5 ms·
Your reasonable options are: 1. I stop sharing the software I write 2. You take responsibility for the software you use Any software you use with this clause,
by 6keZbCECT2uB 6mo ago
Your reasonable options are:
1. I stop sharing the software I write
2. You take responsibility for the software you use
Any software you use with this clause, "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE."
Already attests that the authors do not offer guarantees that the software will have the features you need, supply chain security or otherwise.
- skeeter2020 6mo agothat clause - even in all caps - doesn't absolve them like you think it does. A quick example: if credentials were comprimised and malware pushed and it was determined to be due to reasonably preventible negligence an author could be held responsible.
- cuu508 6mo agoDoes this really happen? Can you provide concrete examples?
- well_ackshually 6mo agoNo. Because the only reason you then get hit by this new version with malware is either that you're not pinning your versions (and that's irresponsible), or you're blindly bumping (and that's irresponsible.) The software is provided as is.
- ahtihn 6mo agoAre companies that are compromised by supply chain attacks held responsible for their negligent behavior? Blindly pulling updates from providers that offer you no contractual guarantees has to be gross negligence right?
- trollbridge 6mo agoNo, they wouldn't be "held responsible". There is a great deal of insecure code out there and I have yet to see some open-source author found liable for that.
- general1465 6mo agoIf I will poison you (for free of course) am I absolved of guilt because I did not want a payment for that?
- skydhash 6mo agoPoisoning is intent. If I leaves a cup of some liquid with a clear warning that it has not be tested for being drinkable, I don’t think that I’m liable for you being poisoned when you go and drink it. Especially if I do not sell drinks. Of course, there are regulations about safety, but they are mostly about when you’re at risk of being harmed while I use my tools for myself. They’re not about you ignoring warnings labels and getting harmed. IANAL.
- general1465 6mo agoYou can get poisoned unintentionally, as it happens in supply chain attacks.
- doubled112 6mo agoA supply chain attack would be intentional, just not intentional by the creator. If I mix some ecoli into your drink mix, I did this on purpose. You just don’t know it until it is too late. Are you liable for allowing this to happen?
- general1465 6mo agoYou screw up by poisoning me. However if I will sell that drink to somebody else then I will be on the hook for poisoning them.
- skydhash 6mo agoNo one is selling anything. A lot of OSS projects don't even distribute binaries, only code tarballs. If the risks are substantial enough for you to worry about, you take the source code and review them. Then you run it if it's satisfactory. Let's take npm. The postinstall scripts and auto fetching of dependencies have always been seen as problematic. So plenty of warnings beforehand, but people chose convenience over security. Debian's package management has the same feature (postinstall scripts and dependencies management). But the risks are lower, mostly because your main targets would be a core group of committers, which I'd like to believe is more conscious about security risks. And there's a lot of reviews before binaries are built and made available in a stable version. And I'd also like believe popular packages like nginx, curl, coreutils, postgresql,... have a lot more eyeballs on them.