<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://www.osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/19230/HP_Develops_Tools_to_Track_Down_OSS</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2012, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Wed, 15 Feb 2012 13:58:18 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Why?</title>
			<link>http://www.osnews.com/thread?298229</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298229</guid>
			<description>What a useless product. Why would using OSS pose management and legal problems? Sounds like FUD to me.</description>
			<pubDate>Tue, 29 Jan 2008 18:15:00 GMT</pubDate>
			<author>donotreply@osnews.com (NxStY)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>If you say so...</title>
			<link>http://www.osnews.com/thread?298232</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298232</guid>
			<description>&quot;...to help companies address the potential legal, financial and security risks involved in the <br />
adoption of free and open source software.&quot;<br />
<br />
Right.</description>
			<pubDate>Tue, 29 Jan 2008 18:43:00 GMT</pubDate>
			<author>donotreply@osnews.com (rexstuff)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Much ado about nothing</title>
			<link>http://www.osnews.com/thread?298233</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298233</guid>
			<description>Business people try to pinch a dollar out of you no matter what you are doing.<br />
<br />
If you don't know what you have installed on your systems, ask your system administrators to keep updated documentation on how your network is set up and evolves. Make it part of their job evaluation.</description>
			<pubDate>Tue, 29 Jan 2008 18:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (porcel)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Why?</title>
			<link>http://www.osnews.com/thread?298236</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298236</guid>
			<description><div class="cquote">What a useless product. Why would using OSS pose management and legal problems? Sounds like FUD to me. </div><br />
<br />
OSS/copyleft projects can be very talented at hiding their licenses in obscure places.  Additionally, there's currently no law requiring that open-source projects identify themselves as such in marketing and during installation so the user can opt out, so many people use open-source programs unknowingly.</description>
			<pubDate>Tue, 29 Jan 2008 19:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (Almafeta)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Much ado about nothing</title>
			<link>http://www.osnews.com/thread?298240</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298240</guid>
			<description><div class="cquote">Business people try to pinch a dollar out of you no matter what you are doing. </div><br />
<br />
HP has released this as GPL. Although I can't seem to find an application for it within my company, HP is not charging for the ability to use it.</description>
			<pubDate>Tue, 29 Jan 2008 19:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (jharrell)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: If you say so...</title>
			<link>http://www.osnews.com/thread?298242</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298242</guid>
			<description><div class="cquote">&quot;...to help companies address the potential legal, financial and security risks involved in the <br />
adoption of free and open source software.&quot;<br />
<br />
Right. </div><br />
<br />
I don't think anyone will quibble about security risks running unknown copies of open source; if it's unknown, it is likely not going to be upgraded when security flaws are discovered and fixed.<br />
<br />
As for financial and legal risks, there are, in fact, legally encumbered <i>binaries</i> (at least in some jurisdictions) which cannot be copied under the license terms.  While this can be overcome by building equivalent binaries from the source (which does require some work), not doing so could result in risks, however small in practice.</description>
			<pubDate>Tue, 29 Jan 2008 19:34:00 GMT</pubDate>
			<author>donotreply@osnews.com (james_parker)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]:  HP has released this as GPL</title>
			<link>http://www.osnews.com/thread?298252</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298252</guid>
			<description>So, this is a great solution to the &quot;issues&quot; you have raised.</description>
			<pubDate>Tue, 29 Jan 2008 20:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (glarepate)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Why?</title>
			<link>http://www.osnews.com/thread?298262</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298262</guid>
			<description>&quot;What a useless product. Why would using OSS pose management and legal problems? Sounds like FUD to me.&quot;<br />
