frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

My insulin pump controller uses the Linux kernel. It also violates the GPL

https://old.reddit.com/r/linux/comments/1puojsr/the_device_that_controls_my_insulin_pump_uses_the/
125•davisr•2h ago

Comments

raverbashing•1h ago
Good luck trying to enforce the GPL against a Chinese company
caminanteblanco•1h ago
Well it looks like insulet is the primary offender here, and Nuu (the Chinese company) is just the hardware manafacturer
themafia•15m ago
An actual good use case for tariffs.
mijoharas•1h ago
Out of interest is there a process to petition the FSF to take up something like this?

How do they triage and decide what to pursue?

LukeShu•59m ago
TL;DR: Not the FSF, but SFC; email compliance@sfconservancy.org

The dominant legal theory is that the GPL can only be enforced by the party holding the copyright. SFC's lawsuit against Vizio is strategically trying to establish precedent changing that; establishing that end-users are "third party beneficiaries" under the GPL, so others can enforce the GPL; but for now the copyright holder is the only one who can enforce it.

So the FSF could only take it up if the violation is on projects that do copyright-assignment to the FSF (i.e.: most GNU stuff). If you do find a violation of GNU stuff, the process is "email license-violation@gnu.org". I do not know what process Craig and Krzysztof use when triaging reports and deciding what to pursue.

Many Linux-kernel contributors (also, SFC member projects such as OpenWrt, Git, Qemu) have assigned their copyright to SFC or named SFC as their legal representative (also, SFC member projects; so SFC can take up something like this. Similarly, you can report violations to them by emailing compliance@sfconservancy.org (see https://sfconservancy.org/copyleft-compliance/help.html for more info).

Now, SFC is aware of more violations than they could ever possibly pursue, so they're strategic about pursuing ones that are high-impact. I'm not sure how they decide that. But I can say that medical devices are near-and-dear to them, between executive-director Karen Sandler's implanted defibrillator and policy-fellow Bradley Kühn's blood glucose monitor.

Tomte•36m ago
> Bradley Kühn's

I saw that spelling for the first time last week, I think.

Did he change his name? Has he always been Kühn, but went with Kuhn, because Umlaute are hard for Americans?

ralph84•24m ago
He changed his name.

https://fedi.copyleft.org/@bkuhn/115461658201124515

anigbrowl•1h ago
As always, the solution is to contact their legal department, preferably via a lawyer. Engineers and support staff are not going to risk their jobs making legal decisions about giving away company property.

The FSF could help a lot here by publishing demand letter templates outlining the statutory and precedential basis for license enforcement and recovery of damages.

whatshisface•1h ago
It is not company property.
Aurornis•51m ago
Support staff or even engineers are not in a position to be making that call. It’s a legal department decision, even if it seems obvious to you.
anigbrowl•35m ago
But it's the company's legal department which would evaluate that claim. Because it's a legal claim. Licenses aren't magic spells, they're social agreements and non-executive employees don't want to get in trouble for making executive decisions.
abigail95•11m ago
Derivative works are owned by those who create them. What copyright says you can do with them depends on the specifics, but the general case is true.
teddyh•1h ago
> I then decided to contact Insulet to get the kernel source code for it, being GPLv2 licensed, they're obligated to provide it.

This is technically not true. It is an oversimplification of the common case, but what actually normally should happen is that:

1. The GPL requires the company to send the user a written offer of source code.

2. The user uses this offer to request the source code from the company.

3. If the user does not recieve the source code, the user can sue the company for not honoring its promises, i.e. the offer of source code. This is not a GPL violation; it is a straight contract violation; the contract in this case being the explicit offer of source code, and not the GPL.

Note that all this is completely off the rails if the user does not recieve a written offer of source code in the first place. In this case, the user has no right to source code, since the user did not recieve an offer for source code.

However, the copyright holders can immediately sue the company for violating the GPL, since the company did not send a written offer of source code to the user. It does not matter if the company does or does not send the source code; the fact that the company did not send a written offer is in itself a GPL violation.

(IANAL)

jstanley•54m ago
Are you saying that in the general case if you send someone a written offer for something and then don't honour it, you are in breach of contract?

That doesn't sound right to me.

A written offer is not the same thing as a contract.

dspillett•32m ago
The written offer is part of the licence, as is the need to respond to that offer with the source code offered. It is all part of the same agreement.

A written offer on its own would not normally be directly enforceable in many (most?) jurisdictions, for the same sort of reason that retailers can't be held to incorrectly published prices (in the UK at least, a displayed price is an “invitation to tender”, not a contract or other promise) except where other laws/regulations (anti bait&switch rules for instance), or the desire to avoid fighting in the court of public opinion, come into effect.

But in this instance, the written offer and the response to that offer are part of the wider licence that has been agreed to.

teddyh•27m ago
I don’t think so; I can’t recall any support for such a connection between the written offer and the GPL itself written into the GPL license text.
teddyh•28m ago
Maybe it’s not technically “breach of contract”, and an offer might or might not be a contract. But if you don’t honor an offer you made, you must surely be guilty of something. Otherwise, all offers would be meaningless and worth nothing.
jstanley•16m ago
I don't think you're guilty of anything for failing to honour an offer in most cases.
Group_B•1h ago
Oh well. The whole thing has already been reverse engineered. Look up Loop or Trio or OpenAPS. Diabetic companies like Insulet have been very lax when it’s come to the hacking of their devices. This isn’t really that big a deal. What we need right now is help REing the Omnipod 5
duban•39m ago
I’m aware of a few people working on REing the Omnipod 5. The furthest issue that I have seen is that when a PDM/Omnipod 5 app signs into your insulet id, it gets a private key from the API which is stored in the keychain (and uses SSL pinning to prevent MiTM retrieval of the private key). When pairing with the pod they exchange public keys and then a derived key from the devices private key+pods public keys, but haven’t been able to get a copy of a private key yet to make further progress.
fyhn•5m ago
Not all though, I've been looking at Minimed pump reverse engineering (which would be just reading glucose data, not controlling the pump), and that's not solved yet, at least not for the 780G. But I hope it will be, and perhaps I'll be able to contribute.
Aurornis•55m ago
Be sure to read the top comment where someone who claims to have worked for the company provides some inside information.

In my experience, this is quite common when the development of hardware is viewed as a cost center and is outsourced to various providers and teams. Those providers and teams churn a lot and nobody who worked on that is likely still involved with the company via contracts or direct employment.

Front line support people aren’t equipped to respond to these requests. If you’re lucky they’ll get bounced around internally while project managers play hot potato with the e-mail until it gets forgotten. You might get lucky if you go the corporate legal route, but more likely is that the lawyers will do the math on the likelihood of you causing them actual legal trouble for anything and decide it’s best to ignore it.

When I worked at a company that had a history of GPL drama one of the first things I did was enforce a rule that every release had a GPL tarball that was archived and backed up. We educated support people on where to forward requests. I handled them myself. 7 out 10 times, the person on the other end was angry because they assumed the GPL entitled them to all of our source code and they were disappointed when they only found GPL code in the tarball. It really opened my eyes to some of the craziness you get exposed to with these requests (though clearly not the polite and informed request in this Reddit thread) which is probably another reason why support staff are uneasy about engaging with these requests.

teddyh•8m ago
> 7 out 10 times, the person on the other end was angry because they assumed the GPL entitled them to all of our source code and they were disappointed when they only found GPL code in the tarball.

Well, if your non-GPL code direcly linked to, or closely interoperated with, any GPL code, those users would have been right.

jacquesm•26m ago
Let me guess. Omnipod. They've had some pretty bad recalls too. Never in a lifetime would I trust my well-being to their p.o.s. hardware / software combo. Apologies that person in this thread that worked there, but I hope you are working for a better company now.
abigail95•9m ago
I get mad triggered by software license violation discussions.

Please for the love of all that the FSF thinks is holy - just file a damn lawsuit if you are telling me they are violating the law. State your claim and have a court sort it out.

It costs hundreds of dollars. For a medical device? Seems like a good deal.

The State of DevOps Jobs in H2 2025

https://devopsprojectshq.com/role/devops-market-h2-2025/
1•thomster•1m ago•0 comments

The golden age of Indie software

https://www.markbernstein.org/Dec25/TheGoldenAge.html
1•hermitcrab•4m ago•0 comments

An Imprecision Problem

https://codeforces.com/blog/entry/149528
1•de_sousa•8m ago•0 comments

Giscus: A comments system powered by GitHub Discussions

https://giscus.app/
1•indigodaddy•9m ago•1 comments

Eastern Market Detroit

https://easternmarket.org/
1•marysminefnuf•12m ago•0 comments

Uv: An Fast Python Package Manager

https://www.janestreet.com/tech-talks/uv-an-extremely-fast-python-package-manager/
4•simonebrunozzi•13m ago•0 comments

Humanist Plumbing

https://www.tbray.org/ongoing/When/202x/2025/12/18/Humanist-Plumbing
1•praptak•16m ago•0 comments

Show HN: An AI-generated daily quiz app I built on my bike

https://www.dailyquiz.ai
1•GFuller•18m ago•0 comments

OGhidra: Automating dataflow analysis and vulnerability discovery via local LLMs

https://github.com/llnl/OGhidra
1•rmast•18m ago•1 comments

The Untold Story of the Nintendo Entertainment System [video]

https://www.youtube.com/watch?v=uJvpRGibFhg
1•zdw•20m ago•0 comments

Show HN: Jotter – A Note Keeping App

https://jotter.marstol.com/
1•sethhovestol•24m ago•1 comments

Zodiac Z13 Decryption on Colab – experts claim validation of Baber's decipher

https://colab.research.google.com/drive/19p4n1aMyeYte1jC4P3GKflMgD6xuZAvV
1•Artix187•25m ago•0 comments

China's TFR dev team has disbanded, following the arrest of its head dev by MSS

https://www.reddit.com/r/hoi4modding/s/5MTCy4s7HO
2•DustinEchoes•26m ago•1 comments

Amazon non-consensually forced TikTok onto my family's device

https://mastodon.neilzone.co.uk/@neil/115787607800144474
3•ColinWright•26m ago•0 comments

Attention Is Not What You Need: Grassmann Flows as an Attention-Free Alternative

https://arxiv.org/abs/2512.19428
2•lexandstuff•29m ago•0 comments

Tiny chip could change the future of quantum computing

https://www.sciencedaily.com/releases/2025/12/251226045341.htm
1•tsenturk•32m ago•0 comments

Capsules transforms writing into cinematic, interactive experiences

https://capsules.ink/
1•fcpguru•32m ago•1 comments

Association of healthy sleep patterns with risk of mortality and life expectancy

https://pubmed.ncbi.nlm.nih.gov/37831896/
1•RickJWagner•32m ago•0 comments

Apparatus for facilitating the birth of a child by centrifugal force

https://patents.google.com/patent/US3216423A/en
2•boguscoder•33m ago•1 comments

I Think about Kubernetes

https://garnaudov.com/writings/how-i-think-about-kubernetes/
10•todsacerdoti•35m ago•0 comments

use Claude Code via Nvim and ACP

https://github.com/jonmorehouse/avante.nvim/pull/1
1•MorehouseJ09•39m ago•1 comments

Police Say He Killed in Self-Defense. His Phone Tells Another Story

https://www.wsj.com/us-news/spivey-killing-stand-your-ground-f45a3492
2•JumpCrisscross•47m ago•1 comments

Teaching Tech Together (2019)

https://teachtogether.tech/en/index.html
1•Tomte•47m ago•0 comments

The Impossibility of Virus Detection [pdf]

https://www.cs.virginia.edu/~evans/pubs/virus.pdf
3•friedrich12•47m ago•0 comments

Administration Is the Root Bug of Civilization

https://blog.hermesloom.org/p/administration-is-the-root-bug-of
2•sigalor•48m ago•0 comments

Kubernetes 1.35: In-Place Pod Resize Graduates to Stable – Kubernetes

https://kubernetes.io/blog/2025/12/19/kubernetes-v1-35-in-place-pod-resize-ga/?trk=comments_comme...
2•abdelhousni•50m ago•0 comments

Toys with the highest play-time and lowest clean-up-time

https://joannabregan.substack.com/p/toys-with-the-highest-play-time-and
3•surprisetalk•51m ago•1 comments

T-Ruby is Ruby with syntax for types

https://type-ruby.github.io/
2•thunderbong•52m ago•0 comments

Friday Deploys: Sometimes That Puppy Needs Murdering

https://charitydotwtf.substack.com/p/on-friday-deploys-sometimes-that
1•BerislavLopac•52m ago•0 comments

SaaS Is the New Mall

https://sagivo.com/blog/saas-is-the-new-mall
2•sagivo•53m ago•0 comments