|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 4:01 UTC (Wed) by pizza (subscriber, #46)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem

Or, to put it more explicitly -- Debian-and-Gentoo-the-organizations hold (and actively use) EU Trademarks for the software products (eg "Debian GNU/Linux") they produce and actively make available in the EU.

Under what twisted reasoning would the CRA *not* apply to them?


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 10:32 UTC (Wed) by Wol (subscriber, #4433) [Link] (41 responses)

> they produce and actively make available in the EU.

>Under what twisted reasoning would the CRA *not* apply to them?

The twisted reasoning that assumes "actively make available" means "place on the market"?

Those are two different phrases, one of which is written in plain English, the other in Legalese. The twisted reasoning is assuming that they mean the same thing.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:11 UTC (Wed) by khim (subscriber, #9252) [Link] (3 responses)

> The twisted reasoning is assuming that they mean the same thing.

That would be very strange, isn't it? If they mean the same thing then why even have different sublanguages.

> The twisted reasoning that assumes "actively make available" means "place on the market"?

That couldn't be right. Various companies give out simplified “personal” versions of their products for free all the time. Some even give their products completely free and just collect money from ads.

That activity should be covered by law because otherwise it's obvious loophole to be exploited by megacorps… and I couldn't see where and how such activity would be separated from what Debian and Gentoo are doing.

More: I don't even see the desire (on the lawmakers side) to try to create such separation. They are much more concerned about the fact that Google/Microsoft/etc may use AOSP, Debian and other such outlets as a means to shirk their responsibility than they concerned about the fact that this may destroy Debian, Gentoo or some other such group.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 13:33 UTC (Wed) by bluca (subscriber, #118303) [Link] (2 responses)

> That couldn't be right.

And yet, that's exactly how the single market works, as it has been explained many times already.

> Various companies give out simplified “personal” versions of their products for free all the time. Some even give their products completely free and just collect money from ads.

Which are both part of a business activity consisting of placing products in the single market for EU customers.

> I couldn't see where and how such activity would be separated from what Debian and Gentoo are doing.

The separation is due to missing the fundamental first step: marketing products in the single market for EU customers.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 14:41 UTC (Wed) by pizza (subscriber, #46) [Link] (1 responses)

> The separation is due to missing the fundamental first step: marketing products in the single market for EU customers.

Genuinely curious. Am I correct in understanding that no formal registration is needed to place (some/many/most) products on the market? If so, what exactly entails "marketing" in this context?

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 15:17 UTC (Wed) by Wol (subscriber, #4433) [Link]

It's defined in the "Blue Book" or something like that. That was pointed to in a earlier re-run of this saga.

Basically it's something like "making an open offer to treat", another bit of legalese. But that's effectively putting up a shop window, with a load of products, WITH PRICE TAGS, and saying to the world and his wife "come in, look around, and if you want to give me what I'm asking for we have a deal".

This is VERY different from shoving a load of products on a table at the end of your driveway, and sticking up a sign that says "help yourself. When they're gone they're gone".

The first is a contract - there is a two-way exchange of benefit between the parties to the contract. The second may well be to the benefit of the giver, but there is no guarantee of any benefit and the benefit may not come from the recipient.

All this nasty legalese is simply to prevent people disguising the first version as the second, with the intent of avoiding responsibility or benefiting unfairly.

(And where you are doing contract work for someone, you make them an "offer to treat" - pay you a decent wage for your work - and then you have a contract where you tell them either they guarantee your work, or if they want to offload liability onto you, they have to pay the insurance premium as part of your invoice. The "open offer" simply means anyone can walk in off the street and accept what's on the table, whereas an "offer" can be "please negotiate".)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 14:24 UTC (Wed) by pizza (subscriber, #46) [Link] (36 responses)

> The twisted reasoning that assumes "actively make available" means "place on the market"?

In other words, the "twisted reasoning" taken from the actual text of the CRA itself?

(Taken from the latest available marked-up version here: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CONSIL:ST_12536_2023_INIT dated 2023-08-31)

"(10) This Regulation applies only to products with digital elements made available on the market, hence supplied for distribution or use on the Union market in the course of a commercial activity. The supply in the course of a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services when this does not serve only the recuperation of actual costs or pursues a profit or the intention to monetise, by providing a software platform through which the manufacturer monetises other services, or by requiring as a condition for use, the processing of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software. The circumstances under which the product has been developed, or how the development
has been financed should not be taken into account when determining the commercial or non-commercial nature of that activity. A package manager, code host or collaboration platform that facilitates the development and supply of software is only considered to be a distributor if they make this software available on the market and hence supply it for distribution or use on the Union market in the course of a commercial activity. Taking account of the above-mentioned elements determining the commercial nature of an activity, this Regulation should only apply to free and open-source software that is supplied in the course of a commercial activity."