<br />
In general there would be none. The one time it could pose a risk is if you are a software development house. That can cause legal problems if a developer uses the GPL versions of the files versus the paid for ones, such as with QT. That is the management/legal problem. Mainly because if the prodct can not be GPL for whatever reason,  such as being a DoD project or such.</description>
			<pubDate>Tue, 29 Jan 2008 21:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (DrillSgt)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>HP is having problems</title>
			<link>http://www.osnews.com/thread?298265</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298265</guid>
			<description>as far as we can see. They want licenses to be sold.<br />
HP-UX is pretty arcane, incomplete, runs on hardware that isn't avalable anymore (PA-RISC) and now they bet in Itanium. Even a DVD set will cost you list price $800 or so.<br />
<br />
HP has a hard time and they try to compensate..</description>
			<pubDate>Tue, 29 Jan 2008 21:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (sgibofh)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by i3X171UM</title>
			<link>http://www.osnews.com/thread?298271</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298271</guid>
			<description>&quot;There is a significant benefit for enterprises to understand how much of this software they have and be able to manage it. Companies are running huge risks -- financial and otherwise -- by not knowing what open source software they're using and therefore not knowing what license obligations and security violations come along with it,&quot; Martino said.<br />
 <br />
 That was the only explanation in the article. I tried to play devil's advocate and come up with some legally compromising scenarios of my own, but I honestly couldn't.<br />
 <br />
 If anyone is curious, you can download the tool here: <a href="http://www.fossology.org/" rel="nofollow">http://www.fossology.org/</a>. It's GPL, somewhat ironically.<br />
<br />
Ed: it appears to scan local files for text in 30 types of OSS licenses (\agents\foss_license_agent\Licenses\Raw\) and store the results in an sql-based &quot;fossrepo.&quot;Edited 2008-01-29 22:19 UTC</description>
			<pubDate>Tue, 29 Jan 2008 22:06:00 GMT</pubDate>
			<author>donotreply@osnews.com (Alex Forster)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298272</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298272</guid>
			<description><div class="cquote">&quot;HP gave an example of a recent customer that had three times as many FOSS licenses as originally estimated -- 75 licenses rather than 25. This left customers with a choice: implement governance policies to allow the safe use of FOSS, or replace the software at an estimated cost of $80 million.&quot; </div><br />
<br />
75 FOSS licenses? Really? I assume this does not refer to having software under 75 different OSI-approved license terms in their organization, but rather to having 75 devices running on FOSS software under licenses unknown.<br />
<br />
Does HP mean to imply that not obtaining (read: paying for) licenses for FOSS software is somehow illegal or against government policy? I find this somewhere between comical and disingenuous. Is it unsafe to use unpaid-for software, even if that is in compliance with its license?<br />
<br />
I understand that some organizations might like to know how much unapproved FOSS software has crept in to their infrastructure, purely for informational and planning purposes, but to advertise this service in a way that suggests that they are ferreting out illicit or illegal installations and making people pay for them is... unpleasant.</description>
			<pubDate>Tue, 29 Jan 2008 22:08:00 GMT</pubDate>
			<author>donotreply@osnews.com (sorpigal)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>What about Windows</title>
			<link>http://www.osnews.com/thread?298291</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298291</guid>
			<description>I wonder if they make one for Windows and Proprietary software? I mean I have always wondered how any body could determine that a Binary only distributed applications could be checked.Edited 2008-01-30 00:04 UTC</description>
			<pubDate>Tue, 29 Jan 2008 23:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (de_wizze)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: If you say so...</title>
			<link>http://www.osnews.com/thread?298329</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298329</guid>
			<description><div class="cquote">I don't think anyone will quibble about security risks running unknown copies of open source; if it's unknown, it is likely not going to be upgraded when security flaws are discovered and fixed. </div><br />
 <br />
 While unknown copies of proprietary programs are, by contrast, not subject to these issues.Edited 2008-01-30 01:40 UTC</description>
