Bottomley: Solving the Looming Developer Liability Problem
Bottomley: Solving the Looming Developer Liability Problem
Posted Dec 14, 2023 13:24 UTC (Thu) by pizza (subscriber, #46)In reply to: Bottomley: Solving the Looming Developer Liability Problem by bluca
Parent article: Bottomley: Solving the Looming Developer Liability Problem
They don't have to do it directly, but they are legally obligated to ensure that _someone_ will provide those updates. Which means either doing it themselves, or (far more likely) entering into a binding contract with an entity that will.
> In practice, again, there would be little difference: Lenovo's Linux laptop ship with a vanilla Fedora IIRC, which is perfectly able to deliver security updates out of the box and has always done so, so the only thing Lenovo has to ensure is that it
doesn't sell laptops with EOL versions of Fedora pre-installed.
It's not as simple as "don't sell laptops with EOL software" -- Fedora's EOL is 13 months after initial release. IIRC in the EU 24-month warranties are the minimum, and that applies from date of _sale_. That's a (minumum) 11-month coverage gap that Lenovo, not Fedora, not Firefox, will be on the hook for.
I'm afraid that "In practice" will result in one or two companies [1] utterly dominating the market, because they'll be the only ones with the resources to provide those guarantees.
Meanwhile. Given that warranty/support periods _do_ expire, and the tendency for folks to use "digital elements" long after said warranty/etc has expired, I can't help but wonder if this is going to make any practical security difference in the end.
[1] I was originally going to say someone like Red Hat, but it's more likely to be someone like Microsoft and Amazon.
