5 ms·
This would be a great win for the lawyers. T The better alternative would to be to completely rework the software developing discipline to be as rigorous as ci
by pylua 3y ago
This would be a great win for the lawyers. T
The better alternative would to be to completely rework the software developing discipline to be as rigorous as civil engineering from the top down. Requiring proper licensing, and security clearances for accessing U.S. customer data.
- bee_rider 3y agoSoftware is tricky in this regard because of the dependency mess. If you throw your “little garden path” program up on GitHub and somebody decides to use it to build their “highway,” it really ought to be on them, not you. Edit: I suspect any reasonable law would account for that, and these are the folks who do the Lawfare podcast, right? It is pretty good. I haven’t finished the paper yet but I’d be surprised if they missed this.
- carols10cents 3y ago> these are the folks who do the Lawfare podcast, right? Yep, and they had a podcast episode with the author of this paper: https://www.lawfaremedia.org/article/the-lawfare-podcast-jim-dempsey-on-standards-for-software-liability https://www.lawfaremedia.org/article/the-lawfare-podcast-jim...
- alilleybrinker 3y agoCool thing to note: this argument was made a lot in responses to the Office of the National Cyber Directors' recent Request for Input on improving open source software security. That said, there's a state of tension on this topic right now. The European Union's draft Cyber Resilience Act has included language across multiple versions that would in at least some cases assign liability to producers of open source software. They've tried to modify the language to exclude non-commercial open source projects, but there's been a lot of wrangling over the exact definition of "commercial."
- bee_rider 3y agoHonestly, there should be tension and arguing there. For example, Google should (IMO) very clearly be treated as selling products in the cases of Android and Chrome despite the fact that these technically are related to open source projects. I’m quite glad they aren’t ignoring the complexity.
- alilleybrinker 3y agoI agree that there are details to sincerely work out here. I know in earlier drafts the wording of the "commercial" definition was such that it could be read to classify cases like a solo OSS developer who makes $10/month from GitHub Sponsors as "commercial" (and thus assign liability to them). This received substantial pushback from organizations like (as I recall) the Eclipse Foundation and the Electronic Frontier Foundation. I'm not sure where the draft language stands now.
- bee_rider 3y agoThat seems like a really hard edge case. I wonder how the liability works out for, say, a carpenter who makes home-made chairs if one breaks and hurts somebody.
- jjav 3y ago> but there's been a lot of wrangling over the exact definition of "commercial." That's disturbing since the definition should be trivial! If I publish a library (whether open source or not, doesn't really matter) and charge you money to use it in your product, that's commercial. I'm happy to take the liability (and will of course charge you enough money to make it worth it to me). If I throw out some code on github but you're not paying me, that's obviously not commercial.
- ghaff 3y agoIt's not as different as you might think. Civil/structural engineers are dependent on lots of upstream inputs--or maybe planes where a lot of people here (correctly) think the ultimate manufacturer is mostly liable. Everyone down the chain needs to do their own vetting/testing.
- beaeglebeached 3y agoOr you end up with situation such as US housing where everything is regulated and liability insured out the ying yang to the point I built a house worth a few hundred k for like 40 grand by building it myself and taking all the liability (because I'm not going to sue myself).
- jjav 3y ago> If you throw your “little garden path” program up on GitHub and somebody decides to use it to build their “highway,” it really ought to be on them, not you. It used to be this way (at least in the companies I was involved in back then). In the 90s there was plenty of open source but it was generally a huge no-no to use it in commercial software (even when the license was permissible). Incorporating an open source library (just one!) to our product in the 90s meant months and months of meeting with company lawyers to get that approved. And it meant we (the team developing the product) were 100% on the hook for all fixes. While I'll admit it was a pain, in hindsight there was a lot of benefit from that approach. It discouraged importing random libraries unless there was a lot of value in them, so we had to be selective. It made it crystal clear that open source is not free, there's a lot of cost and liability. While it's convenient today to import a library that brings in 700 other libraries, none of them vetted, any one of which might be full of malware, maybe that's actually not so smart. I increasingly feel we need to go back to explicitly admitting that we (the company) are 100% responsible and liable for the code we ship. If we import it from open source, no matter, we're still on the hook.
- mustache_kimono 3y ago> This would be a great win for the lawyers. T My POV it's better than pretending certain segments of the economy are special and can completely avoid all liability. People really hate the idea of slip and fall cases until their grandmother slips and falls. > The better alternative would to be to completely rework the software developing discipline to be as rigorous as civil engineering from the top down. Requiring proper licensing, and security clearances for accessing U.S. customer data. Yeah, maybe. It's kind of incredible this kind of seat of the pants engineering has lasted as long as it has.
- pylua 3y agoThe problem with liability here is that software as a discipline is so subjective anything can be argued from any expert just out of a boot camp. Which is why it is a lawyers dream unless it is completely reworked.
- mustache_kimono 3y ago> The problem with liability here is that software as a discipline is so subjective anything can be argued from any expert just out of a boot camp. I'm really not sure this is case. I'm sure there are plenty of people who would have argued medical practice is more of an art, than a science, before the introduction of strong med mal regimes. Everyone tends to think their field is special!
- pylua 3y agoAgain, I don’t think it’s special. I think it lacks objectivity. I wish the field had more objectivity. If we go down this path then we need proper licensing, certifications, and changes should be as well tested as the fda process. Aka releasing software is as rigorous as releasing a new drug.
- mustache_kimono 3y agoYeah I think we agree.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]