|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:12 UTC (Tue) by dottedmag (subscriber, #18590)
Parent article: Bottomley: Solving the Looming Developer Liability Problem

What would happen with older versions of software, already distributed under a license without idemnification clause?

Could somebody incorporate into their product a version of software from 2012 and thus make the developers liable, even if the project has changed the license?


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:32 UTC (Tue) by snajpa (subscriber, #73467) [Link] (37 responses)

Why should the new regulations be feared, when pretty much _all_ the F/OSS licenses already state the software is provided 'AS IS' without _any_ guarantees from the developer at all? It was always understood that if they're doing it for free, they can't be held liable. Why are some people trying to act like we've got some huge problem all of a sudden? Like these clauses in the licenses don't exist? It's been practically mitigated since the very early days of FOSS. +- all of the licenses do so. My guess is, that some see the fear as a way to boost their declining relevance (like it seems to be the case with the author of the linked blog post).

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:36 UTC (Tue) by dottedmag (subscriber, #18590) [Link] (27 responses)

Have you read the article?

The new regulation says "you're liable, no matter what the license says".

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:43 UTC (Tue) by snajpa (subscriber, #73467) [Link]

Have _you_ read it? I can't find a better example of "Fear, Uncertainty and Doubt" for the day. This wins. I mean, for example: " The no warranty disclaimer is already judged not to be sufficient to prevent this, so the cracks are starting to appear in it as a defence against all liability claims." Already judged? By whom? Where? Asking for a link on such a unimportant statement would be too much? The whole article is built like this. Takes a fact, wraps it up in opinion and serves it up as a nice load of FUD to the reader.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:49 UTC (Tue) by farnz (subscriber, #17727) [Link] (25 responses)

Have you looked at the regulation? That's not what it says - it says that you're liable if you're supplying a product or service in return for money that's connected to the software you're supplying regardless of what the licence says.

If you're not selling anything, you're allowed to disclaim liability; if you're selling something, but you can show that the software you're supplying is completely unrelated to anything you're selling, you can disclaim liability, and there are even rules established that set a hard boundary where you're able to disclaim liability even if you also sell things (which would, for example, protect Google's contributions to the Linux kernel as a whole, while still making Google liable for the version of the Linux kernel on the Pixel devices).

Now, you can argue that the exemption is too broad (or too narrow), but please argue based on the actual regulations being proposed, and not on one person's strawman that they've put in place to set up a blog post (and therefore haven't hardened against criticism).

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:13 UTC (Tue) by jejb (subscriber, #6654) [Link] (24 responses)

> Have you looked at the regulation? That's not what it says - it says that you're liable if you're supplying a product or service in return for money that's connected to the software you're supplying regardless of what the licence says.

The current draft CRA text doesn't say that. The Article 3 section 18 definition actually says:

‘manufacturer’ means any natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under his or her name or trademark, whether for payment or free of charge;

I think the EU is trying to make sure that products you get for free (that Whatsapp app say) also comply with the CRA.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:03 UTC (Tue) by Wol (subscriber, #4433) [Link] (23 responses)

> ‘manufacturer’ means any natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under his or her name or trademark, whether for payment or free of charge;

The crucial words here are "and markets them". If you look up the definition of marketing, it does not include "making available for J Random Passerby to help themself". In other words, uploading to a download site is definitely not included.

If you're not marketing, you're not liable. If you're sharing stuff with no commercial interest in it, that's not marketing.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:22 UTC (Tue) by jejb (subscriber, #6654) [Link] (14 responses)

> The crucial words here are "and markets them". If you look up the definition of marketing, it does not include "making available for J Random Passerby to help themself". In other words, uploading to a download site is definitely not included.

Well this is what Article 1 section 23 actually says:

‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;

So J Random Passerby helping themselves absolutely is included. The problems for us all come from the ambiguity in that phrase "course of a commercial activity", which isn't defined. Lawyers have opined that simply getting paid to work on an open source project could be deemed commercial activity. The open source carve out (Recital 10 in the preamble) is phrased similarly:

In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation.

And then goes on to muddy the whole thing by saying:

In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.

but that's not an exclusive definition, it's just a list of examples of what commercial activity might be.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:43 UTC (Tue) by bluca (subscriber, #118303) [Link] (13 responses)

> So J Random Passerby helping themselves absolutely is included.

No, it is most definitely not included, by any definition of the verb "market" as used by the EU.

