks (including you) that know what the heck is going on and would vet and check you code, versions, and licenses ahead of time. Funny though that very large organizations often do not, or possibly can not, because of their size and geographically dispersed team of developers. These are the folks who have the Top 5 Most Overlooked OS vulnerabilities (and many more but let's stick with 5) and don't know it.

So in general, our message and mantra has always been "Know What's In Your Code." It's a message that shouldn't be considered FUD, because not knowing has very real consequences (can anyone say Busybox?).




Since H-P came under similar unjustified scrutiny we brought up this issue, which quite expectedly revealed sympathy:




In general, we like HP but here's something to think about. Back at the beginning of Palamida, folks used to ask us, "Why wouldn't I just use Google Code Search instead of paying for Palamida?" Our response was always that they certainly could use Google if they only wanted a skim the surface view of what was going on in one single segment (say, JBoss code). However, our expertise coupled with the depth and breadth of our code base (which weighs in at 3 Terabytes) could give you a little more (to put it mildly). So I personally feel the same about FOSSology. This is my singular opinion, it's a fantastic tool but it answers only one of the many, many questions people need to be asking (take a look at the blog we just posted Friday) about: what code are you using? What version? What license is it under? Is it secure?

How often is the FOSSbazaar updated? What does it include? What are its rates of false positives or irrelevant search matches? How comprehensive is it? Who has tested it? Would you bet your eBanking system security on it?

That sort of thing.




This hopefully resolves the issue, at least for those who were involved in a blame game. Censorship (aka "selective approval") of comment was probably the main reason for going this far. We never delete comments in this Web site and only a single abusive reader has his comments flagged (still truly visible) for repetitive abuses even against other readers. Transparency brings better answers than censorship, which we last complained about just an hours ago (ODF/OOXML).

Comments

Recent Techrights' Posts

We've All Had Managers and Colleagues Like These, But This is How it Works at IBM
Competent people scare the failing ones; so they get ousted, they're perceived to be "rivals"
Gemini Links 17/12/2025: Wrongs, "Wokeness", and 3D-Printable Accessible USB Input Device
Links for the day
"Social Justice Warriors" Make Violent Threats Against Event Organisers, Developers, and Journalists
As a left-leaning person (I've always been rather strongly on the left), I generally reject people who call themselves "SJWs"
Linus Torvalds Seems to Have Aged Faster Since the Bullying by the 'CoC Brigade' (Enforced via Linux Foundation, a GAFAM Front Group)
We previously wrote a lot of articles about the ageing of Torvalds and how stress (from his masters) may have contributed to deterioration of his health
Cuts, Shutdowns, and Layoffs at Microsoft
It is potentially catastrophic for yet another studio that sold its soul to Microsoft
 
Horizon Shows the Travesty of Proprietary Software in British Government, No Lessons Learned?
When it comes to the government, we don't get to choose what systems to use and we also don't get to choose between businesses
WordPress Begs You to Dump It (for SSGs), Just Like Mozilla With Firefox
Even more worryingly, this does not boil down to some rogue employee or 'bad apple'
Tom Silvagni sentencing: not Xavier College but DPP and social media to blame
Reprinted with permission from Daniel Pocock
Links 17/12/2025: Operation Bluebird Lawsuit, GoDaddy Made to 'Dox' Clients
Links for the day
Mental Problems in Free Software
Nobody seems to be interested in this topic or, at the very least, nobody wants to talk about it; instead, there are efforts to suppress discussion about it
Love and Activism
Love is fertile soil for positive activism
Windows Has Fallen to All-Time Low of 60% in Laptops and Desktop in Canada
Maybe next year Windows will fall below 50% there
Debian Misfits Really Do Not Want You to Read This Article
portions from this article
Gemini Protocol Saw Significant, Measurable Growth in 2025
Next year (in summer) Gemini Protocol turns 7
The Collapse of Good Development Practices
Software becoming bloated is not an inevitability
More GAFAM Layoffs in Seattle, Bellevue (Washington)
Microsoft laid off (by our count) over 30,000 workers this year
Microsoft GitHub is Dying and Bot Activity in GitHub Won't Save It
Doing what it can to keep it alive, Microsoft only loses more money (it now classifies it as "AI" to justify all the losses)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 16, 2025
IRC logs for Tuesday, December 16, 2025
Firefox and Mozilla Commit Suicide With Slop, Market Share Falls to New Low
Mozilla just isn't a serious company anymore
"The Register Hot Seat" is Just More Paid-for SPAM Promoting a Pyramid Scheme to Readers of The Register MS
The main issue is that The Register MS is, as usual, begging for and bagging money to promote a pyramid scheme that will end up very badly and hurt a lot of people
Red Hat Wastes Money on Slop and on Slop Pushers While Laying Off Red Hat Staff
In order to manipulate the share price IBM is peddling vapourware
Getting Back on Top of Exclusive Articles, Leaks, Whistleblowing
We still have some material to publish about Microsoft OSI and various other rogue institutions
Links 17/12/2025: User Data Compromised in SoundCloud and Efforts to Release Jimmy Lai for the 'Crime' of Journalism
Links for the day
The Register MS Does the "AI" Keyword Stuffing Because It Gets Paid to Do "AI" Keyword Stuffing
They are in effect profiting from legitimisation and promotion of a Ponzi scheme
Blogs to Read (or Even Binge on) When You Look for a Daring and Different Perspective
If you have free time and want to check out interesting old articles/posts, consider these people
Paying the Price for IBM's Leadership Buying Worthless Companies With Capital It Doesn't Have
For some people the last day at the company is Christmas Eve
When Malformed RSS or Atom Feeds Clog Up (or Even Crash) Programs
RSS readers are an excellent way to keep on top of news online
Publication Plans for the Coming Weeks
We've begun this week with many articles and plan to carry on until tomorrow
EPO People Power - Part XIV - EPO Management Living in Fantasy Land
wrongly assumes that any crime committed by the EPO will always be brushed aside
Secret Code is Undesirable
If someone wants you to use proprietary software, say no. Secret code is even worse.
Google News Still Has an LLM Slop Problem (With Slop Images Too), But Google Itself is a Pusher of Slop
If Google keeps shilling and selling slop as "AI", and moreover if people keep hating slop (there's growing awareness of this problem), then at the end Google will suffer greatly
Gemini Links 16/12/2025: Bingo Card and i586 in 2025
Links for the day
Links 16/12/2025: Security and Conflict (No Territorial Concessions in Ukraine)
Links for the day
With Half of December Over, FSF Two-Thirds of the Way Towards Funding Goal
If you can share some money this month, the FSF should be a priority
A Lot of People Don't Want "Smart" (Things That Spy, Stop Working, Cannot be Repaired Easily)
They also don't want slop disguised as "intelligence"
Claim That Finance and HR at IBM Already Work on the Next Wave of IBM Layoffs, Media Silence Persists
The media is still telling misleading nonsense about IBM layoffs (like some fantasy about 'rehiring' thousands for "AI")
Links 16/12/2025: More GAFAM (Now Amazon) Layoffs and iRobot Chapter 11
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 15, 2025
IRC logs for Monday, December 15, 2025
Claims of More IBM Layoffs a Week Before 'Christmas Week'
Of course, as usual, nobody in the media says anything
Wrapping Up and Ending "Slopwatch"
An "end-of-life" improvement
Gemini Links 15/12/2025: How We Lost Communication to Entertainment, Dichotomy Between the Real and the Digital
Links for the day
The New Chief Editor at The Register MS is a Microsofter, Now They Increase Microsoft Coverage and Add Microsoft Slant to 'Linux' Coverage
Did Microsoft pay some more?
GAFAM "doesn't depend on any sort of lock-in, humans just don't want to be free anymore," according to MinceR
As many readers are aware, our criticism of UEFI (restricted boot in particular) attracted a lot of online harassment against us, including stalking and libel
IBM Layoffs in India and IBM's CEO Spins His Lack of Market Share as a Strength
If this leadership carries on, the only red left at IBM won't be Red Hat but a red stain
Links 15/12/2025: "Life in Prison" for Criticising China, Tikhanovskaya Says 'Pressure Works'
Links for the day
Due to 'Secure Boot' (An Anti-Security Measure, a Kill Switch) Computer Users Are Afraid of GNU/Linux
This is what Microsoft wanted
'Crypto' 'Currencies' Are a Ponzi Scheme. So Is "AI". Both Destroy the Planet, Not Just the Economy.
Believe it or not, millions of these GPUs just sit there boxed, unopened, unconnected, unused
The Register MS Has Just Been Paid to Promote the Ponzi Scheme Some More ("AI" Keyword Stuffing)
This won't end well for The Register MS
Microsoft Colonialism in Africa is Not Sustainable
Microsoft's situation in Nigeria is not
Perpetuating the Lie of "No Red Hat Layoffs" Because of the Bluewashing (Red Hat Became Just "IBM")
Many Red Hat employees were pushed out and/or removed lately
EPO People Power - Part XIII - If the EPO's Chief Propagandist (Berenguer) Told the Police He Was a Spanish Tourist (or Similar) or That He Does Not Reside in Munich, Then He May Have Lied to the Police (in Addition to Doing Cocaine in Public)
Lying to the police in Germany is a criminal offense
Links 15/12/2025: Chromebooks as Work Machines, "Americans [Who] Moved to Australia" to Avoid Cheeto
Links for the day
Breaking Your Proprietary Router in the Name of "Security"
Each time they "patch" the router something that previously worked OK is likely to just break
IBM May be Breaking the Law to Silence Staff It Laid Off
Observation to add regarding IBM layoffs
Demonisation Attacks on Richard Matthew Stallman (RMS) - Including Antisemitic Attacks - Have Not Worked
Name-calling doesn't work
Slop ("AI") Will Replace People and Take Away Jobs, Say the Slopfarms With Fake (LLM-Generated) Text and Slop Images
"AI" often means slave labour in a poor country
More Than a Million Bytes Should be Enough for Most Computer Programs
Who said computing would improve over time?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 14, 2025
IRC logs for Sunday, December 14, 2025
Another "AI" (Slop) Use Cases Turns Out to be a Fraud
Those who talk about this fraud get SLAPPed
They Say Rules Are Made to be Broken, at Microsoft That Became an Imperative (e.g. Accounting Fraud, Bribery and So on)
Its biggest client is itself
In Russia, Microsoft is Already a Dying Breed Online
A lot of Europe also dumps Microsoft. Europe is a big revenue source of Microsoft.
The Future of News on the World Wide Web
No "greener pastures" on the Web
𝐈𝐁𝐌 𝐂𝐄𝐎 𝐀𝐫𝐯𝐢𝐧𝐝 𝐊𝐫𝐢𝐬𝐡𝐧𝐚: Proof That at IBM People Fall Upwards
IBM is collapsing
EPO People Power - Part XII - The Mobbing Got So Bad People Were Unable to Work
What's at stake here isn't just the EPO or the patent system