Live data from Hacker News

Open source liability is coming

developersalliance.org

221–230 of 239 posts

Re: Open source liability is coming

#221
post #104

Earlier quoted context omitted.

I think I must be misunderstanding. The article makes it seem like the user of open source code is responsible for making sure it is suitable and they are liable for when it fails. Doesn't that mean that someone who merely releases code onto GitHub will, in fact, not be liable, since it is the user of said code that is liable? As far as > when faced with a choice between being liable for their own code or being liabl…

There are two issues here. The first is when there's some product that's being sold. It could be directly, like selling someone software, or indirectly, like selling them a device that includes software. In that case, whoever sold the thing is responsible for all of the software. I think that's more-or-less fine. There's a concern that companies don't want to be responsible for open source code, and will write everyt…

> the worst case scenario is that it turns out to be bad for developers and for free software.

Which would in turn be very bad for society.

Re: Open source liability is coming

#222
post #14

I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so har…

You failed to read and understand the article. Not only commercial vendors but also authors of open source software aimed at consumers , could be held liable. The courts would decide.

> "whether “open source” is exempt from liability in a law designed to protect consumers. So far the answer is “probably not?” Exemption means consumers bear the cost – exactly what the law is trying to change. Perhaps if the open source in question remains an academic or research tool, versus reaching consumers, we’re okay? The proof may come when the first consumer demands compensation, and the courts step in.

Re: Open source liability is coming

#223

This is great. Software is important, software has an impact, and so we need liability. This regulation ensures that whoever sells the software to the consumer is responsible, and that's the way it should be. The creator of a library doesn't know how his library will be used in the wild, he can't anticipate all possible problems, the product maker can. It is the product maker's responsibility to integrate external co…

No, it is bad because it could also apply to open source software aimed at consumers, not only commercial vendors integrating OSS.

> whether “open source” is exempt from liability in a law designed to protect consumers. So far the answer is “probably not?” Exemption means consumers bear the cost – exactly what the law is trying to change. Perhaps if the open source in question remains an academic or research tool, versus reaching consumers, we’re okay? The proof may come when the first consumer demands compensation, and the courts step in.

Re: Open source liability is coming

#224

Earlier quoted context omitted.

I agree it's very ambiguous, but if you read the whole thing it's clear that when dev A releases code under an open source license and it's included in a commercial product by company B that then harms person C, the liability will be on company B. Most of the hot-under-the-collar responses here are assuming it will fall on dev A, which is a misinterpretation the article's author did not do much to discourage.

That completely ignores the second half of the article. I agree that it's confusing why the article goes into so much depth on "companies are now liable, similar to how everyone expects" in the first half when the main talking point is/should be "open source devs are now liable if consumers use their software directly" (as discussed in the second half).

Most commenters here only read the first half it seems, I expected more of the hn audience.

Re: Open source liability is coming

#226

Earlier quoted context omitted.

Public healthcare? You mean the free healthcare for 1000EUR that single German freelancers have to pay monthly? For $1k you can get a US insurance for the whole family!

It’s tax funded, so you have a point. Still, it covers everyone so you never see anyone doing gofundmes just to stay alive.

Well, maybe try not to pay your health insurance as a freelancer and the insurance company promptly disowns you and you are at the same spot as uninsured US folks immediately. In Germany. Just because fees are hidden from you doesn't mean they aren't there and a failure to pay them results in similar consequences to US.

Re: Open source liability is coming

#227
post #221

Earlier quoted context omitted.

There are two issues here. The first is when there's some product that's being sold. It could be directly, like selling someone software, or indirectly, like selling them a device that includes software. In that case, whoever sold the thing is responsible for all of the software. I think that's more-or-less fine. There's a concern that companies don't want to be responsible for open source code, and will write everyt…

> the worst case scenario is that it turns out to be bad for developers and for free software. Which would in turn be very bad for society.

To be clear I agree with this, I didn't intend to downplay the impact of that consequence. I think the continued existence of free software is both a practical and moral necessity.

What I was trying to communicate here is that I think meaningful negative impact to free software and to developers is a worst-case scenario and not the most likely scenario. It's plausible, and we should be concerned, but I think there's also a plausible outcome that is neutral or positive for free software if companies end up contributing more to free software as a way of ensuring they are meeting their obligations under the law.

Re: Open source liability is coming

#228

Earlier quoted context omitted.

It’s tax funded, so you have a point. Still, it covers everyone so you never see anyone doing gofundmes just to stay alive.

Well, maybe try not to pay your health insurance as a freelancer and the insurance company promptly disowns you and you are at the same spot as uninsured US folks immediately. In Germany. Just because fees are hidden from you doesn't mean they aren't there and a failure to pay them results in similar consequences to US.

I wouldn't know, but I live in Ireland anyway, and while we have a two-tier system, we pay insurance only for the better hotel services in hospitals - things such as single-patient apartments.

Re: Open source liability is coming

#229
post #221

Earlier quoted context omitted.

> the worst case scenario is that it turns out to be bad for developers and for free software. Which would in turn be very bad for society.

To be clear I agree with this, I didn't intend to downplay the impact of that consequence. I think the continued existence of free software is both a practical and moral necessity. What I was trying to communicate here is that I think meaningful negative impact to free software and to developers is a worst-case scenario and not the most likely scenario. It's plausible, and we should be concerned, but I think there's…

Thanks for the clarification :)

Re: Open source liability is coming

#230

This is great. Software is important, software has an impact, and so we need liability. This regulation ensures that whoever sells the software to the consumer is responsible, and that's the way it should be. The creator of a library doesn't know how his library will be used in the wild, he can't anticipate all possible problems, the product maker can. It is the product maker's responsibility to integrate external co…

No, it is bad because it could also apply to open source software aimed at consumers, not only commercial vendors integrating OSS. > whether “open source” is exempt from liability in a law designed to protect consumers. So far the answer is “probably not?” Exemption means consumers bear the cost – exactly what the law is trying to change. Perhaps if the open source in question remains an academic or research tool, ve…

The directive has not finished the legislative process yet so it's difficult to be exact but according to the briefing on the New Product Liability Directive redacted by the European Parliamentary Research Service

> In the aim of not hampering innovation: (i) free and open-source software developed or supplied outside the course of commercial activity, as well as (ii) the source code of software, should be excluded from the definition of products covered under the proposal.

https://www.europarl.europa.eu/RegData/etudes/BRIE/2023/7393...

Post reply on HN