"(18) ‘manufacturer’ means any natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under his or her name or trademark, whether for payment or free of charge;"

"(22) ‘placing on the market’ means the first making available of a product with digital elements on the Union market;"

"(23) ‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;"

(Note paragraph 10, which only applies to F/OSS stuff if there is no commercial activity of any sort affiliated with it. My meager support business clearly qualifies. RHEL and SLES is of course covered; Fedora/OpenSUSE is probably completely screwed due to its connection with Red Hat/SUSE, and Ubuntu has numerous inseparable commercial sub-components that Canonical requires to be included. Debian and Gentoo may skate just under here if they don't charge more than cost recovery fees for the media they distribute, but their use of trademarks might, on its own, make their software distribution in the EU into a commercial activity. It certainly would in the US.)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 15:03 UTC (Wed) by khim (subscriber, #9252) [Link] (34 responses)

> Fedora/OpenSUSE is probably completely screwed due to its connection with Red Hat/SUSE

I don't think so. In fact precisely that connection may easily save them. Because for them it's easy to argue that what they are offering is personal-use-only or development-only limited version (similar to Windows Home or these Phone devkits that you may use before final hardware is available) which is explicitly not suitable for use as base of any commercial offering. You have RHEL and SLES for that. Which would, of course, include insurance and all other such things.

And the same can be said about “Android AOSP” vs “Certified Android”, “Chromium OS” vs “ChromeOS” and so on: in all these cases open source variant may be easily portrayed as something similar to a “development board” and everyone who may want to develop something on top of it may be directed to $$ variant.

In fact I find it amusing how free software zealots are looking forward to see how this law would crush Google and Microsoft and make them pay: Google and Microsoft already have well-defined structure to adjust and include these money needed to cover insurance into their offers for the commercial entities while their free offerings can easily be framed as “test sample”.

It's entities that don't have commercial $$ offerings that are in trouble.

> Debian and Gentoo may skate just under here if they don't charge more than cost recovery fees for the media they distribute, but their use of trademarks might, on its own, make their software distribution in the EU into a commercial activity. It certainly would in the US.

Significantly more problematic, from EU comission POV, is the fact that there are no $$, indemnified, alternative.

I think eventually Debian would be forced to create some kind of Debian Corporation which would handle commercial support and indemnification.

Because that's the obvious goal that EU is seeking: to create an entity which would be responsible for that codebase. They certainly don't plan to make someone to do that work for free, this would be, most likely, $$ version, but right now it doesn't exist… and that is the problem CRA tries to solve.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 16:44 UTC (Wed) by bluca (subscriber, #118303) [Link] (33 responses)

> I think eventually Debian would be forced to create some kind of Debian Corporation which would handle commercial support and indemnification.

The text could not possibly be any clearer, plus it has been explained many times what it means, and yet you keep willingly misreading it, and hallucinating the most outrageous nonsense out of it. Read this again:

> this Regulation should only apply to free and open-source software that is supplied in the course of a commercial activity

Debian did not, does not and will not engage in any kind of commercial activity in the EU single market.

> Because that's the obvious goal that EU is seeking: to create an entity which would be responsible for that codebase.

No. You misunderstand - again - the intent, purpose and spirit of the law. It is abundantly clear: to ensure customers buying products that contain software are covered. The EU couldn't give two fucks about any codebase, unless and until it makes its way into a product on the market. The supplier of said product is then liable.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 17:38 UTC (Wed) by pizza (subscriber, #46) [Link] (32 responses)

> The EU couldn't give two fucks about any codebase, unless and until it makes its way into a product on the market. The supplier of said product is then liable.

....What magic incantation is needed in order for something to be "placed on the market"

(Every definition I've seen actually cited refers to physical goods, in some sort of defined store front)

I don't think anyone would try to claim Google Chrome is not "commercial". But what about the Firefox browser? Mozilla has offices located in the EU, and a lot of money changes hands, indirectly (==donations) and directly (==people paying for Firefox add-ons, like Pocket and their VPN). These activities appear to be explicitly counted as commercial by the CRA text. But what if you download Firefox from mirrors.fedoraproject.org instead of Mozilla.com? Does this make Fedora the manufacturer/importer instead? Or is "Firefox from Fedora" not technically "placed on the market" by anyone? (After all, Mozilla only provided bare source code the world, and Fedora customized the build in some small way, and at no point did money change hands) What if this was part of RHEL instead, where clearly there is a commercial relationship between the user and Red Hat? Is Red Hat the manufacturer of "Firefox" as embodied in RHEL? Or is RHEL a "Service" and not a "product"? Whatever that answer, why wouldn't it also apply to Chrome?

