Live data from Hacker News

Open source liability is coming

developersalliance.org

211–220 of 239 posts

Re: Open source liability is coming

#211
post #204

Earlier quoted context omitted.

You couldn't sue me for 2 reasons: 1 - This regulation only concerns commercial activity. So you could only sue the company I work for, and only if you've bought their products. Also by definition that excludes my personal projects. 2 - You can only sue for defects (in this legal context it means unsafe to use) or damage (physical or material). You can't sue for simple bugs. These kinds of liabilities already exist f…

A law and regulation is written one way and interpreted a different way by the courts. In the USA it's all about case law. Hypothetical: I write a nifty alarm clock app. To cover some costs I charge a nominal fee. Some unknown condition occurs a user misses a flight and loses their job. According to your position I should be sued. Why should I be held liable? Daniel Stenberg has a blog post somewhere about all the ha…

> A law and regulation is written one way and interpreted a different way by the courts. In the USA it's all about case law.

This is about the EU, not the US.

As someone who used to practice law in the EU before moving into software development, I can tell you that your hypothetical will never lead to a suit nor judgment in the EU, nor is your personal experience concerning a subpoena a thing that happens in the EU, if only because the concept of discovery doesn’t exist in civil law systems.

To put it differently and respectfully, you’re applying your knowledge of and experience with the US legal system to a completely different legal system that rarely produces outcomes similar to those in the US system.

Even the order of magnitude of judgments is leagues apart.

€1m judgments lead to coverage in legal outlets there if not regular mainstream media. In contrast, in the US, that money is thrown across the table to make an unviable but annoying class action disappear just because it’s cheaper than litigating it.

I’m bringing that up because, even in the unlikely instance of your hypothetical leading to a case that makes it to a hearing in the EU, the judgment against you will be close to, if not outright be, the nominal fee you charged the user (+ court fees) due to how the chain of causation works in the EU. The connection with losing your job is just too remote for any judge to consider liability.

Even if this would be about a car breaking down on the way to work, which already has strict liability under the current PLD, loss of job is just not going to be part of the equation, ever.

Re: Open source liability is coming

#212
post #25

There seems to be some confusion in the comments regarding what this means for people releasing open source software. The article makes it clear that (as the author understands it, at least) someone who uses open source software in their commercial product is liable; the people who wrote the open source code [1] are not. > If a user is harmed by software, the person they paid (targeted ads would count) must compensat…

Can you comment on the part starting with > What if an open source project is used directly by consumers, and causes them harm? The public policy is clear: they must be compensated. It's expressly not clear what the implications here are, according to the article.

The article is written by the CEO of a big tech lobbying group[0] who is trying to spread FUD to prevent the changes to the EU’s PLD that would include software once the intended changes go into effect.

The part you quoted continues with:

> Their business is bankrupt, their files are in a hacker’s hands, or their own customers are suing them.

Those are not consumers. That's B2B and comes with significantly lesser protections (if any) in EU law due to the EU’s view of B2B relationships being less asymmetrical w/r/t power and businesses being better at assessing the risks.

The implications are clear because this is not some new thing the EU conjured out of thin air but rather an expansion of which products will fall under the PLD, so we know how this has shaken out historically.

The long and short of it is that with physical merchandise, manufacturers have long been liable if their products caused damage (e.g., batteries of electric scooters catching fire). Still, when it came to software, companies often just shrugged and said, “We provided it as is, so tough luck.” The EU now says that's simply not good enough, and software companies should be held to the same liability standards as merchandise manufacturers.

Software lobbyists, of course, don't like this, so to stop that, they've decided to spread FUD about FOSS.

That's it, that's the story.

0: https://www.bigtechwiki.com/index.php/Developers_Alliance

Re: Open source liability is coming

#213

A likely scenario is that software will become more expensive to consumers because the vendors will have to buy liability insurance in-house. Also, it will raise the barrier to entry for any small vendor or a solo dev trying to make a living with open source. "Trying to start your own small business in the EU? Tough shit. Go get a job, peasant!"

There's a liability exemption for software manufacturers that are microenterprises or small enterprises at the time of placing the relevant product on the market.

Re: Open source liability is coming

#214
This article is FUD by the CEO of a big tech lobbying firm[0], which lobbied against opening up the walled app store gardens in the US.

The long and short of it is that this talks about expanding product liability laws in the EU. Currently, software doesn't fall within the PLD, and software developers can shrug and say their software was provided as is if damages occur (e.g., loss of data, data leak, etc.), whereas manufacturers of merchandise are on the hook if their product causes damage (e.g., fire)

The EU says this isn't good enough and wants to include software in the PLD. This would only pertain to commercially exploited software (e.g., sold, provided with maintenance contracts, etc.), excluding tiny software developers.

The only relation this has to FOSS is that software developers that use FOSS in their product would need to, you know, make sure they know what they are including in their software (something they should do anyway).

This has zero effect on Joe Schmoe and their GitHub repo, but this lobbyist likes you to think otherwise to help him stop this change in EU regulation.

That's it.

0: https://www.bigtechwiki.com/index.php/Developers_Alliance

Re: Open source liability is coming

#215

Earlier quoted context omitted.

The CRA is not about liability or consumer compensation. The remedies for non-compliance are fines or removal of a product from the EU market. The forthcoming update of the Product Liability Directive, which will probably take a similar approach (exempting open source unless it is placed on the market, so as the article describes, developers of products that are placed on the market are responsible for the security o…

[flagged]

"What few people understand is that it is already the law that developers owe duties to their users that cannot be eliminated through communist licensing."

What law exactly?

Re: Open source liability is coming

#216

Earlier quoted context omitted.

For the same reason literally every other industry does. You are forgetting that software is unique in not having these regulations. It’s not hard to figure out what life was like before these laws, and we don’t want history repeating itself on a platform that moves at light speed.

Software is also unusual in being invented from scratch in living memory. Nobody knows how to do this flawlessly yet, and the few serious attempts (e.g., seL4) have taken stunning levels of time and effort. In 1350, people were dying of the plague, and doctors didn’t know how to treat them. That sucks, but medicine wouldn’t exist if they couldn’t have kept trying and failing. That’s where we are.

Yes and in 1900-2000 pills and vaccines where killing people because the manufacturer either didn't follow any quality standards or didn't test it on pregnant women but still sold it to them.

That was the time the fda got far more rights to sanction and sue medical manufactures and I think we are in a better world for that.

The new law explicitly says what liability it wants to add:

* death or personal injury, including medically recognised psychological harm;

Whether software (including apps) was covered under the existing PLD has always been controversial.i For instance, there is controversy as to whether software should qualify as a product in the sense of the directive, ii or whether it is part of either the services or of the intangible goods category, iii which falls outside the scope of the existing PLD. iv

i) D. Wuyts, The product liability directive – more than two decades of defective products in Europe, 2014, and BEUC position paper on the Review of Product Liability Rules, 2017.

ii) See Article 2 of the existing PLD. A product has to be distinguished from a service and must be understood as 'all movables even if incorporated into another movable or into an immovable'.

iii) See pages 53-54 of the Commission staff working document on the approximation of the laws, regulations and administrative provisions of the Member States concerning liability for defective products, 2018: 'The definition of "product" as per article 2 of the Directive is related to the concept of "movable". This has been interpreted as meaning that only tangible goods shall be considered products [...] the non-tangible nature of some new technological developments (software, applications, Internet of Things, Artificial Intelligence systems) makes it difficult to classify them as products rather than services'.

iv) K. Alheit, The applicability of the EU Product Liability Directive to software, 2001. EPRS | European Parliamentary Research Service 6

* property damage, while removing the threshold of €500 and the possibility for Member States to impose a financial ceiling of €70 million; and

* loss or corruption of data that is not used exclusively for professional purposes

You don't even have to do it flawless, you still have the same defences available as in other product liabilities:

* the defect did not exist when they placed the product on the market;

* or the state of technical knowledge at the time of placing the product on the market made it impossible to discover the defect (i.e., the 'development risk defence').

We all buy medical devices and the companies are fully liable for them and they contain software, so it is quite possible to build software without getting sued.

see:

https://www.europarl.europa.eu/RegData/etudes/BRIE/2023/7393...

edit: formatting

Re: Open source liability is coming

#217

Earlier quoted context omitted.

Yea, the “pragmatic” EU approach to legislation: write it in draconian language and let it carry incredible sanctions (like millions of euros), but then just don’t enforce it. Unless you anger some bureaucrat of course.

They enforce it, just not against small companies as that is not the intent of these laws. You know, unlike pragmatic US legislation where you can fuck over anyone anytime over nothing valid.

If that’s not the intent of these laws then it should say so in the law. That’s what rule of law is all about.

Re: Open source liability is coming

#218
post #186

Earlier quoted context omitted.

Doesn't seem to be working too bad so far.

I must be living in another world then. GDP of EU is stagnant since 2008 whereas US and Chinese GDP exploded during that time. Ultimately whoever has the most money is going to win so let's not try to redefine economical indicators and say that GDP is no longer relevant etc.

Japan's GDP has been stagnant since 1995.

Re: Open source liability is coming

#219

Earlier quoted context omitted.

They enforce it, just not against small companies as that is not the intent of these laws. You know, unlike pragmatic US legislation where you can fuck over anyone anytime over nothing valid.

If that’s not the intent of these laws then it should say so in the law . That’s what rule of law is all about.

Not really: it formulates what is illegal etc but then, when there is an infringement, a judge should still interpret the intent vs the letter. Countries that rule too heavy towards the letter suck for ‘the little guy’ as, invariably, it gets abused to get people in trouble. But you cannot formulate a law like that as then the little guy that actually is abusing cannot be caught out. Again, law sucks everywhere, but, in my opinion, it’s vastly worse in countries that are ‘tough on crime’ as they use more so the letter of the law and so screwing poor people over nothing.

Re: Open source liability is coming

#220
post #84

Earlier quoted context omitted.

> Maybe, I don't know, quality of life...? I’m very happy with my public healthcare. I think every American would be as well. And not to mention that our kids don’t need to do active shooter drills in school.

Public healthcare? You mean the free healthcare for 1000EUR that single German freelancers have to pay monthly? For $1k you can get a US insurance for the whole family!

It’s tax funded, so you have a point. Still, it covers everyone so you never see anyone doing gofundmes just to stay alive.
Post reply on HN