			<pubDate>Wed, 30 Jan 2008 01:39:00 GMT</pubDate>
			<author>donotreply@osnews.com (sbergman27)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Why?</title>
			<link>http://www.osnews.com/thread?298351</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298351</guid>
			<description><div class="cquote">Additionally, there's currently no law requiring that open-source projects identify themselves as such in marketing and during installation so the user can opt out, so many people use open-source programs unknowingly </div><br />
<br />
There's no law requiring closed source software to indentify themselves as such in marketing and during installation so many people use closed source programs unknowingly.</description>
			<pubDate>Wed, 30 Jan 2008 02:57:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: If you say so...</title>
			<link>http://www.osnews.com/thread?298352</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298352</guid>
			<description><div class="cquote">I don't think anyone will quibble about security risks running unknown copies of open source; </div><br />
<br />
Please explain how this is different from running unknown software that isn't open source.</description>
			<pubDate>Wed, 30 Jan 2008 03:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by Soulbender</title>
			<link>http://www.osnews.com/thread?298355</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298355</guid>
			<description><div class="cquote">&quot;HP gave an example of a recent customer that had three times as many FOSS licenses as originally estimated -- 75 licenses rather than 25. This left customers with a choice: implement governance policies to allow the safe use of FOSS, or replace the software at an estimated cost of $80 million.&quot; </div><br />
 <br />
 Wow. Welcome to the land of bullshit.<br />
 Seriously, that sentence makes no sense. Did they have software licensed under 75 different OSS licenses? Did they have 75 users of some OSS software that is per-seat licensed? Or something else entirely? What governance policies?<br />
 <br />
 <div class="cquote">&quot;Open source software is different than traditional proprietary software </div><br />
 <br />
 Other than how it's licensed it's no different.<br />
 <br />
 <div class="cquote">and most people don't know how much they have embedded in their hardware.&quot; </div><br />
 <br />
 What? Embedded in the hardware? Why the fsck would that matter? If it's embedded it comes with the damn product. Why does it matter if a hardware device is using OSS or not?<br />
 <br />
 <div class="cquote">Users have uniformly told us that they don't know how much open source software they had </div><br />
 <br />
 I doubt &quot;users&quot; know how much software they have, regardless of license.<br />
 <br />
 <div class="cquote">FOSSology and FOSSBazaar are completely free, but HP refused to issue pricing for its Health Check Services, which vary depending on the service. </div><br />
 <br />
 Wow really. No price eh? There's a surprise for ya.<br />
 <br />
 You know, if they had said that it helped you find unknown OSS software so you could keep track of it and keep it updated that would have been one thing but this, this is just bullshit,Edited 2008-01-30 03:28 UTC</description>
			<pubDate>Wed, 30 Jan 2008 03:27:00 GMT</pubDate>
			<author>donotreply@osnews.com (Soulbender)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Why?</title>
			<link>http://www.osnews.com/thread?298363</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298363</guid>
			<description><div class="cquote">What a useless product. Why would using OSS pose management and legal problems? Sounds like FUD to me. </div><br />
<br />
Well, the FSF is taking an aggressive stance now with pursuing legal action against GPL violators.<br />
<br />
Steve Ballmer is beating a tin drum about OSS projects violating MS IP.<br />
<br />
Sun themselves are in a two-way lawsuit over patent violations in ZFS.<br />
<br />
Trend Micro is barking patent claims against ClamAV, which is integrated into a surprising number of commercial enterprise-class security applications/products.<br />
<br />
Linux kernel devs like Grek KH claim that closed drivers such as nvidia's are GPL violating, whereas Linus himself disagrees.<br />
<br />
Qt respects a multitude of OSS licensing options but requires a commercial license for any applications that don't meet those OSS requirements.<br />
<br />
The list goes on...<br />
<br />
It's one thing to argue semantics on a tech-oriented forum such as OSNews. It's completely different to argue them with compliance-regulated commercial organizations that risk liability for license violations.<br />
<br />
This isn't a bad thing HP is doing, so let's take the tinfoil hats off for a second and stop assuming that they're somehow trying to undermine OSS adoption, particularly considering they are a significant backer and contributor to OSS.  <br />
<br />
Commercial organizations operate under different priorities and requirements than your average tech enthusiast. Despite the growing adoption of OSS within enterprise class organizations, it's still a scary concept for many CIO's to try and navigate the requirements and obligations of various OSS licenses, particularly if they're creating software applications around them. Sarbox also implies a requirement for due diligence when it comes to things like IP issues, so execs often discard alternatives in favor of the warm and comfy proprietary licenses they are familiar with, complete with legal indemnity.<br />
<br />
If you've got a bone to pick, don't blame HP. Blame MS for bringing up the issue of IP compliance to enterprises when it comes to OSS. Used appropriately, this is a tool for OSS-favorable CIO's to get a measurable handle on how non-proprietary tech is being used within their organizations.<br />
<br />
I see the glass as being half-full, but I imagine that there will be many that insist on seeing it half-empty.</description>
			<pubDate>Wed, 30 Jan 2008 04:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (elsewhere)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Answer : Lot of Illegal BSD code </title>
			<link>http://www.osnews.com/thread?298379</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298379</guid>
			<description>Most of BSD and OSS is illegal and raise flag about there provenance and sustainability in court , unlike GNU/Linux and real Free Software it as not been proven as legal.<br />
<br />
Lots of Management are paid or convinced to remove FOSS for Proprieatry solution , they just don't know the real cost of there decision.<br />
<br />
HP is trying to be legal here and a lot of OSS is illegal , not to be compared to GNU/Linux and Free Software who is always legal and most OSS need to be removed completely as it is a liability for company.</description>
			<pubDate>Wed, 30 Jan 2008 05:40:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>HP need to read the license.</title>
			<link>http://www.osnews.com/thread?298386</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298386</guid>
			<description>FTA: <div class="cquote">&quot;HP gave an example of a recent customer that had three times as many FOSS licenses as originally estimated -- 75 licenses rather than 25. This left customers with a choice: implement governance policies to allow the safe use of FOSS, or replace the software at an estimated cost of $80 million.&quot; </div><br />
<br />
If it really is FOSS, then it is absolutely free to &quot;use&quot; (that is, to run). Free as in freedom <b>AND</b> free as in beer. It says so right in the license.<br />
<br />
The only restriction comes when you are a software developer yourself, and only then if the code that you produce actually includes FOSS source code within it, and only then if it is licensed under a copyleft FOSS license (such as the GPL) rather than a permissive FOSS license (such as BSD), and only then if your product itself is closed-source.<br />
<br />
So are HP trying to claim that their customer was a developer who had released 75 closed-source applications which included copyleft FOSS source code, when they thought they had made only 25 applications?<br />
<br />
HP's customer needs to buy $80 million dollars worth of free software? Is that a silly claim or what? HP are sounding utterly stupid with this press release. Either stupid or ignorant of what the licenses actually say.<br />
<br />
If I were a non-developer customer of HP's and HP tried to scare me into buying a HP product with FUD like that, I would drop HP like a ton of hot bricks.<br />
<br />
Even if I were a software developer, I'd take HP's press release to mean that HP thought that I didn't know what I was doing ... and still I would drop HP like a ton of hot bricks.</description>
			<pubDate>Wed, 30 Jan 2008 06:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298387</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298387</guid>
			<description>&quot;I assume this does not refer to having software under 75 different OSI-approved license terms in their organization&quot;<br />
<br />
No , because most OSS license are not aproved or recognised or identified by the OSI. Also the OSI does not certify the legality or integrity in the face of the law of the license used. just that it meet some of it's basic Open Source criteria. <br />
<br />
Example : Heckler &amp; Koch G36 ( a military class assault rifle ) is certified ISO , that's a method of production , the ISO cannot come in court and testify that the G36 is legal and useable as a hunter riffle in CANADA because it's certified ISO.<br />
<br />
Now it may come to you as a shock but in some country many OSS license are declared illegal , BSD being one , because they figure the text is incomplete and that it's not really a license but a contract or protection clause.<br />