There is a lot of FUD around this, mostly coming from anarcho-capitalist corners of society for which every regulation is bad and every bad business practice is sacred, but the intent and spirit of the law is extremely clear, as expressed by the legislators, for example:

"A number of stakeholders have submitted their views to the Commission, including arguments pointing to the necessity to correctly distinguish between commercial and non-commercial OSS, particularly in certain grey areas, where making such distinction would not be immediate.

The Commission is therefore fully aware of the characteristics and complexities of the OSS sector and attaches great importance to the issues brought to its attention in this regard."

https://www.europarl.europa.eu/doceo/document/E-9-2023-00...

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:06 UTC (Tue) by pizza (subscriber, #46) [Link] (12 responses)

> The Commission is therefore fully aware of the characteristics and complexities of the OSS sector and attaches great importance to the issues brought to its attention in this regard.

....Until those words are embodied in a new draft of the CRA, they're barely worth the pixels used to display them.

...We have to judge the CRA on what it actually says NOW, not what a future revision might hypothetically say.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:17 UTC (Tue) by bluca (subscriber, #118303) [Link] (11 responses)

Exactly, and it clearly uses the verb "market", which most definitely does not include J. Random doing a git clone out of the first repository it finds on the internet.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 16:34 UTC (Tue) by paulj (subscriber, #341) [Link] (8 responses)

The next issue is that EU Directives are *not law*. They are /directives/ for member states to /implement/ a law that meets at least the requirements in the Directive. Nothing stops a member state implementing a directive plus more. The member state law will be - in the first instance - interpreted according to the member state's own jurisprudence for any cases arising within the member state. The /intent/ of the EU legislators has /little/ to do with this.

We will, for quite a while, have all kinds of differences between member states in precisely what "markets" means in different member states. Some may be very trivial differences, some may be more significant. There may be member states whose legislature and/or judiciary creates a law where "markets" has a meaning much wider than any of us here would like. Further, it may take a long time before a case ever gets to the European Court of Justice to decide whether or not that difference is worth addressing/fixing. Indeed, one member state's interpretation of the Directive, as expressed in its implementation may influence others and lead to there being no difference for the ECJ to have to rule on.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:27 UTC (Tue) by pizza (subscriber, #46) [Link] (3 responses)

> The next issue is that EU Directives are *not law*. They are /directives/ for member states to /implement/ a law that meets at least the requirements in the Directive.

That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities, it doesn't make much of a difference how much (or what type) of accelerant each member state chooses to use.

> We will, for quite a while, have all kinds of differences between member states in precisely what "markets" means in different member states. Some may be very trivial differences, some may be more significant.

In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:44 UTC (Tue) by paulj (subscriber, #341) [Link] (1 responses)

It is not at all unusual that member states implementations end up differing. Again, a Directive is a baseline - a member state may go further. Sometimes, member states implement something /looser/ than the Directive, for whatever reason. Sometimes this is deliberate, sometimes it is just because the Directive uses general words and different member states interpreted them differently.

It is not unusual to see a series of "first round" / "early adopter" implementations by a subset of member states, with differences, which then inform the interpretation, and lead to further implementations taking that into account (including some of the "early adopter" member states passing another law). I.e., there may be a legistlative convergence process that goes on, over 5+ years, across member states, where they all look at what each other are passing, with EU committees or industry bodies perhaps criticising some implementations for not meeting some intent.

Least, it is not unusual for the member state I live in to take a few goes at implementing a Directive. Also, it is not that unusual for there to be further Directives on the same matter, to deal with experience from implementations.

And even at the end of all that, there may still be differences, which may take another 5 to 10 years or more to sort out - e.g. cause a member state just disagrees, or didn't prioritise something, and it goes to the ECJ - and only then if there is enough of an issue for someone with standing (EU commission, a member state, or a member state's judicial system) to actually think it should sent to the ECJ.

So yes, it's going to take a good number of years for this to converge on settled and harmonised law across member states.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 21, 2023 16:55 UTC (Thu) by jepsis (subscriber, #130218) [Link]

Direct effect means that certain provisions of EU law, including directives, can be invoked and enforced by individuals or entities in national courts, even if the directive has not yet been implemented into the national legal system.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 21:04 UTC (Tue) by kleptog (subscriber, #1183) [Link]

> That's a distinction without a meaningful difference. if every member state in the EU is required to effectively set fire to F/OSS activities

They wouldn't do it. No seriously. The EU Commission has no effective enforcement mechanism to ensure countries actually implement the directives faithfully. The whole point of the marathon trilogues and engagement of the Council and Parliament is to get a draft text the member states are actually willing to implement faithfully. If a member state at this point already feels that they'll get push back from their national parliament then they have to keep renegotiating until they get something that will work. (Note: it's up to the member state to organise this feedback loop properly.)

So every national parliament gets to give its own twist to this and no national government is going to "set fire to F/OSS activities" as you put it. This will lead to about a decade of discussion and negotiation while all the kinks get sorted out. The problem with this kind of pioneering legislation is that it's really hard to think of all the corner cases up front and you're better off just doing the best you can and keeping the enforcement light while all the kinks get worked out.

> In other words, no matter what the CRA looks like when it finally passes, it's going to produce a massive mess that's going to take many, many years to coalesce into a meaningful set of rules that an individual [business] can use as a blueprint to stay out of trouble.

Welcome to the EU. We don't want to be a federation, so we do everything the hard way. The alternative, where every state does their own thing without any coordination, would be much much worse.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 21:14 UTC (Tue) by bluca (subscriber, #118303) [Link] (3 responses)

No, the CRA is a regulation, not a directive: https://european-union.europa.eu/institutions-law-budget/law/types-legislation_en
It has immediate and direct effect.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:41 UTC (Wed) by paulj (subscriber, #341) [Link] (2 responses)

I had missed it was a regulation. Thanks for pointing that out. Huge difference. I'm surprised something as sweeping as this can be done by regulation.

Reading the CRA, they appear to be exercising authority to regulate primarily based on Articles 173, and 322(2) (for budgetary things?) of the Treaty on the Functioning of the European Union:

https://www.legislation.gov.uk/eut/teec/article/173 (Industry Competitiveness)
https://www.legislation.gov.uk/eut/teec/article/322 (Common Provisions)

Article 173 is worth reading carefully. Does the CRA follow the objectives of paragraph 1? Does it distort competition? Does it favour or disfavour small and medium-sized businesses?

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:45 UTC (Wed) by paulj (subscriber, #341) [Link]

Note that in the first instance it will still be member state agencies and judicial systems that interpret this Regulation and apply it practically. And differences can arise - between what we here think the legislators intent was, and also between member states. And such differences ultimately must go to the ECJ, to be harmonised - which may take time, if ever.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 16:26 UTC (Wed) by kleptog (subscriber, #1183) [Link]

Just one last comment (just saw corbet's note).

The Act includes a section about why it is a regulation, every act has to specify why it is a directive or regulation and the legal basis for it. While in principle a regulation is effective everywhere at once, the actual enforcement is to be done by entities which don't exist yet and will need to be created by the member states. The entities will be underfunded (they always are) and will not have time to go after anything but the biggest companies.

Also note the fines are actually the sideshow. The primary goal is that the terms get included in B2B contracts and that businesses start holding each other to account. That's the only way to influence suppliers outside the EU.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 28, 2023 10:35 UTC (Thu) by gfernandes (subscriber, #119910) [Link] (1 responses)

As used in the text, it would imply "market" is a noun - not a verb ("...made available *in the market*). Therefore would imply the regulation reads indirectly on developers contributing directly or indirectly to what eventually is assembled into a product that is shipped either for a price or made available free of cost.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 28, 2023 12:01 UTC (Thu) by Wol (subscriber, #4433) [Link]

> Therefore would imply the regulation reads indirectly on developers

Spot on. I like the use of the word *INDIRECTLY*. Which means the legislation does *not* apply to developers.

Sure they have to take it into account - inasmuch as they have a *contractual* relationship with the people to whom the regulation *does* apply.

NO CONTRACT? NO LIABILITY!

As the Europeans here keep saying !!!

I know in America anybody can sue anybody else for any thing. And in America, it can be a business tactic for bankrupting the competition.

But in the UK, the Court's very first question is going to be "Where is the agreement between you? I want to read it". And if that agreement says "here's a freebie, if it breaks you can keep both pieces", the Court is going to be EXTREMELY upset with the plaintiff.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:26 UTC (Tue) by khim (subscriber, #9252) [Link] (7 responses)

When one discusses bills (that are not yet turned into law) the best way to understand what said bill is supposed to achieve is to… gasp… talk to lawmakers.

And Apache foundation did precisely that! They meet these guys and have tried to explain that what they propose would make entities like Apache Foundation or Rust Foundation liable for that they make.

And the answer they got was, of course: indeed, that was our intent, why do you think we don't understand that??

I think if people would understand the logic behind that decision instead of trying to glean it from actual preliminary text everyone would be much happier: even if today the text that we have doesn't align with goals lawmaker have it doesn't mean we should go with text. Text may be fixed or altered, intent would remain.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:47 UTC (Tue) by pizza (subscriber, #46) [Link]

> Text may be fixed or altered, intent would remain.

Good intentions do not automatically result in good outcomes.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 17:17 UTC (Tue) by pizza (subscriber, #46) [Link] (5 responses)

> And the answer they got was, of course: indeed, that was our intent, why do you think we don't understand that?

To be honest, I found that Apache blog post pretty frightening.

Because it appears to show that what most of the doomsayers are saying about the effects of CRA-as-drafted is the actually its legistlated _intent_ , and not collateral damage that could be "fixed" -- in other words, the opposite of what I and many others thought.

...Either you're all-in and treated the same as a multibillion-euro megacorp, or you have to divest yourself of _any_ activities that could be remotely construed as commercially-adjacent -- which is a threshold so low that it's trivial to accidentally cross it.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 23:36 UTC (Tue) by bluca (subscriber, #118303) [Link] (4 responses)

That ASF blog is scaremongering anarcho-capitalism at its finest. Not surprising, seeing who pays the bills: https://www.apache.org/foundation/sponsors

Corporations like Google are terrified of this regulations. The Android market, that forms the core of its profit-making, will be decimated once vendors are no longer allowed to throw devices over the wall and forget about them. Good!

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 2:19 UTC (Wed) by pizza (subscriber, #46) [Link] (3 responses)

> That ASF blog is scaremongering anarcho-capitalism at its finest. Not surprising, seeing who pays the bills

Do you have an actual refutation of Apache's citations, or are you just going to spew more unsupported nonsense?

(Seriously. Your consistent position here is "the EU's efforts are well intentioned so it will all work out fine eventually, and any concerns are complete BS and could only possibly benefit the Googles of the world)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 10:39 UTC (Wed) by Wol (subscriber, #4433) [Link] (2 responses)

Given that your position (sorry pizza) is that this legislation is going to completely up-end and overturn the fundamental basis of contract law and consumer protection in Europe, I really fail to see how your position has any support, either!

Courts really do not like (thanks, PJ) legislation that completely redefines the legal landscape. That comes into a total vacuum. If things really are as bad as you say, European contract law will collapse, and the legislative panic will be the Eighth Wonder Of The World. If things really are as bad as you say, certainly in the UK the Judges will completely gut it, on the basis that it conflicts with other - long standing - legislation that it was never meant to overturn.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 13:06 UTC (Wed) by bluca (subscriber, #118303) [Link] (1 responses)

It's worse than that - it completely misunderstands how the single market works and who is responsible for what, and what constitutes marketing a product. The charitable interpretation is that it was put together by Americans applying their understanding of their market rules to a completely different context.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 18, 2023 16:46 UTC (Mon) by nim-nim (subscriber, #34454) [Link]

> The charitable interpretation is that it was put together by Americans applying their understanding of their market rules to a completely different context.

Someone corp just mistakenly awarded the FUD-ing contract to its Washington lobbying office, forgetting Europe in in another continent. Had it been awarded to its Brussels office, the drivel would be different and better camouflaged.

That or the whole lobbying effect is targeted Washington-side, see, sir, time for a new commercial war, because the Brussels office already lost the first round.

Or else the corp could not figure how to influence US relays from Brussels using people who understood EU law.

There are lots of interpretations. The only sure thing is that it’s a publish-this-thing-we’ve-written-for-you lobbying run that does now reflect well on the ASF.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:43 UTC (Tue) by coriordan (guest, #7544) [Link] (5 responses)

Law trumps licence clauses.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 9:50 UTC (Tue) by snajpa (subscriber, #73467) [Link] (4 responses)

OK, is anyone here able to provide a link to such a draft of such a law? I mean, a specific clause, paragraph, or something, which would in effect null any "AS IS" in the FOSS licenses? I haven't seen that so far. The argument is always "but potentially..." (== FUD)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 11:11 UTC (Tue) by coriordan (guest, #7544) [Link] (3 responses)

This is too basic. I'm not going to search google for a legal basis.

Think it through. The legal system wouldn't work if licences and contracts could say that laws don't apply. It has to be the other way around, and it is.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 11:21 UTC (Tue) by snajpa (subscriber, #73467) [Link]

Yes, providing a solid foundation for the debate we're trying to have is too basic. Of course the law is above any contracts, I'm not even trying to dispute that. But what law are we talking about here? That is my point. Any hint of transferring liability to hobbyists anywhere, in any actual draft of upcoming law? Everyone can write speculative blog post :) But where is the basis for this one?

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 11:48 UTC (Tue) by james (guest, #1325) [Link] (1 responses)

If you want examples of laws over-riding clear terms in software licenses, look at Britain's Copyright, Designs and Patents Act 1988:
296A Avoidance of certain terms.

(1) Where a person has the use of a computer program under an agreement, any term or condition in the agreement shall be void in so far as it purports to prohibit or restrict—

(a) the making of any back up copy of the program which it is necessary for him to have for the purposes of the agreed use;

(b) where the conditions in section 50B(2) are met, the decompiling of the program; or

(c) the observing, studying or testing of the functioning of the program in accordance with section 50BA.

Sections 50A, 50B and 50BA make it clear that these things don't breach copyright, either.

(Extra terms apply: this is not legal advice; consult a real lawyer before relying on any of this!)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 12:19 UTC (Tue) by snajpa (subscriber, #73467) [Link]

To make it more relevant, can you provide an example of a law which is shifting the responsibility of corporations/profit seeking entities to unengaged parties with no skin in the game?

My point is that the hobbyist developers aren't exactly begging the profit-makers to make profit specifically off of their code. The hobbyists mostly couldn't care less about users of their code who in most cases don't even bother contributing back, ever. I'd love to see an example of _this_, because this is the core of the FUD arising from the newest legislative "innovation" attempt in the EU. Shifting the blame for mishaps in commercial product to someone who is not in the profit chain of suppliers to make that product possible. Any example of that?

Being in the chain "by random chance" without any profit or even any engagement at all IMHO will always mean the shift-blaming attempts will turn out unsuccessful. The judicial power would have to get hijacked by the profit seeking entities ~completely for this to happen - and when that happens, we've got bigger problems, than a random FOSS contributor getting blamed for something they had no influence over.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:12 UTC (Tue) by ballombe (subscriber, #9523) [Link] (2 responses)

The GNU GPL disclaimer:
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.

The apache 2.0

7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.

the BSD disclaimer:

THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED.

The two first explicitly allows for "applicable law". All three disclaims 'MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.' which is the key: they are not marketed.

Concretely that means that free software developers should probably not directly advertise their software since this is could be seen as an attempt at marketing.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:59 UTC (Tue) by khim (subscriber, #9252) [Link] (1 responses)

All three disclaims 'MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.' which is the key: they are not marketed.

Yes. But if you are creating a GitHub page and write README there then now you are marketing something.

The bar is pretty low. You may get away with a simple README file, especially if you would put disclaimers there in place of usual “I have created something wonderful” spiel. What you may see on Apache.org or rust-lang.org is definitely marketing. And that's by design.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 1:36 UTC (Wed) by bluca (subscriber, #118303) [Link]

A readme, or a website, are not equivalent to marketing a product.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:02 UTC (Tue) by jejb (subscriber, #6654) [Link] (3 responses)

> Could somebody incorporate into their product a version of software from 2012 and thus make the developers liable, even if the project has changed the license?

Theoretically yes. However practically, to comply with the cybersecurity best practices mandated by the ERA you have to be on the latest stable revisions of the project.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:17 UTC (Tue) by farnz (subscriber, #17727) [Link] (2 responses)

Note that the proposed rules do not "mandate" cybersecurity best practices; rather, they say that when a supplier offers an update to a piece of software you're using, that supplier is no longer liable to you if you fail to take the update and then fall foul of a defect in the software.

Basically, there's lots of places in the rules where liability is brought to a hard stop by the buyer's inaction, and this is one of them; if I tell you that there's an update that fixes bugs, and you don't take the update, I'm no longer liable to you for any bugs in the software I supplied, because you refused to update. You don't have to update, of course, it's just that I stop being liable to you if you don't update.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:33 UTC (Tue) by jejb (subscriber, #6654) [Link] (1 responses)

> Note that the proposed rules do not "mandate" cybersecurity best practices

Well they try to. It's one of the explicit goals stated in Article 1:

This Regulation aims to set the boundary conditions for the development of secure products with digital elements by ensuring that hardware and software products are placed on the market with fewer vulnerabilities and that manufactures take security seriously throughout a product’s life cycle. It also aims to create conditions allowing users to take cybersecurity into account when selecting and using products with digital elements.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:57 UTC (Tue) by farnz (subscriber, #17727) [Link]

It tries to set market conditions that will lead to people taking cybersecurity seriously, but it doesn't try to mandate any particular set of practices; part of the idea is that I now have to face up to the tradeoff of updating every week (because my vendor releases a required update weekly) versus being liable for cybersecurity issues for 3 weeks out of every month.

Equally, as the vendor, I now have a tradeoff to make; do I release an update daily, and risk upsetting my customers (who have to keep up or take on the liability that used to be mine), or do I release monthly, increasing my window of risk, but making my customers happier?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds