|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:17 UTC (Tue) by farnz (subscriber, #17727)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by jejb
Parent article: Bottomley: Solving the Looming Developer Liability Problem

Note that the proposed rules do not "mandate" cybersecurity best practices; rather, they say that when a supplier offers an update to a piece of software you're using, that supplier is no longer liable to you if you fail to take the update and then fall foul of a defect in the software.

Basically, there's lots of places in the rules where liability is brought to a hard stop by the buyer's inaction, and this is one of them; if I tell you that there's an update that fixes bugs, and you don't take the update, I'm no longer liable to you for any bugs in the software I supplied, because you refused to update. You don't have to update, of course, it's just that I stop being liable to you if you don't update.


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 13:33 UTC (Tue) by jejb (subscriber, #6654) [Link] (1 responses)

> Note that the proposed rules do not "mandate" cybersecurity best practices

Well they try to. It's one of the explicit goals stated in Article 1:

This Regulation aims to set the boundary conditions for the development of secure products with digital elements by ensuring that hardware and software products are placed on the market with fewer vulnerabilities and that manufactures take security seriously throughout a product’s life cycle. It also aims to create conditions allowing users to take cybersecurity into account when selecting and using products with digital elements.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 12, 2023 14:57 UTC (Tue) by farnz (subscriber, #17727) [Link]

It tries to set market conditions that will lead to people taking cybersecurity seriously, but it doesn't try to mandate any particular set of practices; part of the idea is that I now have to face up to the tradeoff of updating every week (because my vendor releases a required update weekly) versus being liable for cybersecurity issues for 3 weeks out of every month.

Equally, as the vendor, I now have a tradeoff to make; do I release an update daily, and risk upsetting my customers (who have to keep up or take on the liability that used to be mine), or do I release monthly, increasing my window of risk, but making my customers happier?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds