|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:29 UTC (Thu) by Wol (subscriber, #4433)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem

> > Was it a commercial transaction? Did you download it off a website, and Debian has no idea you've done so? In the NORMAL COURSE OF EVENTS would they go through their logs digging for downloads to see who downloaded what? I think the answer here is clearly "no", which means it's not commercial.

> By this logic, Google Chrome is not commercial either.

AND THAT IS THE POINT!

If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

If, on the other hand, you bought a phone with Chrome pre-installed, then the SHOP you bought it from is liable for making sure you have access to updates. If they can't pass that liability onto Google, or Samsung, or Apple, then they will simply refuse to stock that phone. Which will mean either (a) you will be forced to buy direct from the manufacturer's own distribution system in the EU, and it'll be the manufacturer on the hook because they're the shop you bought it from, or (b) you will have to buy it from China or wherever and just accept the fact that you have no comeback whatsoever if your £1000 i-phone or Pixel-8 or whatever dies the day after it arrives.

Not many customers will accept option (b), and it only takes one manufacturer to say "we're happy with the CRA", and the rest of them will be forced into line as that first manufacturer basically cleans up in the European market.

So no, it's not that Google Chrome is commercial or not, it's whether Google Chrome is part of a commercial product. As others have repeatedly said, it all depends on HOW you acquire whatever digital product it is. And manufacturers will be forced to provide security updates yada yada because it they don't their distribution channels will go "toooo risky, mate!", and slam the doors shut.

You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you. At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed, but that's a contract matter between you and your customers. And if you have a problem with that, you're exactly the sort of supplier who shouldn't be going anywhere near anything remotely security-sensitive. Which again is the point. And if you do have a problem with that, any of your customers who supply to the EU will either have to certify it themselves (which is okay), or find another supplier who will certify their *component* products.

Cheers,
Wol


to post comments

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:47 UTC (Thu) by pizza (subscriber, #46) [Link] (12 responses)

> AND THAT IS THE POINT!
> If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.

So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

I'm sorry, but that's... completely absurd. I'm not _disagreeing_ with your assessment, but if accurate, it provides an Ever-Given-sized loophole for "obviously commercial" concerns to escape liability for security flaws in software they provide to folks in the EU. And it's a loophole so large that it makes this whole CRA exercise into a complete farce.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:59 UTC (Thu) by farnz (subscriber, #17727) [Link] (1 responses)

You have to require the user to obtain and install the software themselves, and you cannot direct them to the software to install - they've got to find it themselves.

It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS. Sell a bare phone with no software at all (not even a bootloader), and you're not on the hook under the CRA: pre-install Android, and you're on the hook for the entire pre-installed OS and all its parts. Tell the user how to install Android on the phone, and now you're on the hook for the variant on Android you tell them to install.

And yes, this is a loophole; the point is that a device with software is more valuable to the end user than a device without software, and you're not (for example) going to sell a car that needs software and tell the user "yep, you've got the hardware, go build or find the software elsewhere". Even if you do, many people will then buy the software themselves, and if they buy from an EU supplier, that supplier is on the hook.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:39 UTC (Thu) by Wol (subscriber, #4433) [Link]

> It means (for example) that if you sell a laptop with no OS installed, you're not on the hook for anything other than the firmware; if you sell the laptop with ChromeOS preinstalled, you're on the hook for ChromeOS.

And importantly, if the user installs gentoo over the top of ChromeOS - never mind the fact that ChromeOS is gentoo "under the bonnet" - you're not on the hook for gentoo. You're on the hook for whatever you supplied, and that's it.

Oh - and I guess if you try and avoid liability by saying "Oh, you'll need to install ChromeOS on this in order to make it work" - so you're not telling them exactly what they need - you've now dropped your distributor completely in it because if they mess up installing ChromeOS they can return the device as "not fit for purpose". That really will upset your distributors.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:33 UTC (Thu) by Wol (subscriber, #4433) [Link] (9 responses)

> So all you have to do to avoid liability under the CRA is to require the user to install software themselves (and perhaps downloaded from a server not physically within the EU?)

But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

As was pointed out, if you tell them where to find the software, you are accepting liability for that software.

By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

If you try and hide that fact from your customers, it's a pretty open-and-shut case of fraud.

And your distributors will very rapidly cease to be distributors because they will be sick to death of explaining to customers "no your hardware may have a warranty, but it's the software that's the problem and that's nothing to do with us".

And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

And there's no come back under things like GATT, because the regulations aren't discriminatory - "If you're not prepared to provide a warranty for your goods, your customers won't want to buy your goods".

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:59 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> But by FORCING the customer to FIND the software themselves, you're making it clear to the customer that you are dodging liability.

I don't follow.

Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

After all, the PC maker will stand behind _their_ product; if there's a manufacturing or safety defect, they'll fix it right up. The OS (or any of the application) is a product of a different company, after all.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:38 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> Is a PC maker selling an OS-less PC "dodging liability"? Or providing "consumer choice"?

