|
|
Log in / Subscribe / Register

Cisco isn't malicious -- just organizationally-challenged

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 14, 2008 17:10 UTC (Sun) by shaneo (guest, #48399)
Parent article: The FSF raises the stakes for Cisco

After having recently spent some time at Cisco working in the GPL-compliance area, I'm confident that this breach is not one of intent. In fact, Cisco has taken HUGE strides in ensuring GPL-compliance across Cisco-proper. However, Linksys is still held at arm's length and is not forced to be subject to most of Cisco's new GPL-related requirements.

The strongest argument against Cisco in this case is simply the fact that this happens EVERY time Linksys releases a new product and Cisco-proper--which acknowledges the importance of GPL compliance in its other product lines--doesn't step in to stop the madness. The FSF has been more than patient with Cisco (as Jonathan notes above) and they've chosen now to apply leverage.

It's sad that Cisco couldn't get its act together to prevent this, especially considering their awareness and compliance with their enterprise and carrier products. Perhaps this is the call to action they needed.


to post comments

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 15, 2008 16:52 UTC (Mon) by NAR (subscriber, #1313) [Link] (3 responses)

Did Linksys/Cisco actually modify the included GPLd software? If not, a simple ftp://ftp.gnu.org/gnu/ link somewhere in the license documentation would be (nearly) enough...

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 17, 2008 11:22 UTC (Wed) by etienne_lorrain@yahoo.fr (guest, #38022) [Link]

Well, Linksys is manufacturing wireless routers, isn't it?
So there is a linked-in wireless driver - probably closed source (i.e. not developped by Linksys, they just licensed it from another company) - and that is possibly/probably the reason the source of the whole product is closed.

People cannot complain about those two things at the same time:
1) GPL is too restrictive, companies should be able to produce/sell Linux derived products using binary only drivers (wireless drivers, windows printers/modems, graphic and video drivers, hardware RAID...).
2) The open-source driver for their well known chipset (from the list above) does not exists, is not debugged enough - is not working.

Because if the GPL system were working correctly, the offending company would have had to pay more for the driver (so that it could be released as open source) before they produce/sell their own product.
And so there would be an available and working open source driver for Linux for your own computer on your distribution.

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 18, 2008 11:59 UTC (Thu) by alex (subscriber, #1355) [Link]

If not, a simple ftp://ftp.gnu.org/gnu/ link somewhere in the license documentation would be (nearly) enough...

Except it's not as your "nearly" comment alludes to. The responsibility of ensuring the source code is available resides with the entity distributing the binaries. I suppose if they made arrangements with a third party to ensure the source would be available for the next 3 years they might get away with it.

The company I'm currently working for distributes a product which is essentially Ubuntu + it's own proprietary user space. As it wanted to control the updates that go out we mirrored the Ubuntu release and made an apt repository available. When I was building the server I made sure we mirror the source packages as well so apt-get source will work. You get exactly the same source code as you would downloading from Ubuntu's servers (modulo the snapshot date) but this way ensures we are in compliance.

If companies can have lawyers looking at the contracts they sign with proprietary vendors why can't they offer the same care and attention to detail when dealing with FLOSS code? It's not rocket science.

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 18, 2008 18:23 UTC (Thu) by dlang (guest, #313) [Link]

it's not nearly enough. the FSF has gone after a linux distro in the past that did this. (this is the mepis lawsuit that Rob is so upset about)

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 19, 2008 23:49 UTC (Fri) by giraffedata (guest, #1954) [Link]

It isn't malicious, but it's obviously not simple negligence either. It's impossible to believe that at some point in the lengthy release process a Cisco employee didn't ask a representative of the far east manufacturer if there is any code in there it didn't write. And if so, what Cisco would have to do to get a license to distribute it.

Not only that, the unimportance of copyright in the far east country in question does not explain the copyright violation, as the article suggests. The far east company is in the business of producing products for the US and European markets, for customers subject to US and European laws; I'm sure it is more familiar with US copyright issues than those of the home country.

Someone had to have actively decided to ignore the problem. Instead of negligence, I would call that insouciance or apathy, or maybe recklessness.

You really can't distinguish between Cisco and Linksys in this discussion; if Cisco management chooses to let its Linksys employees run wild, it's part of Cisco's recklessness. But it would be fair to say there are two pieces to Cisco, one that's good with GPL compliance and one that isn't.

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 20, 2008 10:34 UTC (Sat) by rwmj (subscriber, #5474) [Link]

You just have to replace GPL software with (eg) Windows CE in there to see how serious this is.

In fact, Cisco has taken HUGE strides in ensuring [Windows licensing] across Cisco-proper. However, Linksys is still held at arm's length [and continues to include unlicensed copies of Windows CE in their routers].

How many nanoseconds do you think Microsoft would have tolerated those sorts of violations? The FSF by contrast has been far more than just "patient". It has been exceptionally forgiving of something which, in the proprietary world, would have seen Cisco's offices raided repeatedly from day 1.

Cisco has saved probably hundreds of millions in licensing and support by using Linux and the GNU toolchain, and being "organizationally-challenged" is no excuse at all.

Rich.

Cisco isn't malicious -- just organizationally-challenged

Posted Dec 22, 2008 4:04 UTC (Mon) by shaneo (guest, #48399) [Link]

Sorry, Rich, but you're wrong. Cisco's inability to get its arms around licensing IN GENERAL is flawed and that's what they are working to remedy. Microsoft CE, Linux, gcc -- pick your poison; if Cisco doesn't know it's being used in a product, they cannot comply with the license. My point is that what's fundamentally "broken" here is Cisco's processes that allow this to occur, not their corporate ethical stand. I'd guess with some confidence that there is a team of folks DEDICATED to fixing to this problem so it doesn't happen again, but when you're fixing an organization and a culture, it's more difficult than just adding another step to a process.

Cisco has been down this same path (serially, in some cases) with commercial vendors as well. Always quick to remedy, Cisco isn't trying to steal anything from them either and always pays (and sometimes pays contractual penalties as well).

I don't think you understand how licensing typically works w/ big companies that have LOTS of products, global presence, and few controls. Software in most of these companies is described as an "image" or a "load" and rarely contains a "Bill of Materials" that describes everything in that image. Lacking that Bill of Materials, how can a manufacturing group (which is separate and distinct from the group that built the software) enforce compliance by shipping the code? Thus my point on this being organizational in nature.

Sure, the basic commercial licensing model still holds: $BIG_COMPANY decides to build a product, they decide what components they are going to use/license, they contact those vendors and negotiate a deal for including their software in the product, and some money changes hands. The problem is different for "freely-downloadable" software--most engineers are NOT familiar with open source licenses and aren't aware what they are (or potentially are) obligating their company to when downloading the software. This is a shift in the problem from your Microsoft CE use-case, since you can't just go out and download Microsoft CE and embed it in your product...you need license keys, etc.

In many ways, ease of access to the code is the weak link in the chain for Cisco and other values of $BIG_COMPANY.

And to be clear, I'm not saying that Cisco isn't on the hook for compliance here, I'm simply making the point that non-compliance is not done with intent or malice. Doesn't make it right and Cisco SHOULD improve its processes (and I'd bet that this suit will be the catalyst for that exact response), but Cisco shouldn't earn the wrath of the Slashdot fan-boys for this. There are too many other valid reasons for Cisco to earn their wrath...


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds