EU situation should be looked at by everyone
EU situation should be looked at by everyone
Posted Dec 12, 2023 20:19 UTC (Tue) by mfuzzey (subscriber, #57966)In reply to: EU situation should be looked at by everyone by khim
Parent article: Bottomley: Solving the Looming Developer Liability Problem
So if I publish some piece of open source code that then gets used by $COMPANY in their $GADGET the entity that should be liable for any bugs (security or otherwise) is $COMPANY, not me after all they are the ones deciding to use it and, more importantly, the context in which it is used whith has a great impact on the exploitability of any vulnerabilities. Perhaps $COMPANY could shift some of the liability to $OTHER_COMPANY if they had a commercial relation with them to provide some software for their product and $OTHER_COMPANY decided to use my code.
If I were providing prebuilt binaries for people to download (as pure software because an individual isn't likely to be shipping devices) then it's a bit muddier. But if I only ship source and let people build it not so much
