From: Nikolai Weibull Date: 2005-04-15T19:31:46+09:00 Subject: Re: Practical considerations for licensing software written with dynamic/non-compiled languages/platforms Matt Pelletier, April 15: > What options does one have, as a company that produces software that is > distributed directly to clients/VARs, when that software is built with a > platform/architecture that uses a dynamic (non-compiled) language, and > further, when that platform and/or language is open-source? This > question qualifies for Rails and Ruby, but also it could hold for PHP, > Perl, etc. Documentation, Support, and updates. > I'm interested not just in the general legal considerations (like > licensing, intellectual property rights), but also practical > considerations. For example, I could get an airtight licensing contract > written for me, but if I have to hand the software to a client or > vendor, they could easily turn around and get a team to re-sell it under > another name (Pear PC anyone?). At least with designer bag knockoffs > there is the latent pride on the part of the consumer of having the > *real-thing* (albeit at 10x the cost). With software, if it walks like a > duck and talks like a duck... who cares if it's a rip-off? I could force > the use of keys or certificates, but these are easily cracked even when > the software is written in C++. This is less likely to happen in the > ever-litigious US, but it's a major concern for any company working > internationally, where well-trained techies, cheap labor, and loose > laws/enforcement abound. You couldn't get an airtight licensing contract. They don't exist. And if you could, how could the client then turn around and get a team to re-sell it under another name? That'd be breaking the license, right? Still, what you get with the "authentic" software is a sense of reliability, right? Cheap labor is everywhere but the US is it? Loose laws/enforcement everywhere but the US? Man, I don't want to be a bastard, but you're sounding just a tad racist right about now. > If we wrote software in assembly it would still be a concern, but when > there is little-to-no reverse-engineering needed for languages that > don't need to be compiled in the first place, it affects decision-making > when selecting platforms/languages, which is rather unfortunate. With > Java/.NET you can download a decompiler and have source code exported in > a day. You can obfuscate, but that's a small comfort; anyone with time > and interest can figure that out. With dynamic languages, all the hard > work is done for you. One days work isn't really that much work, is it? So the difference between decompilable languages and uncompiled languages is non-existant really. > If you are operating as an ASP (a la 37 signals with Basecamp), this > isn't much of an issue. However, if you have to give your software to > *anyone*, whether a client to run on their own network, or to a 3rd > party in general, what are your options? Why do you have to give it away? > This isn't really a concern when dealing with smaller projects for > smaller clients, where the compensation is based on project time, even > if license it to them (as opposed to letting them own it). In those > cases, PHP (and from this point forward RoR!) is usually the best > choice, for all the reasons that we love (quick development, simple > changes / customization). But when you're licensing software that you > own, the value - which at face value is the feature set and > maintenance/support services - ultimately boils down to the source code, > and needs to be protected to the fullest possible extent. Yes there are > business models where the value is strictly your support (Red Hat, at > least at first), but that's not really what I'm asking about (though I > welcome the comments). You obviously haven't had much experience with open source. It seems that you should get more information before posting questions regarding open source to a programming-language mailing list. Opensource.org should have all the information you may need. I am not trying to end this discussion, but I don't think you'll get much out of this discussion if you haven't tried to understand how open source works. > This is something I've been curious about for some time, but PHP et al > have never been attractive alternatives for larger projects. RoR is > compelling enough that these concerns have escalated. Again, when you're developing an online service, you really don't have to worry about anyone trying to steal your work. You control everything. Check out some of the essays by Paul Graham (paulgraham.com) on the subject, nikolai -- Nikolai Weibull: now available free of charge at http://bitwi.se/! Born in Chicago, IL USA; currently residing in Gothenburg, Sweden. main(){printf(&linux["\021%six\012\0"],(linux)["have"]+"fun"-97);}