Practical Technology

for practical people.

September 13, 2004
by sjvn01
0 comments

No News is Open-Source Solaris News

Dear Sun,

Since your president and COO is so fond of open letters, I thought I might deliver one of my own.

On Monday, at a press conference in Burlington, Mass., you announced that you were open-sourcing Solaris 10. You also said that Solaris 10 would have a new file system, and that Solaris 10 users will be able to run Linux programs.

I dont understand. Is it just me, or have we heard all this before?

You said you still didnt know what you were going to do about an open source license. In fact, I found out that you havent approached OSI (Open Source Initiative) about any license for open-source Solaris yet. Danese Cooper, head of Suns Open Source Programs Office, does tell me, “It will be under an OSI -approved license. We have not yet submitted a license.”

Maybe its just me but isnt having an open-source license kind of fundamental to having an open-source project?

Now, I do know that youve been talking with some developers under non-disclosure agreements lately about open-source Solaris. I also know theyre not happy with what they see as a lack of any real progress.

Jason Perlow, owner of Argonaut Systems, an integrator, and someone in the know when it comes to open-source Solaris, says that Suns Monday announcement, “showed no actual plans or forward movement with the open source community.”

Could it be that thats because, as Perlow puts it, “I dont see how they can open source Solaris until SCO is no longer a viable company and to say anything else is just smoke and mirrors.”

Ah yes, thats right. SCO owns Unix. Or, well, at least they and their high-powered attorneys claim they do anyway.

As Dan Kusnetzky, IDCs program VP for system software, told me, “Its hard for me to understand this (Sun open sourcing Solaris). While Sun pre-paid their royalties for Unix a long time ago, they would still agree that it is a derivative work-it is Unix. The SCO Group is the current owner of Unix and is not at all likely to allow its intellectual property to be freely given away under any open source license. I dont understand how Sun could give away what they dont own.”

Thats a good question. So I asked SCO for an answer.

This is what the boys from Lindon, Utah had to say through Blake Stowell, SCOs PR director: “All I can say is that Sun has the broadest rights of any Unix licensee while at the same time, were confident that Sun knows and understands the terms of that Unix license.”

That doesnt sound like a ringing endorsement for Sun to go ahead and open source System V Unix, Solaris Unix foundation, to me.

Now, I have an idea. Call me crazy, but how about the next time your competitors—like Novell, with its Linux announcements, or IBM with its Power5 Linux release—have real news, why dont you keep quiet until you have something real to say yourself?

It seems to me that youve developed a bad habit of manufacturing news when you really dont have any. Remember how your president said Sun was thinking of buying Novell during LinuxWorld a few weeks back and no one took you seriously?

If you want me, and much more importantly your customers and partners to take you seriously, I think you should stick to announcing news only when you have real news.

Sincerely,

Steven

A version of this story first appeared in eWEEK.

August 2, 2004
by sjvn01
0 comments

Open-Source Insurance Provider Finds Patent Risks in Linux

SAN FRANCISCO—On Monday, OSRM, a provider of open-source consulting and risk mitigation insurance, announced that the group has found that there are 283 issued, but not yet court-validated, software patents that could conceivablly be used in patent claims against Linux.

Thats the potential bad news for Linux developers and users. The good news is that the Linux kernel contains no court-validated software patents. For those who are seriously concerned about the risks, OSRM (Open Source Risk Management)will be offering a litigation insurance policy starting in 2005.

OSRM began offering copyright infringement insurance to Linux users in April 2004.

Patent attorney Dan Ravicher, leader of the OSRM patent study and executive senior counsel to the Free Software Foundation, added that only about “half of software patents stand up in court.”

Of those 283 issued patents, Ravicher continued, “about a third are held by organizations or companies that are seen as Linux friendly: IBM, HP, Novell, Red Hat, etc. At the same time, though, 10 percent of these patents are held by Microsoft.”

Ravicher also points out that, “This is not a doomsday scenario. This number of potential patent concerns is typical for a software product of the size and complexity of Linux.”

OSRM wont publicly say what the specific software patents are that potentially affect Linux because it “would put the whole developer community at risk.”

Thats because of what he describes as the “Catch-22 of patent law … Patent law is meant to popularize technology, but at the same time if you look at software patents as a developer, you put yourself at more legal risk.”

“Current U.S. patent law creates an environment in which vendors and developers are generally advised by their lawyers not to examine other peoples software patents, because doing so creates the risk of triple damages for willful infringement,” explained Daniel Egger, chairman and founder of OSRM.

“This studied ignorance leaves the field open to those who would spread fear and disinformation. It also means that only a vendor-neutral entity, like OSRM, has the freedom and incentive to assess the true risks.”

So what can developers and users do?

According to Ravicher, they have five possible approaches.

First, he suggests advocating for “patent policy reform.” Because as it is now, “Its ridiculous.” But, while this would be the best, comprehensive answer, “it will take a while-years-if ever before the laws are reformed.

Next, if you already suspect theres a specific patent that might be a problem for Linux, start looking for prior art to get the patent overturned if its holder tries to take it to court.

There is already a public project, Grokline, which is working on “creating a history of Unix and Unix-like code with the goal of reducing, or eliminating, the amount of software subject to superficially plausible but ultimately invalid copyright, patent and trade secret claims against Linux or other free and open source software.” Grokline is directed by Pamela Jones of Groklaw, the well-known SCO litigation news site, and receives support from OSRM.

You can also be ready to design around existing patents. This can only be done on a case by case basis and again its something of a Catch-22 since you can only design around it, said Ravicher “after the threat is upon you.”

In such cases, however, its not enough to show that you immediately acted to take care of the patent issue. Ravicher explains, “The rule is that you must have an attorney state that, in their expert opinion, youve taken such action.” Such letters, Ravicher continued from qualified attorneys run around 20 to 40 thousand dollars.

Finally, Ravicher says “You can simply pay for a patent license so long as you do so in a way that doesnt conflict with the GPL.”

Many people, he adds think that patent licenses almost always conflict with open source licenses but thats not the case. “Some patent licenses are compatible with GPL and some patent-holders are willing to expressively say that in their licenses.

The problem with most of these solutions continued Ravicher is “that theyre one-shot, case-by-case answers. There is no immediate and comprehensive solution.”

In response, OSRM will be expanding its risk mitigation and insurance offerings to cover this quantifiable risk.

“Patents pose a financial risk to corporate Linux users-just like they do to corporate users of almost any software-because, whether or not a patent is truly infringed, it costs $3 million dollars on average to defend a patent lawsuit,” said Ravicher. “This heavy cost of proving even weak patents invalid could fall on unprepared end-users, who, until now, have often been forced to pay settlements to avoid risking millions on litigation. Orems new patent insurance gives such end-users another way to address the issue, as it is a direct competitive alternative to licensing or litigating.” Ravicher summed up his findings.

Specifically, OSRM will be supplying patent-infringement defense insurance for Linux developers and users. At first, this program, which will roll out in 2005, will only be available for the Linux kernel, but OSRM will it extend it to more open-source programs over time. The insurance, which caps out at $5 million, will pay for a legal defense and for damages.

“The most important message to take away, based on Orems proprietary research and quantitative models and the best independent legal analysis available to us, is that the core of the Linux operating system appears to be a normal, insurable patent risk for the businesses that use it. And, based on our hands-on work with many different types of customers, we have found the total cost of ownership of using Linux to still be dramatically lower than proprietary alternatives for customers that add in the cost of effective risk-management,” said Egger.

“What it boils down to is that Linux has patent risks; but they can and will become conventional insured risks, just an everyday cost of doing business. OSRMs whole mission is to make the issue of Linux liability simple, routine, and manageable.”

A version of this story first appeared in eWEEK.

July 12, 2004
by sjvn01
0 comments

Firefox 1.0 is almost here

The final version of Mozilla’s Firefox will be arriving on September 14th accoding to lead engineer, Ben Goodger.

Open source browser fans, and those who have grown distrustful enough of Internet Explorer’s security flaws to consider alternative browsers, will be looking forward to the first non-beta release of the Mozilla Foundation’s Firefox. This standalone browser has been in development since 2002.

The Mozilla Foundation renamed its standalone browser, formerly known as Mozilla Firebird, to Firefox with its 0.8 release earlier this year.

Goodger’s says, ” Our target for our 1.0 release is ‘best of breed’ browser product on Windows, Linux, and MacOS X and before we can make that claim, a number of things need to be done.” These include squashing “high complexity/risk and localization impact” bugs.

To make the ambitious release date, some features, such as the Font Options UI (user interface) and the Bookmarks Manager UI have been frozen.

Still, as a quick look at the Firefox 1.0 Release Forum will show, users are concerned that the developers are pushing too hard to release the program on time without fixing minor bugs, such as memory leaks, which others regard as “showstoppers.”

Goodger addresses these concerns in the forum writing, “Again, no software release is ever flawless. We need to draw a line in the sand otherwise we’ll never ship, which means we’ll never be able to begin the more aggressive feature goals we have for the post 1.0 period.”

Goodger is also well aware that recent Internet Explorer security problems has greatly increased interest in Firefox, ” as a result of the IE security scares, (there has been) 722,000 downloads of 0.9.1 in one week from Mozilla servers.”

Marius Kirschner, president of the small NY/NJ ISP, Agora Online, is one of those 722-thousand, “I tried FoxFire last week. I have to say I’m impressed. The pages load faster, I’m in love with the tabbed browsing, it has a build-in popup stopper and a host of other well thought out features. It’s been now 5 days and I don’t intent to switch back.”

That said, as others have observed, Kirschner has found some trouble with IE-specific sites. “The bad news is that at least one of my admin sites was written for IE and if I want to access that site I need to use IE. However, unless I run into some major problems I’ll keep FoxFire as my primary browser.”

So it is that between IE security concerns and Firefox’s increased functionality, it appears that there will already be a large user community awaiting Firefox’s final release this fall.

A version of this story first appeared in eWEEK.

June 28, 2004
by sjvn01
0 comments

Internet Explorer Is Too Dangerous to Keep Using

OK, I confess it: I’ve used Internet Explorer a lot. After being a die-hard Netscape user, I finally got fed up with the sheer bulk of that browser and started using Internet Explorer on my Windows machines.

As time went on and open-source Mozilla matured, I started using Mozilla as my main Linux Web browser and as my secondary Windows browser. This past Friday, though, I started installing Firefox, the browser-only side of Mozilla, on every one of my production Windows machines.

Why? Because Internet Explorer, like Outlook, has finally become, to my mind, a permanent security hole that masquerades as a useful application.

Strong words? Have you really thought about this latest exploit? It could hit every Internet Explorer (IE) browser that merely visited any page served by an infected Microsoft IIS (Internet Information Server).

No anti-virus program would stop it, no firewall would slow it down and no shipping IE security patch would even notice it. Visit the page, get the infection. It was that simple.

Oh, but the few thousand people running Release Candidate 2 of Windows XP Service Pack 2 were not vulnerable to the client-side attack. And if you were one of the very few people who had all of the current critical patches installed and were running IE with its security settings at “high,” you’d be OK. That leaves, oh, say, 95 percent of all IE users wide open to this attack. I feel so much better now.

And just how bad was this attack? Boys and girls, let me tell you, this was the worst security violation I have ever seen. But don’t take my word for it.

Johannes Ullrich, a handler at the Internet Storm Center at The SANS Institute in Bethesda, Md., wrote, “A large number of Web sites, some of them quite popular, were compromised earlier this week to distribute malicious code.

“The attacker uploaded a small file with JavaScript to infected Web sites and altered the Web server configuration to append the script to all files served by the Web server (IIS). The Storm Center and others are still investigating the method used to compromise the servers. Several server administrators reported that they were fully patched.”

What sites were spreading the infections? We still don’t know. Neither the security companies nor the businesses running the infected sites are talking. Since theyre not being any help, I can only suggest that you update your anti-viral software and run it—now.

The only other thing I can say is that sites running IIS 5, which hadn’t been patched up to Aprils MS04-011, were the ones targeted by this exploit. But, Im sorry to say, its still not clear that even sites that had been patched with MS04-011 were safe. There are reports that even patched IIS servers were infected.

What happened next was that after simply visiting what looked like a perfectly ordinary page, the JavaScript hidden with the page would direct your browser to quietly download and install one of several different programs from a Russian Web site. “These Trojan horse programs include keystroke loggers, proxy servers and other back doors providing full access to the infected system,” Ullrich said.

A version of this story was first published in eWeek.

May 23, 2004
by sjvn01
0 comments

Solaris on Intel: Here We Go Again

Back when we built computers with stone knives and bear skins—OK, 1993—I reviewed the first version of Solaris for Intel for PC Magazine. I liked it. I also noticed at the time that Solaris on Intel wasnt the equal of Solaris on SPARC. It never did catch up.

It didnt because Sun didnt want it to catch up. And why was that? It was because Sun was making a lot more money from its SPARC hardware than from its software.

And so it was that Solaris on Intel, also known as Solaris x86, was a loss leader to give business customers a taste of what Solaris could do. Then, when they needed to do more, theyd come to Sun to buy a SPARC box. It was an arrangement that was profitable for both Sun and its resellers.

But by the early 2000s, it wasnt working anymore. Linux was eating up what little market Solaris on Intel had. By 2002, Solaris on Intels market had shrunk so low that it was no longer working as a way to get people to move to Solaris SPARC.

Mind you, it wasnt that it wasnt popular. Solaris on Intel was, and is, popular. Suns Graham Lovell, director of Solaris product marketing, told me in 2002 that more than 1.2 million copies of Solaris under the Free Solaris program have been downloaded, and that “the vast majority—approximately a million—has been Solaris 8 on Intel.”

But Linux downloads were in the tens of millions and, popularity doesnt pay the bills.

Almost all of the downloaders were playing with Solaris, not deploying it in the enterprise. Dan Kusnetzky, IDCs vice president of system software research and grandmaster of all statistical things operating system, told me at the time that almost no one was actually using it in business.

So it was that early in 2002, Sun announced that there would be no Solaris 9 for Intel. That should have been the end of the matter. Instead, a vocal group of Solaris on Intel fans called Save-Solaris.org, refused to let Solaris on Intel die.

Now, I was sure that Solaris on Intel was as dead as a Norwegian Blue Parrot, but Sun brought Solaris 9 on Intel back from the dead.

Lovell told me at the time that Sun, then and now in financial trouble, was looking for additional sources of revenue. And it “found a lot of customers who told us that there was a value to Solaris 9 on Intel platform and they were prepared to pay for it.”

Fast forward to 2004, and Solaris x86 is still popular. I still like it, for that matter. But youll have to look long and hard to find it deployed in many businesses.

Despite the fact that it hasnt gone much of anywhere in the enterprise, Sun has found 15 more systems and embedded-device device vendors, albeit small ones, to ship Solaris on Intel.

I dont get it. I mean, yes, I like it. But then, I also like BeOS, OS/2 and CP/M-80. What can I say? Some people collect baseball cards, I collect operating systems.

As far as I and the operating-system market analysts I know can tell, there simply is no significant business market for this operating system.

The funny thing is that Solaris x86, though, could be a serious enterprise operating-system contender. It has most of the Solaris family virtues. The only thing its really lacking is real support from Sun.

For example, where do you think Solaris x86 is in the line of updates of StarOffice, Suns own office suite? If you guessed dead last, youd be right.

It was only in February of this year that StarOffice for Solaris x86 appeared, long after versions for Windows, Linux and Solaris on SPARC had been out for ages.

So, whats really going on here? I dont think you have to look far to see what the real story is. Sun, while officially on the Linux bandwagon, is continuing to rail against the leading commercial Linux company—and ironically enough its own best Linux partner—Red Hat Inc.

Once more, Sun is using Solaris on Intel not for its own virtues, but as a pawn for other business purposes. First, it was a way to try to get people off the Intel platform to SPARC. Now, its being used to try to stem the tide of people moving away from SPARC to Linux on Intel. It didnt work that well the first time; I dont think it will work that well this time.

So, Sun, would you please either really embrace Linux or just dump it from your inventory, start really pushing Solaris on Intel and declare it the one, true, Sun x86 way? This going back and forth hurts you more than it does the cause of commercial Linux.

A version of this story first appeared in eWEEK.

May 14, 2004
by sjvn01
0 comments

Why Linux Users Hate Red Hat

Tthe company most hated by Linux fans is quite possibly … no, not Microsoft, but Red Hat. I often hear longtime Linux enthusiasts say things like “Red Hat has betrayed Linux” and “Red Hat wants to be the next Microsoft.”

If you look closely, its not hard to see why so much ire is tossed on Red Hat. Late last year, Red Hats CEO, Matthew Szulik, said that for home users today, Windows is probably “the right product line.” Thats sure to win the hearts and minds of Linux fans right there.

Then, Red Hat decided to kill off its low-end Linux distribution: Red Hat Linux. You would have thought from all the screaming in some Linux circles that Red Hat was proposing dog food be made from kittens. Some Linux fans even said Red Hat is on its way to becoming a proprietary software company.

Red Hats corporate enemies and, in one case, a purported partner—Sun—are jumping on this last point It isn’t true, of course. Red Hat is still an open-source company.

What is true, though, is that Red Hat mishandled the affair. Red Hat 9 had a life span of just over a year with its April 2003 release date and its end of support on April 30, 2004. Business customers, who usually expect to get at least three years of work out of an operating system, were as mad as wet hens to find their support disappearing from underneath them. Indeed, theres been enough outrage that several integrators including at least one mid-major Linux vendor—Progeny—are making a business of supporting Red Hat 9 customers.
The release of Fedora, Red Hats free and cutting-edge Linux distribution, doesnt appear to have been enough for some of these users.

Of course, what Red Hat really wanted was to have its commercial customers switch to Red Hat Enterprise Linux (RHEL). Some Linux fans were outraged because they felt they were being forced to upgrade.

Rant, rave, rant, rave … theres a lot of hate out there aimed at Red Hat.

But you know what? Theres nothing new about this. As early as 1999, I was writing stories about people who hated Red Hat for the same general reasons, which boil down to the fact that Red Hat is getting too big for its breeches. Heck, the ill-fated UnitedLinux consortium was in many ways an attempt by other Linux powers to take Red Hat down a peg.

Now, this isn’t to say that Red Hat hasnt made mistakes. Both the timing and delivery of its message concerning the end of life for Red Hat 9 were awful. It placed many of its customers in the awkward position of having to upgrade before they were ready. It left others, including yours truly, completely bamboozled as to whether Red Hat would even continue to have a desktop distribution. As it happens, Red Hat is offering a Linux desktop, but there never should have been any doubt.
Nevertheless, the move itself was one that Red Hat had to make. For better or worse, Red Hat has decided that it wants its Linux distribution to be a high-end, profitable business distribution. Given that, the Raleigh, N.C., company had no choice but to leave Red Hat 9 behind so that it would no longer have two competing lines.

You know what? Its been a successful move. Red Hats last quarter was its best ever. Why? In large part, it was because RHEL sales increased by 87,000 during the quarter while RHEL renewal rates remained at about 90 percent. Red Hat is a profitable Linux company, and its getting more profitable.

Perhaps thats the real reason why Sun has been so grumpy with Red Hat. Sun is much bigger, but its been declining, in large part due to competition from Linux in the server market, while Red Hat has been growing.
And maybe too thats the real problem some Linux fans have with Red Hat. The company has always been about open source and profits. To these fans, the idea that Linux is becoming mainstream, that their darling, iconoclastic operating system is no longer just for rebels, is abhorrent. For these vocal, malcontent users, Red Hat is the poster child of Linuxs commercial success.

These users will likely always hate Red Hat, but you know what? Get over it. For those of us who want a solid Linux that will be successful in the enterprise, Red Hat—blunders and all—is doing just fine.

A version of this story was published in eWEEK.