<br />
It's a lie by the BSD that all OSS code is equal and that all are legal. <br />
<br />
BSD is not part of OIN for a reason.</description>
			<pubDate>Wed, 30 Jan 2008 06:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Why?</title>
			<link>http://www.osnews.com/thread?298389</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298389</guid>
			<description><div class="cquote">Well, the FSF is taking an aggressive stance now with pursuing legal action against GPL violators. </div><br />
 <br />
 Applies only to software developers who include GPL code in their own product which they then try to release as closed source and charge people for.<br />
 <br />
 <div class="cquote">Steve Ballmer is beating a tin drum about OSS projects violating MS IP. </div><br />
 <br />
 A lot of noise and no substance. Not one actual mention to date of an alleged infringement of an actual patent number from Steve.<br />
 <br />
 <div class="cquote">Sun themselves are in a two-way lawsuit over patent violations in ZFS. </div><br />
 <br />
 Has nothing to do with Sun's use of FOSS. ZFS is Sun's own product.<br />
 <br />
 <div class="cquote">Trend Micro is barking patent claims against ClamAV, which is integrated into a surprising number of commercial enterprise-class security applications/products. </div><br />
 <br />
 These claims are not against ClamAV itself, but rather are against the manner in which one company has used an anti-virus scanner (any one at all would qualify here) in a firewall product. Lots of prior art would indicate this action doesn't have a prayer anyway.<br />
 <br />
 <div class="cquote"> Linux kernel devs like Grek KH claim that closed drivers such as nvidia's are GPL violating, whereas Linus himself disagrees. </div><br />
 <br />
 Which one of these is a copyright lawyer? As long as nvidia binaries contain no FOSS code itself, and do not statically link to GPL code (LGPL doesn't matter), then it does not infringe. This is in fact the case AFAIK, so Linus is correct it would seem.<br />
 <br />
 <div class="cquote">Qt respects a multitude of OSS licensing options but requires a commercial license for any applications that don't meet those OSS requirements. </div><br />
 <br />
 Like any software at all, if you want to include it in your closed-source product, then you must get permission from the author. The GPL does not give you permission to do that, so you must get a separate license from trolltech. This is no different <b>WHATEVER</b> code you use in your closed-source product ... if you did not write it yourself, you must get permission from the author. That would normally involve paying a FEE. This also has nothing to do with FOSS ... this is use in a commercial product.Edited 2008-01-30 06:22 UTC</description>
			<pubDate>Wed, 30 Jan 2008 06:18:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Why?</title>
			<link>http://www.osnews.com/thread?298394</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298394</guid>
			<description>&quot;the FSF is taking an aggressive stance now with pursuing legal action against GPL violators.&quot;<br />
<br />
Nothing new here , at all , the FSF as won every single case of GPL violation it pursued. Mostly by having the thieve comply before going to court.<br />
<br />
The problem is that not all OSS certified code and Free<br />
software licensed code is legal and equal.<br />
<br />
GNU/Linux and Free Software is legal and come with patent legality assured and protected.<br />
<br />
Where as say BSD is Illegal come with no patent legality and is not insured or reviewed for removal of infringing code. They are not even covered by OIN and are infringing on most of OIN patents ( pretty much almost all patent outside Microsoft ).</description>
			<pubDate>Wed, 30 Jan 2008 06:25:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Why?</title>
			<link>http://www.osnews.com/thread?298397</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298397</guid>
			<description><div class="cquote"> Applies only to software developers who include GPL code in their own product which they then try to release as closed source and charge people for. </div><br />
<br />
NO the FSF will pursu all GPL violation. The thing is most of them comply as soon a sthe FSF show up since it's a legal and recognised license tested in court.<br />
 <br />
 <div class="cquote"> A lot of noise and no substance. Not one actual mention to date of an alleged infringement of an actual patent number from Steve. </div><br />
<br />
Microsoft is sending it's satellite company to do this job as to not appear as the bad wolf with the antitrust regulation they are under in the US. Problem ( for them ) is everyone they send is striked down in court.<br />
 <br />
 <div class="cquote">  Which one of these is a copyright lawyer? </div><br />
<br />
Neither but Linus is known to make illegal and costly legal mistake.<br />
<br />
- GPL is the second license of the Linux kernel.<br />
- Trademark is not elgal and recognized worldwide beacuse of him.<br />
- Lots of OSS code he included turned out have to be removed.<br />
<br />
<div class="cquote">so Linus is correct it would seem. </div><br />
<br />
No , Linus just don't know what he is talking about as usual when he goes out of the kernel coding. There is a serious graphic driver problem due to them being mostly OSS , Lot of incompatibilities with upgrade is due to slow fix coming from the proprietary graphice drivers. <br />
 <br />
There are 6 month to a year gap on the higher end graphic driver cards release.</description>
			<pubDate>Wed, 30 Jan 2008 06:41:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298419</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298419</guid>
			<description><div class="cquote">It's a lie by the BSD that all OSS code is equal and that all are legal.  </div><br />
<br />
Sorry to burst your bubble Moulinef, but it is not at all illegal to write software (as long as you actually write it yourself and refrain from copying someone else's work), nor is it in any way illegal to let someone else run the software you have written. As long as you have written the software, then the law is such that you the author gets to say how others may, or may not, use it.<br />
<br />
There is nothing &quot;illegal&quot; about FOSS software.</description>
			<pubDate>Wed, 30 Jan 2008 09:31:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: If you say so...</title>
			<link>http://www.osnews.com/thread?298525</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298525</guid>
			<description><div class="cquote">"<i>I don't think anyone will quibble about security risks running unknown copies of open source; </div><br />
<br />
Please explain how this is different from running unknown software that isn't open source. </i>"<br />
<br />
In general, there is no difference.  However, in server environments (which this software is geared toward), nearly all closed source software is commercial, and generally requires such things as licence information and root access to install, not to mention a commercial agreement prior to receiving the software.<br />
<br />
In contrast, open source can generally be installed without such restrictions, making it far easier to overlook.</description>
			<pubDate>Wed, 30 Jan 2008 19:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (james_parker)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: If you say so...</title>
			<link>http://www.osnews.com/thread?298550</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298550</guid>
			<description><div class="cquote"> nearly all closed source software is commercial, and generally requires such things as licence information and root access to install, not to mention a commercial agreement prior to receiving the software<br />
<br />
...<br />
<br />
In contrast, open source can generally be installed without such restrictions, making it far easier to overlook. </div><br />
<br />
Open source code does not need &quot;looking over&quot;. You are granted permission to install it and run it without any commercial agreement in place. Since you don't need any commercial agreements to install it and run it, what exactly is the point of trying to keep track of commercial agreement papers which don't exist and aren't required?</description>
			<pubDate>Wed, 30 Jan 2008 22:22:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: If you say so...</title>
			<link>http://www.osnews.com/thread?298551</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298551</guid>
			<description><div class="cquote">"<i> nearly all closed source software is commercial, and generally requires such things as licence information and root access to install, not to mention a commercial agreement prior to receiving the software<br />
<br />
...<br />
<br />
In contrast, open source can generally be installed without such restrictions, making it far easier to overlook. </div><br />
<br />
Open source code does not need &quot;looking over&quot;. You are granted permission to install it and run it without any commercial agreement in place. Since you don't need any commercial agreements to install it and run it, what exactly is the point of trying to keep track of commercial agreement papers which don't exist and aren't required? </i>"<br />
<br />
You missed the original context of my initial reply; the problem is that if the software is untracked entirely, the software may not be upgraded to pick up fixes for security flaws that are discovered.  These known but unfixed flaws pose a risk to the company using the software, especially on servers which are accessed or updated by multiple people.<br />
<br />
While being easier to obtain, install, and run is one of the advantages of Open Source, there is a corresponding disadvantage that it is so easy that it can be done with little thought.  That in turn makes it easy to overlook the need to install security updates.</description>
			<pubDate>Wed, 30 Jan 2008 22:40:00 GMT</pubDate>
			<author>donotreply@osnews.com (james_parker)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298618</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298618</guid>
			<description>&quot;Moulinef&quot;<br />
<br />
M o u l i n n e u f , use copy paste if you can't write my real life name properly.<br />
<br />
&quot;it is not at all illegal to write software&quot;<br />
<br />
It is when your not legally given the permission to do it.<br />
<br />
&quot;There is nothing &quot;illegal&quot; about FOSS software&quot;<br />
<br />
I agree.<br />
<br />
The problem is with some &quot;OSS&quot; software.<br />
<br />
You seem to mix Open Source Software with Free Software as if both are all the time the same and equal all the time.<br />
<br />
as for living in a bubble :<br />
<br />
hal twokone aka hal 2001 :<br />
<br />
<a href="http://www.google.com/search?client=opera&amp;rls=en&amp;q=hal+2001&amp;sourceid=opera&amp;ie=utf-8&amp;oe=utf-8" rel="nofollow">http://www.google.com/search?client=opera&amp;rls=en&amp;q=hal+2001...</a> <br />
<br />
...</description>
			<pubDate>Thu, 31 Jan 2008 09:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>I just checked to site out</title>
			<link>http://www.osnews.com/thread?298621</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298621</guid>
			<description>And realized that it was like to ultimate flame-bait generator ... <br />
<br />
<i>Psst ... are you gonna let them use your code like that?</i><br />
What are you talking about?<br />
<i>Well something tells me that Abiword might be using your BSD licensed code and the calling the whole thing GPL</i><br />
Yeah you're right<br />
<i>I'm not saying you have to do something, I'm just saying</i><br />
No your right !!</description>
			<pubDate>Thu, 31 Jan 2008 10:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (de_wizze)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298626</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298626</guid>
			<description><div class="cquote">It is when your not legally given the permission to do it.  </div><br />
  <br />
  Sigh! You really do have a major, major disconnect from reality here.<br />
  <br />
  It is not illegal to write code. You just sit down and type it. As long as it is your own work, no-one can stop you. You do <b>NOT</b> need permission, from anyone.<br />
  <br />
  Once you have written your own work, your very own piece of code ... you are then the author of it. <b>You</b> automatically own the copyrights to it. Not the US government, not Microsoft, not your local pastor ... nobody but you.<br />
  <br />
  As the copyright owner in the code, you may license it however you wish. <b>You</b> set the terms by which others may use it and copy it.<br />
  <br />
  Once again, and with emphasis ... you <b>DO NOT NEED ANYONE'S PERMISSION</b> to write your own code.<br />
  <br />
  <a href="http://en.wikipedia.org/wiki/Freedom_of_speech" rel="nofollow">http://en.wikipedia.org/wiki/Freedom_of_speech</a><br />
  <br />
  <br />
  <a href="http://en.wikipedia.org/wiki/Copyright" rel="nofollow">http://en.wikipedia.org/wiki/Copyright</a><br />
  <div class="cquote">&quot;Copyright - is a legal concept enacted by most national governments, that gives the creator of an original work exclusive rights to it&quot; </div><br />
  <br />
  <a href="http://en.wikipedia.org/wiki/Free_content" rel="nofollow">http://en.wikipedia.org/wiki/Free_content</a><br />
  <div class="cquote">&quot;Because the law by default grants copyright holders monopolistic control over their creations&quot; </div><br />
  <br />
  Since the creator of a work has control rights over that work, they can choose to do this with it if they so please:<br />
  <a href="http://en.wikipedia.org/wiki/Free_software" rel="nofollow">http://en.wikipedia.org/wiki/Free_software</a><br />
  <br />
  PS: sorry about the mis-spelling of Moulinneuf. That was lazy of me.Edited 2008-01-31 11:23 UTC</description>
			<pubDate>Thu, 31 Jan 2008 11:20:00 GMT</pubDate>
			<author>donotreply@osnews.com (lemur2)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[5]: Comment by sorpigal</title>
			<link>http://www.osnews.com/thread?298669</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?298669</guid>
			<description>OK ... That's your point. But it as nothing to do with what I said.<br />
<br />
copyright ownership on the derivative is what's the problem.</description>
			<pubDate>Thu, 31 Jan 2008 15:48:00 GMT</pubDate>
			<author>donotreply@osnews.com (Moulinneuf)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>

