Live data from Hacker News

Open source liability is coming

developersalliance.org

71–80 of 239 posts

Re: Open source liability is coming

#71
So what happens in this situation:

I write open-source software, and make it available on GitHub, together with a nice installer. I deny any liability in my license, and the users are free to install it or not. They don't pay me in any way (not even in ads).

Am I liable according to new EU law?

Re: Open source liability is coming

#72
post #44
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

i think the article is deliberately written to be confusing

Maybe, but maybe the legislation also is:

"What if an open source project is used directly by consumers, and causes them harm? The public policy is clear: they must be compensated. Does it matter if they signed a license or didn’t pay someone? Their business is bankrupt, their files are in a hacker’s hands, or their own customers are suing them. Someone should be strictly liable. But who?

The EU is grappling with that very question, and it culminates in whether “open source” is exempt from liability in a law designed to protect consumers. So far the answer is “probably not?” Exemption means consumers bear the cost – exactly what the law is trying to change. Perhaps if the open source in question remains an academic or research tool, versus reaching consumers, we’re okay? The proof may come when the first consumer demands compensation, and the courts step in. But lawmakers know enough to realize that much of the open source out there – by definition – belongs to no one, or many someones, or really nobody that can be named and made liable. So waiting on a court case might provide clarity but no compensation and no one to even argue the case. Not the clarity a law is designed to provide."

But I rather think that no, the law just talks about products where you pay money for. And when I pay money for something, I do expect liablity in some way and this is allright. But it is not allright to mix them both up for politicial support (or whatever the motivation here is).

Re: Open source liability is coming

#73
post #50

Earlier quoted context omitted.

I agree it's very ambiguous, but if you read the whole thing it's clear that when dev A releases code under an open source license and it's included in a commercial product by company B that then harms person C, the liability will be on company B. Most of the hot-under-the-collar responses here are assuming it will fall on dev A, which is a misinterpretation the article's author did not do much to discourage.

Actually, I may have missed buried lede in this case where there is no company B, and citizen C is harmed by dev A's github project. That is actually kinda concerning, if my MIT license of "no guarantee" won't protect me. Other commenters who got it: https://news.ycombinator.com/item?id=38808821 https://news.ycombinator.com/item?id=38808756

That is concerning, but I think the author’s interpretation of the upcoming regulation may be wrong.

See here for example: https://www.euractiv.com/section/digital/news/eu-updates-pro...

Specifically: “The Directive will not apply to free and open-source software developed or supplied outside a commercial activity. The liability rules apply when the software is supplied in exchange for a price or personal data used for anything other than improving the software’s security or compatibility.”

IMHO the original article is either wrong or trying to spread FUD.

My take is, if this law passes, I’m an EU citizen, and I use your MIT software without paying you and without engaging with it through some service of yours (e.g. sevaghbook.com) then you’re not liable if I get damaged.

Re: Open source liability is coming

#75
This is great. Software is important, software has an impact, and so we need liability.

This regulation ensures that whoever sells the software to the consumer is responsible, and that's the way it should be. The creator of a library doesn't know how his library will be used in the wild, he can't anticipate all possible problems, the product maker can. It is the product maker's responsibility to integrate external components properly, having validated that they are up to standard.

If you're a manufacturer, you can't just pick components at random and then say it's not your fault if your product doesn't work. That's why manufacturers have whole teams of people working to ensure that what they receive from a supplier is up to spec.

Re: Open source liability is coming

#76

I know this legislation is in the EU, but in the US such a regulation seems to run up against the concept of free speech. What is the difference between these hypotheticals: Case 1: I have a blog that takes a conspiracy-level, anti-tax position. In it, I say crazy things like, “The IRS is illegitimate and financial records are unnecessary.” From reading this, someone shreds all their financial documents. As far as I…

It's probably closer to releasing "open source blueprints" for a car (a steam engine is probably better) that explodes and kills it's occupants. Who is responsible for that? A better set of questions might be:

- Why does this person think they can release open source blueprints if they aren't qualified for what they design?

- Or, if a company used these blueprints to build a car, why didn't they do their due diligence?

Re: Open source liability is coming

#77
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

Very bizarre, the implication is literally reversed in the analysis of the problem versus the actual problem.

Re: Open source liability is coming

#78
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

I think that this part of it could break either way, but the concern is that when faced with a choice between being liable for their own code or being liable for open source code, most companies will choose to write their own code. If so, that would be a net harm to open source and user freedom. I'm not sure it'll happen, but it might. The biggest issue I see with this law is around liability for open source projects…

> most companies will choose to write their own code.

That might depend on the ubiquity of the OSS in question. If a company's option is to rely on a piece of open source software that has been used billions of times over without incident versus rolling their own solution that at best has only been tested in-house, could they say the latter is really the safer bet?

Re: Open source liability is coming

#79
post #68

Earlier quoted context omitted.

NPM wasn't the one who pushed the "delete project" button, knowing full well what would happen.

You knew all this before you decided to use it. Next time make better calls instead of blindly pulling shit like an idiot.

I never used it; I just knew about the situation and used it as an example.

Re: Open source liability is coming

#80

Earlier quoted context omitted.

I think that this part of it could break either way, but the concern is that when faced with a choice between being liable for their own code or being liable for open source code, most companies will choose to write their own code. If so, that would be a net harm to open source and user freedom. I'm not sure it'll happen, but it might. The biggest issue I see with this law is around liability for open source projects…

>>> when faced with a choice between being liable for their own code or being liable for open source code, most companies will choose to write their own code. Not even FAANG can achieve this for 1/10th of the code they rely on.

A capitalistic corporation seem to be a terrible way to maintain software since the "means of production" is in the workers' heads. Especially with these new management fads punishing loyalty. The attrition just makes stuff collapse from unknown complexity.

It is not surprising that volunteer run projects kinda can keep up.

Post reply on HN