20 ms·
Open source liability is coming
- newstripeacc 3y ago[flagged]
- theLiminator 3y agoThis is ridiculous, all blame/liability should lie with either the provider of commercial software who chooses to rely on open source software or the end user for relying on free/open source software. I personally will not allow people in the EU to use any software I write going forward, I imagine other open source developers will take these steps as well.
- withinboredom 3y agoThis seems a bit extreme, it isn't even a law yet (or anywhere close). That being said, if you don't audit your open source libraries, you should be held liable. I've seen open source encryption libraries do some really dumb things that I wouldn't touch with a ten foot pole. Yet they are some of the more popular ones.
- deleted 3y ago[deleted]
- RamblingCTO 3y agoWhy should I be held accountable if you just run some code you found on GitHub? Am I reliable when I sell hammers and you bash your face in? /e: let me clarify, I agree with the three comments under me. You, the commercial entity using my code, is accountable. I am not liable if you as a private person run my shitty code. I was thinking of private persons and being on the hook for my GitHub repos.
- sevagh 3y agoNo no, you should be held accountable if _you_ run some code you found on GitHub in your product that I pay you for.
- withinboredom 3y agoI don't think it's like that.
- CuriousCosmic 3y agoI think you might be misreading it. The person who ships the product commercially is liable. If you sell them your code, you'd be liable but if they just use your open source code, they are liable for any potential issues in their program caused by your code (instead of you being liable). Basically they can't just brush off responsibility for using FOSS code by saying "well I didn't write it, it's not my fault" unless you as the FOSS developer are selling them a support contract for any potential issues in your code.
- anonzzzies 3y agoPeople are just npm installing whatever without even checking the github stars or usage; not that that says anything but not even that. As a bare minimum devs should check if their libraries have robust testing, are maintained by people who have the time to do so etc. A lot of open source libraries are really bad and if you are building commercial (packaged / saas, doesn't matter) software on top of that, you definitely should be held liable if that causes harm. This lazy behaviour should end as it indeed does cause horrible messes. This over the top article is, I guess, pointing to open source software that's used by an individual directly from the source as an enduser and then causes harm, not to parts of commercial software that includes open source software when they talk about holding open source devs liable.
- omnicognate 3y agoPerhaps less pitchfork brandishing, more reading the article? > all blame/liability should lie with ... the provider of commercial software Is precisely what the EU intend to do (according to the article - no idea how accurate it is), not put the liability on open source devs. From the article: > So, how is open-source software implicated? If a commercial software product causes harm, whoever put the software on the market will soon be strictly liable. You will need to prove that your code wasn’t to blame to escape the costs. But what if you’ve embedded open-source code, used open-source tools, or called open-source APIs? Under the pending rules, you’d be liable for any errors in those sources as well, regardless of whether you directly contributed or not. A license like the one Apache provides won’t help, since state-imposed strict liability isn’t a harm that can be licensed away by private actors. The user must be made whole, and that’s on you. Worse still, how will you in turn identify or sue the collaborator or collaboration that actually wrote the faulty open-source code to recoup your costs? In that case, the license you signed likely insulates your open-source partners from your claims.
- theLiminator 3y agoWhat does it mean if you publish your open source android application on the play store (with no ads or monetary compensation, simply just to make it easier for users to use?). Seems to me that you'll be liable for any issues.
- bpfrh 3y agoWhy would you be? Did you sell the user the app? If not I can't see how it would be commercial
- galdor 3y agoIt seems the author is refering to the EU Cybersecurity Act that should be voted early 2024. The last draft clearly excludes open source software as long as there is no commercial activity associated. If voted in this state, it won't affect the vast majority of developers releasing some code under an Open Source license. But it will wipe out all small businesses: if you're a solo company selling support or feature development on some Open Source software you wrote, paperwork and liability are just not worth it. And good luck selling anything relying on existing Open Source libraries, because you're now liable for them too. Given the cost of a security audit, you may as well stop trying and just sell SaaS (which is explicitely excluded from the bill, funny). Larger companies of course won't care and will continue shipping buggy software riddled with security holes because they can afford the paperwork and absorb the legal risk.
- formerly_proven 3y agoHe’s probably talking about the Product Liability Directive reform.
- Kon-Peki 3y ago> as long as there is no commercial activity associated My recollection, from previous discussion on HN, is that the definition of "commercial activity" is far more broad than the open source community would like it to be. And by "open source community", I mean the people that run various foundations and non-profits and things like that. I don't think that throwing up a virtual tip jar on your Github page counts, but offering paid support would. If you collect telemetry and then sell "usage insights" that would also count as commercial activity. Advertising on the download page is commercial activity. If you have a Patreon account? I actually don't know about that. Anyone know?
- galdor 3y agoCorrect. I would be perfectly fine with some amount of control and liability proportional to the size of the company, excluding tiny ones as it is often the case. With this new act, even selling 100€/month of support for a piece of software you are contributing to makes you subject to the full force of the bill (and the full force includes scary numbers, millions, with zero information on how precise amounts will be calculated). We can only hope that it is not voted in this sorry state.
