Bruce Perens departing from the Open Source Initiative (OSI), which verifies licenses for compliance with Open Source criteria. Bruce is a co-founder of OSI, one of the authors of the Open Source definition, the creator of the BusyBox package, and the second leader of the Debian project (succeeding Ian Murdock in 1996). The reason cited for his departure is the unwillingness to be associated with an upcoming OSI decision regarding the inclusion of (Cryptographic Autonomy License) into the category of open licenses.
The CAL License is classified as a copyleft license and commissioned by the project specifically for enhanced user data protection in distributed P2P applications. Holochain develops a platform based on a hashchain for creating cryptographically verified distributed applications.
The CAL License allows the use of Holochain as free and open-source software, provided several conditions are met. Firstly, the source code of Holochain and all derivative works must be supplied under the same conditions, including those related to ensuring the confidentiality of cryptographic keys. Secondly, the right to publicly perform Holochain, including the use of the Holochain API for launching applications, is granted only while maintaining the confidentiality and autonomy of each individual user's private cryptographic keys.
Conceptually, CAL differs from other licenses — if a service utilizes software under this license, it encompasses not only the code but also the processed data. According to the CAL license, if a user's key's confidentiality is compromised (for example, if keys are stored on a centralized server), then the right of ownership over the data is breached, and control over one's own copies of the application is lost. In practice, this characteristic of the license allows key handling to occur only on the end user's side, without storage on centralized servers.
For example, the CAL license will not allow a company to create its own corporate P2P chat based on Holochain, where employee keys are stored in a shared company-controlled repository that does not exclude the possibility of reading conversations. Thus, Holochain attempts to ensure that any application built on Holochain is trustworthy and autonomous. If an application relies on centralized systems to manage user keys, it loses its right to operate with Holochain.
Bruce Perens , that the CAL license does not provide the necessary freedom and is aimed at protecting against abuses by developers trying to completely control user data in their applications. The requirement to store keys only on end-user systems in light of may be perceived as a violation of the rights of certain groups and discrimination based on application area.
Perens explained that an important characteristic of open licenses is the ability to apply them without involving lawyers. A user can simply install a program provided under an OSI-approved open license, and if they do not make changes to the code and do not pass the program on to anyone else, they don't even need to read the license. There are over 100 open licenses approved by OSI, and all conform to this model. However, the CAL license breaks this model — if someone works with a program under the CAL license and has users, they incur additional responsibilities to return data to those users.
With the new license, Holochain attempts to control the network of applications and counter the situation where client developers for the distributed platform can lock users in by capturing their data. Perens acknowledges the noble goal of ensuring user data privacy, but believes it is unacceptable that understanding the license and interacting with users will require legal consultation. Perens also pointed out the detrimental increase in the number of licenses, which makes it difficult to combine applications under different licenses, and noted that only three licenses are needed — AGPLv3, LGPLv3, and Apache v2.
The CAL license was developed by the well-known attorney Van Lindberg (), who specializes in intellectual property and open source licensing issues. According to , which was obtained by The Register, Lindberg privately lobbied for OSI directors to recognize the CAL license without going through the public approval process.
Lindberg responded that many people initially formed a biased opinion about the CAL license and are trying to use any excuse to oppose it. The term lobbying is inappropriate in this context, as the review and discussion of the license took place in public forums, and only procedural matters were discussed privately.
Pamela Chestek, chair of the license review committee, pointed out that there is nothing unusual about private correspondence, as the OSI board usually consults with parties before reviewing a license. She had a phone conversation with Lindberg in which she attempted to clarify the issues with the proposed license. This communication may have been misunderstood. As for the CAL license, the discussion regarding it is not yet concluded, and a final opinion has not been formed.
Source: opennet.ru
