4 ms·
Software doesn’t come to be through immaculate conception: the authors created it, knowing it could be used in this way. If a company releases software that is
by phphphphp 4y ago
Software doesn’t come to be through immaculate conception: the authors created it, knowing it could be used in this way.
If a company releases software that is used nefariously, there are very common legal actions to hold them accountable. For example, Facebook has extensive legal obligations to meet to do with behaviour on their platform.
I am not arguing that tornado cash should be illegal (or that encryption should be illegal) rather I am arguing that people are responsible for the software they have created.
If I commit a crime, my intent is absolutely a part of the equation when determining legal action. Why should it be any different with software?
If you wish to argue that the right to privacy is so great that it exceeds any risk of criminal activity, and thus the developers of tornado cash were doing something for the greater good, so be it (that’s probably the position I would take) but it doesn’t absolve them of responsibility.
Taken to the extreme, if I build a piece of software that can save the lives of murder victims by killing the murderer: I am responsible for the killing of (intended) murderers. We might decide that the activity is justified, that the software is operating for the greater good and is therefore permissible, but that doesn’t change my responsibility.
- ziddoap 4y ago>I am arguing that people are responsible for the software they have created. So, is your answer to the asked question yes, the developers of Metasploit should be arrested and jailed? How about the developers of Bitlocker? It's used to encrypt illegal content, impeding police discovery efforts. Every person who developed a file-sharing website should probably also be arrested. Lots of illegal/pirated/etc. content out there. The point being that almost every software on the planet can potentially used for malicious and illegal activities. Seems like if we indefinitely held developers responsible for what other people do with their software, the smart person would never develop any software.
- phphphphp 4y agoLaw isn’t a binary based on responsibility, it’s reductive to suggest that by arguing for responsibility we are also arguing for prison for software developers. I can be responsible for your death and spend no time in prison. Every other industry deals with this challenge — why should software be any different?
- ziddoap 4y agoYou can take the word "jailed" out of my comment, replace it with "responsible for", and I still think my point stands... You said: >If a company releases software that is used nefariously, there are very common legal actions to hold them accountable If you believe that, it follows that you believe that every developer of encryption algorithms should be "held accountable" (be it jail, or "responsible without prison", etc.) because other people use encryption to hide illegal activity. Developers of internet protocols should be accountable for the actions other people take on the internet, because lots of illegal things happen on the internet. Metasploit, Kali, 7-zip, FileZilla, Word/Excel, Putty, OpenVPN... Should I go on? All of these are used for nefarious things all the time. Are you really suggesting that the developers of these should be responsible for the nefarious things that their users do? If not jail, what responsibility are you suggesting? >Every other industry deals with this challenge — why should software be any different? Most other industries have protections against this type of liability, not responsibilities. See knives, guns, planes, cars, etc. Unless their is gross negligence, which isn't just "it was used nefariously", the maker of X is generally not responsible for what some user of X does with X. Edit for clarification: You can argue about purpose-built nefarious software, sure. If I develop ransomware, and advertise it as ransomware, and there's no legitimate use other than ransoming... I should probably be held responsible for the ransomware attacks that occur using that tool (at least, I accept that argument). The problem with applying this to all software is that most everything that is used nefariously was originally designed for and used for legitimate uses. When that's the case, the person who committed the crime with the legitimate tool should be held responsible, not the maker of the legitimate tool.
- phphphphp 4y agoMost industry protections against liabilities are predicated on compliance with expectations about responsibility: the protection against liability is earned. For example, firearm manufacturers are protected from being held liable for actions taken with their firearms as long as they comply with their legal responsibilities, like not selling firearms to children. If a firearms manufacturer sold firearms to children, they would absolutely be held liable for the outcomes. If you knowingly build software that can be used for money laundering and make no effort to prevent money laundering then, if software was treated like other industries, you’d absolutely expect to be held liable.