|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 23:23 UTC (Wed) by bluca (subscriber, #118303)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem

See this excellent comment from Wol below: https://lwn.net/Articles/954927/

In general, where the sources come from doesn't really matter. This is said explicitly in the regulation. Because what matters is who gives you a product that contains said software, and if that qualifies as a commercial activity or not. Assuming Mozilla has employees working on releasing and distributing said software directly to users via mozilla.org, which I'm sure it happens, and assuming they get more money the more users are running Firefox, which is plausible given the multi-millior dollars contract they have with Google w.r.t. being the default search engine, which is ads-based and thus impression-based (more users -> more cash), it's possible that it could be enough to meet the threshold - I don't know for sure, as it gets complicated at this point, with lots of money moving around and whatnot. The important question though is, would it matter? Does anybody believe that Mozilla wouldn't take full responsibility in delivering timely security fixes for their flagship product delivered from their direct distribution channels? Of course not. So, even if, what difference would it make, for anybody, if Mozilla had to do what it already does anyway because of a regulation?

So where does it make a difference? You cited Android and Google. Of course the law can't make Google liable if shoddy Android manufacturers ship known-broken devices with glaring, unpatched security holes, and refuse to do anything about it. Liability is with the phone vendor, if they sell directly, or the shop if there's an intermediary. So how would it happen that, in the end, the buck stops with Google and it's them who pays? Supply contracts. By forcing the seller to be responsible, and unable to disclaim liability, the regulation forces the seller to cover its back - this is normal practice, otherwise customer-facing sellers would be out of business a month after opening up shop. So one of the two things would happen: either J. Random Android Vendor goes out of business, and Google loses precious ads revenue that they need to survive, or J Random Android Vendor and Google get their act together and comply with the CRA and supply security updates for their products. Substitute Android and Google for any consumer product using software sold in the EU, and you get the idea of where the CRA is coming from and what it wants to address.


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 13, 2023 23:39 UTC (Wed) by pizza (subscriber, #46) [Link] (30 responses)

> Of course not. So, even if, what difference would it make, for anybody, if Mozilla had to do what it already does anyway because of a regulation?

My question has to do with Firefox obtained through channels other than Mozilla, and how that changes *who is responsible* for delivering timely updates when, say, it was obtained through through Debian.

Especially when Debian's release has changes versus what Mozilla ships. And might even have security flaws not present in what Mozilla ships (there have been some high profile cases of this happening). Since it can't be Mozilla, who becomes the responsible party under the CRA in this scenario, if not "Debian" ? The mirror operators? The package maintainers? Or the caveat-emptor end-user who chose to install it?

(And what if Debian is pre-installed on a, say, Lenovo laptop? Does Lenovo now bear the full responsibility of ensuring Firefox-and-everything-else-in-Debian is kept up to date?)

Yes, this is all VERY messy, and that's why we're trying to figure out how this is supposed to work.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 8:58 UTC (Thu) by Wol (subscriber, #4433) [Link] (28 responses)

You obtained Firefox from Debian. So the regulation is nice and simple - IFF there is liability, it rests with Debian. End of.

Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

So it's not commercial, there is no contract, no liability, and Debian is on the hook for nothing. Meanwhile, Firefox the organisation does not have any involvement in this transaction whatsoever, so also has no liability.

If it breaks, you get to keep the pieces ... :-)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 9:58 UTC (Thu) by bluca (subscriber, #118303) [Link] (7 responses)

And to add to that:

> (And what if Debian is pre-installed on a, say, Lenovo laptop? Does Lenovo now bear the full responsibility of ensuring Firefox-and-everything-else-in-Debian is kept up to date?)

Yes, Lenovo is responsible in that case, and they need to ensure you can get updates. It doesn't mean Lenovo has to send you the updates directly though. In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it doesn't sell laptops with EOL versions of Fedora pre-installed. That's a good thing!

Same applies to Dell and their Ubuntu-based laptops.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:24 UTC (Thu) by pizza (subscriber, #46) [Link] (6 responses)

> Yes, Lenovo is responsible in that case, and they need to ensure you can get updates. It doesn't mean Lenovo has to send you the updates directly though

They don't have to do it directly, but they are legally obligated to ensure that _someone_ will provide those updates. Which means either doing it themselves, or (far more likely) entering into a binding contract with an entity that will.

> In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it
doesn't sell laptops with EOL versions of Fedora pre-installed.

It's not as simple as "don't sell laptops with EOL software" -- Fedora's EOL is 13 months after initial release. IIRC in the EU 24-month warranties are the minimum, and that applies from date of _sale_. That's a (minumum) 11-month coverage gap that Lenovo, not Fedora, not Firefox, will be on the hook for.

I'm afraid that "In practice" will result in one or two companies [1] utterly dominating the market, because they'll be the only ones with the resources to provide those guarantees.

Meanwhile. Given that warranty/support periods _do_ expire, and the tendency for folks to use "digital elements" long after said warranty/etc has expired, I can't help but wonder if this is going to make any practical security difference in the end.

[1] I was originally going to say someone like Red Hat, but it's more likely to be someone like Microsoft and Amazon.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (5 responses)

There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:09 UTC (Thu) by pizza (subscriber, #46) [Link] (4 responses)

> There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

That presumes Fedora 53 is a strict superset of the software and functionality contained within Fedora 52. That is almost never the case.

If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

(There's already legal precedent for this; Sony had to pay out a large amount of money because their "necessary update" took away advertised-on-the-tin functionality)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:29 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

That is a separate issue; the CRA says you can take away functionality in an update and lose liability that way, but does not protect you from being sued for taking away functionality.

And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:03 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

In that case, why bother with installing Minimal Anything? Just ship FreeDOS as part of the system firmware and let the buyer assume all responsibility.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:08 UTC (Thu) by farnz (subscriber, #17727) [Link]

That works for a PC or laptop (albeit that you can't, under other consumer laws, claim the system has functionality that doesn't work under FreeDOS - so you can say that the device has an Intel AX201 WiFi chipset, but not that it has WiFi 6 support), but not for the vast market of IoT devices where the S in IoT stands for their commitment to security, where people don't care about the software, they care about the function.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:37 UTC (Thu) by Wol (subscriber, #4433) [Link]

> If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

That presumes the system is supplied "With Fedora *52*". Suppliers will rapidly learn. It will be supplied "With Fedora".

As far as Sony were concerned they actively advertised the PS/2 could run Linux. A lot of people bought it BECAUSE of the advertising. That was a blatant bait-n-switch. If Dell or Lenovo advertise "with Fedora", and Fedora drop a load of functionality between 52 and 53, that's not Dell or Lenovo's problem.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:02 UTC (Thu) by pizza (subscriber, #46) [Link] (19 responses)

> Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

By this logic, Google Chrome is not commercial either.

> If it breaks, you get to keep the pieces ... :-)

In other words, a whole lot of additional regulation to ... accomplish nothing. Heck, if anyhting, it will make it _easier_ for pure software "products" to avoid liability.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:29 UTC (Thu) by Wol (subscriber, #4433) [Link] (17 responses)

> > Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

> By this logic, Google Chrome is not commercial either.

AND THAT IS THE POINT!

If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

If, on the other hand, you bought a phone with Chrome pre-installed, then the SHOP you bought it from is liable for making sure you have access to updates. If they can't pass that liability onto Google, or Samsung, or Apple, then they will simply refuse to stock that phone. Which will mean either (a) you will be forced to buy direct from the manufacturer's own distribution system in the EU, and it'll be the manufacturer on the hook because they're the shop you bought it from, or (b) you will have to buy it from China or wherever and just accept the fact that you have no comeback whatsoever if your £1000 i-phone or Pixel-8 or whatever dies the day after it arrives.

Not many customers will accept option (b), and it only takes one manufacturer to say "we're happy with the CRA", and the rest of them will be forced into line as that first manufacturer basically cleans up in the European market.

So no, it's not that Google Chrome is commercial or not, it's whether Google Chrome is part of a commercial product. As others have repeatedly said, it all depends on HOW you acquire whatever digital product it is. And manufacturers will be forced to provide security updates yada yada because it they don't their distribution channels will go "toooo risky, mate!", and slam the doors shut.

You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you. At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed, but that's a contract matter between you and your customers. And if you have a problem with that, you're exactly the sort of supplier who shouldn't be going anywhere near anything remotely security-sensitive. Which again is the point. And if you do have a problem with that, any of your customers who supply to the EU will either have to certify it themselves (which is okay), or find another supplier who will certify their *component* products.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:47 UTC (Thu) by pizza (subscriber, #46) [Link] (12 responses)

> AND THAT IS THE POINT!
> If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

I'm sorry, but that's... completely absurd. I'm not _disagreeing_ with your assessment, but if accurate, it provides an Ever-Given-sized loophole for "obviously commercial" concerns to escape liability for security flaws in software they provide to folks in the EU. And it's a loophole so large that it makes this whole CRA exercise into a complete farce.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (1 responses)

You have to require the user to obtain and install the software themselves, and you cannot direct them to the software to install - they've got to find it themselves.

It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS. Sell a bare phone with no software at all (not even a bootloader), and you're not on the hook under the CRA: pre-install Android, and you're on the hook for the entire pre-installed OS and all its parts. Tell the user how to install Android on the phone, and now you're on the hook for the variant on Android you tell them to install.

And yes, this is a loophole; the point is that a device with software is more valuable to the end user than a device without software, and you're not (for example) going to sell a car that needs software and tell the user "yep, you've got the hardware, go build or find the software elsewhere". Even if you do, many people will then buy the software themselves, and if they buy from an EU supplier, that supplier is on the hook.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:39 UTC (Thu) by Wol (subscriber, #4433) [Link]

> It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS.

And importantly, if the user installs gentoo over the top of ChromeOS - never mind the fact that ChromeOS is gentoo "under the bonnet" - you're not on the hook for gentoo. You're on the hook for whatever you supplied, and that's it.

Oh - and I guess if you try and avoid liability by saying "Oh, you'll need to install ChromeOS on this in order to make it work" - so you're not telling them exactly what they need - you've now dropped your distributor completely in it because if they mess up installing ChromeOS they can return the device as "not fit for purpose". That really will upset your distributors.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:33 UTC (Thu) by Wol (subscriber, #4433) [Link] (9 responses)

> So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

As was pointed out, if you tell them where to find the software, you are accepting liability for that software.

By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

If you try and hide that fact from your customers, it's a pretty open-and-shut case of fraud.

And your distributors will very rapidly cease to be distributors because they will be sick to death of explaining to customers "no your hardware may have a warranty, but it's the software that's the problem and that's nothing to do with us".

And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

And there's no come back under things like GATT, because the regulations aren't discriminatory - "If you're not prepared to provide a warranty for your goods, your customers won't want to buy your goods".

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:59 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

I don't follow.

Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

After all, the PC maker will stand behind _their_ product; if there's a manufacturing or safety defect, they'll fix it right up. The OS (or any of the application) is a product of a different company, after all.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:38 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

And you're being obtuse.

An OS-less PC is still a PC. If that's how it's described, there's no problem.

A smart doorbell with no software to make it smart is (in all likelihood) not even a functional doorbell!

If you sell it for what it is, what's the problem? If it needs software to "function as described", but the software isn't supplied with it, then it's dodgy. If it's sold as "A PC" and it comes without software, well the customer might be surprised, but it is as described. If it comes as "A Windows PC", and the customer is told "well, you'll have to get and install Windows yourself", then it's NOT as described (which is a whole 'nother fraud entirely ...).

At the end of the day, the current situation is that stuff is being sold fraudulently, because it's not as described, and the customer has no recourse because everybody is passing the buck. What's worse is that everybody knows this is happening, and nothing is done about it.

The whole point of the CRA is to force manufacturers - be it smart TVs, mobile phones, cars, doorbells, whatever - to provide guarantees that their kit will work "as described" out of the box, and more to the point CONTINUE to work as described. And given that one of the requirements for mobile phones (and many other devices) is security, that's rather important.

THAT is why my phone has no security - and nothing worth securing! I simply don't trust it to keep my secrets safe ...

Cheers,
Wol

Let's slow this down

Posted Dec 14, 2023 15:40 UTC (Thu) by corbet (editor, #1) [Link] (1 responses)

We don't need to be throwing insults at each other, please stop.

In general, this topic is approaching 200 comments, and I suspect most readers have long since tuned it out. We're clearly not going to resolve this here; can we try to wind it down?

Let's slow this down

Posted Dec 14, 2023 17:08 UTC (Thu) by Wol (subscriber, #4433) [Link]

Sorry Jon. This seems to be trending very much towards trolling territory :-(

Time to walk away.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:13 UTC (Thu) by pizza (subscriber, #46) [Link]

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR.

*laughs*

The entire bruhaha over RHEL rebuilders would beg to differ with you.

Heck, the entire F/OSS ecosystem would beg to differ with you.

Folks will only pay for software if forced to.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:15 UTC (Thu) by khim (subscriber, #9252) [Link] (3 responses)

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

Would it kill you to just do some fact-checking? You may find hundreds of offers of devices with FreeDOS and this number doesn't go down, as economy craters it only goes up. Because they are cheaper.

If you really believe these sellers are expecting that you would stay with FreeDOS in these devices I have nice bridge to sell you.

> By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

You may call it by any name you want but this is what's happening and what would continue to happen.

It would be interesting to see how quickly trend would become like in some other countries outside of EU where the majority of devices are sold in that fashion, but as users would be squeezed more and more it would happen with certain inevitability.

Your crazy idea to force all these sellers to indemnify Debian via CRA just wouldn't work, sorry.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:45 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

Right, but people are choosing those systems because they're cheaper, not because they're better.

And the bigger deal that's triggered action now is all the Internet-connected devices that aren't PCs; can you find me hundreds of offers of cars with ERA-GLONASS (or similar IP-connected system) hardware, but no software pre-installed on any of the many devices that interconnect to the ERA-GLONASS (or eCall, or other mobile IP gateway)? Or home WiFi routers sold without any software or firmware? Or washing machines, dishwashers, fridge-freezers and other "smart home" devices sold without software.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:06 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> Right, but people are choosing those systems because they're cheaper, not because they're better.

No -- They're choosing those systems because cheaper *is* better.

(As the saying goes: "fast, good, cheap; pick two" -- the choice made is by definition the "better" choice here, because "better" is relative to the person making the choice)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:09 UTC (Thu) by farnz (subscriber, #17727) [Link]

The majority of people I know are choosing more expensive systems with a pre-installed OS; the only people I know who are choosing FreeDOS systems already have an OS they want to install separately. Mostly, people are willing to pay a bit more money to avoid spending a lot of time getting frustrated by an OS installer (installing any OS is not trivial for non-technical people).

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:53 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you.

I am not physically located in the EU, but I have some EU clients to whom I provide support and consulting services [1] related to the F/OSS that I freely provide online. The plain text of the CRA [2] explicitly lists this as an example of a commercial activity, and as such, strips me of the blanket exemptions the CRA provides for F/OSS authors.

> At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed.

It's more than that -- Individually, each of these requirements probably isn't that big of a deal, but they add up to a substantial increase in overhead [3]. Worse yet, tasks that used to be directly billable were themselves turned into overhead that I will now be expected to provide as a matter of course. Then there's the matter of potential liability; I'm going to need a more substantial insurance policy that reflects the greater risks which further increases my overhead.

(Or I can just stop doing business with EU entities altogether, not because I'm a shady operator, but because the cost/benefit curve is shifting firmly into "just not worth the effort for a part time side gig" territory. Which will result in less F/OSS for everyone, not just the EU)

[1] Which I provide with a profit (as opposed to cost recovery) motive.
[2] Paragraph 10 of the latest marked-up version, which I quoted verbatim earlier in this thread in a reply to you. [4]
[3] I don't have a citation for this, but I read that official estimates were that compliance with the CRA would lead to an approximately 25% increase in overhead.
[4] https://lwn.net/Articles/954874/

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:02 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> (10) This Regulation applies only to products with digital elements made available on the market,

Which does not describe your consulting services, because they do not fit the definition of "available on the market", as far as I can tell. Do you publish your work on the internet, with a "come and buy it!" notice? Or do you do custom work for your clients AND THEY PUT IT IN THEIR PRODUCTS?

I get they may want more, but it's THEIR actions that incur liability, and if your contract says "here is the source you need, supplied under an Open Source licence, with Open Source disclaimers", then it's down to them to warrant that bugs will be fixed and fixes will be applied. And if they've got the source, they don't *NEED* you to do that. And you're free to publish your source on the internet, as a drive-by download, with no fear of the CRA.

And actually, I had a thought an hour or so ago. What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products! As far as I can tell, that doom hasn't arrived. What has HOPEFULLY arrived is that it's now a lot harder for people to argue "we didn't mean to" when they're discovered to be in blatant breach of copyright - "we didn't realise that was in there" simply lands them in trouble with the BoM regs instead of (or in addition to) copyright.

The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised". And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:41 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

>> (10) This Regulation applies only to products with digital elements made available on the market,

If "product" is limited exclusively to some sort of "physical good" then I retract my statements.

(However, if "product" can be pure software not supplied as part of a physical good, such as, say, Chrome, LibreOffice or Firefox) then I qualify just as much as they do; despite my several-orders-of-magnitude smaller operation.)

> What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products!

(BTW, I'm on the record here many, many times saying BoMs are a _very good_ thing, but the CRA goes far beyond that)

Yes, the doomsayers over here screamed bloody murder over some of the proposals for the same reasons as the earlier CRA drafts -- invalidating "as-is, no warranties whatsoever" clauses suddenly makes individuals on the hook for effectively unlimited liabilities for activities beyond their knowledge, much less control.

IIRC the extent of the "American Regs" so far are executive orders that set requirements for upcoming federal contracts.
frankly While there are "recommended best practices" there's nothing that mandates them for general B2B or B2C activities.
(IMO, insurance carriers are going to be the ones pushing this stuff forward, but forced arbitration clauses in EULAs have removed the main lever non-legislators have to drive change...)

> The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised".

The reason they don't already do these things is because it increases their costs considerably, which means they'd have to charge more. Potentially a _lot_ more.

I think the net practical effect of this is that domestic EU manufacturers (and importers of stuff manufactured elsewhere) will drastically cut back their advertised functionality/features while also significantly increasing their prices. It will lead to a round of industry consolidation as manufactures struggle to get to the scale where they have a chance of competing with already-established $megatech/$megacorp players that can easily eat a percent or two higher internal overhead.

> And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 17:17 UTC (Thu) by Wol (subscriber, #4433) [Link]

> > And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

> I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

That's what it says on my passport. That's not who I am. On my mother's side I'm Jamaican/German/(Scottish). I have very little connection with my father's side of the family (he died young), and while he may have been English my wife despairs I do not associate myself with that public persona - inward looking, petty minded, snobbishly superior ...

I'm more the Scot, proud of my heritage, proud of who I am, and eager to respect other people for being proud of who they are. NOT how I would describe the English (the gutter press lot, at any rate ...)

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:53 UTC (Thu) by Wol (subscriber, #4433) [Link]

> In other words, a whole lot of additional regulation to ... accomplish nothing. Heck, if anyhting, it will make it _easier_ for pure software "products" to avoid liability.

Only if the supplier is not benefitting from the supply. So if I go and buy Microsoft Word from Currys, then Currys will make sure Microsoft signs a contract indemnifying Currys from CRA liability - because there most definitely is liability.

But if I download a load of games I don't pay for onto my phone from the Apple or Google store, then Apple or Google have a CRA obligation to "fix any known bugs" BECAUSE THEY BENEFIT FROM THE ADVERTISING. In practice, this will mean that they then demand from their suppliers (the games writers) that the games are secure, on pain of being kicked off the store.

This actually is probably a good analogy to forges - think of a market or a boot fair. If the market place is charging stall holders for the privilege of having a stall, then they have an obligation to make sure the stall holders are legal and above board. A boot fair charging £10 a pitch to any and everybody who turns up has a far lower duty of care, although they can't turn a blind eye to something illegal.

Plus "pure software products" don't seem to be the target of the CRA anyway. If it's a "pure software product", the CUSTOMER can choose whether they want it or not - if they don't they just don't buy it. But if I buy a smart doorbell, I don't have a choice about the quality of the software that comes with it. The purpose of the CRA is to make sure I don't face a choice of "insecure crap, insecure crap or insecure crap", because I want a physical item called a doorbell.

The whole point of this legislation is to TURN OFF COMMERCIAL DISTRIBUTION CHANNELS to suppliers who aren't prepared to stand by their product. And if those channels are non-commercial, run by volunteers, don't charge, whatever whatever then they are outside the scope of the CRA. And even if those channels ARE RUN by a commercial entity, if they are run as a public service and there is no easily traceable source of income to said commercial entity, then that's still outside the scope of the CRA. Which is why downloading Chrome from Google's own servers is exempt. If the recipient doesn't click on ads, if the recipient runs ad-blockers, heck if the recipient even JUST IGNORES ads, then Google don't benefit from that download.

As for "lots of additional regulation", how does that describe one line in a contract "I will make sure that my products are kept up to date with all known security fixes, and will be made available to you to pass on to anyone who bought it from you".

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 10:31 UTC (Thu) by farnz (subscriber, #17727) [Link]

In all other product cases, liability sticks with the last entity to touch the product before it was sold to the consumer, but that entity may have a claim on the previous entity in the chain; I don't believe that the CRA intends to change that.

So, taking the Lenovo laptop example; Lenovo are responsible for the pre-installed software, but not the rest of Debian, since they supplied the pre-installed software to you. If that includes Firefox, Lenovo are liable (to the limits of the CRA) for the pre-installed Firefox, and it's on Lenovo to ensure that you get offered updates to that in a timely fashion (noting that if you don't take the update, the CRA says Lenovo's liability has ended).

In turn, Lenovo may (and will, if they're sane) contract with someone to keep Debian up to date with a secure Firefox, and to pay for the liability if the latest version on offer to you incurs CRA liability. That entity may pay another entity, and so on, establishing a chain potentially all the way back to Mozilla as the original source of Firefox.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds