Bottomley: Solving the Looming Developer Liability Problem
Bottomley: Solving the Looming Developer Liability Problem
Posted Dec 13, 2023 23:23 UTC (Wed) by bluca (subscriber, #118303)In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem
In general, where the sources come from doesn't really matter. This is said explicitly in the regulation. Because what matters is who gives you a product that contains said software, and if that qualifies as a commercial activity or not. Assuming Mozilla has employees working on releasing and distributing said software directly to users via mozilla.org, which I'm sure it happens, and assuming they get more money the more users are running Firefox, which is plausible given the multi-millior dollars contract they have with Google w.r.t. being the default search engine, which is ads-based and thus impression-based (more users -> more cash), it's possible that it could be enough to meet the threshold - I don't know for sure, as it gets complicated at this point, with lots of money moving around and whatnot. The important question though is, would it matter? Does anybody believe that Mozilla wouldn't take full responsibility in delivering timely security fixes for their flagship product delivered from their direct distribution channels? Of course not. So, even if, what difference would it make, for anybody, if Mozilla had to do what it already does anyway because of a regulation?
So where does it make a difference? You cited Android and Google. Of course the law can't make Google liable if shoddy Android manufacturers ship known-broken devices with glaring, unpatched security holes, and refuse to do anything about it. Liability is with the phone vendor, if they sell directly, or the shop if there's an intermediary. So how would it happen that, in the end, the buck stops with Google and it's them who pays? Supply contracts. By forcing the seller to be responsible, and unable to disclaim liability, the regulation forces the seller to cover its back - this is normal practice, otherwise customer-facing sellers would be out of business a month after opening up shop. So one of the two things would happen: either J. Random Android Vendor goes out of business, and Google loses precious ads revenue that they need to survive, or J Random Android Vendor and Google get their act together and comply with the CRA and supply security updates for their products. Substitute Android and Google for any consumer product using software sold in the EU, and you get the idea of where the CRA is coming from and what it wants to address.