Meanwhile, most $big_tech doesn't "sell" anything to consumers in the EU; the products cost $0 for most users. Does this mean they're not "placing a product on the market?" If not, what's the gating factor, since clearly it's not price? Advertising and data mining? How can Google be held liable for "Android" when they're not actually *selling* it or placing it onto the market via any mechanism other than their line of Pixel phones? (Android is provided to the world as "a bare codebase" after all, and Google supports their Pixel phones longer/better than anything not made by Apple!)

These are the sorts of questions we're trying to get answered; not because we are trying to find loopholes and carry out nefarious plans, but because we are trying to understand the scope of the likely-considerable impact these rules will have on our professional lives.

Your responses to peoples' concerns (many citing chapter and verse of the proposals) are essentially "You're reading it wrong" deflections that appear to be contradicted by the literal plain text of the proposals themselves. I get you can't answer anything conclusively (indeed, nobody other than EU legislators/bureaucrats can) but when you're taking a position that is on the opposite side of literally everyone else (in a profession that is built on identifying and rooting out inconsistencies!) we need _something_ more to go on...

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 23:23 UTC (Wed) by bluca (subscriber, #118303) [Link] (31 responses)

See this excellent comment from Wol below: https://lwn.net/Articles/954927/

In general, where the sources come from doesn't really matter. This is said explicitly in the regulation. Because what matters is who gives you a product that contains said software, and if that qualifies as a commercial activity or not. Assuming Mozilla has employees working on releasing and distributing said software directly to users via mozilla.org, which I'm sure it happens, and assuming they get more money the more users are running Firefox, which is plausible given the multi-millior dollars contract they have with Google w.r.t. being the default search engine, which is ads-based and thus impression-based (more users -> more cash), it's possible that it could be enough to meet the threshold - I don't know for sure, as it gets complicated at this point, with lots of money moving around and whatnot. The important question though is, would it matter? Does anybody believe that Mozilla wouldn't take full responsibility in delivering timely security fixes for their flagship product delivered from their direct distribution channels? Of course not. So, even if, what difference would it make, for anybody, if Mozilla had to do what it already does anyway because of a regulation?

So where does it make a difference? You cited Android and Google. Of course the law can't make Google liable if shoddy Android manufacturers ship known-broken devices with glaring, unpatched security holes, and refuse to do anything about it. Liability is with the phone vendor, if they sell directly, or the shop if there's an intermediary. So how would it happen that, in the end, the buck stops with Google and it's them who pays? Supply contracts. By forcing the seller to be responsible, and unable to disclaim liability, the regulation forces the seller to cover its back - this is normal practice, otherwise customer-facing sellers would be out of business a month after opening up shop. So one of the two things would happen: either J. Random Android Vendor goes out of business, and Google loses precious ads revenue that they need to survive, or J Random Android Vendor and Google get their act together and comply with the CRA and supply security updates for their products. Substitute Android and Google for any consumer product using software sold in the EU, and you get the idea of where the CRA is coming from and what it wants to address.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 23:39 UTC (Wed) by pizza (subscriber, #46) [Link] (30 responses)

> Of course not. So, even if, what difference would it make, for anybody, if Mozilla had to do what it already does anyway because of a regulation?

My question has to do with Firefox obtained through channels other than Mozilla, and how that changes *who is responsible* for delivering timely updates when, say, it was obtained through through Debian.

Especially when Debian's release has changes versus what Mozilla ships. And might even have security flaws not present in what Mozilla ships (there have been some high profile cases of this happening). Since it can't be Mozilla, who becomes the responsible party under the CRA in this scenario, if not "Debian" ? The mirror operators? The package maintainers? Or the caveat-emptor end-user who chose to install it?

(And what if Debian is pre-installed on a, say, Lenovo laptop? Does Lenovo now bear the full responsibility of ensuring Firefox-and-everything-else-in-Debian is kept up to date?)

Yes, this is all VERY messy, and that's why we're trying to figure out how this is supposed to work.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 8:58 UTC (Thu) by Wol (subscriber, #4433) [Link] (28 responses)

You obtained Firefox from Debian. So the regulation is nice and simple - IFF there is liability, it rests with Debian. End of.

Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

So it's not commercial, there is no contract, no liability, and Debian is on the hook for nothing. Meanwhile, Firefox the organisation does not have any involvement in this transaction whatsoever, so also has no liability.

If it breaks, you get to keep the pieces ... :-)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 9:58 UTC (Thu) by bluca (subscriber, #118303) [Link] (7 responses)

And to add to that:

> (And what if Debian is pre-installed on a, say, Lenovo laptop? Does Lenovo now bear the full responsibility of ensuring Firefox-and-everything-else-in-Debian is kept up to date?)

Yes, Lenovo is responsible in that case, and they need to ensure you can get updates. It doesn't mean Lenovo has to send you the updates directly though. In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it doesn't sell laptops with EOL versions of Fedora pre-installed. That's a good thing!

Same applies to Dell and their Ubuntu-based laptops.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:24 UTC (Thu) by pizza (subscriber, #46) [Link] (6 responses)

> Yes, Lenovo is responsible in that case, and they need to ensure you can get updates. It doesn't mean Lenovo has to send you the updates directly though

They don't have to do it directly, but they are legally obligated to ensure that _someone_ will provide those updates. Which means either doing it themselves, or (far more likely) entering into a binding contract with an entity that will.

> In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it
doesn't sell laptops with EOL versions of Fedora pre-installed.

It's not as simple as "don't sell laptops with EOL software" -- Fedora's EOL is 13 months after initial release. IIRC in the EU 24-month warranties are the minimum, and that applies from date of _sale_. That's a (minumum) 11-month coverage gap that Lenovo, not Fedora, not Firefox, will be on the hook for.

I'm afraid that "In practice" will result in one or two companies [1] utterly dominating the market, because they'll be the only ones with the resources to provide those guarantees.

Meanwhile. Given that warranty/support periods _do_ expire, and the tendency for folks to use "digital elements" long after said warranty/etc has expired, I can't help but wonder if this is going to make any practical security difference in the end.

[1] I was originally going to say someone like Red Hat, but it's more likely to be someone like Microsoft and Amazon.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (5 responses)

There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:09 UTC (Thu) by pizza (subscriber, #46) [Link] (4 responses)

> There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

That presumes Fedora 53 is a strict superset of the software and functionality contained within Fedora 52. That is almost never the case.

If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

(There's already legal precedent for this; Sony had to pay out a large amount of money because their "necessary update" took away advertised-on-the-tin functionality)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:29 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

That is a separate issue; the CRA says you can take away functionality in an update and lose liability that way, but does not protect you from being sued for taking away functionality.

And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:03 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

In that case, why bother with installing Minimal Anything? Just ship FreeDOS as part of the system firmware and let the buyer assume all responsibility.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:08 UTC (Thu) by farnz (subscriber, #17727) [Link]

That works for a PC or laptop (albeit that you can't, under other consumer laws, claim the system has functionality that doesn't work under FreeDOS - so you can say that the device has an Intel AX201 WiFi chipset, but not that it has WiFi 6 support), but not for the vast market of IoT devices where the S in IoT stands for their commitment to security, where people don't care about the software, they care about the function.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:37 UTC (Thu) by Wol (subscriber, #4433) [Link]

> If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

That presumes the system is supplied "With Fedora *52*". Suppliers will rapidly learn. It will be supplied "With Fedora".

As far as Sony were concerned they actively advertised the PS/2 could run Linux. A lot of people bought it BECAUSE of the advertising. That was a blatant bait-n-switch. If Dell or Lenovo advertise "with Fedora", and Fedora drop a load of functionality between 52 and 53, that's not Dell or Lenovo's problem.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:02 UTC (Thu) by pizza (subscriber, #46) [Link] (19 responses)

> Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

By this logic, Google Chrome is not commercial either.

> If it breaks, you get to keep the pieces ... :-)

In other words, a whole lot of additional regulation to ... accomplish nothing. Heck, if anyhting, it will make it _easier_ for pure software "products" to avoid liability.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:29 UTC (Thu) by Wol (subscriber, #4433) [Link] (17 responses)

> > Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

> By this logic, Google Chrome is not commercial either.

AND THAT IS THE POINT!

If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

If, on the other hand, you bought a phone with Chrome pre-installed, then the SHOP you bought it from is liable for making sure you have access to updates. If they can't pass that liability onto Google, or Samsung, or Apple, then they will simply refuse to stock that phone. Which will mean either (a) you will be forced to buy direct from the manufacturer's own distribution system in the EU, and it'll be the manufacturer on the hook because they're the shop you bought it from, or (b) you will have to buy it from China or wherever and just accept the fact that you have no comeback whatsoever if your £1000 i-phone or Pixel-8 or whatever dies the day after it arrives.

Not many customers will accept option (b), and it only takes one manufacturer to say "we're happy with the CRA", and the rest of them will be forced into line as that first manufacturer basically cleans up in the European market.

So no, it's not that Google Chrome is commercial or not, it's whether Google Chrome is part of a commercial product. As others have repeatedly said, it all depends on HOW you acquire whatever digital product it is. And manufacturers will be forced to provide security updates yada yada because it they don't their distribution channels will go "toooo risky, mate!", and slam the doors shut.

You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you. At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed, but that's a contract matter between you and your customers. And if you have a problem with that, you're exactly the sort of supplier who shouldn't be going anywhere near anything remotely security-sensitive. Which again is the point. And if you do have a problem with that, any of your customers who supply to the EU will either have to certify it themselves (which is okay), or find another supplier who will certify their *component* products.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:47 UTC (Thu) by pizza (subscriber, #46) [Link] (12 responses)

> AND THAT IS THE POINT!
> If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

I'm sorry, but that's... completely absurd. I'm not _disagreeing_ with your assessment, but if accurate, it provides an Ever-Given-sized loophole for "obviously commercial" concerns to escape liability for security flaws in software they provide to folks in the EU. And it's a loophole so large that it makes this whole CRA exercise into a complete farce.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (1 responses)

You have to require the user to obtain and install the software themselves, and you cannot direct them to the software to install - they've got to find it themselves.

It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS. Sell a bare phone with no software at all (not even a bootloader), and you're not on the hook under the CRA: pre-install Android, and you're on the hook for the entire pre-installed OS and all its parts. Tell the user how to install Android on the phone, and now you're on the hook for the variant on Android you tell them to install.

And yes, this is a loophole; the point is that a device with software is more valuable to the end user than a device without software, and you're not (for example) going to sell a car that needs software and tell the user "yep, you've got the hardware, go build or find the software elsewhere". Even if you do, many people will then buy the software themselves, and if they buy from an EU supplier, that supplier is on the hook.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:39 UTC (Thu) by Wol (subscriber, #4433) [Link]

> It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS.

And importantly, if the user installs gentoo over the top of ChromeOS - never mind the fact that ChromeOS is gentoo "under the bonnet" - you're not on the hook for gentoo. You're on the hook for whatever you supplied, and that's it.

Oh - and I guess if you try and avoid liability by saying "Oh, you'll need to install ChromeOS on this in order to make it work" - so you're not telling them exactly what they need - you've now dropped your distributor completely in it because if they mess up installing ChromeOS they can return the device as "not fit for purpose". That really will upset your distributors.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:33 UTC (Thu) by Wol (subscriber, #4433) [Link] (9 responses)

> So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

As was pointed out, if you tell them where to find the software, you are accepting liability for that software.

By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

If you try and hide that fact from your customers, it's a pretty open-and-shut case of fraud.

And your distributors will very rapidly cease to be distributors because they will be sick to death of explaining to customers "no your hardware may have a warranty, but it's the software that's the problem and that's nothing to do with us".

And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

And there's no come back under things like GATT, because the regulations aren't discriminatory - "If you're not prepared to provide a warranty for your goods, your customers won't want to buy your goods".

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:59 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

I don't follow.

Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

After all, the PC maker will stand behind _their_ product; if there's a manufacturing or safety defect, they'll fix it right up. The OS (or any of the application) is a product of a different company, after all.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:38 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

And you're being obtuse.

An OS-less PC is still a PC. If that's how it's described, there's no problem.

A smart doorbell with no software to make it smart is (in all likelihood) not even a functional doorbell!

If you sell it for what it is, what's the problem? If it needs software to "function as described", but the software isn't supplied with it, then it's dodgy. If it's sold as "A PC" and it comes without software, well the customer might be surprised, but it is as described. If it comes as "A Windows PC", and the customer is told "well, you'll have to get and install Windows yourself", then it's NOT as described (which is a whole 'nother fraud entirely ...).

At the end of the day, the current situation is that stuff is being sold fraudulently, because it's not as described, and the customer has no recourse because everybody is passing the buck. What's worse is that everybody knows this is happening, and nothing is done about it.

The whole point of the CRA is to force manufacturers - be it smart TVs, mobile phones, cars, doorbells, whatever - to provide guarantees that their kit will work "as described" out of the box, and more to the point CONTINUE to work as described. And given that one of the requirements for mobile phones (and many other devices) is security, that's rather important.

THAT is why my phone has no security - and nothing worth securing! I simply don't trust it to keep my secrets safe ...

Cheers,
Wol

Let's slow this down

Posted Dec 14, 2023 15:40 UTC (Thu) by corbet (editor, #1) [Link] (1 responses)

We don't need to be throwing insults at each other, please stop.

In general, this topic is approaching 200 comments, and I suspect most readers have long since tuned it out. We're clearly not going to resolve this here; can we try to wind it down?

Let's slow this down

Posted Dec 14, 2023 17:08 UTC (Thu) by Wol (subscriber, #4433) [Link]

Sorry Jon. This seems to be trending very much towards trolling territory :-(

Time to walk away.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:13 UTC (Thu) by pizza (subscriber, #46) [Link]

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR.

*laughs*

The entire bruhaha over RHEL rebuilders would beg to differ with you.

Heck, the entire F/OSS ecosystem would beg to differ with you.

Folks will only pay for software if forced to.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:15 UTC (Thu) by khim (subscriber, #9252) [Link] (3 responses)

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

Would it kill you to just do some fact-checking? You may find hundreds of offers of devices with FreeDOS and this number doesn't go down, as economy craters it only goes up. Because they are cheaper.

If you really believe these sellers are expecting that you would stay with FreeDOS in these devices I have nice bridge to sell you.

> By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

You may call it by any name you want but this is what's happening and what would continue to happen.

It would be interesting to see how quickly trend would become like in some other countries outside of EU where the majority of devices are sold in that fashion, but as users would be squeezed more and more it would happen with certain inevitability.

Your crazy idea to force all these sellers to indemnify Debian via CRA just wouldn't work, sorry.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:45 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

Right, but people are choosing those systems because they're cheaper, not because they're better.

And the bigger deal that's triggered action now is all the Internet-connected devices that aren't PCs; can you find me hundreds of offers of cars with ERA-GLONASS (or similar IP-connected system) hardware, but no software pre-installed on any of the many devices that interconnect to the ERA-GLONASS (or eCall, or other mobile IP gateway)? Or home WiFi routers sold without any software or firmware? Or washing machines, dishwashers, fridge-freezers and other "smart home" devices sold without software.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:06 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> Right, but people are choosing those systems because they're cheaper, not because they're better.

No -- They're choosing those systems because cheaper *is* better.

(As the saying goes: "fast, good, cheap; pick two" -- the choice made is by definition the "better" choice here, because "better" is relative to the person making the choice)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:09 UTC (Thu) by farnz (subscriber, #17727) [Link]

The majority of people I know are choosing more expensive systems with a pre-installed OS; the only people I know who are choosing FreeDOS systems already have an OS they want to install separately. Mostly, people are willing to pay a bit more money to avoid spending a lot of time getting frustrated by an OS installer (installing any OS is not trivial for non-technical people).

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:53 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you.

I am not physically located in the EU, but I have some EU clients to whom I provide support and consulting services [1] related to the F/OSS that I freely provide online. The plain text of the CRA [2] explicitly lists this as an example of a commercial activity, and as such, strips me of the blanket exemptions the CRA provides for F/OSS authors.

> At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed.

It's more than that -- Individually, each of these requirements probably isn't that big of a deal, but they add up to a substantial increase in overhead [3]. Worse yet, tasks that used to be directly billable were themselves turned into overhead that I will now be expected to provide as a matter of course. Then there's the matter of potential liability; I'm going to need a more substantial insurance policy that reflects the greater risks which further increases my overhead.

(Or I can just stop doing business with EU entities altogether, not because I'm a shady operator, but because the cost/benefit curve is shifting firmly into "just not worth the effort for a part time side gig" territory. Which will result in less F/OSS for everyone, not just the EU)

[1] Which I provide with a profit (as opposed to cost recovery) motive.
[2] Paragraph 10 of the latest marked-up version, which I quoted verbatim earlier in this thread in a reply to you. [4]
[3] I don't have a citation for this, but I read that official estimates were that compliance with the CRA would lead to an approximately 25% increase in overhead.
[4] https://lwn.net/Articles/954874/

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:02 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> (10) This Regulation applies only to products with digital elements made available on the market,

Which does not describe your consulting services, because they do not fit the definition of "available on the market", as far as I can tell. Do you publish your work on the internet, with a "come and buy it!" notice? Or do you do custom work for your clients AND THEY PUT IT IN THEIR PRODUCTS?

I get they may want more, but it's THEIR actions that incur liability, and if your contract says "here is the source you need, supplied under an Open Source licence, with Open Source disclaimers", then it's down to them to warrant that bugs will be fixed and fixes will be applied. And if they've got the source, they don't *NEED* you to do that. And you're free to publish your source on the internet, as a drive-by download, with no fear of the CRA.