And you're being obtuse.

An OS-less PC is still a PC. If that's how it's described, there's no problem.

A smart doorbell with no software to make it smart is (in all likelihood) not even a functional doorbell!

If you sell it for what it is, what's the problem? If it needs software to "function as described", but the software isn't supplied with it, then it's dodgy. If it's sold as "A PC" and it comes without software, well the customer might be surprised, but it is as described. If it comes as "A Windows PC", and the customer is told "well, you'll have to get and install Windows yourself", then it's NOT as described (which is a whole 'nother fraud entirely ...).

At the end of the day, the current situation is that stuff is being sold fraudulently, because it's not as described, and the customer has no recourse because everybody is passing the buck. What's worse is that everybody knows this is happening, and nothing is done about it.

The whole point of the CRA is to force manufacturers - be it smart TVs, mobile phones, cars, doorbells, whatever - to provide guarantees that their kit will work "as described" out of the box, and more to the point CONTINUE to work as described. And given that one of the requirements for mobile phones (and many other devices) is security, that's rather important.

THAT is why my phone has no security - and nothing worth securing! I simply don't trust it to keep my secrets safe ...

Cheers,
Wol

Let's slow this down

Posted Dec 14, 2023 15:40 UTC (Thu) by corbet (editor, #1) [Link] (1 responses)

We don't need to be throwing insults at each other, please stop.

In general, this topic is approaching 200 comments, and I suspect most readers have long since tuned it out. We're clearly not going to resolve this here; can we try to wind it down?

Let's slow this down

Posted Dec 14, 2023 17:08 UTC (Thu) by Wol (subscriber, #4433) [Link]

Sorry Jon. This seems to be trending very much towards trolling territory :-(

Time to walk away.

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:13 UTC (Thu) by pizza (subscriber, #46) [Link]

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR.

*laughs*

The entire bruhaha over RHEL rebuilders would beg to differ with you.

Heck, the entire F/OSS ecosystem would beg to differ with you.

Folks will only pay for software if forced to.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:15 UTC (Thu) by khim (subscriber, #9252) [Link] (3 responses)

> And lastly, supply of software is a SERVICE that customers are willing to PAY FOR. If you're not prepared to let an EU-based supplier supply (AND WARRANTY) your software, some other manufacturer will, and you'll very rapidly find yourself frozen out of the EU. Nobody will want to buy your product, because they will just not trust it.

Would it kill you to just do some fact-checking? You may find hundreds of offers of devices with FreeDOS and this number doesn't go down, as economy craters it only goes up. Because they are cheaper.

If you really believe these sellers are expecting that you would stay with FreeDOS in these devices I have nice bridge to sell you.

> By FORCING them to download from OUTSIDE the EU, you're making it clear that you are dodging liability.

You may call it by any name you want but this is what's happening and what would continue to happen.

It would be interesting to see how quickly trend would become like in some other countries outside of EU where the majority of devices are sold in that fashion, but as users would be squeezed more and more it would happen with certain inevitability.

Your crazy idea to force all these sellers to indemnify Debian via CRA just wouldn't work, sorry.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 15:45 UTC (Thu) by farnz (subscriber, #17727) [Link] (2 responses)

Right, but people are choosing those systems because they're cheaper, not because they're better.

And the bigger deal that's triggered action now is all the Internet-connected devices that aren't PCs; can you find me hundreds of offers of cars with ERA-GLONASS (or similar IP-connected system) hardware, but no software pre-installed on any of the many devices that interconnect to the ERA-GLONASS (or eCall, or other mobile IP gateway)? Or home WiFi routers sold without any software or firmware? Or washing machines, dishwashers, fridge-freezers and other "smart home" devices sold without software.

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:06 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

> Right, but people are choosing those systems because they're cheaper, not because they're better.

No -- They're choosing those systems because cheaper *is* better.

(As the saying goes: "fast, good, cheap; pick two" -- the choice made is by definition the "better" choice here, because "better" is relative to the person making the choice)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:09 UTC (Thu) by farnz (subscriber, #17727) [Link]

The majority of people I know are choosing more expensive systems with a pre-installed OS; the only people I know who are choosing FreeDOS systems already have an OS they want to install separately. Mostly, people are willing to pay a bit more money to avoid spending a lot of time getting frustrated by an OS installer (installing any OS is not trivial for non-technical people).

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 14:53 UTC (Thu) by pizza (subscriber, #46) [Link] (3 responses)

> You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you.

I am not physically located in the EU, but I have some EU clients to whom I provide support and consulting services [1] related to the F/OSS that I freely provide online. The plain text of the CRA [2] explicitly lists this as an example of a commercial activity, and as such, strips me of the blanket exemptions the CRA provides for F/OSS authors.

> At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed.

It's more than that -- Individually, each of these requirements probably isn't that big of a deal, but they add up to a substantial increase in overhead [3]. Worse yet, tasks that used to be directly billable were themselves turned into overhead that I will now be expected to provide as a matter of course. Then there's the matter of potential liability; I'm going to need a more substantial insurance policy that reflects the greater risks which further increases my overhead.

(Or I can just stop doing business with EU entities altogether, not because I'm a shady operator, but because the cost/benefit curve is shifting firmly into "just not worth the effort for a part time side gig" territory. Which will result in less F/OSS for everyone, not just the EU)

[1] Which I provide with a profit (as opposed to cost recovery) motive.
[2] Paragraph 10 of the latest marked-up version, which I quoted verbatim earlier in this thread in a reply to you. [4]
[3] I don't have a citation for this, but I read that official estimates were that compliance with the CRA would lead to an approximately 25% increase in overhead.
[4] https://lwn.net/Articles/954874/

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:02 UTC (Thu) by Wol (subscriber, #4433) [Link] (2 responses)

> (10) This Regulation applies only to products with digital elements made available on the market,

Which does not describe your consulting services, because they do not fit the definition of "available on the market", as far as I can tell. Do you publish your work on the internet, with a "come and buy it!" notice? Or do you do custom work for your clients AND THEY PUT IT IN THEIR PRODUCTS?

I get they may want more, but it's THEIR actions that incur liability, and if your contract says "here is the source you need, supplied under an Open Source licence, with Open Source disclaimers", then it's down to them to warrant that bugs will be fixed and fixes will be applied. And if they've got the source, they don't *NEED* you to do that. And you're free to publish your source on the internet, as a drive-by download, with no fear of the CRA.

And actually, I had a thought an hour or so ago. What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products! As far as I can tell, that doom hasn't arrived. What has HOPEFULLY arrived is that it's now a lot harder for people to argue "we didn't mean to" when they're discovered to be in blatant breach of copyright - "we didn't realise that was in there" simply lands them in trouble with the BoM regs instead of (or in addition to) copyright.

The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised". And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

Cheers,
Wol

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 16:41 UTC (Thu) by pizza (subscriber, #46) [Link] (1 responses)

>> (10) This Regulation applies only to products with digital elements made available on the market,

If "product" is limited exclusively to some sort of "physical good" then I retract my statements.

(However, if "product" can be pure software not supplied as part of a physical good, such as, say, Chrome, LibreOffice or Firefox) then I qualify just as much as they do; despite my several-orders-of-magnitude smaller operation.)

> What happened to those American regs about a software Bill Of Materials? All the doom-mongers saying it would be the end of Open Source? Just because it was mandating that people HAD to know what software was in their products!

(BTW, I'm on the record here many, many times saying BoMs are a _very good_ thing, but the CRA goes far beyond that)

Yes, the doomsayers over here screamed bloody murder over some of the proposals for the same reasons as the earlier CRA drafts -- invalidating "as-is, no warranties whatsoever" clauses suddenly makes individuals on the hook for effectively unlimited liabilities for activities beyond their knowledge, much less control.

IIRC the extent of the "American Regs" so far are executive orders that set requirements for upcoming federal contracts.
frankly While there are "recommended best practices" there's nothing that mandates them for general B2B or B2C activities.
(IMO, insurance carriers are going to be the ones pushing this stuff forward, but forced arbitration clauses in EULAs have removed the main lever non-legislators have to drive change...)

> The CRA is going to be an EQUALLY damn squib, as people begin to realise that all it is doing, is forcing them to do what they SHOULD be doing already - ie supplying products that are "secure by design" and "work as advertised".

The reason they don't already do these things is because it increases their costs considerably, which means they'd have to charge more. Potentially a _lot_ more.

I think the net practical effect of this is that domestic EU manufacturers (and importers of stuff manufactured elsewhere) will drastically cut back their advertised functionality/features while also significantly increasing their prices. It will lead to a round of industry consolidation as manufactures struggle to get to the scale where they have a chance of competing with already-established $megatech/$megacorp players that can easily eat a percent or two higher internal overhead.

> And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 17:17 UTC (Thu) by Wol (subscriber, #4433) [Link]

> > And if products DON'T fit that description, well, I'm a European who will be only too glad to see such shoddy crap forced off the market!

> I thought you were British, and thus no longer part of the European Market? (Sorry, couldn't resist)

That's what it says on my passport. That's not who I am. On my mother's side I'm Jamaican/German/(Scottish). I have very little connection with my father's side of the family (he died young), and while he may have been English my wife despairs I do not associate myself with that public persona - inward looking, petty minded, snobbishly superior ...

I'm more the Scot, proud of my heritage, proud of who I am, and eager to respect other people for being proud of who they are. NOT how I would describe the English (the gutter press lot, at any rate ...)

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds