coordinated compliance efforts addresses the issues of this thread
Felipe Contreras
felipe.contreras at gmail.com
Wed Nov 7 19:03:52 UTC 2012
On Sat, Oct 20, 2012 at 10:19 PM, farmatito at tiscali.it
<farmatito at tiscali.it> wrote:
> I would like
> to bring to your attention a few articles of this law
> as they are in
> the "real" reality:
The reality in Italy.
> Collective works made by the union of other works
Software projects are not a dictionary; it's collaborative work, not
collective work. CPAN is a collection, busybox is not.
> This opens up interesting questions about the ownership of the
> copyright of collective works
> like for example busybox or even the
> linux kernel.
Linus Torvalds has said that it's up to each developer to decide how
to exercise their copyright rights. Even if under *Italian* law the
Linux kernel was considered nothing more than a compilation of other
works, Linus Torvalds wouldn't ask for enforcement.
> it is very naive for the part that concers the
> commercial entity
> as in most law system there are the concepts of:
> 1)
> due diligence
> 2) wilful misconduct
> 3) worngful conduct
The burden of proof is on the plantiff to demonstrate either of those,
and if the defense shows proof of due diligence, and no signs of the
other, they can't be considered at fault.
But let's assume they are, the court will force to either a) get a
proper license from the copyright owner (which might mean complying
with the GPL), or b) stop using that software from their products. But
this doesn't automatically transfer rights to the end-user.
Which is what the court would ask them to do anyway, even if they are
not guilty of misconduct. The only difference is that they won't get
punitive damages.
> I also doubt
> you would dare to make the same example
> if the program at stake would
> be a proprietary software.
Yes I would, specially in this case. If my software is proprietary, a
colleague of mine sells it to another company, how on Earth can the
company be blamed for something they didn't know (and couldn't know).
They can't use Google to search for my code, because it's not there.
So even if the company spends tons of resources in their due
diligence, they won't find anything wrong.
> Now let us reduce and analyze the only
> important step of the example:
>
> 3) Federico (licensor) ->
> Commercial entity (licensee) # Commercial entity gets the
> source code
> by paying money to Federico, which provides it with a __(FALSE)__
>
> propriety license
It is a true license. Federico can sue the Commercial entity for not
complying with the license. The license might get invalidated if it's
found out that Federico had no rights to license the software, but
that makes it invalid, not "false" (whatever that might mean), and
that might not happen at all.
> The commercial entity must follow the principle of
> due diligence
> and have to ascertain that the source code they are
> buying for their product
> is legally sound as they have the knowhow
> legally and technically.
> If they fail to do so it is at least a wilful
> misconduct. In other words no
> commercial entity whatsover will give
> money to the first Federico that comes knocking
> at their door without
> being sure he is the author of the software being sold.
Nobody can be sure of anything. After doing their due diligence they
might find no signs that the software comes from another entity, where
in fact they are wrong. Specially if the software is proprietary.
In a trial, if they show proof of this due diligence, they are out of
the waters.
> In case of a wrongful conduct/wilful misconduct
> there are third parties that are damaged
> and that are entitled to start
> a legal action whatever the outcome will be.
Yes, *in that case*, which might not be.
Either way, in reality, companies might be forced to pay money to the
plantiff, or stop using the software, or if found guilty of
misconduct, punitive damages, but not give rights to the end users.
The company is the one that decides.
--
Felipe Contreras
More information about the busybox
mailing list