And actually, I had a thought an hour or so ago. What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products! As far as I can tell, that doom hasn't arrived. What has HOPEFULLY arrived is that it's now a lot harder for people to argue "we didn't mean to" when they're discovered to be in blatant breach of copyright - "we didn't realise that was in there" simply lands them in trouble with the BoM regs instead of (or in addition to) copyright.

The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised". And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:41 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

>> (10) This Regulation applies only to products with digital elements made available on the market,

If "product" is limited exclusively to some sort of "physical good" then I retract my statements.

(However, if "product" can be pure software not supplied as part of a physical good, such as, say, Chrome, LibreOffice or Firefox) then I qualify just as much as they do; despite my several-orders-of-magnitude smaller operation.)

> What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products!

(BTW, I'm on the record here many, many times saying BoMs are a _very good_ thing, but the CRA goes far beyond that)

Yes, the doomsayers over here screamed bloody murder over some of the proposals for the same reasons as the earlier CRA drafts -- invalidating "as-is, no warranties whatsoever" clauses suddenly makes individuals on the hook for effectively unlimited liabilities for activities beyond their knowledge, much less control.

IIRC the extent of the "American Regs" so far are executive orders that set requirements for upcoming federal contracts.
frankly While there are "recommended best practices" there's nothing that mandates them for general B2B or B2C activities.
(IMO, insurance carriers are going to be the ones pushing this stuff forward, but forced arbitration clauses in EULAs have removed the main lever non-legislators have to drive change...)

> The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised".

The reason they don't already do these things is because it increases their costs considerably, which means they'd have to charge more. Potentially a _lot_ more.

I think the net practical effect of this is that domestic EU manufacturers (and importers of stuff manufactured elsewhere) will drastically cut back their advertised functionality/features while also significantly increasing their prices. It will lead to a round of industry consolidation as manufactures struggle to get to the scale where they have a chance of competing with already-established $megatech/$megacorp players that can easily eat a percent or two higher internal overhead.

> And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 17:17 UTC (Thu) by Wol (subscriber, #4433) [Link]

> > And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

> I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

That's what it says on my passport. That's not who I am. On my mother's side I'm Jamaican/German/(Scottish). I have very little connection with my father's side of the family (he died young), and while he may have been English my wife despairs I do not associate myself with that public persona - inward looking, petty minded, snobbishly superior ...

I'm more the Scot, proud of my heritage, proud of who I am, and eager to respect other people for being proud of who they are. NOT how I would describe the English (the gutter press lot, at any rate ...)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:53 UTC (Thu) by Wol (subscriber, #4433) [Link]

> In other words, a whole lot of additional regulation to ... accomplish nothing. Heck, if anyhting, it will make it _easier_ for pure software "products" to avoid liability.

Only if the supplier is not benefitting from the supply. So if I go and buy Microsoft Word from Currys, then Currys will make sure Microsoft signs a contract indemnifying Currys from CRA liability - because there most definitely is liability.

But if I download a load of games I don't pay for onto my phone from the Apple or Google store, then Apple or Google have a CRA obligation to "fix any known bugs" BECAUSE THEY BENEFIT FROM THE ADVERTISING. In practice, this will mean that they then demand from their suppliers (the games writers) that the games are secure, on pain of being kicked off the store.

This actually is probably a good analogy to forges - think of a market or a boot fair. If the market place is charging stall holders for the privilege of having a stall, then they have an obligation to make sure the stall holders are legal and above board. A boot fair charging £10 a pitch to any and everybody who turns up has a far lower duty of care, although they can't turn a blind eye to something illegal.

Plus "pure software products" don't seem to be the target of the CRA anyway. If it's a "pure software product", the CUSTOMER can choose whether they want it or not - if they don't they just don't buy it. But if I buy a smart doorbell, I don't have a choice about the quality of the software that comes with it. The purpose of the CRA is to make sure I don't face a choice of "insecure crap, insecure crap or insecure crap", because I want a physical item called a doorbell.

The whole point of this legislation is to TURN OFF COMMERCIAL DISTRIBUTION CHANNELS to suppliers who aren't prepared to stand by their product. And if those channels are non-commercial, run by volunteers, don't charge, whatever whatever then they are outside the scope of the CRA. And even if those channels ARE RUN by a commercial entity, if they are run as a public service and there is no easily traceable source of income to said commercial entity, then that's still outside the scope of the CRA. Which is why downloading Chrome from Google's own servers is exempt. If the recipient doesn't click on ads, if the recipient runs ad-blockers, heck if the recipient even JUST IGNORES ads, then Google don't benefit from that download.

As for "lots of additional regulation", how does that describe one line in a contract "I will make sure that my products are kept up to date with all known security fixes, and will be made available to you to pass on to anyone who bought it from you".

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 10:31 UTC (Thu) by farnz (subscriber, #17727) [Link]

In all other product cases, liability sticks with the last entity to touch the product before it was sold to the consumer, but that entity may have a claim on the previous entity in the chain; I don't believe that the CRA intends to change that.

So, taking the Lenovo laptop example; Lenovo are responsible for the pre-installed software, but not the rest of Debian, since they supplied the pre-installed software to you. If that includes Firefox, Lenovo are liable (to the limits of the CRA) for the pre-installed Firefox, and it's on Lenovo to ensure that you get offered updates to that in a timely fashion (noting that if you don't take the update, the CRA says Lenovo's liability has ended).

In turn, Lenovo may (and will, if they're sane) contract with someone to keep Debian up to date with a secure Firefox, and to pay for the liability if the latest version on offer to you incurs CRA liability. That entity may pay another entity, and so on, establishing a chain potentially all the way back to Mozilla as the original source of Firefox.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 15:47 UTC (Wed) by Wol (subscriber, #4433) [Link]

> My meager support business clearly qualifies.

Except it most definitely does NOT clearly qualify. It sounds like (and from what I remember) it is a *service* business. You supply a *service* to your customer, it is he who is making (manufacturing?) the multiple copies, and it is HE who is liable by ADVERTISING FOR SALE the results in the EU.

You have a B2B contract for services outside of the EU. There's no way that can qualify as "a manufacture or digital service made available on the EU market". You just make sure that your contract says you supply all your services in good faith, and you warrant to fix any problems for a reasonable fee (including maybe fixing your own mistakes for free?) as soon as is practicable once brought to your attention. Actually, that wording in the contract would probably get both you and your employer off the hook for any liability claims. A breach of that contract, on the other hand, all hell would probably break loose ...

Don't forget, unlike America, the EU tends to prioritise making sure history doesn't repeat itself. Demonstrate good faith, and you'll get away with a lot. The American system, on the other hand, tends to emphasise the letter of the law and encourages people trying to game it.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:17 UTC (Wed) by farnz (subscriber, #17727) [Link] (1 responses)

A charitable entity can hold trademarks without placing any products on the market. Heck, a company can make money selling components that are not considered to be "products on the market", since they are not, per the definition of "product" for the purposes of EU acquis, selling a product - they're selling a component of a product, and are thus exempted from most product safety regulations (as an example).

So, for example, I can sell a seatbelt tensioner in the EU market without "putting a product on the market", since the seatbelt tensioner is not considered a product; it's considered a "component of a product". If Volkswagen AG buy my component and integrate it into a product, they take on liability if my component fails to perform as promised; they almost certainly push that liability back onto me contractually, since they don't want to pay the penalties if I deliver crap.

Now, some EU states take different views on this to others; Germany, for example, makes it very difficult to sell something without "putting a product on the market". But the core principle is already present; when something is transferred to another business in a sufficiently incomplete state, it's no longer a "product", but a "component of a product", and liability can be disclaimed in the contract governing that transfer. Once you assemble a product (and everything sold to consumers is a product), you've got liability to worry about.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 11:53 UTC (Wed) by khim (subscriber, #9252) [Link]

> But the core principle is already present; when something is transferred to another business in a sufficiently incomplete state, it's no longer a "product", but a "component of a product", and liability can be disclaimed in the contract governing that transfer.

Yeah, that's similar to CRA's exceptions for hobbyists. But software is different from cars: “seatbelt tensioner” can not be picked up on some random backyard of some random person, while code produced by someone “just for fun” may become a basis for billions of devices.

That's why their tried to lower the bar for liabilities as much as feasible: otherwise the whole law would become a moot point: so much software would have no “owner” which may be held liable that it just wouldn't work.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 15:49 UTC (Wed) by kleptog (subscriber, #1183) [Link]

> Or, to put it more explicitly -- Debian-and-Gentoo-the-organizations hold (and actively use) EU Trademarks for the software products (eg "Debian GNU/Linux") they produce and actively make available in the EU.

Debian isn't actually selling software though. You can buy CDs/DVDs with free software on it. The pricing obviously does not relate to the value of the software being delivered. The licence for said software comes directly from the author, not Debian (the GPL is quite explicit in this).

Interestingly, I remember this argument in the past mostly being used with shareware. As in you would buy CDs full of shareware and it clearly stated on the packaging you were paying for the CD and the shipping to you, but not for anything actually on the CD (mostly because shareware forbade being sold for money).


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds