Open source of contention - SSH!

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
For security-conscious system administrators, three letters have become a household word when it comes to securing remote computers: SSH. SSH, which is derived from the term "secure shell", is a set of standards for encrypting the commands and data sent to a server from an administrator's PC. It is widely used by Linux administrators and others in the open-source community. Yet the three letters also describe the original program developed by Tatu Ylonen in 1995 and trademarked in March 1998. Now, as the founder of SSH Communications Security, Ylonen wants others to stop using it. "The use of the SSH trademark... is in violation of my company's intellectual property rights, and is causing me, my company, our licensees, and our products considerable financial and other damage," Ylonen, chairman of SSH Communications, wrote in a letter posted to a developer mailing list in mid-February. That letter has open source developers and executives girding for a what could become a battle that helps define one of the prickly issues surrounding open source computing: how does a company retain control over its products and still participate in the open source programming world? The same programmers whom SSH Communications is trying to woo are the ones who, in its mind, are trying to co-opt its name. In the end, both sides could lose if access to an important component of Internet security and the good will toward SSH Communications become casualties, say open source and intellectual property experts. It's also not a problem that seems destined to go away quietly. "SSH has become a very important part of the Internet. It is required. It is necessary," said Liz Coolbaugh, a founder and managing editor of the Linux Weekly News, which follows the open source community surrounding the Linux operating system. While she stressed that many in the community can understand the issues that SSH Communications may have with several open source projects using the moniker, others are appalled. That's because the open source community has put a lot of time and effort into helping Ylonen develop the program, Coolbaugh said. "Open source is the biological environment in which their ideas were produced, tested and debated," she said. Helsinki, Finland-based SSH Communications maintains two versions of its SSH Secure Shell product, one it sells and one it gives away free. But neither carries the GNU public licence, which would make them open source. The largest open source project -- and Enemy Number One for SSH Communications in the trademark battle -- is OpenSSH, an effort to create a free open source version of the product. "The first time we heard about this issue was the beginning of February," said Niels Provos, a graduate student at the University of Michigan and a developer on the OpenSSH project. Although the project has only been around since late 1998, OpenSSH has based much of its work on a version of SSH that Ylonen released as source code in 1995. Provos asserts the 1995 release came with a public licence, allowing it to be co-opted by open-source developers for use in their projects. That was the same year Ylonen created SSH Communications and a year before he even filed for a trademark. "We are a bunch of people that do this for fun and to give people a more secure way to access the Internet," Provos said. "We didn't expect to get dragged into a trademark war." SSH Communications hopes that such open source projects will continue, just without SSH in their name, said George Adams, chief executive of SSH Communications. "We are not interested in killing any [project] or stopping e-commerce," he said. "We are just protecting our trademarks." Yet SSH Communications' enforcement may be too little, too late. "Trademarks are like patents," said Wyatt Starnes, co-founder and chief executive of security software firm Tripwire. "They are only as good as your ability to defend them. If you are not careful, they can lapse into a quasi-public domain." Tripwire should know. In many ways, the company's flagship product, also known as Tripwire, has a similar lineage. Created at Purdue University in 1992, the data-integrity software was released freely in the past. But when it was, the open source community always understood that Purdue, and then Tripwire, owned the intellectual property, Starnes said. "There were [outside] people who helped write the code in the Purdue process," he said. "But there was explicit ReadMe code that stated that both the trademark and the intellectual property were owned." That confusion over the history of the enforcement of the trademark may be the least of SSH Communications' worries. What could be a worse indicator for the company is that many administrators use the term "SSH" for any command-line interface that securely accesses another computer. "Regardless of its origins, the word has become the generic description for this type of software," said Michael Bednarek, an intellectual property attorney at Washington DC-based law firm Shaw Pittman. "As far as I can tell, there is no other name for it." Bednarek asserts that SSH Communications inadvertently let the name slip into the public domain, similar to how Bayer lost the trademark to "aspirin" in the United States. "In many countries, Bayer has the trademark for aspirin. But here they don't because it became the generic term." That could be a nail in the coffin for the SSH trademark, he said. "If this were the type of thing that was litigated, SSH would have an uphill battle." SSH Communications said it wasn't aware of the confusion in the marketplace until the company recently started selling SSH Secure Shell itself. Originally, SSH Communications used another company, F-Secure, to sell the product. But since SSH Communications took over sales of SSH Secure Shell, the company asserts that it quickly became apparent that customers were confused, thinking that the OpenSSH project was somehow affiliated with the company. "When this came to our attention, we realized we needed to properly enforce our trademarks," Adams said. "I don't think it's too early or too late." Adams added that one organisation that SSH Communications has convinced is the Internet Engineering Task Force, the group responsible for setting technical standards on the Net. "They have agreed to show proper attribution," Adams said, adding that the task force has adopted a non-infringing name, SecSH, for its working group developing secure shell standards. Yet others in the open source community still call the standard by the original "SSH" moniker. And those open-source developers have been prolifically developing software using the name "SSH". There's KSSH, a front-end to SSH for the KDE desktop, ScanSSH, a network scanner using the SSH scanner, FreSSH, a newer implementation of SSH, Nifty Telnet SSH, an SSH client for the Macintosh, and SSHBuddy, a password manager for SSH. All could be infringing the company's trademark. But winning the battle could be a worst-case scenario for SSH Communications, said OpenSSH's Provos. "Tatu is a very respected person in the community because he provided SSH for free and helped make the Internet more secure," Provos said. "Now, no matter what the outcome, he loses a lot of public image." Take me to the Linux Lounge Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Linux lounge Let the editors know what you think in the Mailroom. And read what others have said.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

4 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

7 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

7 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

8 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

9 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

10 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

10 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

10 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

11 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

11 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

11 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

12 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

12 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

15 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

16 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

16 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

17 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

18 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

20 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

1 day ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility

Latest in Application Development