|
|
SOX and the GPL: no "special" risk, but ordinary one bad enough
2006-03-15
This guest column by Wasabi VP and General Counsel Jay Michaelson responds to a reaction from Free Software Foundation General Counsel Eban Moglen to a
target="new">Wasabi whitepaper that discussed potential interactions between Sarbannes-Oxley (SOX) legislation and the GNU General Public License (GPL). Wasabi is best-known for BSD-based embedded operating system stacks licensed under the BSD (Berkeley Software Distribution) license, a less restrictive alternative to the GNU GPL (General Public License) used by Linux. Unlike the GPL, the BSD license does not require modifications and enhancements to be contributed back to the community at large, a "feature" that has made the license popular in some commercial applications, while arguably limiting BSD-licensed software's technical progress and adoption rates, in comparison to Linux. A "talkback" discussion thread linked at the end of Michaelson's column offers LinuxDevices readers a chance to voice their own opinions about GPL/SOX interactions, and about GPL v. BSD license issues in general. We are pleased that FSF attorney Eben Moglen and his colleagues at the Software Freedom Law Center have issued a thoughtful response to our white paper, When GPL Violations are Sarbanes-Oxley Violations. As in our previous discussions with Mr. Moglen, we find ourselves in agreement with him, and find his arguments to be excellent support for our position that cheating on the GPL poses serious Sarbanes-Oxley risks for companies. The SFLC's white paper makes four arguments in support of its claim that the GPL poses "no special risk" in regard to Sarbanes-Oxley ("SOX"):
We agree with all four primary arguments, but there are some important nuances that the SFLC's paper omits. In order:
Perhaps some of the confusion here came from some of the press coverage of the white paper, rather than the white paper itself. Sarbanes-Oxley is not a risk for mere users of Linux (as opposed to developers), private individuals (as opposed to companies), or those who fully comply with the GPL (as opposed to those who cheat). It is a risk for companies that cheat on the GPL, and make their money selling software they don't rightfully own. Or perhaps some of the confusion has stemmed from Wasabi's own product line, which includes a GPL-free embedded operating system called Wasabi Certified BSD. It's certainly fair to observe that we have a stake in the game. But that doesn't invalidate our arguments; take a look at what we say and make up your own mind. In any case, Wasabi is not anti-GPL. Wasabi routinely develops software that is subject to the GPL and contributes it back to the Free Software Foundation. For example, sources contributed back to FSF can be found here and here. Our GNU suite for Intel XScale Processors can be downloaded here. We use Linux for some in-house work, and our Storage Builder line of products is compatible with Linux. What we have noticed, over many years in the business, is that a surprising number of companies are unaware of the requirements of the GPL, and the consequences of cheating on it. We chose BSD as the basis for our embedded OS for a reason: because it allows people (and companies) to be free, not just software. Under the BSD license, Wasabi and its customers can keep code proprietary if they wish, for as long as they wish. That's why no one cheats on it, and why we don't need an enforcement arm prosecuting over fifty violations a year. It's not that Linux poses any "special" Sarbanes-Oxley risk. It's that if you're a company, and you're cheating on the GPL, the ordinary one is bad enough. About the author -- Jay Michaelson is vice president and general counsel of Wasabi Systems. Prior to Wasabi, Michaelson founded and ran one of the first independent Internet consulting firms specializing in the non-profit and academic markets, with clients including Yale University and Tel Aviv University. He also worked for an Israeli law firm specializing in international technology-related transactions. Michaelson's work has been published in several newspapers and magazines, as well as law journals including the Yale Law Journal and the Duke Law Review. He received his J.D. from Yale Law School in 1997 where he was a senior editor of the law journal.Related Stories:
|