Live data from Hacker News

Open source liability is coming

developersalliance.org

101–110 of 239 posts

Re: Open source liability is coming

#101
It's a mixed reaction from me.

Liability to the vendor sounds like a good idea - too many cowboys out there. Also with stretched supply chains someone has to pay attention.

But full liability..? What if I make a crappy, low effort, cheap spreadsheet app, someone builds their business on top of it and it goes boom. Should I really be liable, on the basis of what I consider a casual product?

And then, the main point of the article, what if Vim deletes my files? The suggestion seems to be that Vim "owner" (???) is liable.

It feels like there should be some slider as to what liability the creator accepts (OSS - none, casual app - not much etc) but then we're back to square one, everyone disclaims liability etc.

Maybe it should be somehow linked to the price paid for the software?

Re: Open source liability is coming

#102

Earlier quoted context omitted.

Perhaps less pitchfork brandishing, more reading the article? > all blame/liability should lie with ... the provider of commercial software Is precisely what the EU intend to do (according to the article - no idea how accurate it is), not put the liability on open source devs. From the article: > So, how is open-source software implicated? If a commercial software product causes harm, whoever put the software on the…

What does it mean if you publish your open source android application on the play store (with no ads or monetary compensation, simply just to make it easier for users to use?). Seems to me that you'll be liable for any issues.

Why would you be? Did you sell the user the app? If not I can't see how it would be commercial

Re: Open source liability is coming

#103
post #17

Earlier quoted context omitted.

It seems the author is refering to the EU Cybersecurity Act that should be voted early 2024. The last draft clearly excludes open source software as long as there is no commercial activity associated . If voted in this state, it won't affect the vast majority of developers releasing some code under an Open Source license. But it will wipe out all small businesses: if you're a solo company selling support or feature d…

> as long as there is no commercial activity associated My recollection, from previous discussion on HN, is that the definition of "commercial activity" is far more broad than the open source community would like it to be. And by "open source community", I mean the people that run various foundations and non-profits and things like that. I don't think that throwing up a virtual tip jar on your Github page counts, but…

Correct. I would be perfectly fine with some amount of control and liability proportional to the size of the company, excluding tiny ones as it is often the case.

With this new act, even selling 100€/month of support for a piece of software you are contributing to makes you subject to the full force of the bill (and the full force includes scary numbers, millions, with zero information on how precise amounts will be calculated).

We can only hope that it is not voted in this sorry state.

Re: Open source liability is coming

#104
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

I think that this part of it could break either way, but the concern is that when faced with a choice between being liable for their own code or being liable for open source code, most companies will choose to write their own code. If so, that would be a net harm to open source and user freedom. I'm not sure it'll happen, but it might. The biggest issue I see with this law is around liability for open source projects…

I think I must be misunderstanding. The article makes it seem like the user of open source code is responsible for making sure it is suitable and they are liable for when it fails. Doesn't that mean that someone who merely releases code onto GitHub will, in fact, not be liable, since it is the user of said code that is liable?

As far as

> when faced with a choice between being liable for their own code or being liable for open source code, most companies will choose to write their own code. If so, that would be a net harm to open source and user freedom

goes, even if that is true (I'm not really convinced) it doesn't really matter. What matters is finding the correct answer to "who is responsible" to which the answer can't be "nobody". And if it can't be nobody, then it must be somebody. And if it must be somebody, it absolutely shouldn't be some random guy who never specifically signed off on your usage of their open source code.

Re: Open source liability is coming

#105

So what happens in this situation: I write open-source software, and make it available on GitHub, together with a nice installer. I deny any liability in my license, and the users are free to install it or not. They don't pay me in any way (not even in ads). Am I liable according to new EU law?

No you are not liable. Liability is linked to a commercial activity because it is meant to protect consumers. The article is very ambiguous in the way it describes the regulation. I recommended this one for more clarity : https://www.euractiv.com/section/digital/news/eu-updates-pro...

Would windows or whatever host operating system be liable potentially for the programs running on it even if they are open sourced programs?

Re: Open source liability is coming

#106

The article got me a bit worried about the idea of developing software out in the open, and the comments in this thread give me conflicting ideas. If I make a public repository `ComputerCleaner` with a single file: #!/usr/bin/env bash # rm -rf / Should I soon expect to be defending legal threats from random strangers who ran this code only to gasp find that it deleted their files?

The law pertains to commercial software, see:

https://www.europarl.europa.eu/news/de/press-room/20231205IP...

Re: Open source liability is coming

#107
post #37

Earlier quoted context omitted.

The article is misleading unless you read the whole thing and the reactions are standard knee-jerk ones from HN users that didn't need to read past "EU" to assume the worst possible misinterpretation.

Yes, the author of the article is all over the place >But what if you’re just part of a collaborative open source project, give away your app, or if there’s open source code in the product you put on the market? Who gets blamed when open source might be the heart of the problem? Every other sentence is dripping in "sympathy for open-source creators", but buried in the subtext is "sympathy for the innocent commercial…

So can we expect popular yet understaffed open source software -- like OpenSSL -- to get a lot of paid code review or patches?

Re: Open source liability is coming

#108

I know this legislation is in the EU, but in the US such a regulation seems to run up against the concept of free speech. What is the difference between these hypotheticals: Case 1: I have a blog that takes a conspiracy-level, anti-tax position. In it, I say crazy things like, “The IRS is illegitimate and financial records are unnecessary.” From reading this, someone shreds all their financial documents. As far as I…

Because the software isn't regulated but commercial activity is, which I would imagine is also done in the US.

You are still free to write and release any software you want, but as soon as you sell that software you are liable for damages.

See:

https://www.europarl.europa.eu/news/de/press-room/20231205IP...

Re: Open source liability is coming

#109
post #92
post #55

what's new here? A commercial entity selling a product that also embeds open source components is liable is that entity's product causes harm, even if the fault lies in bugs in the OSS code itself. is that new ? assuming their own license does not also indemnify them. The OSS code, at least if it's mine, has "THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND" right there in the license. What's the change…

The article says that someone is liable. So if a user directly uses open source would the open source maintainers be liable? Would it be the operating systems company for allowing the software to run? It’s very unclear.

Maybe the article but the EU explicitly says opensource free of charge software is fine.

https://www.europarl.europa.eu/news/de/press-room/20231205IP...

Re: Open source liability is coming

#110
post #44

Earlier quoted context omitted.

i think the article is deliberately written to be confusing

Maybe, but maybe the legislation also is: "What if an open source project is used directly by consumers, and causes them harm? The public policy is clear: they must be compensated. Does it matter if they signed a license or didn’t pay someone? Their business is bankrupt, their files are in a hacker’s hands, or their own customers are suing them. Someone should be strictly liable. But who? The EU is grappling with tha…

> But I rather think that no, the law just talks about products where you pay money for.

Ianal but my intuition is that you're on point.

Post reply on HN