- formerly_proven 3y agotl;dr Noooo I can’t be held liable for the (open source or not) code I commercially ship, how dare you.
- withinboredom 3y agoFINALLY. This industry needs some regulation... I'm mostly curious what that means for something like the MIT license... For those who need a refresher, this is the part I mean. > THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
- paulgb 3y ago> This industry needs some regulation Are there cases of open source projects being careless or negligent that have caused harm that this would address? Aside from some unintentional vulnerabilities that have been found, it’s hard for me to think of an example that would necessitate more regulation.
- withinboredom 3y agoI can think of exactly one rather popular one: left-pad. The author should have been liable for the damage they caused. The industry self-regulated itself but that is a case that I can think of, specifically caused by negligence.
- sevagh 3y agoNpm Inc. is the only party liable for left-pad.
- withinboredom 3y agoNPM wasn't the one who pushed the "delete project" button, knowing full well what would happen.
- d_tr 3y ago
- zaptheimpaler 3y agoHonestly just sounds like a misreading of the law to me. I don't believe it. One part says "If open source resources are in/called/touched your code, you’re responsible for their performance too. The open source resource licensed away their liability to you." This is the norm. The private company holds responsibility for vetting everything they ship. It's a speculation on how the law will be enforced for a law with no history and I don't see why you would assume the worst interpretation
- anonzzzies 3y agoAlso the EU laws are read here, by people who live in countries where that would be the case, with way too much weight. People from the US putting cookie accept banners and gdpr blah on their sites while they don't have to, because they are not violating in the first place (the intent of the gdpr is very simple; don't do things you don't want to have done to you to others; tracking, collecting info you don't need to run the business etc; if you do more, you have to be able to defend that and ask for permission), but in the US they can expect a cease and desist in 2 seconds while in the EU that's not going to happen. They are going after large abusers or abusers that won't listen after a ton of warnings. Which they should.
- bjornsing 3y agoYea, the “pragmatic” EU approach to legislation: write it in draconian language and let it carry incredible sanctions (like millions of euros), but then just don’t enforce it. Unless you anger some bureaucrat of course.
- anonzzzies 3y agoThey enforce it, just not against small companies as that is not the intent of these laws. You know, unlike pragmatic US legislation where you can fuck over anyone anytime over nothing valid.
- bjornsing 3y ago
- deleted 3y ago[deleted]
- pylua 3y agoGitHubs next feature: litigation tracker.
- sevagh 3y agoI find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs. Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so harm to our customers is not our fault!"
- omnicognate 3y agoThe article is misleading unless you read the whole thing and the reactions are standard knee-jerk ones from HN users that didn't need to read past "EU" to assume the worst possible misinterpretation.
- withinboredom 3y agoI read the article, but it was quite ambiguous, at least to me. It isn't very well written / clear on what is actually going on.
- omnicognate 3y agoI agree it's very ambiguous, but if you read the whole thing it's clear that when dev A releases code under an open source license and it's included in a commercial product by company B that then harms person C, the liability will be on company B. Most of the hot-under-the-collar responses here are assuming it will fall on dev A, which is a misinterpretation the article's author did not do much to discourage.
- sevagh 3y agoActually, I may have missed buried lede in this case where there is no company B, and citizen C is harmed by dev A's github project. That is actually kinda concerning, if my MIT license of "no guarantee" won't protect me. Other commenters who got it: https://news.ycombinator.com/item?id=38808821 https://news.ycombinator.com/item?id=38808821 https://news.ycombinator.com/item?id=38808756 https://news.ycombinator.com/item?id=38808756
- kstrauser 3y agoThis is BS. I've talked employers into releasing all sorts of useful things under FOSS licenses over the years. The conversation has always been like "we have this handy thing, and it's not related to our core business at all, and there's no way it'd be a marketable product, but other people could probably use it, too." And the release process has always been like "here's a thing we made to solve a problem we had, and it works for us, and maybe other people could also use it." In every case, we used those projects in production in our own shop. The tools worked for us. If they didn't, we kept tweaking until they did. They may not have been perfect in all possible scenarios, but they were useful for us. And if my employers faced any liability problems whatsoever, they'd never have given me permission to release them. Imagine suing Linus because Linux turns out to be vulnerable to an attack that hasn't been invented yet. The OpenBSD gang for finding and fixing a bug, even though it wasn't known to be exploitable, because it could have been. My boss because a little tool I wrote turned out to have a problem in an environment and use case we'd never imagined anyone using it in. This is bullshit. Update: A lot of readers have been quick to point out that the BS laws don't apply to all situations. That doesn't help the situation. "Hey, boss, can I give this tool I made away? If an ambulance chaser sues us for idiotic reasons, we'll probably be fine because the law doesn't cover how we're releasing it. Hey, come back here! Stop running!" I present as evidence jackasses like this: https://www.abc15.com/news/local-news/investigations/disbarred-attorney-continues-to-file-ada-lawsuits https://www.abc15.com/news/local-news/investigations/disbarr... Yeah, I'm sure my employer would eventually win a frivolous lawsuit, but the mere possibility of that being an issue would be catastrophic to FOSS as we know it.
- omnicognate 3y agoThis adds no new liability for the employers you persuaded to release that code open source, only for others that choose to include it in their commercial products. Please attempt to understand things before calling them "bullshit".
- kstrauser 3y agoThat strikes me as an unrealistically naive interpretation of what could possibly go wrong. When there's blood in the water, sharks may not be choosy in whom they bite. I understand this. My reading and understanding of the issue leads me to believe that it's potentially disastrous.
- monooso 3y agoThere seems to be some confusion in the comments regarding what this means for people releasing open source software. The article makes it clear that (as the author understands it, at least) someone who uses open source software in their commercial product is liable; the people who wrote the open source code [1] are not. > If a user is harmed by software, the person they paid (targeted ads would count) must compensate them for the harm – unless the software provider can prove their software played no role in the ... harm. If open source resources are [used by] your code, you’re responsible for their performance too. *The open source resource licensed away their liability to you*. (Emphasis mine) [1] Assuming they used a license that limits liability, such as Apache.
- pylua 3y agoThe article says it is not clear who provides relief if the user directly uses open source with no middle man. That is the most concerning part for me.
- sgt101 3y agoIf you use open source you are accepting the license that says that there is no liability. This is similar to going walking in a national park, there is no liability for an injury that you incur. This is very different from walking in a shopping mall. If you fall in a hole on a mountain this is your problem. If you fall in a hole in a mall it's the mall's problem. The article is attempting to create a scare about things that have always been true. If a telco's services crash the telco has to compensate customers even if it was a postgres failure that caused it by failing to authorise handsets for a connection in a cell. For example.
- rini17 3y agoThe line is very unclear to me. What if that national park accepts donations/has entry fee expressly to maintain the trail, would that make them liable for accidents or not? The telco has service agreement with customers and it's clear exactly what service it was supposed to do and failed. Where is such agreement for a random github repository? To put it a bit ad absurdum, say user supplies parameter to your math function so that it divides by zero and it results in some injury or loss. Who is liable for that? Shold judge try to parse some piece of code for whether it was reasonable for user to expect passing zero will work?
- treprinum 3y agoEU is really bent on destroying itself by any means. First AI regulation, now open source destruction, killing off any avenues for growth for the next century. It's already uncompetitive at both.
- CrLf 3y agoIt may be difficult to understand, but maybe the EU has other things where they want to be competitive instead? Maybe, I don't know, quality of life...? Please stop measuring the EU using US standards.
- rbanffy 3y ago> Maybe, I don't know, quality of life...? I’m very happy with my public healthcare. I think every American would be as well. And not to mention that our kids don’t need to do active shooter drills in school.
- treprinum 3y agoPublic healthcare? You mean the free healthcare for 1000EUR that single German freelancers have to pay monthly? For $1k you can get a US insurance for the whole family!
- rbanffy 3y agoIt’s tax funded, so you have a point. Still, it covers everyone so you never see anyone doing gofundmes just to stay alive.
- treprinum 3y agoWell, maybe try not to pay your health insurance as a freelancer and the insurance company promptly disowns you and you are at the same spot as uninsured US folks immediately. In Germany. Just because fees are hidden from you doesn't mean they aren't there and a failure to pay them results in similar consequences to US.
- notfed 3y ago> the EU is finalizing rules that will make open-source creators and licensees liable for any user harm their software might cause Citation?
- formerly_proven 3y agoWhere this thread is going we don’t need any of them.
- droopyEyelids 3y agoThis nonsensical sentence is the heart of whats wrong with the article. There is a tremendous difference between creator and licensee, and lumping them together shows either a fundamental misunderstanding or incentives so perverse they're blinding the author. From what I understood, the liability would only touch the creator if they're providing a _service_ to the public, and wouldn't touch people who release code for others to use. And looking at it like that, doesn't this make sense? Who would have ever expected the provider of a service would be free from liability they cause? Regardless of what tools they're using to provide it.
- RamblingCTO 3y agoThe article leans a bit towards a pessimistic tone imho, so here's another source: https://www-heise-de.translate.goog/news/EU-Regulierung-Ausnahmen-fuer-Open-Source-in-Produkthaftungsrichtlinie-9579307.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp https://www-heise-de.translate.goog/news/EU-Regulierung-Ausn... Apparently the current state of affairs is that open source (non-commercial!) devs and projects are safe. If you pack OSS as part of a commercial offering, you're on the hook for that as well (read: you're liable for the whole product you sell and can't put off some aspects to open source). So nothing to fear for us so far. Still in process though.
- cryptonector 3y agoI.e., TFA is just FUD.
- Mountain_Skies 3y agoHopefully this will change attitudes in application security. Developers often try to ignore vulnerabilities found in the libraries they used, coming from the POV of "well, that's not my code so it's not my fault" instead of "we chose that library so we're responsible for any vulnerabilities it creates for the company". If you're going to use FOSS and don't do anything to correct or mitigate the vulnerabilities in the part you choose to use, then it's your vulnerability. But they only see it from a POV of feeling blamed for something they didn't do as it's not their code and ignore the bigger picture of attackers not caring the slightest who introduced a vulnerability for them to exploit, they're just happy that it exists.
- jalk 3y agoI have never ever met at dev with that attitude. I've seen managers trying to postpone fixes, because they naively thought there was little chance it would be discovered by hackers. A quick tour of Shodan, logs of SSH access attempts and access logs with the various script-kiddy attempts, usually convince that type of manager to prioritize hardening
- jahav 3y agoThat is already part of CRA: > It is of particular importance for manufacturers to ensure that their products do not contain vulnerable components developed by third parties. > Manufacturers shall, upon identifying a vulnerability in a component, including in an open source component, which is integrated in the product with digital elements, report the vulnerability to the person or entity maintaining the component. EDIT: Also, I concur the poster below. It's developers who oppose against management to allocate time for bugs and technical debt instead of new features.
- pylua 3y agoThere is nothing preventing scammers from modifying the software once they receive it then saying it is faulty. Especially with web technologies but even with desktop applications too.
- cuu508 3y agoAsk scammers to demonstrate the fault using an unmodified copy downloaded from your downloads page. If the can not, no case.
- pylua 3y agoSome bugs are one in a million and may not be easily reproduced. How would you prove it’s not one of those?
- deleted 3y ago[deleted]
- cuu508 3y agoWhat specific scenario are you thinking of? Who is trying to prove what?
- pylua 3y agoAnything? I tried to send money to someone but the button did not debounce the request and I ended up with more than one payment ?
- cuu508 3y agoAh, OK, so the end user is trying to prove there is a hard-to-reproduce fault in the software. I do not know how this is being handled in practice, but I think it would be reasonable to require evidence.
- ctoth 3y agoI use an open source screen reader, NVDA. It is completely open, and they produce an installer for people or you can build it yourself from Git. Can you help me understand now, if there is a bug in NVDA (which is under the GPL) and it causes me trouble, say, it can't read a webpage that I need for some government thing, I could now sue my screen reader, which is actually just a bunch of dudes hacking something together? Is that the new behavior that is enabled by this upcoming law? Next question, if this is the actual state of things, why would anyone ever make anything open source and allow it to be distributed in the EU now? It sounds like, and please please correct me if I am wrong, but it sounds like you could sue the makers of The Gimp, for instance, if a bug caused ... what, your pictures to come out looking wrong? > Someone, or some entity, will need to accept financial and legal responsibility for what the project does in consumer hands. Here's a crazy idea, maybe that person should be the consumer?
- bpfrh 3y agoYou can't. Product liability excludes non commercial open source software, see: https://www.europarl.europa.eu/news/de/press-room/20231205IPR15690/deal-to-better-protect-consumers-from-damages-caused-by-defective-products https://www.europarl.europa.eu/news/de/press-room/20231205IP...
- treprinum 3y agoSo basically open source devs can't make living off their work because some clueless EU regulator sees no other way? This is super heavy-handed and makes no sense outside ancient uncompetitive EU tech conglomerates trying to protect their turfs.
- warkdarrior 3y agoIf the open source devs charge for their software, they should have the balls to accept the liability for whatever they are selling.
- treprinum 3y ago
- 2OEH8eoCRo0 3y ago> If a user is harmed by software, the person they paid (targeted ads would count) must compensate them for the harm – unless the software provider can prove their software played no role in the breach/loss/failure/psychological/physical/financial or other harm. If open source resources are in/called/touched your code, you’re responsible for their performance too. The open source resource licensed away their liability to you. This, especially the last sentence, sounds like a good thing.
- zzzeek 3y agowhat's new here? A commercial entity selling a product that also embeds open source components is liable is that entity's product causes harm, even if the fault lies in bugs in the OSS code itself. is that new ? assuming their own license does not also indemnify them. The OSS code, at least if it's mine, has "THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND" right there in the license. What's the change?
- pylua 3y agoThe article says that someone is liable. So if a user directly uses open source would the open source maintainers be liable? Would it be the operating systems company for allowing the software to run? It’s very unclear.
- bpfrh 3y agoMaybe the article but the EU explicitly says opensource free of charge software is fine. https://www.europarl.europa.eu/news/de/press-room/20231205IPR15690/deal-to-better-protect-consumers-from-damages-caused-by-defective-products https://www.europarl.europa.eu/news/de/press-room/20231205IP...
- friend_and_foe 3y agoWhat if its free of charge but I'm rattling a tin can? Is that "thanks for making my life better free of charge, buy yourself a beer" or is it "here's a quarter in exchange for 100% insurance covering anything I use this free thing you made for"?
- bpfrh 3y agoAs far as I understood it it would be ok to have a option for donating. But I have no real basis for that, I would assume that based kickstarter and co also getting money from consumers without having to abide by any consumer rights. I assume that the option of donating while keeping the software available free of charge would fall under the same category as getting gifts from strangers Contrary getting displaying ads directly in the app would fall under commercial activity because you force the user of the app to give you money(via an ad provider)
- elicksaur 3y agoI know this legislation is in the EU, but in the US such a regulation seems to run up against the concept of free speech. What is the difference between these hypotheticals: Case 1: I have a blog that takes a conspiracy-level, anti-tax position. In it, I say crazy things like, “The IRS is illegitimate and financial records are unnecessary.” From reading this, someone shreds all their financial documents. As far as I can tell, the blog is perfectly legal under the First Amendment. Case 2: I am an open source maintainer of a home assistant program. It includes personal file management. Due to a bug in the software, an end-user’s financial documents are deleted. The easiest distinction is that the conspiracy reader is taking an affirmative act of destroying their own documents. But, I think that’s less different than at first glance. The software user is setting up a computer system based on an open source program that may have bugs in it, and that causes a loss of data. The conspiracy reader is setting up a worldview based on information that may have bugs in it, and that causes a loss of data. Why would the software bug be regulated, but the conspiracy falsehood not?
- withinboredom 3y agoIt's probably closer to releasing "open source blueprints" for a car (a steam engine is probably better) that explodes and kills it's occupants. Who is responsible for that? A better set of questions might be: - Why does this person think they can release open source blueprints if they aren't qualified for what they design? - Or, if a company used these blueprints to build a car, why didn't they do their due diligence?
- tdba 3y agoInterestingly, something similar to your case 1 has actually happened and the text was banned with the justification that it contained fraudulent information: https://en.m.wikipedia.org/wiki/Irwin_Schiff#Case_regarding_The_Federal_Mafia https://en.m.wikipedia.org/wiki/Irwin_Schiff#Case_regarding_...
- bpfrh 3y agoBecause the software isn't regulated but commercial activity is, which I would imagine is also done in the US. You are still free to write and release any software you want, but as soon as you sell that software you are liable for damages. See: https://www.europarl.europa.eu/news/de/press-room/20231205IPR15690/deal-to-better-protect-consumers-from-damages-caused-by-defective-products https://www.europarl.europa.eu/news/de/press-room/20231205IP...
- auggierose 3y agoSo what happens in this situation: I write open-source software, and make it available on GitHub, together with a nice installer. I deny any liability in my license, and the users are free to install it or not. They don't pay me in any way (not even in ads). Am I liable according to new EU law?
- TheBigRoomXXL 3y agoNo you are not liable. Liability is linked to a commercial activity because it is meant to protect consumers. The article is very ambiguous in the way it describes the regulation. I recommended this one for more clarity : https://www.euractiv.com/section/digital/news/eu-updates-product-liability-regime-to-include-software-artificial-intelligence/ https://www.euractiv.com/section/digital/news/eu-updates-pro...
- pylua 3y agoWould windows or whatever host operating system be liable potentially for the programs running on it even if they are open sourced programs?
- tester89 3y agoI would think they would be *if* said program was included with the system, which makes sense. The manufacturer cannot be responsible for user-supplied programs, but they surely must know what they include with their system upon install.
- transfire 3y agoSo what constitutes “harm”?
- TheBigRoomXXL 3y agoThis is great. Software is important, software has an impact, and so we need liability. This regulation ensures that whoever sells the software to the consumer is responsible, and that's the way it should be. The creator of a library doesn't know how his library will be used in the wild, he can't anticipate all possible problems, the product maker can. It is the product maker's responsibility to integrate external components properly, having validated that they are up to standard. If you're a manufacturer, you can't just pick components at random and then say it's not your fault if your product doesn't work. That's why manufacturers have whole teams of people working to ensure that what they receive from a supplier is up to spec.
- grumps 3y agoplease provide a link to all your software, so I can find bugs and then sue you for everything you have.
- warkdarrior 3y agoPlease provide receipts or contracts showing you purchased said software from them, before you can sue.
- grumps 3y agohttps://daniel.haxx.se/blog/2023/11/26/you-have-hacked-into-my-devices/ https://daniel.haxx.se/blog/2023/11/26/you-have-hacked-into-... He's got many other examples of emails he gets from people. They find his name or whatever in some apps attribution. It doesn't matter if there's legal grounds or not. Someone and some lawyer will make your life hell. They don't understand software nor do they care. It will be horrifically stressful and potentially very expensive for someone. Maybe it's better in the EU but the second the lawyers or the insurance companies get involved it will make everything awful.
- TheBigRoomXXL 3y agoYou couldn't sue me for 2 reasons: 1 - This regulation only concerns commercial activity. So you could only sue the company I work for, and only if you've bought their products. Also by definition that excludes my personal projects. 2 - You can only sue for defects (in this legal context it means unsafe to use) or damage (physical or material). You can't sue for simple bugs. These kinds of liabilities already exist for all the objects in your life and yet you don't spend your time suing people every time something does not work as expected I imagine
- pockmockchock 3y agowe need liability in politics rather
- andrew_eu 3y agoThe article got me a bit worried about the idea of developing software out in the open, and the comments in this thread give me conflicting ideas. If I make a public repository `ComputerCleaner` with a single file: #!/usr/bin/env bash # <imagine an MIT license here> rm -rf / Should I soon expect to be defending legal threats from random strangers who ran this code only to gasp find that it deleted their files?
- bpfrh 3y agoThe law pertains to commercial software, see: https://www.europarl.europa.eu/news/de/press-room/20231205IPR15690/deal-to-better-protect-consumers-from-damages-caused-by-defective-products https://www.europarl.europa.eu/news/de/press-room/20231205IP...
- ImmutiableTruth 3y ago> Should I soon expect to be defending legal threats from random strangers who ran this code only to gasp find that it deleted their files? Yes. The developers of software have a fiduciary duty to users of their software. The UK court of appeals already determined that the MIT license does not eliminate these duties when it found the authors of Bitcoin Core liable for billions of pounds of damages to Satoshi Nakamoto when they failed to change the Bitcoin protocol to return the coins that hackers took from him. If you don't want to get sued and end up homeless and bankrupt like those Bitcoin Core developers you need to learn to obey the law and act in the best interest of your user.
- jansommer 3y agoWould like to see some actual cases where this was an issue. If a plane goes down due to bugs in open source software, could Airbus just say it wasn't their fault? Can't imagine that. Or if you got hacked and customer's data exposed because of the log4j-bug, could you just say it was because of that library, case closed? That would be interesting to find out, but it sounds insane to me if you can just point at something that explicitly has no liability, that you chose to use in commercial software, and not be liable yourself.
- pnathan 3y agoThe idea that vendors should be responsible under the law for all of what they release is good. I concur that the long term likely outcome for the late adopter crowd is "certified lts editions, supported by BlahCorp" and the long tail of decay. I don't envy anyone in that system. The early adopter crowd probably won't notice, they will steam ahead and keep their own patchset on upstream with regular contribute-back and CI. Sure, they are liable, but they will staff to certify their own systems.
- rich_sasha 3y agoIt's a mixed reaction from me. Liability to the vendor sounds like a good idea - too many cowboys out there. Also with stretched supply chains someone has to pay attention. But full liability..? What if I make a crappy, low effort, cheap spreadsheet app, someone builds their business on top of it and it goes boom. Should I really be liable, on the basis of what I consider a casual product? And then, the main point of the article, what if Vim deletes my files? The suggestion seems to be that Vim "owner" (???) is liable. It feels like there should be some slider as to what liability the creator accepts (OSS - none, casual app - not much etc) but then we're back to square one, everyone disclaims liability etc. Maybe it should be somehow linked to the price paid for the software?
- jandrewrogers 3y agoThere is a principle that liability rests with the party best equipped to mitigate the liability. The commercial-ness of the product doesn't really enter into it, you see this kind of liability attribution all the time in non-commercial settings. Your product being "casual" isn't a defense per se. The gray area where this often gets litigated is liability due to inappropriate use of a product, since liability for clear and obvious inappropriate use typically falls on the user. What constitutes an "inappropriate use" is frequently unclear, especially for casual products where you are unlikely to clearly document and delineate what does and does not constitute appropriate use. If you read the fine print of commercial enterprise software licenses, it frequently has a long list of applications for which the software is deemed inappropriate for legal purposes. The product may in fact be fine for those applications but the producer does not want to take on the liability. It is difficult to enumerate all possible inappropriate uses of software. Enumerating inappropriate use cases to limit liability arguably conflicts with open source's principle of non-discriminatory licensing.
- rich_sasha 3y agoTFA seems to imply that under the proposed rules, none of that careful analysis will matter. A software "vendor" is liable and that's the end of the story. Microsoft or GNU foundation, doesn't matter TFA might of course be wrong, but otherwise, my concerns stand I think.
- lucasyvas 3y agoLike most, I'm convinced of the efficacy of the open source model. I'm convinced that authors should receive reliable financial compensation for their work so the model is sustainable. Counter to some fears about liability with a move like this, I am not convinced this will result in a negative outcome. Businesses will pay big bucks to dump liability on someone else. And an author won't accept that liability for free. I see an opportunity for authors or distributors of open source software to demand a fee for maintenance and shouldering some of some the liability for its use. I see an opportunity for software professionals to vet the paid consumers of their libraries and, via consult, approve to take on the liability based on sound usage (charging fees to confirm sound usage). I see an opportunity for a license that requires you, as the consumer, agree to take on all liability via signature if you aren't paying. Is this not in the spirit of traditional open source? Maybe yes... Or, maybe it is more like a source available model with as few strings attached as possible to get the story straight. Maybe this is not a bad thing. Personally? If the dynamics change so that I can realistically write software for a living independendent from a single company without begging for donations, I would more strongly consider doing so. Incentives here might allow for that.
- BirAdam 3y agoI personally find it strange that software has acted differently… ever. Typically, if you cause damage, you are liable without any regulatory burden being in place. Failure to maintain a motor vehicle can put an operator at risk in event of an accident, a car exploding at random when well maintained puts the vehicle maker at risk, slippery floor not being disclosed to someone and that someone then slipping and getting hurt makes the property owner (or lease holder) liable. It would make sense that software would be absolutely no different except in cases where ownership were in question such as purely open source and non-commercial software. I am glad that the EU is clarifying this and I hope that other jurisdictions follow. On a not-so-rational footing, I hope this puts an end to megacorps freeloading and using FOSS without contributing in any way despite making tons of money off of it.
- Lariscus 3y agoThis has been a long way coming and is, in my opinion, a important step in the professionalization of software development. This article seems to refer to the Cyber Resilience Act but doesn't really explain the problem many[1] open source communities seem to have with the current draft. The CRA actually attempts to exempt open-source software by exempting non-commercial software contributions from its rules. "Commercial Activity" however includes more activities than some open-source developers would like. Any kind of regular income related to the project might fulfill the requirements to count as commercial activity. I recommend the linuxfoundations article[2] for a more comprehensive understanding of the proposed rules. [1] https://blog.opensource.org/the-ultimate-list-of-reactions-to-the-cyber-resilience-act/ https://blog.opensource.org/the-ultimate-list-of-reactions-t... [2] https://www.linuxfoundation.org/blog/understanding-the-cyber-resilience-act https://www.linuxfoundation.org/blog/understanding-the-cyber...
- hexer303 3y agoA likely scenario is that software will become more expensive to consumers because the vendors will have to buy liability insurance in-house. Also, it will raise the barrier to entry for any small vendor or a solo dev trying to make a living with open source. "Trying to start your own small business in the EU? Tough shit. Go get a job, peasant!"
- turquoisevar 3y agoThere's a liability exemption for software manufacturers that are microenterprises or small enterprises at the time of placing the relevant product on the market.
- scrps 3y agoI think there are multiple wins but one I see is that the liability falls on open source commercial entities, support services, and any services that handles PII but also if I am reading the law right there is mandatory disclosure so open source projects will essentially get free code audits, patches included thanks to the liability risk. Unless I've terribly misinterpreted the text which is entirely plausible given a lack of sleep and a enough coffee to jump start a small star. Edit: typo
- hgs3 3y agoWho is responsible for damages when the commercial software in question ships with its source code? What about a small business that sells a closed-source license for its copyleft software? In these cases, there is commercial activity, however, the licensee has full access to the source code. What about open core projects where the code isn't available until the time of purchase?
- tomkarho 3y agoThis article reminds of Daniel Stenberg (the developer of curl) and the emails I recall seeing him display on occasion that think he is responsible for them being hacked etc. because someone (everyoneish) bakes curl into their tools. I wonder if this new legislation might muddy the waters as to whether people like him might actually get sued for the software they provide to the world? Even if the legalese doesn't actually support the notion that this could happen, we won't know for sure until someone puts it to the test. Which means someone needs to get sued so the actual law is tested in a courtroom. A chilling effect for any developer who doesn't have big money backing them. The risk of getting sued or even the very notion of it might just be too great to risk it and not worth the hassle for majority of people.
- cryptonector 3y agoTFA is just a bunch of FUD. Non-commercial open source developers will be liable for nothing, and commercial software developers will be liable, and that liability will include their use of external open source, so what? Pretty much every bit of commercial software uses some external open source, and so what, using external open source does mean that one has to be able to deal with issues arising from that use. For example, even w/o liability if there's some bug in some external open source library that you use, you may have to spend time chasing it down and upgrading or contributing a fix, or locally patching the issue, etc. -- you used that external open source because it saved you time and money (but I repeat myself) and you took on some liability even before any jurisdictions might force you to take on even more liability. That's just normal. The calculus will almost certainly still be that using external open source is better and cheaper than writing your own bloat in-house, but you might need to do a bit more due diligence in picking better, safer external open source. https://www.europarl.europa.eu/news/de/press-room/20231205IPR15690/deal-to-better-protect-consumers-from-damages-caused-by-defective-products https://www.europarl.europa.eu/news/de/press-room/20231205IP...
- grumps 3y agoThis is outrageous and ridiculous. Cool, don't use my code if you're in Europe or within Europe. We will need amended licensing for denying use within Europe.
- lifeisstillgood 3y agoIf I get it right the EU has read the story of boiler manufacturers in the 19C. They exploded - a lot, because commercial pressures pushed a tragedy if the commons. But insurance came along - we will insure you against liability for your boiler killing the train passengers - as long as you follow these best practises and stnadrards and .. boilers blew up less. The question is, are boilers the same as software? Sometimes maybe? Theros-25 is definitely true. Crud HR apps are a maybe.
- theendisney2 3y agoSeems a fun monetization formula. Something to buy from the dev
- ImmutiableTruth 3y agoThis is already true in the UK. The "open source" developers of Bitcoin Core were personally bankrupt with a multi-billion pound judgement because they refused to alter the protocol to allow Satoshi to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove. You either make good software and comply with your duty or you will be ruined. That is the law. Next year those Bitcoin developers will go to prison because the have not paid the billions they owe. Open source communism doesn't protect you from the law.
- olliej 3y agoHere's the problem as I see it: * Person A makes OSS project P * Organisation/Person B uses P * A vulnerability in P causes financial harm to B Is person A now liable under this law? What happens if person A has a Patreon or GitHub sponsor page? The latter seems to imply you're being paid for development and so this is now a commercial project? Or is the requirement that the end user directly pays for the product? In that case this directive would not cover a variety of large objectively commercial products: Chrome, Slack, Java, arguably macOS and iOS (because you get new versions for "free" so the software is "free", right? Apple makes a point of stating its products are the hardware), etc - hence you can't say the "commercial" restriction requires money being exchanged directly for the software, but that gets you back to "does a Patreon, GitHub sponsor, etc mean you're now a commercial developer?" Again the problem here is the ambiguity, and the massive disparity between revenue and liability. If you make a few hundred (or even a few thousand) a year from sponsorship should you be subject to massive liability because a huge organisation, or a large number of different organizations pick up your project, you could now be liable due to damages the organizations are subject to. There's a lot of focus in these threads on "company uses your OSS project in products they sell and a a bug impacts their customers" rather than "company uses your OSS project, and a bug causes the company itself harm", e.g. the company is now the end user. To make it even more direct, what would happen if (as some companies do) the companies provide "sponsorships"(or whatever) for the OSS project development, now the company is the end user and they're paying for development and that sounds pretty "commercial". But also this legislation completely undermines all OSS licenses as they all say the software is distributed without liability or warrantee. The liability restriction is completely neutered, so now contributing to any OSS project requires you to be able to afford a lawyer to determine whether you can do so without acquiring boundless liability, which seems like a sure fire way to immediately price-out the overwhelming majority of OSS contributors from ever contributing to any OSS projects. [addendum] One other follow on from this would be that if you do have any sponsorship mechanism it would seem you're now liable for bugs in code submitted from other people unless you're paying every contributor for their contributions, specifically to transfer liability. If you don't do that you're acquiring liability for code written by others.
- mnau 3y agoGo to the source: https://single-market-economy.ec.europa.eu/system/files/2022-09/COM_2022_495_1_EN_ACT_part1_v6.pdf https://single-market-economy.ec.europa.eu/system/files/2022... > In order not to hamper innovation or research, this Directive should not apply to free and open-source software developed or supplied outside the course of a commercial activity. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. However where software is supplied in exchange for a price or personal data is used other than exclusively for improving the security, compatibility or interoperability of the software, and is therefore supplied in the course of a commercial activity, the Directive should apply Wheather sponsors/patreon means "outside the course of a commercial activity" would likely be for courts to decide. It could mean that you only work on something that is "sponsored"... yeah, that would likely be covered. Getting few euros with no obligations hopefully not. But ultimately, it's a chilling effect, until some court decides.
- turquoisevar 3y agoThis article is FUD by the CEO of a big tech lobbying firm[0], which lobbied against opening up the walled app store gardens in the US. The long and short of it is that this talks about expanding product liability laws in the EU. Currently, software doesn't fall within the PLD, and software developers can shrug and say their software was provided as is if damages occur (e.g., loss of data, data leak, etc.), whereas manufacturers of merchandise are on the hook if their product causes damage (e.g., fire) The EU says this isn't good enough and wants to include software in the PLD. This would only pertain to commercially exploited software (e.g., sold, provided with maintenance contracts, etc.), excluding tiny software developers. The only relation this has to FOSS is that software developers that use FOSS in their product would need to, you know, make sure they know what they are including in their software (something they should do anyway). This has zero effect on Joe Schmoe and their GitHub repo, but this lobbyist likes you to think otherwise to help him stop this change in EU regulation. That's it. 0: https://www.bigtechwiki.com/index.php/Developers_Alliance https://www.bigtechwiki.com/index.php/Developers_Alliance
- tesdinger 3y agoMy 2024 prediction is that open source software will be hosted anonymously on the dark web or offshore to avoid legal liability.
- simne 3y agoCould somebody predict, when these things could become power? How long to got approved by EU? Must admit, they are two-sided proposals, but anyway, I think we should be ready to react in time. My prediction, if this will happen, many people will remove their software from public repositories, to avoid liability. And/or will be changed licenses, probably many OSS will become "only for educational purposes", something like this. This is from one side, dangerous for OSS, as will lost many third part "unimportant" depends, but from other side, will be powerful opportunity to make paid version to cover costs of development and could significantly increase level of OSS quality.