raikas,
@raikas@mementomori.social avatar

:alert: Software startup Skiff.com falsely advertises it's email client as

I currently recommend avoiding using, and/or contributing to their products, until they fix their false advertising.

They are actually licensed under CC-BY-NC-SA (Non commercial, share-a-like), which is not an open source license (as commercial use allowed is a requirement for open source).

When confronted on Github, the issue was shortly closed, saying that the libraries used for the apps are open source, and that they have no plan for allowing commercial use for their apps.

I pointed out that open source requires commercial use, and I got this reply from their CEO:

"Commercial use is not a requirement for open source software. Study the MongoDB case."

Didn't know that MongoDB is open source. Because it's not. It's source-available, not open source.

Well, can't blame for users not checking this. Even It's FOSS News publication (https://news.itsfoss.com/skiff-mail-review/) got baited. Startups are using open source software's reputation, without contributing to the community (by using an proper license).

Issue: https://github.com/skiff-org/skiff-apps/issues/93

dushman,

@raikas
Didn't know this app existed and looked it up. We've had this for decades, it's called pgp lol.

raikas,
@raikas@mementomori.social avatar

@dushman They mentioned problems of "managing and losing keys" and unencrypted metadata.

https://skiff.com/blog/pgp-dead-what-next

dushman,

@raikas

pgp is dead

What are these people smoking? It's the universally agreed on standard in practice.

raikas,
@raikas@mementomori.social avatar

@dushman They're drugged up on VC funding. False advertising themselves as open source and privacy-first E2EE email (well, only to other Skiff users 😂).

dushman,

@raikas
​:laugh_about_it:​

Moon,
@Moon@shitposter.club avatar

@dushman @raikas it is unacceptably easy to use gnupg incorrectly and lose your security and shockingly hard to use in a general usability sense

dushman,

@Moon @raikas
Also gui managers like kleopatra exist

animeirl,
@animeirl@shitposter.club avatar

@dushman @Moon @raikas gpgtools on mac is pretty good i wish linux had something on that level

aral,
@aral@mastodon.ar.al avatar

@raikas @jolek78 Not to mention, there’s a reason why you don’t use Creative Commons for your software projects: there’s no limitation of liability clause. (Lawrence Lessig told me that when I asked him about it years ago.)

danb,
@danb@fosstodon.org avatar

@raikas Well done for calling this out. @illiliti shared this with me, so have added it as a case to watch on my repo where I track and document many of these kinds of cases:

https://github.com/ssddanbrown/Open-Source-Confusion-Cases/issues/22

slink,
@slink@fosstodon.org avatar

@danb thank you for your work on this!

i'd be interested: what is your opinion on the (i believe growing) number of closed saas backends pretending to be open just because they release a foss client?

https://fosstodon.org/@slink/110835925356201904

danb,
@danb@fosstodon.org avatar

@slink Thanks! I think the license setup itself is fine, more open is more better, but if they're advertising the wider product/scope as open source then that's misleading and wrong.

There's a similar trend of "open-core" repos with mixed licensing, advertising as open source, but their open code depends on closed code.

slink, (edited )
@slink@fosstodon.org avatar

@raikas thank you for speaking up! is a slap in the face of all honest opensource contributors.
on top of that, i read a lot of advertising which may even be factually correct, but suggests that saas was . like when boasts about their "support for opensource" or here: https://www.honeycomb.io/open-source-observability
neither services are open source, neither grant the four freedoms of free software https://www.gnu.org/philosophy/free-sw.en.html

raikas,
@raikas@mementomori.social avatar

@slink It's sad to see. At least there are some legitimate open source startups still doing good work.

Open source on top 💪

raikas,
@raikas@mementomori.social avatar

Wrote an blog article that can be more easily shared.

https://raikas.dev/skiff-is-lying-about-being-open-source/

Or you can take a screenshot the post with https://mastopoet.ohjelmoi.fi 😉

illiliti,

@raikas I wouldn't recommend protonmail because they are not fully open-source due to proprietary backend. Plus they don't support standard protocols like SMTP/IMAP and thus endorse vendor lock-in practice. They even invented their so-called "bridge" to workaround that, but it is so convoluted mess that nobody wants to use because it breaks certain types of messages. See https://github.com/ProtonMail/proton-bridge/issues/26

funkybuddha,
@funkybuddha@mastodon.green avatar

@illiliti @raikas I’m not an expert, but both imap and smtp are ancient technologies that don’t support E2EE. For example the subject of each email always travels unencrypted. I think that’s what they’re trying to remedy. There’s one reason for Bridge.

slink,
@slink@fosstodon.org avatar

@funkybuddha @illiliti @raikas on encrypted subject lines, this looks like a very good summary: https://superuser.com/a/1626568

i use this with

funkybuddha,
@funkybuddha@mastodon.green avatar

deleted_by_author

  • Loading...
  • slink,
    @slink@fosstodon.org avatar

    @funkybuddha @illiliti @raikas Protected headers. Here is how an actual (raw as seen with CTRL-U) email looks like (with most headers and the actual message removed)

    Thank you for the article list, it is now on my reading backlog.

    raikas,
    @raikas@mementomori.social avatar

    Good work @illiliti good debating in the issue 🙌. Even if they try to suppress you by deleting comments 😉

    raikas,
    @raikas@mementomori.social avatar

    @illiliti They marked your comments as "abuse" 😂

    illiliti,

    @raikas Yes, abuser marked my comments as abuse. How pathetic...

    illiliti,

    @raikas Oh, I have been banned as well.

    raikas,
    @raikas@mementomori.social avatar

    @illiliti From commenting and creating issues?

    Also looks like Github removes reactions from reported posts :blobsad:

    illiliti,
    illiliti,

    @raikas I don't have twitter account, but it seems to be the only way to contact privacytools.io. Do you have a twitter?(yes you do) You could ping them about skiff's behavior and if they have good moral stance, they will remove it from their website: https://www.privacytools.io/privacy-email

    raikas,
    @raikas@mementomori.social avatar

    @illiliti I'll look into the situation.

    The thing is proceeding in issue , which was reopened. I tried to be a bit more civil and offered a possible solution to the problem (strong copyleft license like AGPL), and seems like they are trying to fix the licensing thing soon, when they can.

    illiliti,

    @raikas You are wasting your time. They will delay actual action essentially ignoring you no matter what you suggest them. See openreplay case.

    raikas,
    @raikas@mementomori.social avatar

    @illiliti Well, only time will tell. I'm probably not going to comment on the situation any further, but I have some hope for it, as they have lately relicensed the libraries from CC to MIT 🤷

    illiliti,

    @raikas They already said they won't relicense anything beyond already relicensed projects like skiff-ui. They are simply giving a false hope by intentionally dragging their feet with these useless discussions. This is not a new way how to create an impression "we are working on it" while keeping abusing open-source term without giving a shit at all. Don't fall for this because only real action will bring peace, not these discussions about nothing.

    Sorry for this, I'm just a bit pissed off.

    slink,
    @slink@fosstodon.org avatar

    @illiliti @raikas i'd like to add that even in the best case where they relicensed all the client code as copyleft, the saas would remain inherently non-free, proprietary, lock-in.
    so in my mind a service is only if the service code itself and all the environment is, too, such that anyone can self-host.
    maybe we need a new term? for free open source software service? or ?

    illiliti,

    @slink I think they just need to be clear that backend code is proprietary and client code is open-source(if they relicense to an open-source license). That would be enough, really.

    slink,
    @slink@fosstodon.org avatar

    @illiliti as far as honest marketing is concerned, definitely. as far as following the spirit of , i have some doubts.

    raikas,
    @raikas@mementomori.social avatar

    @slink @illiliti

    Well, seems like also the 2 major "open source" privacy email providers (Tutanota and Protonmail) have proprietary backends.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • opensource
  • DreamBathrooms
  • magazineikmin
  • thenastyranch
  • Youngstown
  • mdbf
  • rosin
  • slotface
  • InstantRegret
  • khanakhh
  • Durango
  • kavyap
  • osvaldo12
  • tacticalgear
  • GTA5RPClips
  • megavids
  • ngwrru68w68
  • everett
  • tester
  • ethstaker
  • cisconetworking
  • cubers
  • modclub
  • provamag3
  • anitta
  • normalnudes
  • Leos
  • JUstTest
  • lostlight
  • All magazines