Live data from Hacker News

Open source liability is coming

developersalliance.org

121–130 of 239 posts

Re: Open source liability is coming

#121
post #115
post #100

Earlier quoted context omitted.

I don't understand your confusion. If you sell a product e.g. a car and the brakes don't work you are liable If you sell a product e.g. a medical software which calculates and runs your insulin pump and it responds to a division by zero error with injection 1000x the amount of insulin your are liable. You don't have to focus on the how, only on if it was your product and was sold to a customer. Who was at fault (prod…

Neither article nor the PDF explains who is considered provider and who is not. Please point out where it says "only on if it was your product and was sold to a customer". I did not find it. There's a reference to "Decision No 768/2008/EC of the European Parliament and of the Council of 9 July 2008", which does not distinguish for-profit activity at all. Just "all poducts on market and all who manufacture and distrib…

From the linked pdf: 'In order not to stifle innovation, the rules will not apply to open-source software developed or supplied outside of a commercial activity'

(if you receive donations, it isn't commercial activity. If you display ads like Firefox or Brave, it is)

Re: Open source liability is coming

#122
Like most, I'm convinced of the efficacy of the open source model. I'm convinced that authors should receive reliable financial compensation for their work so the model is sustainable.

Counter to some fears about liability with a move like this, I am not convinced this will result in a negative outcome.

Businesses will pay big bucks to dump liability on someone else. And an author won't accept that liability for free.

I see an opportunity for authors or distributors of open source software to demand a fee for maintenance and shouldering some of some the liability for its use.

I see an opportunity for software professionals to vet the paid consumers of their libraries and, via consult, approve to take on the liability based on sound usage (charging fees to confirm sound usage).

I see an opportunity for a license that requires you, as the consumer, agree to take on all liability via signature if you aren't paying.

Is this not in the spirit of traditional open source? Maybe yes...

Or, maybe it is more like a source available model with as few strings attached as possible to get the story straight.

Maybe this is not a bad thing.

Personally? If the dynamics change so that I can realistically write software for a living independendent from a single company without begging for donations, I would more strongly consider doing so. Incentives here might allow for that.

Re: Open source liability is coming

#123
post #37

Earlier quoted context omitted.

The article is misleading unless you read the whole thing and the reactions are standard knee-jerk ones from HN users that didn't need to read past "EU" to assume the worst possible misinterpretation.

Yes, the author of the article is all over the place >But what if you’re just part of a collaborative open source project, give away your app, or if there’s open source code in the product you put on the market? Who gets blamed when open source might be the heart of the problem? Every other sentence is dripping in "sympathy for open-source creators", but buried in the subtext is "sympathy for the innocent commercial…

The end of that paragraph continues in the same line:

> Worse still, how will you in turn identify or sue the collaborator or collaboration that actually wrote the faulty open-source code to recoup your costs? In that case, the license you signed likely insulates your open-source partners from your claims.

I sincerely hope this will never become a possibility. The chilling effect would presumably be catastrophic for Free and Open Source software in the relevant legal jurisdiction. Why would anyone voluntarily release their code as FOSS if it opens them up to lawsuits?

Re: Open source liability is coming

#124

I know this legislation is in the EU, but in the US such a regulation seems to run up against the concept of free speech. What is the difference between these hypotheticals: Case 1: I have a blog that takes a conspiracy-level, anti-tax position. In it, I say crazy things like, “The IRS is illegitimate and financial records are unnecessary.” From reading this, someone shreds all their financial documents. As far as I…

It's something of a digression, but your understanding of Free Speech is incomplete.

>> As far as I can tell, the blog is perfectly legal under the First Amendment.

The blog is legal, but things can be legal and still have consequences.

Let's say you work at the office, and forget to lock up one night. Someone walks in and takes a laptop. -you- haven't committed a crime, but you'll likely lose your job.

Free Speech prevents the govt from locking you up based on what you say. (Unless what you say is a crime, like say inciting a riot.)

It does not provide you with the right to say whatever you like on a private (non govt) platform, nor does it absolve you from legal liability (consequences) of what you say.

The obvious example is "conspiracy to commit xxx" - sure all you did was -talk-, but Free Speech doesn't give you a pass for that.

Re: Open source liability is coming

#125
post #115
post #100

Earlier quoted context omitted.

I don't understand your confusion. If you sell a product e.g. a car and the brakes don't work you are liable If you sell a product e.g. a medical software which calculates and runs your insulin pump and it responds to a division by zero error with injection 1000x the amount of insulin your are liable. You don't have to focus on the how, only on if it was your product and was sold to a customer. Who was at fault (prod…

Neither article nor the PDF explains who is considered provider and who is not. Please point out where it says "only on if it was your product and was sold to a customer". I did not find it. There's a reference to "Decision No 768/2008/EC of the European Parliament and of the Council of 9 July 2008", which does not distinguish for-profit activity at all. Just "all poducts on market and all who manufacture and distrib…

Sorry, at first I thought I couldn't reply to this comment.

I don't understand why you want to know what the provider is?

For the purpose of liability and open source the definition is that any open source free of charge software is excluded from the proposed changes, so the provider doesn't matter.

This can be seen in the first link,on the third headline bullet point "Not applicable to free-of-charge open-source software" as well as the second paragraph.

The provisional agreement on the liability of economic operators for damage caused by defective products aims to respond to the increase in online shopping (including from outside the EU) and the emergence of new technologies (such as AI) as well as to ensure the transition to a circular economic model. In order not to stifle innovation, the rules will not apply to open-source software developed or supplied outside of a commercial activity.

I also added the the briefing of the proposed EU law with the details

Re: Open source liability is coming

#126
I personally find it strange that software has acted differently… ever. Typically, if you cause damage, you are liable without any regulatory burden being in place. Failure to maintain a motor vehicle can put an operator at risk in event of an accident, a car exploding at random when well maintained puts the vehicle maker at risk, slippery floor not being disclosed to someone and that someone then slipping and getting hurt makes the property owner (or lease holder) liable. It would make sense that software would be absolutely no different except in cases where ownership were in question such as purely open source and non-commercial software. I am glad that the EU is clarifying this and I hope that other jurisdictions follow.

On a not-so-rational footing, I hope this puts an end to megacorps freeloading and using FOSS without contributing in any way despite making tons of money off of it.

Re: Open source liability is coming

#127

Honestly just sounds like a misreading of the law to me. I don't believe it. One part says "If open source resources are in/called/touched your code, you’re responsible for their performance too. The open source resource licensed away their liability to you." This is the norm. The private company holds responsibility for vetting everything they ship. It's a speculation on how the law will be enforced for a law with n…

Also the EU laws are read here, by people who live in countries where that would be the case, with way too much weight. People from the US putting cookie accept banners and gdpr blah on their sites while they don't have to, because they are not violating in the first place (the intent of the gdpr is very simple; don't do things you don't want to have done to you to others; tracking, collecting info you don't need to…

Yea, the “pragmatic” EU approach to legislation: write it in draconian language and let it carry incredible sanctions (like millions of euros), but then just don’t enforce it. Unless you anger some bureaucrat of course.

Re: Open source liability is coming

#128
post #109
post #92

Earlier quoted context omitted.

The article says that someone is liable. So if a user directly uses open source would the open source maintainers be liable? Would it be the operating systems company for allowing the software to run? It’s very unclear.

Maybe the article but the EU explicitly says opensource free of charge software is fine. https://www.europarl.europa.eu/news/de/press-room/20231205IP...

What if its free of charge but I'm rattling a tin can? Is that "thanks for making my life better free of charge, buy yourself a beer" or is it "here's a quarter in exchange for 100% insurance covering anything I use this free thing you made for"?

Re: Open source liability is coming

#129
post #103

Earlier quoted context omitted.

> as long as there is no commercial activity associated My recollection, from previous discussion on HN, is that the definition of "commercial activity" is far more broad than the open source community would like it to be. And by "open source community", I mean the people that run various foundations and non-profits and things like that. I don't think that throwing up a virtual tip jar on your Github page counts, but…

Correct. I would be perfectly fine with some amount of control and liability proportional to the size of the company, excluding tiny ones as it is often the case. With this new act, even selling 100€/month of support for a piece of software you are contributing to makes you subject to the full force of the bill (and the full force includes scary numbers, millions, with zero information on how precise amounts will be…

Yes, proportionality, or at the very least some sort of clarity on where the line is drawn. Nobody wants to be the test case that determines if something is commercial or not.

An acknowledgment that it costs some small amount of money to host a website for the code, or that you may from time to time want to hire someone to do something specialized (design a logo?) and need to raise some amount of money for that to happen.

By world-wide standards (though not necessarily by Silicon Valley standards) I am fairly wealthy and thus could afford to support a completely commercial-free open-source project out of my professional salary. And this would make my project liability-free in the EU. But someone else, who didn't grow up in the USA at a time when university tuition was cheap, would not be able to do the same and their otherwise-identical project is subject to legal liability.

How is that fair? Isn't this just going to further concentrate open source contribution and leadership in a handful of rich countries (that are mostly not in the EU)?

Re: Open source liability is coming

#130

It's a mixed reaction from me. Liability to the vendor sounds like a good idea - too many cowboys out there. Also with stretched supply chains someone has to pay attention. But full liability..? What if I make a crappy, low effort, cheap spreadsheet app, someone builds their business on top of it and it goes boom. Should I really be liable, on the basis of what I consider a casual product? And then, the main point of…

There is a principle that liability rests with the party best equipped to mitigate the liability. The commercial-ness of the product doesn't really enter into it, you see this kind of liability attribution all the time in non-commercial settings. Your product being "casual" isn't a defense per se.

The gray area where this often gets litigated is liability due to inappropriate use of a product, since liability for clear and obvious inappropriate use typically falls on the user. What constitutes an "inappropriate use" is frequently unclear, especially for casual products where you are unlikely to clearly document and delineate what does and does not constitute appropriate use. If you read the fine print of commercial enterprise software licenses, it frequently has a long list of applications for which the software is deemed inappropriate for legal purposes. The product may in fact be fine for those applications but the producer does not want to take on the liability.

It is difficult to enumerate all possible inappropriate uses of software. Enumerating inappropriate use cases to limit liability arguably conflicts with open source's principle of non-discriminatory licensing.

Post reply on HN