|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:24 UTC (Thu) by pizza (subscriber, #46)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by bluca
Parent article: Bottomley: Solving the Looming Developer Liability Problem

> Yes, Lenovo is responsible in that case, and they need to ensure you can get updates. It doesn't mean Lenovo has to send you the updates directly though

They don't have to do it directly, but they are legally obligated to ensure that _someone_ will provide those updates. Which means either doing it themselves, or (far more likely) entering into a binding contract with an entity that will.

> In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it
doesn't sell laptops with EOL versions of Fedora pre-installed.

It's not as simple as "don't sell laptops with EOL software" -- Fedora's EOL is 13 months after initial release. IIRC in the EU 24-month warranties are the minimum, and that applies from date of _sale_. That's a (minumum) 11-month coverage gap that Lenovo, not Fedora, not Firefox, will be on the hook for.

I'm afraid that "In practice" will result in one or two companies [1] utterly dominating the market, because they'll be the only ones with the resources to provide those guarantees.

Meanwhile. Given that warranty/support periods _do_ expire, and the tendency for folks to use "digital elements" long after said warranty/etc has expired, I can't help but wonder if this is going to make any practical security difference in the end.

[1] I was originally going to say someone like Red Hat, but it's more likely to be someone like Microsoft and Amazon.


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (5 responses)

There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:09 UTC (Thu) by pizza (subscriber, #46) [Link] (4 responses)

> There's no coverage gap for the CRA; if I supply a laptop with Fedora 52 installed, and a month later, the laptop offers the buyer an update to Fedora 53, my liability ends if the user doesn't take the Fedora 53 update - they were offered an update, and chose not to take it. I'm only on the hook if you keep taking the updates that you're offered.

That presumes Fedora 53 is a strict superset of the software and functionality contained within Fedora 52. That is almost never the case.

If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

(There's already legal precedent for this; Sony had to pay out a large amount of money because their "necessary update" took away advertised-on-the-tin functionality)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:29 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

That is a separate issue; the CRA says you can take away functionality in an update and lose liability that way, but does not protect you from being sued for taking away functionality.

And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:03 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> And, in any case, you wouldn't be on the hook for all of the software in Fedora - only the bits you preinstalled. You could install a minimal Fedora 52, and that's what you're on the hook for.

In that case, why bother with installing Minimal Anything? Just ship FreeDOS as part of the system firmware and let the buyer assume all responsibility.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:08 UTC (Thu) by farnz (subscriber, #17727) [Link]

That works for a PC or laptop (albeit that you can't, under other consumer laws, claim the system has functionality that doesn't work under FreeDOS - so you can say that the device has an Intel AX201 WiFi chipset, but not that it has WiFi 6 support), but not for the vast market of IoT devices where the S in IoT stands for their commitment to security, where people don't care about the software, they care about the function.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:37 UTC (Thu) by Wol (subscriber, #4433) [Link]

> If you sell a system with F52, you're on the hook to support it in its entirety; you don't get to say "to get security updates for package/feature Y you have to agree to lose package/feature Z"

That presumes the system is supplied "With Fedora *52*". Suppliers will rapidly learn. It will be supplied "With Fedora".

As far as Sony were concerned they actively advertised the PS/2 could run Linux. A lot of people bought it BECAUSE of the advertising. That was a blatant bait-n-switch. If Dell or Lenovo advertise "with Fedora", and Fedora drop a load of functionality between 52 and 53, that's not Dell or Lenovo's problem.

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds