Sage accused of misselling perpetual licenses it knew would soon be obsolete
- Reference: 1659352514
- News link: https://www.theregister.co.uk/2022/08/01/sage_perpetual_licensing_dispute/
- Source link:
Earlier this month, [1]The Register revealed Sage was advising customers with small business software Sage 50 Accounts and Sage 50cloud Accounts v26.2 (published 2020) or below to move to subscription software because these packages use Transport Layer Security 1.0 and 1.1 – dated versions of the security protocol.
Sage is not offering customers the ability to patch or upgrade their software on a perpetual license. Those who have not moved to a subscription license by 30 September will lose access to their software and their data, [2]according to a statement .
[3]
However, developers on a separate Sage platform, the cloud-based Intacct, were told in March 2018 to "Ensure your application is configured to negotiate connections using TLS 1.2 or higher."
[4]
[5]
The [6]2018 post explained: "Once Sage Intacct disables support for TLS 1.0 and 1.1, any browser or API access originating from a resource that does not support TLS 1.2 or higher will fail."
Customers with Sage 50 Accounts perpetual licenses activated after this date are arguing they were effectively missold the software because Sage knew it to be out of date with the communications protocol, knew it would need to be upgraded, and Sage planned to only offer that upgrade on a subscription license.
[7]
"[Sage] have sold a software to me on a perpetual license knowing that it's going to be invalid within an unknown period of time," one customer told The Register .
Users of the affected version of Sage 50 Accounts get a pop-up dialog box telling them to upgrade to 26.3 or 27, but when they try to download the software, only subscription options are available.
"They had full knowledge of this all happening. They are telling us to upgrade and they're refusing to provide [the] very software they're telling us to upgrade to," the customer said.
[8]
In Sage's [9]terms and conditions [PDF] accompanying perpetual license purchases, it says users have a right to expect the software to be usable for 15 years provided they keep their systems up to date.
Meanwhile, The Register understands that customers have been offered refunds on recently purchased upgrade packages, a refund of time remaining on the 15-year perpetual license when they move to the subscription model, and a 12 months free subscription.
In correspondence seen by The Register , Sage appeared to admit some customers had the right to expect their perpetual licenses to be valid for a longer period than they will be.
Nonetheless, customers are still arguing they will be worse off under subscription licenses, even with the new offers. A perpetual license might cost £650 (c $790) while a subscription for Sage 50cloud Professional costs £145 ($176) per month. A Sage 50cloud Standard subscription costs £72 (c $87) per month. Customers are likely to be worse off paying a subscription license after less than a year.
Earlier this month, a Sage spokesperson said: "TLS v1.0 and v1.1 is an industry-wide security protocol that is used to facilitate privacy and data security for communications over the internet. The stability and security of the protocol is the core focus, not the age of it. The need to amend to a new protocol occurred following the launch of our products and after the Internet Engineering Task Force (IEFT) formally discouraged the use of it."
They added: "Sage communicated with its customers about this, the action they needed to take, and how we could support them. We will always prioritize the security of our products and protect customer data in accordance with the latest industry standards, today and for the future."
[10]Sage accused of strong-arming customers into subscriptions
[11]Sage to acquire remaining stake in ecommerce platform Brightpearl for £225m
[12]When ERP migrations go bad: Games Workshop says project issues are delaying refresh of 'dated' online store
[13]In Microsoft's world, cloud email still often requires on-premises Exchange. Why?
We asked why Sage can't update v24 and after to use TLS1.2 to verify software licensing, and were told: "We recognize that due to these changes to the TLS Protocol, our customers will be impacted in different ways. Providing temporary patches is not the most effective solution in this instance, but ensuring that the systems provided by Sage are continually up to date is key for businesses to operate effectively and securely. The change required is a simple process for customers on the latest versions of our software, and we are ready to support all customers to make the changes so they are secure and have the best experience."
When asked whether customers would lose access to their data, the spokesperson said: "No. We have communicated with customers about the options available to them. If the customer upgrades to a compatible version of Sage 50 Accounts, they will continue to access their data. If they do not wish to upgrade, they can export their data before the cut-off date in September. We appreciate this will impact customers in different ways and our customer contact team is happy to discuss needs on an individual basis."
The Register asked Sage to comment and it sent this statement:
"Software platforms are built in different ways and as such giving prior notice to upcoming changes in terms of security protocols and other technological changes is standard practice.
"The stability and security of The Transport Layer Security protocol is the core focus, not the age of it. The need to amend to a new protocol occurred following the launch of our Sage50 products and after the Internet Engineering Task Force (IEFT) formally discouraged the use of it.
"Any customer with an active support contract or subscription has access to the latest version without any cost to them. We appreciate this will impact customers in different ways and our customer contact team is happy to discuss needs on an individual basis." ®
Get our [14]Tech Resources
[1] https://www.theregister.com/2022/07/19/sage_subscription_tls/
[2] https://gb-kb.sage.com/portal/app/portlets/results/viewsolution.jsp?solutionid=200910142529173
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yuf4s7@izQlvRp2cM-PMzQAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yuf4s7@izQlvRp2cM-PMzQAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yuf4s7@izQlvRp2cM-PMzQAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://developer.intacct.com/blog/2018/02/Disabling-TLS.html
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yuf4s7@izQlvRp2cM-PMzQAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yuf4s7@izQlvRp2cM-PMzQAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.sage.com/en-ie/-/media/images/sagedotcom/master/global/feature/pdf/legal/consolidated-perpetual-and-subscription-licence.pdf
[10] https://www.theregister.com/2022/07/19/sage_subscription_tls/
[11] https://www.theregister.com/2021/12/20/sage_brightpearl/
[12] https://www.theregister.com/2021/09/14/games_workshop_wants_to_freshen/
[13] https://www.theregister.com/2021/08/31/microsoft_on_prem_exchange/
[14] https://whitepapers.theregister.com/
Shooting self in the foot
Come on, TLS was updated in other Sage products and compoenents years ago (Same with Java runtime in products which used them), instead of keeping customers on your product, you are just pushing them to go look elsewhere.
Ah, cloudy stuff and software subscriptions... the stuff any company uses to milk their customers...
Except that the only thing that is cloudy about this piece of s**tware is the pricing model.
TLS 1.1 → TLS 1.2
It's clearly a (very poor) excuse to get some people to move to a subscription model, but you could in theory use a proxy.
Not that I would trust any vendor who claims to be unable to modularly upgrade their connection security stack. What happens if a game ending vulnerability is found in current versions of TLS and you're unable to patch in a replacement?
Purely commercial, not technical decision
There is absolutely no reason why TLS could not be lifted to 1.2 on perpetual license products, other than using this as a lever to extort more money from their customers.
This is not like an AV or other cybersecurity service that may require daily updates (with associated ongoing operational costs) - it is a (very rare) change in protocol only.
Shame on Sage!
Hill St. Blues ...
I vaguely recall a scene from an episode that hinged on whether it was the "perpetual" or "eternal" package that kept a flame burning in a cemetery,
15-year perpetual license
... Accurate name? -- for some definitions of "year" and "perpetual"?
Take the refund. Take the free year's subscription. Spend the year looking at migrating to a package from some other vendor.
Clearly you don't work with accountants. Nothing happens fast in that world, especially change...
Also if your audit company uses Sage it's a big wrench/hassle to switch. Sage know this better than anyone.
Still, if you push folks hard enough eventually they will walk away. We have been Autodesk free for a decade now for the same reason.
Don't forget that these are the folks who'll push all sorts of crazy cost-cutting ideas.
Having said that I've mentioned here before the client's accountants who, having been provided with and completed user acceptance testing of a nice Y2K compatible version of their S/W running on brand new H/W insisted on not taking the risk(!) of moving from their old, non-Y2K capable version until they'd finished closing out 1999 in mid-January 2000.
Spend the year looking at migrating to a package from some other vendor
That presupposes they haven't all taken the same route.
And, as has already been pointed out, your accountant is ultimately in charge of your fate: if they can't (or won't) easily deal with your data then any potential savings will simply evaporate.
Incredible...
This may sound slightly on the spectrum, so sorry, but I always fail to understand how people with such obviously bad characters can look into the mirror in the mornings.
Re: Incredible...
Because they don't have a reflection in the mirror? Probably don't case a shadow either....
Asked whether customers would lose access to their data
> If they do not wish to upgrade, they can export their data before the cut-off date in September.
…they confirmed that yes, come October customers' data will be toast.