9 ms·
The author's stance is that because it was a volunteer effort, he bears no responsibility for transferring ownership to an unknown third party who wants to comm
by nmg 8y ago
The author's stance is that because it was a volunteer effort, he bears no responsibility for transferring ownership to an unknown third party who wants to commandeer the code used by millions of people. I believe this is false.
He also feels that there's nothing anyone can do about it except scramble to control the damage. I believe this is currently true.
- raesene9 8y agoYou may not like it but from a license standpoint, I think you may be incorrect As quoted elsewhere in this thread " THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE."
- M2Ys4U 8y agoThere's a difference between legal liability and moral liability.
- JumpCrisscross 8y ago> There's a difference between legal liability and moral liability Making business decisions on the hope that someone else's moral codes will perfectly align with your own is unscalable. That's why we have written laws, codes and contracts.
- ddingus 8y agoWhen that happens, pay people. Seriously. Having a moral discussion in tandem with scale seems very poorly misaligned with the interests, needs, risks of pretty much everyone involved.
- raesene9 8y agoyep, and that's why I said "from a license standpoint". Software licenses aren't moral constructs, they are legal constructs.
- perfunctory 8y agoI don't even see any moral issues here. Is there any reason to believe the original author acted in bad faith? If you sell your used car and it gets used to rob a bank, did you act immorally?
- michaelmrose 8y agoIf you run a business where you have convinced people to give you access to their house to do some chore and you sell your business and your copy of their keys to a criminal it could be morally problematic. A car is merely a fungible vehicle the customer would have been no better or worse off had the robber been driving a different car. This would be an apt analogy for just giving / selling a code base. Had it been distributed under a new account/name users could have decided to trust or not trust a new maintainer. The dev allowed new people to trade under his name and rep worse allowed new people to delegate further to unknown others. He is morally liable and ought to have known better.
- perennate 8y agoHe was doing this for free and releasing it under an open source license. In your analogy the business would be performing the chores for free and telling the users that the business is not responsible for any damage related to the access granted by the key. I don't think most people would sign up for that without a business relationship.
- perfunctory 8y ago> sell your business and your copy of their keys to a criminal This implies the seller _knows_ the one they are handing over the keys to is indeed a criminal. In that case it is certainly morally problematic. I see your point but I still think calling the maintainer's behaviour immoral is going a bit too far. Perhaps careless. Or maybe naive. But not more than that.
- perfunctory 8y ago> Had it been distributed under a new account/name users could have decided to trust or not trust a new maintainer. This is the myth we keep telling each other but I don't seriously believe this is how open source works in reality.
- kmonsen 8y agoI hope everyone talking about motel responsibility are donating to all the open source projects they depend on. If not I find the moral preaching a bit one sided.
- preommr 8y agoYou and I both know they aren't. It astounds me how many popular OSS projects are terribly funded despite how many people use them.
- jwhitlark 8y agoThere's a moral liability to do your due diligence when using upstream software, too. Otherwise it's just whining about "the untrustworthy system I built upon is untrustworthy".
- michaelmrose 8y agoPutting it on paper does not make it so. A single lawsuit and you could easily be out thousands even if you win. The legal outcome could vary widely state to state and nation to nation. If putting a blurb in a text file makes you feel safe about being sued for negligence you haven't considered all possible venues. Here is an article about liability waivers https://www.enjuris.com/blog/questions/liability-waivers/ https://www.enjuris.com/blog/questions/liability-waivers/
- raesene9 8y agoSo you reckon that people who publish open source software should be liable for flaws/vulnerabilities in their code? It's a bold assertion, I'd be interested to see if you can provide any case law where it's been tested.
- merb 8y agoit depends. laziness can actually be used against you. even in european countries.
- raesene9 8y agoBut on this topic specifically, I've never heard of Open source software authors being held liable in any fashion for software they've released in any country. I'd be interested to hear if such precedent existed.
- dragonwriter 8y agoEnd-users are harmed and are not licensees, and so, even if the license disclaimers are effective (boilerplate disclaimers are often broader than the law of some jurisdictions will give effect to) the claims they would have for negligence would not be covered (and would not be transferred to downstream maintainers, who likely have concurrent liability, absent a indemnity clause as well as a disclaimer in the license.) So, while I don't think the upthread claim was about the maintainer having legal responsibility, I don't think it would be entirely wrong, even with the license text, if it did.
- raesene9 8y agoThe people with legal liability to the end-users, I expect, are the developers that made use of this library without properly vetting all changes to it.
- dragonwriter 8y agoLiability is very often not exclusive in law, and, in particular, tends to flow the whole way up supply chains. With nothing being sold you probably aren't dealing with strict product liability upstream, but exposure of end users is reasonably foreseeable so there's no immediately obvious blanket reason for ruling out upstream negligence liability to end users. The idea that the party most proximate to end users is exposed to potential liability is true, but the idea that this must mean noone else in the chain is exposed is not.
- raesene9 8y agoYou honestly think that the author of software released as open source is going to be liable for vulnerabilities in that software ... really? If that were the case, you'd pretty much wipe out the software industry as it stands today :) I'd be very interested in case law where you can see the users of a service (which might not even disclose what software they use) are able to sue the author of a package used as part of that service.
- 8y ago
- dmitriid 8y agoThis license is invalid in quite a few jurisdictions around the world.
- deleted 8y ago[deleted]
- benologist 8y agoThe other person set out to subvert node modules, the author was just a target interchangeable with 100,000s of other module maintainers. There are already documented cases of very popular node modules having their passwords compromised so this is probably a form of attack we will see grow significantly more prevalent since these modules can see database credentials, encryption keys etc. This is also very similar to bad entities obtaining or acquiring browser extensions to discretely poison with spyware and advertising, which happened a lot of times.
- eropple 8y ago> I believe this is false. It's literally not, though. That's what the license says. It expressly disclaims any such thing. If you want somebody to incur responsibility, you have to get them to take it on. You can't just demand it of them. Fortunately, there is a good way to do exactly this. Did you bring your wallet?
- eli 8y agoIf I thought I might be on the hook for damages caused by a mistake in how I run an open source project, I would never open source anything.
- jwhitlark 8y agoYeah, no kidding. That's why the idea of commercial support exists. You need to depend on it? Pay for it.
- PurpleBoxDragon 8y agoWhat was he compensated with in exchange for taking on responsibility? Without compensation the contract by which he takes on responsibility is not valid.