Feeds

Google open codec 'not open,' says OSI man

Net video play faces 'serious questions'

SANS - Survey on application security programs

A board member with the Open Source Initiative (OSI) — the organization that approves open source licenses — has warned that there are "some serious questions" surrounding Google's swashbuckling efforts to create an open and royalty-free codec for web video.

Hoping to defend the VP8 codec against patent attack, Google has open sourced the technology under a new license that includes some patent-centric language, but it has yet to submit the license for OSI approval. With a Monday blog post, OSI director Simon Phipps questioned whether there's a hole in the license that could expose users to third-party patent holders, and he urged Google to join hands with the OSI on the project, saying that before it does so, the codec cannot be considered open source.

But he also urged Google to release more information about the patents backing the technology so that software makers can adopt it with added confidence. And he called on the company to work with an open standards organization with a strong patent disclosure policy.

At the same time, Phipps — the former head of open source at Sun Microsystems — took a jab or two at Google for building a new license after criticizing others for "license proliferation." But he tells The Reg that the primary aim is to bring Google to the table, and Google open source guru Chris DiBona has told us that the company intends to approach the OSI "in the coming weeks."

Last week, at its annual Google I/O developer conference, Mountain View announced that VP8 had been open sourced under a royalty-free license, hoping to challenge the patent-backed H.264 codec favored by Apple and Microsoft. Acquired last year when Google purchased video compression outfit On2 Technologies in a deal worth $124.6 million, VP8 has been rolled into a larger media format known as WebM, and it has already been included in developer-build browsers from Mozilla and Opera.

With his blog post, the OSI's Simon Phipps called Google's move "a positive and welcome development," praising the company for offering an alternative to H.264 and the existing open source codec Ogg Theora. And he pointed out that Google had "done their homework" in securing the backing of Mozilla, Opera, and even Flash-maker Adobe.

But his post was meant to show that more homework lies ahead. "Once all the hoopla had died down, it became clear there are some serious questions that need considering," he said.

For starters, there's the license issue. Google has used a new license to open source VP8, and at Google I/O last week, the company told us the license had not been submitted to the Open Source Initiative. Product manager Mike Jazayeri said that Google will "certainly follow the best practices" where the license is concerned, but it still hasn't submitted it to the OSI, and Phipps questions whether the license can be approved without changes.

Google's license is essentially a BSD that has been modified to include language that provides the licensee with patent rights to the technology and at the same time prevents them from using other patents to file an infringement suit against the technology. "The main difference between the standard BSD license and the VP8 license is that this license grants patent rights, and terminates if patent litigation is filed alleging infringement of the code," Google says in a WebM FAQ.

The addition is a bastardized version of language that appears in the Apache 2 license. Like Apache 2, Google rescinds patent rights if you file suit, but it also rescinds your right to use the technology. "The main reason it was not used is that filing patent litigation against someone using the Apache 2 license only terminates patent rights granted under the license. Whoever filed the litigation would still be able to use the software they are suing over and still be in compliance with the license," Google's FAQ says.

"This license, however, terminates all rights when patent litigation is filed. Rather than modify the Apache license to meet our needs, which would probably lead to significant confusion, we went with the simpler approach of a BSD style license + patent provision."

Simon Phipps questions whether the added language is a stumbling block. "As it stands it possibly can't be approved due to Google's ironic inclusion of a 'field of use' restriction in the patent grant (which is restricted to 'this implementation of VP8' rather than the more general grant in the Apache license from which the text started)," he wrote.

Whereas Google specifically refers to "this implementation of VP8," the Apache license simply refers to "the work." Phipps wonders whether Google's license still grants patent rights if someone uses only a portion of the VP8 code and not the whole thing. "One of the questions I would ask is: 'Does this narrowing of the language cause any problems?'" he told The Reg. "And that's the sort of question that gets answered during an OSI license review."

High performance access to file storage

Next page: Googly irony

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Oh no, Joe: WinPhone users already griping over 8.1 mega-update
Hang on. Which bit of Developer Preview don't you understand?
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
IRS boss on XP migration: 'Classic fix the airplane while you're flying it attempt'
Plus: Condoleezza Rice at Dropbox 'maybe she can find ... weapons of mass destruction'
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
New Facebook phone app allows you to stalk your mates
Nearby Friends feature goes live in a few weeks
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.