5 ms·
The Administration will work with Congress and the private sector to develop legislation establishing liability for software products and services. Any such leg
by caseysoftware 3y ago
The Administration will work with Congress and the private sector to develop legislation establishing liability for software products and services. Any such legislation should prevent manufacturers and software publishers with market power from fully disclaiming liability by contract, and establish higher standards of care for software in specific high-risk scenarios.
It's interesting that they use both the phrases "manufacturers" and "software publishers".
Obviously Microsoft, Oracle, etc are both manufacturers and software publishers but what about that random open source project? At minimum, they're "software publishers".
The "with market power" clause might seem like a protection but it's trivially easy to see many major open source packages with huge market share as having "market power". In that case, it's less about revenue and more about adoption and interop.
Frankly, this is the nightmare scenario that I thought Microsoft, et al would use to kill Open Source ~20 years ago. If the Feds demand liability, that kills OSS both from a “no company” standpoint and from a licensing “as is” standpoint.
Even if they don't outright BAN it, they could just make it painful to get approved, which is nearly the same result but lets everyone keep their hands clean.
- loup-vaillant 3y agoAn easy cut-off point to avoid axing Free Software is to limit to commercial activity: you want to sell software for money? You are liable. Your software depends on some library? Then you’re liable for this library too… unless you can have someone else accept liability, and trace that in the SBOM. Concrete example: I wrote a cryptographic library, which I give away for free. No guarantee, no liability, if I make a mistake the only thing you can take away is my reputation. But what if you want to use my library, and don’t want to be liable for it? There are two alternatives: you can approach me and pay me for me to accept liability… or you can approach a reputable audit company, and have them accept liability for a given version. Legislate like that, and I’ll still be able to contribute potentially critical code for free.
- c0pium 3y agoContributing critical code for free is a non-goal, and having critical software that the creator has no liability for is an antipattern. You’re crowding out safer software with a free option and everyone is worse off for it.
- loup-vaillant 3y agoYeah, yeah I have heard this time and again. Do you know what critical code you’re talking about? I’m not hard to search: https://duckduckgo.com/?q=loup-vaillant+cryptographic+library https://duckduckgo.com/?q=loup-vaillant+cryptographic+librar... And yes it is a risk. And yes I had one critical bug in 6 years, the horror. I did it anyway because it was pushing the Pareto envelope (speed/size mostly). And of course I knew what I was getting into, which is why it is not a weekend project, but a professional grade library. More explanations on my choices here: https://monocypher.org/why/ https://monocypher.org/why/ And by the way, Monocypher is currently being used to operate the TKey from Tillitis. https://tillitis.se/products/tkey/ https://tillitis.se/products/tkey/ Good luck porting libsodium there. --- You do have a point however: actively distributed critical software with no one being liable is an anti-pattern. Though strictly speaking, my code is only critical when it starts being used, so… we’re going back to the place of amateur work: if you want to use my code, you can pay me to get a license that does not waive my liability, or you can pay someone else to audit my library, or you can be liable yourself. And if I sell my code, I should indeed be automatically liable. The point with my example is that with proper legislation, even cryptographic libraries can continue being open source.
- c0pium 3y agoI don’t see how what code it is matters, the principle doesn’t change based on the people involved. The people who wrote OpenSSL thought they knew what they were doing. As did the people who approved Dual_EC_DRBG. “Professional grade library” is an interesting choice of words in a thread about how we need to have liability for software, especially for software that is today in use exclusively licensed under no-liability licensing. If anything, all of the words on your site make it worse. A reasonable person, upon reading those fancy words, would be lead to the conclusion that this is Serious Software and thus safe to use. Are you liable under the license they’re using? Their site has a lot of “trust me bro” security words on it, which is a great illustration of my point. You wrote it, you chose of your own free will to make it available, you’re responsible if it gets people hurt.
- 3y ago