6 ms·
This is a quote from the linked document: > 10) In order not to hamper innovation or research, free and open-source software developed or supplied outside the
by knlje 3y ago
This is a quote from the linked document:
> 10) In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.
- tgvaughan 3y agoHow does this work for free software projects which aren't themselves commercial but list employees of big companies among their major contributors? E.g. the Linux kernel?
- layer8 3y agoIt will likely be tied to the “productization”. That is, the liability chain will only go as far as there is someone who turned the software into a product for monetization purposes. If a company sells a product that uses Linux, they will be liable regardless of whether they contributed to Linux development or not. If part of the product was itself purchased from a third party, the third party will be liable for that part. But open-source developers who don’t monetize the software won’t be liable. One case that could potentially become problematic is OSS developers who have Patreon subscribers or similar, where those subscribers could conceivably pass on liability claims.
- deleted 3y ago[deleted]
- paol 3y agoThat's from the "Cyber Resilience Act" link, and the "Product Liability Act" link has pretty much the same text in item 13.
- luckylion 3y agoI'm not a lawyer, but I see no way a sane and reasonable person could read this as "and if someone you've supplied the software in a foss & non-commercial setting to uses that software in a commercial way, you're on the hook for everything". Yeah, it could be even clearer (but laws tend to not want to enumerate everything that is obvious or they'd become books), but it feels somewhat exaggerated. Or is the actual fear that commercial support services by the authors could trigger liability? As far as I understand, that has been a preferred way to get paid and remain not-liable for the original product.
- ncphil 3y agoI _was_ a lawyer for a decade before going into tech. One of the good habits I acquired in practice was making sure to read all the way through every document, no matter how boring it got. I agree with you completely, except the article isn't just exaggerated: it's borderline FUD. Regulation is necessary because too many humans find self-regulation in the public interest too hard. The problem is that writing effective, targeted, regulations is also hard, and often beyond the capacity of those given the power to do it. Even when they mean well (never a given, as evidenced by a sordid history of self-sealing and favoritism), it often gets mucked up.
- A4ET8a8uTh0 3y agoThank you. Do you think blogger missed it, focused on the 'should' part or it is part of clickbaity nature of our news cycle? Either seems as a likely possibility. I don't think EU would be stupid enough to kill open source.
- occamrazor 3y agoIt’s more than clickbait. The intent of the proposed legislation in not to make volunteer open-source contributors liable for bugs, but the current draft may set the boundary between commercial and non-commercial developers in the wrong place.
- mananaysiempre 3y agoThe Internet Society quotes[1] that part and thinks selling support for stuff would count it as being supplied in “the course of commercial activity” even to those who aren’t buying the support. [1] https://www.internetsociety.org/blog/2022/10/the-eus-proposed-cyber-resilience-act-will-damage-the-open-source-ecosystem/ https://www.internetsociety.org/blog/2022/10/the-eus-propose..., via another comment here: https://news.ycombinator.com/item?id=35525876 https://news.ycombinator.com/item?id=35525876 [A previous version of this comment mentioned BIND, because I confused ISOC and ISC.]
- ginko 3y agoIf someone sold me support for a piece of open source software (like ISC and BIND) then I definitely would expect some level of liability if there's something wrong with it. Otherwise why would I pay for support if I could just self-host? They can strictly define the parts they are willing to support, though.
- luckylion 3y agoI believe the point they're making is that while you could expect liability, I couldn't if I'm not buying support services but run it myself. As in "offering the support services to anyone" would assume global liability.
- parasense 3y ago> If someone sold me support for a piece of open source software (like ISC and BIND) then I definitely would expect some level of ... The word you were looking for is "support". If there is something wrong with the "supported" open-source software, then you may expect a certain level of "support". Full-stop. That generally entails an SLA that says your issue will be reacted to within N-time of opening the issue, which might be nuanced by the tier-level of support purchased. That you are provided access to documentation, or even the source code itself. You might be provided with best-effort support by an agent, which is limited to resolving documented defects, or configuration, or acknowledging standing-bugs which cannot be resolved. What you cannot expect is the software is updated in accordance with the support incident. For that, send patches, or pay somebody to send patches.
- lars_francke 3y agoThis section has been rewritten (changed) in the latest (internal) draft of the CRA based on feedback of various open source foundations as far as I know. I'm not sure how much I'm allowed to share but it'll be public at some point in April I believe.
- mordae 3y agoHaving it in the recital is way less safe than it being explicitly spelled out in an Article.
- octacat 3y agothat is sooo bad. Basically anyone can give you support with some open source code (i.e. consultancy, they fix a bug/deploy/tweak for you and go away) except the authors of the code. Because if the authors do this, they are liable for the whole code base of the product. Nice. Also, many open source projects have very complex authorship, good luck digging which company is responsable to do the audit. Also, basically your favourite cloud provider could host your favourite open source database, but the authors providing hosting would be liable. Because "This Regulation does not regulate services, such as Software-as-a-Service (SaaS)"