5 ms·
This seems like a good thing? Making software makers have liability for a shifty product should have happened a long time ago.
by enkid 3y ago
This seems like a good thing? Making software makers have liability for a shifty product should have happened a long time ago.
- AnimalMuppet 3y agoAs with many good things, it comes at a price. Windows, back in the day, was both buggy and full of security holes. It was also $99, and enabled an inexpensive computer to do near-workstation feats. If it cost, say, three times as much, that would have changed the market dynamic quite a bit. Fewer of us would have been able to afford computers with Windows, and few of us wanted bare-metal computers. Well, you say, that's just fine, we could have put Linux on it, and the world would have been a better place. Well, could you have put Linux on it? Can Linux survive in this regulatory environment? Can it survive as open as it is, as modifiable as it is, as free as it is? What about the rest of free software, that doesn't necessarily have a large company behind it? The second-order effects of this could completely change the software landscape. We may not like the results.
- phoehne 3y agoYou'll have a blessed version of Linux from IBM/RedHat that specifically meets USC x.y.z requirements for use in a, b, and c industries. You'll have a supported version of Postgres, etc. etc. They'll be a version or two behind and everything else we might have to add riders on the licenses like 'not for use in the following industries' or 'for demonstration and education purposes only.' Given that everything's getting either a WiFi or bluetooth chip in it, could we see coffee makers that are not approved for use in a commercial, health-care, industrial, or business setting?
- red-iron-pine 3y agoI mean Redhat is already FIPS compliant, and there are things like CMMC.
- pipo234 3y agoAll for curation of components, as part of developing reliable, secure, resilient software. I just don't think you gain a lot of reliability, security or resilience by mandating a concrete&steel OS foundation. For sure, a shoddy, insecure, duck-tape application on some homebrew Linux can be ported RedHat just fine. There is nothing preventing insecure use of "Military Grade" AES256 encryption. You just can't certify your way to resilient software.
- phoehne 3y agoNo, but this will largely target producers of software. So they'll have to show they've done their due diligence by probably producing documentation about procedures they followed, designs, conformance to the designs, procedures for on-boarding dependencies, etc. etc. That's no their real shield, however. That's the insurance policy they buy from Lloyd's, who will require that they check all the boxes. They way I won't get sued, as a developer, will probably be to work for a big company that can afford all that or add clauses to my license stating it's either 'for demonstration purposes only' or 'no licensed for use under ...'. Kind of how a lot of financial information is doled out with the disclaimer it's [sic] only for entertainment purposes.
- c0pium 3y agoYou’re ignoring the safer futures that were choked off by allowing developers to totally ignore safety and security. People are smart, they would have figured out really solid mechanisms that gave you great software that’s actually safe. Look at any of the fields that deserve to use the word engineering for examples.
- molticrystal 3y agoWhat is market power & what is high risk? Could high risk be the ability to monitor heart rate, or control motors? Could it be example code for those abilities that make them liable? If RaspberryPi or Alphabet releases an educational board for experimenters but has features that could be used in a way that is considered high risk and if they are considered market powers, should they keep it from interested people because they can't fully disclaim liability? How much should they reduce their feature set so that it doesn't tangentially run into this law. Can they just disable that part of the code, or would they run into the same problem as the GTA Hot Coffee case if it isn't gutted enough. While it has good intentions, it will likely backfire some way as the lists of prohibited things grow or the market power clauses are reinterpreted to be applied to a wider range and smaller targets.
- enkid 3y agoThe law is full of gray areas. If we couldn't have any laws that weren't ambiguous, we just wouldn't have laws.
- caseysoftware 3y agoThe Administration will work with Congress and the private sector to develop legislation establishing liability for software products and services. Any such legislation should prevent manufacturers and software publishers with market power from fully disclaiming liability by contract, and establish higher standards of care for software in specific high-risk scenarios. It's interesting that they use both the phrases "manufacturers" and "software publishers". Obviously Microsoft, Oracle, etc are both manufacturers and software publishers but what about that random open source project? At minimum, they're "software publishers". The "with market power" clause might seem like a protection but it's trivially easy to see many major open source packages with huge market share as having "market power". In that case, it's less about revenue and more about adoption and interop. Frankly, this is the nightmare scenario that I thought Microsoft, et al would use to kill Open Source ~20 years ago. If the Feds demand liability, that kills OSS both from a “no company” standpoint and from a licensing “as is” standpoint. Even if they don't outright BAN it, they could just make it painful to get approved, which is nearly the same result but lets everyone keep their hands clean.
- loup-vaillant 3y agoAn easy cut-off point to avoid axing Free Software is to limit to commercial activity: you want to sell software for money? You are liable. Your software depends on some library? Then you’re liable for this library too… unless you can have someone else accept liability, and trace that in the SBOM. Concrete example: I wrote a cryptographic library, which I give away for free. No guarantee, no liability, if I make a mistake the only thing you can take away is my reputation. But what if you want to use my library, and don’t want to be liable for it? There are two alternatives: you can approach me and pay me for me to accept liability… or you can approach a reputable audit company, and have them accept liability for a given version. Legislate like that, and I’ll still be able to contribute potentially critical code for free.
- c0pium 3y agoContributing critical code for free is a non-goal, and having critical software that the creator has no liability for is an antipattern. You’re crowding out safer software with a free option and everyone is worse off for it.
- fallingknife 3y ago> work with Congress and the private sector The "private sector" here will be FAANG and other huge tech cos. They will argue for massive liability. Congress will agree because it makes them look tough and decisive. They know that only they can afford such liability. Smaller companies will be crushed by the liability insurance they need to cover these requirements.