|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 10:49 UTC (Tue) by kleptog (subscriber, #1183)
Parent article: Bottomley: Solving the Looming Developer Liability Problem

This whole discussion seems to start from the position that those warranty disclaimers in open source licenses were actually legally enforceable in the first place. But this has never been the case. The Uniform Commercial Code in the US has always required "merchantability" and cannot be disclaimed. Some states may modify this. In the EU warranty disclaimer are subject to a fairness test (and some states go further). In some jurisdictions software warranty disclaimers must be explicitly accepted by the user to be effective.

The idea that we could add some language to licences to indemnify developers is a non-starter: Microsoft could just add the same language to their licences to indemnify themselves.

The magical world where licences magically protected open source developers from lawsuits never existed. It was always other elements (primarily, since you're not selling a product, the whole discussion of product liability goes away). All the recent legal changes are merely clarifying that "merchantability" also covers "being reasonably secure".


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 11:37 UTC (Tue) by bluca (subscriber, #118303) [Link] (4 responses)

Indeed. The reason publishing free software can get away with not providing warranties is because publishing free software is not the same as making a product or a service available on the market.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:38 UTC (Tue) by pizza (subscriber, #46) [Link] (3 responses)

> Indeed. The reason publishing free software can get away with not providing warranties is because publishing free software is not the same as making a product or a service available on the market.

That is, until the law gets changed to effectively make "publishing" the same as "making available on the market".

...Along with broadening the definition of "commercial activity" to include stuff entirely unrelated to the production of said software.

...Along with making the potential liabilities wildly disproportionate to the amount of commercial gain.

This unholy trio of changes makes F/OSS work either into purely a hobby (ie donations or occasional commercial work to cover your costs!) or something that only large organizations can afford to create.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:52 UTC (Tue) by snajpa (subscriber, #73467) [Link]

In the Czech Republic, we've made the Charter of Fundamental Rights and Freedoms a part of our constitution, but with every fundamental right and freedom having a condition "if an appropriate law doesn't say otherwise". It's been over 30 years now and it still hasn't turned into a dictatorship, those Fundamental Rights and Freedoms do still hold. I don't think this line of argumentation is valid. We'd get nowhere, would have no progress, because every regulation change (esp. regulating previously unregulated stuff) can take a turn for the worse in the future.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:01 UTC (Tue) by gspr (subscriber, #91542) [Link]

It sounds to me that at some point the lines between software and prose might blur. Surely fictional prose is well-established enough that nobody can conceive of holding an author liable for describing e.g. damaging/dangerous/illegal behavior. How contrived must code be to not be considered code? Can one imagine publishing code as prose or art, and requiring the user to transform said prose into code, to firmly shift any idea of liability away from the author of the software?

Going the opposite direction: At some level of formal language, mathematics becomes code. Most mathematics is not done in such formal languages, but can be translated into one (with lots of work). Are mathematicians liable for damage done by our proofs?

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:47 UTC (Tue) by bluca (subscriber, #118303) [Link]

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:13 UTC (Tue) by Wol (subscriber, #4433) [Link] (5 responses)

> The Uniform Commercial Code in the US has always required "merchantability" and cannot be disclaimed.

But if you're not involved in commerce, it doesn't apply. (Or I presume it doesn't.)

"Merchantability" means "fit to be sold". And if you're not selling it, where's the problem?

(Yes, you might be trying to get around the law, and deserve to be slammed, but you might not, too ...)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:10 UTC (Tue) by pizza (subscriber, #46) [Link] (4 responses)

> "Merchantability" means "fit to be sold". And if you're not selling it, where's the problem?

The problem is that the [current draft] CRA says that it will apply to "Digital elements" whether or not they are sold or provided free of charge.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:20 UTC (Tue) by bluca (subscriber, #118303) [Link] (3 responses)

No, it does not. It applies to products on the market. And that is not a problem, because nobody here who is not running a business needs to care about the distinction, because it doesn't apply.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 15:45 UTC (Tue) by pizza (subscriber, #46) [Link] (2 responses)

Except that I *am* running a business!

And before I had a legal business registered, I was still "accepting recurring compensation" from EU-based entities for support/bugfix activities. AKA the primary mechanism that "hobby" F/OSS writers use to offset their F/OSS operational costs.

My business has booked a whopping $180 in revenue from European clients in the past 12 months. That's still enough to trigger the full weight of the (draft) CRA's compliance, reporting, and liability provisions, because the threshold is anything more than zero, and my liability extends to all possible users of my software, not just the ones for whom I have a business relationship.

You (and they) say this sort of outcome is not their intent. That's great! But good intentions are, while necessary, are no guarantee of a good outcome.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 20:42 UTC (Tue) by kleptog (subscriber, #1183) [Link]

> And before I had a legal business registered, I was still "accepting recurring compensation" from EU-based entities for support/bugfix activities. AKA the primary mechanism that "hobby" F/OSS writers use to offset their F/OSS operational costs.

Sounds to me like you're providing a bugfixing service, not selling a product. So I don't see how product liability is relevant in you're case. The Digital Services Act might be relevant though.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 23:32 UTC (Tue) by bluca (subscriber, #118303) [Link]

Good. If you sell software on the market, then you need to be held responsible for it to your customers. Just like if you were selling medicines, or food, or industrial equipment, or anything else for that matter.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds