Live data from Hacker News

Open source liability is coming

developersalliance.org

151–160 of 239 posts

Re: Open source liability is coming

#151
post #44

Earlier quoted context omitted.

i think the article is deliberately written to be confusing

Maybe, but maybe the legislation also is: "What if an open source project is used directly by consumers, and causes them harm? The public policy is clear: they must be compensated. Does it matter if they signed a license or didn’t pay someone? Their business is bankrupt, their files are in a hacker’s hands, or their own customers are suing them. Someone should be strictly liable. But who? The EU is grappling with tha…

The CRA is not about liability or consumer compensation. The remedies for non-compliance are fines or removal of a product from the EU market. The forthcoming update of the Product Liability Directive, which will probably take a similar approach (exempting open source unless it is placed on the market, so as the article describes, developers of products that are placed on the market are responsible for the security of their products, including open source incorporated in said product) on the other hand is.

I only skimmed the OP and doubt it's intentionally confusing, but it is confusing because its prediction of doom is wacky. Manufacturers (eg developers of IoT devices, the insecurity of a major impetus for the legislation, apps, etc) will need to adopt modern development practices such as updating their dependencies when a vulnerability is known -- and that includes manufacturers that wrap a mostly open source codebase in a final product or monetise an open source codebase in various ways called out in the legislation.

Yes if a consumer is harmed by a completely open source thing not placed on the market, say something in Debian, they will not be able to sue the developers, and the developers aren't subject to fines etc under the CRA. That's the balance intended by the legislation (after lots of attempts to get it right), to not wreck incentives to develop open source, but to make product developers more responsible. In other words, the public policy is not exactly as you state it. :)

Re: Open source liability is coming

#152

This is great. Software is important, software has an impact, and so we need liability. This regulation ensures that whoever sells the software to the consumer is responsible, and that's the way it should be. The creator of a library doesn't know how his library will be used in the wild, he can't anticipate all possible problems, the product maker can. It is the product maker's responsibility to integrate external co…

please provide a link to all your software, so I can find bugs and then sue you for everything you have.

Re: Open source liability is coming

#153

It's a mixed reaction from me. Liability to the vendor sounds like a good idea - too many cowboys out there. Also with stretched supply chains someone has to pay attention. But full liability..? What if I make a crappy, low effort, cheap spreadsheet app, someone builds their business on top of it and it goes boom. Should I really be liable, on the basis of what I consider a casual product? And then, the main point of…

There is a principle that liability rests with the party best equipped to mitigate the liability. The commercial-ness of the product doesn't really enter into it, you see this kind of liability attribution all the time in non-commercial settings. Your product being "casual" isn't a defense per se. The gray area where this often gets litigated is liability due to inappropriate use of a product, since liability for cle…

TFA seems to imply that under the proposed rules, none of that careful analysis will matter. A software "vendor" is liable and that's the end of the story. Microsoft or GNU foundation, doesn't matter

TFA might of course be wrong, but otherwise, my concerns stand I think.

Re: Open source liability is coming

#154
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

How in the world is this good for devs? It's terrible. Do you really think that "big corp" will not figure out how to pass the liability directly to the author?

What will happen the opensource world once you're held liable for some moron who uses some software I wrote for myself? or incorrectly uses it?

do you really believe the curl should be held liable because some POST failed and a user lost something over it?

what about my old backup scripts? I need to remove them from my repos?

Re: Open source liability is coming

#156
post #107
post #37

Earlier quoted context omitted.

Yes, the author of the article is all over the place >But what if you’re just part of a collaborative open source project, give away your app, or if there’s open source code in the product you put on the market? Who gets blamed when open source might be the heart of the problem? Every other sentence is dripping in "sympathy for open-source creators", but buried in the subtext is "sympathy for the innocent commercial…

So can we expect popular yet understaffed open source software -- like OpenSSL -- to get a lot of paid code review or patches?

expect new, certified companies with security and finance, to become the officially required caretakers along with many fees; expect new monetized systems to distribute security patches passed through new bureaucracies, with logging of the government ID of all recipients; expect the restriction of new security patches to authorized users only.

Re: Open source liability is coming

#157
post #138

Earlier quoted context omitted.

I don't mean THESE new laws, just new laws in general. > nothing specifying that you need to continue making your open-source package continually and indefinitely available. There's a difference between making it available, and deliberately causing harm and untold productivity loss in a single day. This was a case of the latter.

Someone deleted a publicly accessible file off the internet, and it broke workflows of people with whom they have no existing contract. Good luck proving that was done to deliberately cause harm.

In this case, they freely admitted to doing it with the intent to harm. A person slapping me in the face doesn’t have a contract with me, but they are still liable for that harm. This isn’t rocket science.

Re: Open source liability is coming

#158
post #40

EU is really bent on destroying itself by any means. First AI regulation, now open source destruction, killing off any avenues for growth for the next century. It's already uncompetitive at both.

It may be difficult to understand, but maybe the EU has other things where they want to be competitive instead? Maybe, I don't know, quality of life...? Please stop measuring the EU using US standards.

Maybe ask yourself how is EU going to pay for all that if it misses on all trends in the industry and over-regulating anything that could be the next growth factor.

Re: Open source liability is coming

#159
post #84
post #40

Earlier quoted context omitted.

It may be difficult to understand, but maybe the EU has other things where they want to be competitive instead? Maybe, I don't know, quality of life...? Please stop measuring the EU using US standards.

> Maybe, I don't know, quality of life...? I’m very happy with my public healthcare. I think every American would be as well. And not to mention that our kids don’t need to do active shooter drills in school.

Public healthcare? You mean the free healthcare for 1000EUR that single German freelancers have to pay monthly? For $1k you can get a US insurance for the whole family!

Re: Open source liability is coming

#160
If I get it right the EU has read the story of boiler manufacturers in the 19C. They exploded - a lot, because commercial pressures pushed a tragedy if the commons. But insurance came along - we will insure you against liability for your boiler killing the train passengers - as long as you follow these best practises and stnadrards and .. boilers blew up less.

The question is, are boilers the same as software? Sometimes maybe? Theros-25 is definitely true. Crud HR apps are a maybe.

Post reply on HN