Slashdot Mirror


How Do You Deal With Pirated Programs At Work?

LoneAdminOK writes "I started working for a small company in the middle of January as their IT Manager. I am the first actual 'IT Guy' that they have had; before me it was someone that performed another job within the company and just handled the IT on the side. The problem that I am running into is that most of the software I am finding on the network and on people's computers isn't owned by the company. The person before me would just get it from 'somewhere' and install it on the computers as needed. This is putting me in a bad position when I have to reinstall the program or find it to install on someone else's computer. Often, I am telling people that we don't have it or we have to buy another license, and they get mad at me because the other guy said that we had it. I can't even tell where the versions of Windows Server that they are running came from. The only one I know is legit is the one that is installed on an HP server with the OEM sticker on it. How have any of you handled a situation like this? I don't install 'borrowed programs' in a production environment because I know that if the BSA got wind of this, it would all fall on me when they stormed in."

79 of 958 comments (clear)

  1. Your choice by SatanicPuppy · · Score: 4, Insightful

    All you can do is go to the higher ups and lay out the entire situation. If they don't care about the consequences, have them put it in writing to CYA, and then decide whether you want to trust that YA is truly C'd, and whether you want to add "Installer of Illegal Software" on to your CV. That's all you can do.

    In my experience, the smaller the company, the more pirated software you find. If it's one guy working out of his house, it'll be lucky if he's actually using his own internet connection, more less software that he actually owns.

    Now queue 500 posts saying, "ZOMG, replace it all with OSS."

    --
    ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
    1. Re:Your choice by KyleTheDarkOne · · Score: 5, Funny

      ZOMG, replace it all with OSS.

    2. Re:Your choice by Akido37 · · Score: 4, Insightful

      All you can do is go to the higher ups and lay out the entire situation. If they don't care about the consequences, have them put it in writing to CYA, and then decide whether you want to trust that YA is truly C'd, and whether you want to add "Installer of Illegal Software" on to your CV. That's all you can do.

      In my experience, the smaller the company, the more pirated software you find. If it's one guy working out of his house, it'll be lucky if he's actually using his own internet connection, more less software that he actually owns.

      Now queue 500 posts saying, "ZOMG, replace it all with OSS."

      In summary, you're screwed.

    3. Re:Your choice by Toreo+asesino · · Score: 5, Interesting

      I actually remember being told by management in a much previouser place to hook up our internet to the unsecured cafe wireless below us because no one could work until the ISP reconnected us (didn't pay the bills). They must've got one hell of a shock as 20 or so machines all started connecting out to the mail server through their wireless via one tablet PC dangling down below through an office window via the Ethernet to get the best connection possible.

      And yeah, "management" (far too classy a word for these people) knew exactly what they were doing.

      Happy days :)

      --
      throw new NoSignatureException();
    4. Re:Your choice by cptdondo · · Score: 5, Informative

      I was in a similar situation long ago... I wrote up a memo outlining the software we had installed, an estimated budget to get everyone legal with what they needed, and an approval to go ahead. (At the time there was no FOSS...)

      I got my ass chewed for putting it in writing, but it got their attention. We ended up getting legal in most of the larger packages.

      Today I would also do the homework and add "direct FOSS replacements" for the software in question as much as possible. MS server -> CentOS + Samba; MS OFfice -> OpenOffice, and so on. I would create a roadmap to get everyone legal and ask for approval.

      Above all, be professional, curteous, and politically astute. It won't do to create a "fear reflex" where you get shitcanned and blackballed. You may want to have a closed-door conversation first and ask to see if management would like to see the roadmap you've prepared.

    5. Re:Your choice by BitwiseX · · Score: 5, Insightful

      I agree 100%. I've seen this a million time at smaller companies, that I've gone into as a contractor. As a contractor I've had to refuse requests to install software. It was usually one copy of Office '97 that a husband brought in to install on 10 or so PCs.

      The sad part is MOST small business don't even realize what they are doing is illegal. Then when you analyze what they have and what the cost of going legit is, they say "Thanks!" and show you the door.

      In your case I would hope asking for a CYA letter from the higher powers would at least throw up a red flag and make them realize the seriousness of the situation. I'd be interested to know what legal position that puts you in however, since you know what you are doing is illegal, CYA letter or not. If your boss said to shoot his secretary and gave you a letter saying he told you to do it... I don't think it would hold up in court (A little extreme, but still..)

    6. Re:Your choice by NotBornYesterday · · Score: 4, Informative

      Surprisingly, those 500 FOSS-supporting slashdotters might be right. Apparently, the economic poo we are wading through has a lot of businesses (esp smaller ones) considering FOSS. I don't know if Microsoft will ever again resort to auditing and suing its own install base en masse like it did years ago, but with their balance sheets sliding south just like everyone else, they might start looking to maximise the revenue from their unofficial install base, as it were. I sure wouldn't want to chance it. There are more FOSS equivalents now than ever for proprietary software. Now might be the perfect time to switch.

      --
      I prefer rogues to imbeciles because they sometimes take a rest.
    7. Re:Your choice by mitchell_pgh · · Score: 5, Insightful

      Inventory, inventory, inventory... and make recommendations.

      Also, when talking to the higher ups, make sure to consider a "transition period" where you go from illegal software to "gray software", to a fully licensed office. It makes them recognize that it doesn't all have to happen overnight.

      I worked at a design firm and they had illegal versions of Adobe CS and MS Office floating around like it was their business. I basically performed an inventory of every system, created a spreadsheet highlighting the illegal software and then created a strategic timeframe/cost for how you are going to go legit.

      If they don't want to go legit, you should consider a new company or push FOSS alternatives.

    8. Re:Your choice by Anonymous Coward · · Score: 4, Insightful

      "The sad part is MOST small business don't even care that what they are doing is illegal. Then when you analyze what they have and what the cost of going legit is, they say "Thanks!" and show you the door.

      There, fixed that right up for you.

    9. Re:Your choice by gmack · · Score: 4, Interesting

      Better yet wait for the next virus hits and then blame it on a lack of security updates caused by all of the pirated windows versions they are running.

    10. Re:Your choice by spun · · Score: 5, Funny

      Apparently, the economic poo we are wading through has a lot of businesses (esp smaller ones) considering FOSS.

      Open Source! It's the Pointy Stick that will remove the Economic Poo from your Software Licensing Shoes!

      --
      - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
    11. Re:Your choice by Vancorps · · Score: 5, Informative

      You present a fairly sensible approach except for the fact that presumably the company already has a working solution for them so they just need to get it legal. With Microsoft this is easy, you just get a select agreement and based on the number of installs you get a substantial discount.

      I had the exact same situation happen to me when I moved into this job. I had a closed door meeting with the owner and my boss to determine what the priorities were and what the best way to proceed was. In the end a select agreement allowed us to instantly make all of our servers legal since I had no prior documentation illustrating that we had legitimate licenses.

      Server side you simply can't just drop in replacements when you already have running systems. With the Microsoft approach you can just change your license key to the new volume license key you get with your select agreement and away you go without reinstalling anything.

      On the desktop a simple PDF writer is more than sufficient and free for end-user PDF creation instead of having to purchase Acrobrat in most situations, obviously not all. Of course Foxit is my preferred choice for reading PDFs.

      In the end I went through department by department to determine what everyone needed to do there jobs with minimal impact, the company spent a load of money and now we're a completely legal shop. It actually feels good to provide the transition.

      Also in my case I outlined the cost to get us legal and then outlined ways we could reduce costs in future by deploying Linux in places it makes sense like with our new Asterisk system. It removes the fear they have that it will keep happening so they will be less resistant to getting the company legal.

    12. Re:Your choice by cbreaker · · Score: 5, Insightful

      That's the perfect answer and exactly what needs to be done.

      You can even go a step further and contact some of these companies to let them know your situation ahead of time.

      Call Microsoft sales/licensing and tell them your situation and tell them you're working to resolve the licensing issues. Same with Adobe and the others. Get quotes and stuff. That way, if anything bad ever did happen, you have documentation that you're in the process of shoring up the licensing.

      No company is going to sue you if you're in the process of correcting the issue because that means you're going to be a future paying customer.

      --
      - It's not the Macs I hate. It's Digg users. -
    13. Re:Your choice by gustgr · · Score: 4, Insightful

      including the conversations you have regarding your findings and the solutions you're offering.

      You, sir, has just revealed the fastest way to get canned. I'm not saying it is the wrong thing to do, but I really believe his boss would not appreciate having his words written to stone by an employee. He may even see this as blackmail or something, which would make the case much much worse.

    14. Re:Your choice by tverbeek · · Score: 5, Interesting

      I ran into this kind of situation in my first job. When I included a license for WordPerfect on a PO I wrote for a new system, the exec who had to sign off on it crossed that line item out, with the note "We already have this." Fortunately, a short time after I started they hired an IT manager who'd previously worked for a software developer, so I got his support. What we did at first was, rather than trying to bring the whole company into compliance all at once (which would have been a large chunk of money), he insisted on including software with every new hardware purchase, and we got that. In those days software came with manuals, so we were able to use that as a selling point to the execs who didn't grasp licensing or legal vulnerability. The next step was to offer existing users an upgrade to the latest version... which they had to pay for by buying a full license. After a while of this, the cost of fixing all of the remaining unlicensed software got small enough (and the execs had been educated enough) that we got approval to make it all (or at least mostly) legit.

      --
      http://alternatives.rzero.com/
    15. Re:Your choice by cptdondo · · Score: 4, Interesting

      You make a good point... I guess I would modify the roadmap to include things like:

      Option A: Buy license for MS Server, $2K/yr but no disruption
      Option B: Obtain and test CentOS + Samba, 2 weeks of my time testing and deploying

      That way you give them a choice. People like to choose.

    16. Re:Your choice by Anonymous Coward · · Score: 4, Informative

      microsoft partnership for small business. 400$ ca year, and is a buffet of cal and offices business

    17. Re:Your choice by xda · · Score: 4, Interesting

      First of all, don't worry about people getting upset with you. All you have to do is locate all the licenses you do have. If your servers pass a WGA check then they are probably ok, but make sure you have a backup system in place in case WGA kills that server.

      Next you need to start transitioning people off the illegal software. OSS is a very good choice to implement in office environments.

      Don't make a federal case out of it. But don't contribute to the problem either. If you start getting allot of negative feedback you need to simply explain, sans-drama, that the previous IT Admin wasn't keeping track of licensing and even if the software they installed is legit you can't prove it. You can however provide them with software that will meet their needs without costing the company any more money, but they will need to give a tiny bit of cooperation in order to make it happen.

      If your superiors give you any trouble about licensing explain to them, again sans-drama, that they can't expect you to break the law on a daily basis as part of your job requirements. DO NOT in any way make any statements like "I have to report this" or "you guys are running illegal software". You don't work for the BSA or anything like that it isn't your responsibility to report anyone.

      there is no need to use pirated software GO OPEN SOURCE. I have 3 small businesses all owned by friends that operate entirely on Ubuntu and OpenOffice.org. My mother doesn't get computers at all, she has been using Ubuntu now for about 5 months. I never even showed her how to use it, I keep a PC in my living room for her to use, she just started using it without any help from me at all! Open source software is easier to use than ever before just run with it, it won't let you down.

    18. Re:Your choice by John+Hasler · · Score: 5, Insightful

      > If they don't want to go legit, you should consider a new company or push FOSS
      > alternatives.

      Switching to Free Software *is* going legit.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    19. Re:Your choice by kilodelta · · Score: 4, Interesting

      You are right on point. Also be aware that the BSA first looks at company financials before they initiate a case against the company.

      I had a former employer that played fast and loose with licensing rules. When I left the job I reported it to the BSA. The BSA got back to me and said "Sorry, they don't have deep enough pockets."

    20. Re:Your choice by RollingThunder · · Score: 5, Insightful

      That also tends to be an easier thing to make happen because it's a bit here and a bit there, rather than a $50,000 price tag to bring every single system in to compliance.

      $1,500/mo slips in to the noise; $50K makes itself seen.

    21. Re:Your choice by LoadWB · · Score: 5, Insightful

      Yup. I have walked out of jobs like this and let some of my less scrupulous colleagues take them on. While no one I know of locally has ever had a visit from the BSA, they are a bit like lightning.

      I have been advised by legal counsel that a "CYA" letter does not "CYA." If you run into a situation where illegitimate (I prefer not to use the term illegal) is in use, you bring it to the attention of management, and management does not care, GTFO.

      Make your arguments, wait for the final word, and walk. Do not stop, do not talk, do not even say good bye... WALK AWAY. As a consultant, you have the freedom to do that. As an employee, polish up your CV.

      Although, at this point they are playing a very dangerous game with themselves and with you. Another tidbit of advice given was to write up a document which essentially held them hostage in return for your reputation: you agree not to report their use of illegitimate software in return for you never being there. Shitty, yes, but those are the games we play and the chances we take.

      Unless the guy's name is "Tony" and he runs a "waste management" business. Then you just say "yes, sir!" and move to another country in the middle of the night. Better yet, get off the damn planet.

      Another guy here mentioned an alternative plan of attack, which is gradual compliance. If you can present that as an option, I think that would work as well. You are still on sticky legal grounds with the BSA, though. They consider unlicensed software like child porn, and if you ever THINK it is there and do nothing immediately, you are considered complicit.

      This work makes me sick sometimes.

    22. Re:Your choice by BeanThere · · Score: 4, Interesting

      It's also worth pointing out to the higher-ups (I presume one would write up a report) that pirated software can often cause costly problems - torrents of popular software, for example, may come with viruses or back doors embedded (not speaking from personal experience *cough* *cough*). Also it's often harder to get updates for pirated software, leaving you with unfixed bugs or security holes. Sometimes pirated software can unexpectedly cause data corruption problems (3DSMAX is a classic example - random aberrant vertices). I know you can often avoid these issues if you know what you're doing, but there's always an additional cost in the time required to figure that all out etc. Definitely weigh this in, and evaluate OSS wherever it can be used.

    23. Re:Your choice by Z00L00K · · Score: 4, Interesting

      If you are lucky it's only that, if not you will get all kind of problems. Murphy's law is the most prominent feature in cases like these.

      You never know if there is a secondary software that is depending on the product key and will go and die if it's changed.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    24. Re:Your choice by PitaBred · · Score: 4, Informative

      And don't forget to drop the BSA card... an unhappy employee (or ex-employee) can easily report them and cause lots of problems.

    25. Re:Your choice by Gerzel · · Score: 5, Informative

      While it might not be a choice for OS, you probably should consider OFFERING FOSS to your employers when you go speak to them.

      Remember going with FOSS doesn't mean going whole hog linux and software vegan.

      You can offer things like Open Office as an alternative to shilling out huge $ for MS Office licences.

      There are a lot of good FOSS programs for windows. Offering them as an alternative will help to balance the argument that the company needs to be legal in its software usage, esp if they complain that their people don't know how to use the FOSS, because you can tell them to choose between training time or spending money.

      It basically helps kill the argument/rational of "We have to pirate there is no other way."

    26. Re:Your choice by DrSkwid · · Score: 4, Funny

      whole hog *AND* vegan

      I'd like to sign up for _your_ newsletter!

      --
      There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
    27. Re:Your choice by mapsjanhere · · Score: 4, Interesting

      looks pretty much like my experience, took me years to get the value of compliance into the business people. What is much harder so is keeping the employees from clamoring for all the "free" software from the internet. They just don't want to see that just because the download is free you cannot ignore the license terms (the usual "free for non-commercial use"). But after making the first guy pay for his own license when he just couldn't live without a program he liked (and for which a paid equivalent was installed) people are reevaluating how much they realllllly need their individual programs.

      --
      I'm aging rapidly, I bought a new game and had no idea if my machine was good for it.
    28. Re:Your choice by Arslan+ibn+Da'ud · · Score: 5, Funny

      $1,500/mo slips in to the noise; $50K makes itself seen.

      Here we have Mr. RollingThunder from The Burrows. He is proposing a $50,000 price tag to bring every single system in to compliance. Mr. RollingThunder, would you stand up, please?

      <bang>

      This demonstrates the value of not being seen

      --

      Practice Kind Randomness and Beautiful Acts of Nonsense.

    29. Re:Your choice by c_g_hills · · Score: 4, Interesting

      Perhaps it is different with Server 2008 but with 2003 you cannot simply swap the license key for an OEM server key to a volume licensing key. You have to do an "upgrade" with the corp media. This is a problem when you want to migrate a physical server to a virtual one running on a different host, since OEM-licensed Microsoft server OSs are only allowed to run on the metal the license was purchased with. Silly!

  2. Yarr... by nacturation · · Score: 5, Funny

    I'd just keep me head down and swab the deck, me hearty!

    --
    Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
  3. Don't be a pussy by BadAnalogyGuy · · Score: 5, Funny

    Everyone is doing it. What are you afraid of?

    Don't be a baby! Go on, do it!

    1. Re:Don't be a pussy by geobeck · · Score: 5, Funny

      Better yet:

      "What's the matter, Colonel Sanders? Chicken?"

      More geek appeal. :P

      --
      Find environmentally and socially responsible products on http://buy-right.net
  4. It doesn't have to be production to be piracy... by omkhar · · Score: 5, Insightful

    >I don't install 'borrowed programs' in a production environment

    'borrowed programs' shouldn't be installed anywhere - prod, test, uat whatever. Non-production piracy is still piracy.

  5. Nuke... by Anonymous Coward · · Score: 5, Funny

    Nuke the site from orbit. It is the only way to be sure.

  6. Where are you located? by El_Muerte_TDS · · Score: 5, Funny

    For what company do you work?
    I'm sure we can figure something out.

    Your friend,
    BSA

  7. Replace with Open Source by Foofoobar · · Score: 5, Interesting

    Jeff Bezos once said to me 'you can't take something away from someone without giving something back of equivalent value without them being pissed off'. Obviously you have to take the software away but try to give them an open source equivalent for the time being. They may actually even start using it longterm and save the company money from having to purhcase licenses of the other software.

    --
    This is my sig. There are many like it but this one is mine.
  8. Turn them in. by Shadow+Wrought · · Score: 5, Funny

    Collect the reward.

    --
    If brevity is the soul of wit, then how does one explain Twitter?
  9. What the hell? by Anonymous Coward · · Score: 4, Insightful
    Why the hell have you taken the time to "Ask Slashdot" when your first duty should have been to call an urgent meeting with the board to explain the situation? If the shit hits the fan you will be the one responsible, so get it in order!

    Start with auditing your network (use automatic auditing software) and then work out:
    1. What licenses can I reclaim from users who do not need the software they have?
    2. What licensed software do we use for which we require more licenses?
    3. What unlicensed software do we have?
    4. How much will this all cost to fix?

    You should have already done this. Then you take it all to the board and get them to stump up the cash to fix it.

    If you can't/won't do this, go find another job.

    1. Re:What the hell? by SQLGuru · · Score: 5, Funny

      So, do you know where I can "borrow" this automatic auditing software of which you speak???

  10. CYA = cover your ass by Spy+Handler · · Score: 5, Informative

    CYA = cover your ass

    in case some of our international readers missed it ;)

    1. Re:CYA = cover your ass by Anonymous Coward · · Score: 4, Funny

      tks. Thought it meant Caramel Yak Association and I was getting all confuzed.

    2. Re:CYA = cover your ass by Captain+Splendid · · Score: 4, Funny

      Caramel Yak Association

      Splitters!

      --
      Linux, you magnificent bastard, I read the fucking manual!
    3. Re:CYA = cover your ass by Anonymous Coward · · Score: 5, Funny

      CYA = cover your ass

      in case some of our international readers missed it ;)

      The international readers would like to point out that we will not miss your bare arses.
      Had you been french or italian ladies, things would have been different.

      Kind regards,
      The International Readers

  11. Are you mad? by drolli · · Score: 4, Insightful

    Rules for dealing with that

    1) *Never states the existence of pirated software as a fact to outside you company*.!!!

    2) Ask your Boss at a cup of tea outside his office

    3) Depending on your bosses answer and your morality
        a) Boss says: hunt down priated software -> you do that
        b) Boss says: dont touch the issue and you are not too worried about the moral/legal issues: close your eyes
        c) Boss says: dont touch the issue and you are worried about the moral/legal issues AND you are brave: state is explicictely in an e-mail to your boss with somebody else in the company in the CC
        d) Boss says: dont touch the issue and you are worried about the moral/legal issues AND you are reasonable: leave.

  12. How we deal with pirated programs? by kdawson+(3715) · · Score: 5, Funny

    Easy! Keygens.

    1. Re:How we deal with pirated programs? by morgan_greywolf · · Score: 5, Informative

      Along with a heavy dose of virus/trojan/malware scanning and removal, no doubt. Seems these days about 70-80% of keygens on The Pirate Bay are infected with something. People install this crap and they call me in to clean up the mess. ;)

    2. Re:How we deal with pirated programs? by Zeio · · Score: 4, Informative

      Please, download VMWare or Virtual PC or something and use rollbacks (always go back to the previous snapshot after running a keygen/crack) and ALWAYS run these keygens and/or cracks in a virtual machine. They are responsible for a large number of really insidious back door infections.

      I know people copying software is a fact of life, but people are getting nailed on the keygens.

      --
      Legalize the constitution. Think for yourself question authority.
    3. Re:How we deal with pirated programs? by Antidamage · · Score: 4, Interesting

      A lot of the keygens are marked as malware regardless of the actual presence of malware. People need to stop writing cute little custom text display apps and just use flash apps for keygens. Goodbye malicious false positives.

  13. Oh yeah? by qoncept · · Score: 5, Funny

    I know that if the BSA got wind of this, it would all fall on me when they stormed in.

    And those Boy Scouts are rotten little bastards.

    --
    Whale
  14. ask some questions by uglyduckling · · Score: 5, Informative

    Rather than presuming that it's all pirated, start by presuming that everything as it stands is legitimate. Write a memo to whoever does the accounting and ask for copies of the invoices for all of the software purchased over the past five years "so that I know what licenses we currently possess and don't end up paying for software twice over when someone asks me to install something".

    When/if the accounting person/dept comes back with nothing, then take it to the bosses and explain how surprised you were when accounting were unable to find any invoices. Stress the safety issues of illegitimate software (viruses, trojans etc.) and discuss the options. Make it look like you are a contentious employee doing your best for the company and avoid looking like a self-righteous jobsworth.

  15. Same as you deal with pirated music by kiwimate · · Score: 4, Insightful

    I'm bound to get modded a troll or flamebait or off-topic or something for this, but how is this different from pirating music? /. group-think says it's not theft and trots out a whole bunch of other self-justification about the evil RIAA and so forth, because you're "not depriving anyone of something physical", etc. It's the same, right?

    Is it different in this case because it's a small company doing it rather than a whole bunch of individuals? Does that mean it's okay if it's just me, but wrong if my company is doing it?

    So to answer the question at hand: go the CYA route suggested by the very first poster, and make sure you point out (nicely as you need to, given this economy and how sure you are of being able to find another job) that this is illegal.*

    * Just like music piracy. Even if you want to claim it's not theft.

    1. Re:Same as you deal with pirated music by cyber-vandal · · Score: 4, Informative

      Probably because there is no Slashdot groupthink - it's just paranoia on part of people like yourself. I see plenty of anti-piracy and pro-MS posts here personally. And it isn't theft it's unlicensed use. Adobe still have the source and binaries to Photoshop.

  16. BSA by SuperBanana · · Score: 5, Informative

    I know that if the BSA got wind of this, it would all fall on me when they stormed in.

    They can't. They love to pretend they can, or they try to strongarm people into letting them do surveys. It's all just evidence gathering for when they sue you later, or use it to extort you into paying massive fines.

    If they show up, tell reception not to let them past the waiting room. Call the cops IMMEDIATELY if they won't follow your instructions or requests (your business is private property.) Fetch the highest person in the company, preferably an officer, and tell them the BSA has no legal ability to search without a warrant or court order (which requires a lawsuit) and they need to shoo them away. The BSA should get nothing but the phone number of your lawyer.

    Now, on the second part of your question: what to do? It's very simple. Ask your boss. Explain the risk. Include some sort of plan for inventorying and an estimate of how long it'll take. OCS Inventory is a pretty good way to do this if you have more than a dozen or so systems. Possibly include some (qualified) estimates of what it is going to cost to come back in line (remember there are significant volume discounts for things like Office) based on what you've seen before; stick to the facts. Include alternatives such as OpenOffice, but don't get too crazy (ie, don't list "convert to linux" for unlicensed servers as $cost_of_MS_Server in "savings"...factor in some healthy labor estimates AND you have the time to take on such tasks. Don't forget that there is opportunity cost too.)

    Lastly: you need to make sure you have BOTH purchase records (receipts/packing slips) and the license files (ie those thingies with the holograms and barcodes) for EVERY PIECE OF SOFTWARE YOU HAVE. The company accountants / office manager can help with part of that. It's going to mean going through a lot of boxes- get a big filing cabinet. If you get any electronically, PRINT THEM IMMEDIATELY, and keep them in a safe place.

  17. Re:It doesn't have to be production to be piracy.. by profplump · · Score: 5, Interesting

    I realize that's true from a pure copyright standpoint, but in the real world it's sometimes useful to say, install a copy of a tool for evaluation in your workflow before deciding to spend $600 on a license for that tool.

    Or do you know of a merchant that will accept opened software package for return, should I decide that $600 isn't worth the cost for deployment, or doesn't do what I need? Because I'd be happy buy a license if I had the right to terminate the license and return the product for refund, and even to pay some reasonable fee for my trial usage -- I'm just not willing to pay full price with no opportunity for refund for a product that I've never had the opportunity to test. I wouldn't do it for a car or a DVD player and I won't do it for software either.

  18. Standard Corporate Practices by girlintraining · · Score: 5, Funny

    There are several solutions, and which one is adopted depends a lot more on corporate culture than technical merit.

    In large businesses (10,000+ employees), I see two common approaches. The first is lock-down.

    Lock down.
    * Centralize everything and lock down the workstations. All software comes from one department, is distributed by SMS or Altiris, and (sometimes) workstations are monitored for compliance. Businesses like this often go with Dell for their hardware provider and have only about 5 or so workstation configurations in active use. Patches and install requests can take months to fulfill, and if the software isn't on their list, chances are good that you'll never see it. These businesses have security weaknesses in their network due to this centralization -- typically using flat topology models with very little or no firewalling between various business units. USB ports are typically fiddled with so flash drives cannot be used. For some reason, DVD/CD drives always do though. Go figure. Everything is vanilla-flavored, stock, and the same. If you find a weakness on one workstation, chances are good they all have it. Standardization is great! The servers are backed up. The workstations, where all the real data is, is ignored.

    Multiple IT departments
    * You'll see this with businesses that absorb other businesses -- financial companies in particular. Each business unit has its own IT, distribution schema, and enforcement of IT policies vary wildly. You won't be able to change your desktop wallpaper, but regedit still works with full admin rights. Firewalling between various business units is more common, but the policies are often out-of-date, and multiple routes exist. VPNs are commonly stacked over them, and if you know where to look, you can usually find a way through. The upshot is that the hardware is much more diverse, users are sometimes "left to their own devices" (literally and figuratively), and homebrew software solutions are more common. Nobody really knows what Server X does, but it has a sticker on it saying "Do not touch, Very Important." Often, hardware inventory and diagnostics in such environments consists of unplugging it and waiting to see who complains. If nobody complains, pack it up and ship it to Corporate. Nobody really knows what the company owns, but by god, we've got a lot of it. The good news is, if you can find your IT guys, they'll usually have your software loaded in a few hours. They won't care as much about software licensing either (I just gotta make my 8 hours, man)... Contractors typically run the show, and they have no idea what they're doing (because nobody wants to tell them anything). Servers are backed up, sometimes workstations are too. Sometimes. Maybe.

    Mid-size businesses (less than 100,000 employees)
    Sometimes you'll see centralization, but more often it's the scenario above, but with only one IT department. The network topology is generally laid out better though, hardware is more consistent, and the helpdesk is actually (le gasp) helpful, typically being a stone's throw away from the admins who maintain the servers. This is a good deal for you users -- they're too busy to be making many software policies and auditing, but not too monolithic that they're inaccessible. Your USB flash drive will work, even though you're told not to. Hello iTunes! Don't download pr0n though... For some reason, medium-sized corporate IT departments know everything you do on the internet, even though they don't know where the database server is. There is one rack of equipment... somewhere... and if it dies the entire business will collapse. But nobody knows. The servers are sometimes backed up, and so are the workstations. We're not sure... What's a "backup policy"? Can I use MMC to set one up?

    Small business (less than 10,000 employees)
    There is one guy or a small team and they are zyzzy GOD on the network. They don't care what you are running on your workstation... There's a pile of install CDs at his desk. Help yourself. Talk to the pimply-face

    --
    #fuckbeta #iamslashdot #dicemustdie
  19. Re:We will audit it for you by mlts · · Score: 5, Funny

    This reminds me of an occurance on a mailing list. Someone asked if they should report their employer for pirating a certain fairly expensive program, posting from their work E-mail.

    Reply from someone who worked at the company, "You just did."

  20. Re:Tell the truth, plainly by Sun.Jedi · · Score: 5, Insightful

    and no executive is going to wantonly commit federal fraud.

    Wow. Thats a naive, and highly innacurate opinion.

  21. which $600 package? by way2trivial · · Score: 4, Informative

    most large commercial software do have free trials
    what $600 purchase are you alluding to that does not?

    Photoshop http://www.adobe.com/support/downloads/product.jsp?platform=windows&product=39
    autocad http://usa.autodesk.com/adsk/servlet/mform?id=9106363&siteID=123112
    Sony Vegas http://www.sonycreativesoftware.com/download/trials/vegaspro

    MS office- http://us20.trymicrosoftoffice.com/default.aspx
    you can in fact with a tech net subscription-
    trial EVERYTHING Microsoft produces for $349 a year--
    which is a worthwhile investment and negligable sum for ANY company large enough to have a full time IT person on staff

    not an unreasonable purchase amount at all.

    --
    every day http://en.wikipedia.org/wiki/Special:Random
  22. I walked into this by Capt.DrumkenBum · · Score: 5, Interesting

    same situation two years ago. Last month I cleared out the last of the questionable software. It has taken 2 years, much hard work, and more than a few shouting matches, but we are fully licenced here at last. Much of what I replaced was replaced with OSS.

    Since simply licencing everything would have bankrupted the company, and inertia prevents a switch to Linux on the desktop, the bosses want outlook. I got a policy stating that all new laptops would be purchased with a copy of Office.
    One day without notice I blocked access to the update server for the pirated antivirus software, and just waited. Two days later there was a panic, and the next day I had a site licence for the antivirus I wanted instead of the crap I was stuck with by the person I replaced.

    In a nutshell, here is my advice:
    Document everything. What you found, when you found it, and your plan to get rid of it.
    Think creatively about ways to get what you want.
    Take your time. Cleaning up a mess like this is a long process.

    --
    If I were God, wouldn't I protect my churches from acts of me?
  23. get shitcanned, its good for character by hildi · · Score: 5, Insightful

    some of the finest people in history have been shitcanned and blackballed for simply saying the truth, no matter how politely, professionally, or curteously they did it.

    1. Re:get shitcanned, its good for character by postbigbang · · Score: 5, Insightful

      "shitcanned" isn't the right word. "liberated" is the right word. Better to be free and hungry than fat and fucked up.

      --
      ---- Teach Peace. It's Cheaper Than War.
    2. Re:get shitcanned, its good for character by gad_zuki! · · Score: 4, Interesting

      Obviously you have no experience with the BSA, not to mention your casual use of the word rape is offensive. The BSA wont do 'revenge' for just anyone, and certainly not the guy in this scenario.

      In reality the BSA doesnt care about some small company thats using its photoshop license two or three times or that it has two windows 2003 servers it didnt pay for. They want big shops with big roll-outs who, regardless of due dilligence, missed a license or two. These are big wins for them because of PR and awarded damages.

      Small company with some shenanigans? Thats common and you'll be ignored. A multi-billion dollar international corp, yes, then they might come calling. Of course at that point you wont be anonymous anymore. You'll be implicated immediately (gee, who else would have called, the old sys admin we just fired?) and you'll probably have trouble finding a job afterwards. Heck, you'll probably be blamed for some of it too! Get a lawyer.

    3. Re:get shitcanned, its good for character by rbochan · · Score: 4, Informative

      ...In reality the BSA doesnt care about some small company thats using its photoshop license two or three times or that it has two windows 2003 servers it didnt pay for....

      Ernie Ball would beg to differ.

      --
      ...Rob
      The American Dream isn't an SUV and a house in the suburbs; it's Don't Tread On Me.
  24. BitTorrent by lymond01 · · Score: 5, Funny

    I download all my software from BitTorrent. Why pay for something you can get for free? It doesn't hurt anyone...it's not like the programmers are making the bulk of the money off the software sales...Microsoft is a billion dollar company but do you think they pay their programmers even millions of dollars a year? Pssht.

    The day programmers start making even 50% of the profit from their labors is the day I start buying software.

    Software? Oh, I meant music. :-)

    Disclaimer: Outside of the Slashdot Virtual Reaility, I do purchase CDs, AACs, MP3s. I use licensed MS software at work and home and even buy video games now and then. I do NOT, however, pay for bottled water at the movie theater. Preposterous!

  25. Re:Yes, it's a horrible situation I've faced too by Greg_D · · Score: 4, Insightful

    Ah, yes, the ivory tower scenario. Here's how it works in real life:

    1. Grab everything "IT" (install disks, licenses, purchase invoices etc.) for hardware and software and get them to a single secure location. Your bosses will wonder why you're wasting time, but that's okay, you're on a mission.

    2. Thoroughly audit the whole lot. Your bosses will wonder why you're wasting time auditing the lot since you already have everything in a single, secure location.

    3. Refuse point blank to (re-)install stuff you're not sure about. At this point, they will fire you on the spot and hire someone willing to install pirated software like the last guy did.

    4. Maybe you can push FOSS as a solution at the unemployment office.

    The vast majority of small businesses don't care about pirated software, because most of these people use pirated software regularly at home too. The correct thing to do would be to raise a concern about the lack of licensing, and if you meet resistance, find another job.

  26. Re:That's not your fault by MadKeithV · · Score: 5, Funny

    I was the other guy, and we *did* have licenses. I just took them all with me when I left.

  27. Spiceworks IT management by witherstaff · · Score: 4, Informative

    Spiceworks is a spiffy tool. It'll get all the software and hardware info you need for your network. Borrow it on their website - it's free!

  28. One thing to make sure of by Sycraft-fu · · Score: 5, Insightful

    If you offer OSS replacements, be ready to back that shit up. What I mean by that is you need to be ready to support it to do all the same things that whatever you replaced did. Saying "Well you shouldn't do that," or "You need to read the manual," isn't ok. You recommended it, you have to support it.

    Now in terms of things like OpenOffice, this means doing testing before hand to make sure it does everything they need. Don't assume, do real tests. Find out what they actually do and try it. Do they do mail merge? Do they have power point presentations that integrate with Excel files (for realtime data update)? Find that out and test it. Make sure it all works. Only then should you recommend an OSS solution. Two reasons for this:

    1) Your job may rely on it. If you recommend something that works poorly, they may show you the door. Goes double if it was because you were "making trouble" about their pirated software. They figure you are just going to be a problem and thus want nothing to do with you.

    2) Even if you don't get axed (and probably if you do as well), you may ruin any chances of future OSS use. The message that'll be taken away is "OSS is broken and doesn't do what you need." It'll be seen as a cheap replacement that doesn't get the job done. Thus they won't want to use it in the future. Someone will say "free software" and they'll say "no way."

    So while an OSS recommendation is a great way to legally save money, do your homework first. Make sure that it truly is a replacement for what they use now. Not a "kinda sorta works" substitute. Not a "well it does some of what you want," substitute. A true replacement for all the functions they need. Also make sure you are fully prepared to train people on it since even if the differences are small, they'll trip people up.

  29. Re:It doesn't have to be production to be piracy.. by icebrain · · Score: 4, Informative

    Stop calling it "piracy"! Installing software you haven't licensed is breach of contract, or something like that.

    Piracy, on the other hand, isn't some little look-the-other-way offense that gets you in trouble with the BSA and sends you to court. It's a brutal, nasty, bloody, violent, and sometimes deadly crime committed against a vessel (aircraft or ship) and the people and property on board People get hurt from piracy. People die from piracy.

    And you know what the punishment for piracy traditionally was?

    Death, usually by hanging.

    It's not something that's just a storybook tale made for Disney movies. Piracy still happens, only now the pirates operate from fast boats, use radar and GPS to track their prey, and arm themselves with rocket launchers and machine guns. They still hold ships for ransom, steal the valuable cargo, and sometimes mutilate or kill their victims.

    Piracy and copying software aren't even on the same level.

    --
    The meek may inherit the earth, but the strong shall take the stars.
  30. devil's advocate by TheSHAD0W · · Score: 5, Interesting

    I think BSA gives bounties to whistleblowers, and the size varies on how much stolen software they discover... Depending on the size of your company it could run to years worth of salary.

    If the company won't correct the problem, and you think the blame will fall on you...

    1. Re:devil's advocate by SteveFoerster · · Score: 5, Funny

      -1, Evil.

      --
      Space game using normal deck of cards: http://BattleCards.org
    2. Re:devil's advocate by berend+botje · · Score: 5, Funny

      +1, Evil.

    3. Re:devil's advocate by gknoy · · Score: 4, Insightful

      I'd say that reporting knowledge of wrongdoing, when you know there's a bounty and have given them an opportunity to reform, is:

      +1 ethical
      (and we hope +1 lucrative also. It's also probably -1 Bad Career Choice, though.)

      Doing it right off the bat isn't very nice, but if the management insists on unethical (and illegal?) behavior being company policy, then you're in the clear.

  31. Sounds familiar... by fprintf · · Score: 4, Interesting

    http://ask.slashdot.org/article.pl?sid=09/02/04/022257 is a discussion very recently about software piracy at the Beijing office of a company. While the location is different, the responses are quite similar. Basically, document your actions in writing, and be prepared to leave if the situation doesn't improve.

    --
    This post brought to you by your friendly neighborhood MBA.
  32. Finding the Licenses by cbdougla · · Score: 4, Informative

    One thing you might try is use a software product to find the license numbers.

    http://www.magicaljellybean.com/ has a utility that will print out all the Microsoft license number for all the MS programs installed on the computer.

    Now I am not suggesting you do that for all the computers but certainly taking a sample of machines and seeing if they're using the same license on them could help determine the true nature of the situation.

  33. Here's what you do by Spazmania · · Score: 4, Insightful

    First off, let the higher-ups know what's going on and that it's neither a joke nor a hassle but a serious issue of stolen property about which they have now been unambiguously advised.

    Second, try to handle this in a "moving forward" manner. You'll find no support for suddenly spending hundreds of thousands of dollars on software. If you push it, you'll probably be fired for not being a "team player." Instead, make sure that any new systems you set up run correctly licensed software. You'll replace all the computers over the course of the next several years anyway, so this will get you where you need to be while spreading the cost out into something manageable.

    Third, get together with the company accountant and and scrutinize the purchase receipts for the last 3 years. You probably have more licenses than you think, but they were purchased ad-hoc with poor recordkeeping.

    Fourth, don't be too literal with the license details. If you have three VMs running XP on a XP host and you try to call that four licenses you'll get skewered by your boss, just as you should. Practices like refusing to let employees install Office on their home PCs because the company hasn't paid for an extra license will earn you a rep for having a stick up your tail. Get exactly one Office license for each employee and no more. And as long as you have a license for each copy of Windows, don't worry about whether the individual installations were done with a crack.

    Fifth, recall that individuals often install useful software on their individual machines. This is a good thing. You think you only have two solutions: the company licenses the software or you remove the software. In fact, you have a third: the individual to which the computer is assigned can take direct responsibility for the software, and sign a form to the effect that, "The following software on my computer is provided by the company. I, the undersigned, take responsibility for the legality of any other computer software found on my machine."

    Finally, do the obvious stuff... Replace Norton Antivirus with AVG Free, Secure Shell Client with Putty, etc. MS Office with OpenOffice if you dare.

    Now, obviously this is not legal advice. If you want legal advice, the answer is: "Open your wallet and close your eyes 'cause if you see this it'll just make you cry." This is social advice. It'll get your company to a point where it's operating ethically without unduly annoying your boss or colleagues.

    --
    Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
  34. my successful approach by itzdandy · · Score: 4, Interesting

    I came into a job where the previous guy had installed upwards of 300 copies of MS Office 2000 Pro and a number of other programs such as terminal emulators.

    I went to the management with this and got pretty much nowhere. I did win on the fact that I would not under any circumstances install software without a license so I have a solution moving forward.

    For all those machine without proper licenses I went to the software company and explained the issue and that I would like to bring the company into compliance if they would be willing to give me their discounted upgrade rate. I replaced all of the Office 2000 installs with open office and got the vendor of a terminal emulator to make me a good deal.

    We are now 100% compliant and migrating towards more open source software.

    I wish that there were direct OSS replacements for everything I run but there are not. I need perfect VT400 emulation and I have not found an OSS that does that. Putty is about 95% but that other 5% doesnt allow me to have the proper keys mapped to the proper location.

    Good luck and be on Buddha's side. Stick to your principals.

  35. Obligatory Clerks Reference by bazio · · Score: 5, Insightful

    Blue-Collar Man: Excuse me. I don't mean to interrupt, but what were you talking about?
    Randal: The ending of Return of the Jedi.
    Dante: My friend is trying to convince me that any contractors working on the uncompleted Death Star were innocent victims when the space station was destroyed by the rebels.
    Blue-Collar Man: Well, I'm a contractor myself. I'm a roofer... (digs into pocket and produces business card) Dunn and Reddy Home Improvements. And speaking as a roofer, I can say that a roofer's personal politics come heavily into play when choosing jobs.
    Randal: Like when?
    Blue-Collar Man: Three months ago I was offered a job up in the hills. A beautiful house with tons of property. It was a simple reshingling job, but I was told that if it was finished within a day, my price would be doubled. Then I realized whose house it was.
    Dante: Whose house was it?
    Blue-Collar Man: Dominick Bambino's.
    Randal: "Babyface" Bambino? The gangster?
    Blue-Collar Man: The same. The money was right, but the risk was too big. I knew who he was, and based on that, I passed the job on to a friend of mine.
    Dante: Based on personal politics.
    Blue-Collar Man: Right. And that week, the Foresci family put a hit on Babyface's house. My friend was shot and killed. He wasn't even finished shingling.
    Randal: No way!
    Blue-Collar Man: (paying for coffee) I'm alive because I knew there were risks involved taking on that particular client. My friend wasn't so lucky. (pauses to reflect) You know, any contractor willing to work on that Death Star knew the risks. If they were killed, it was their own fault. A roofer listens to this... (taps his heart) not his wallet.

    --
    Set the bar high, then bring a tall ladder.