Bottomley: Solving the Looming Developer Liability Problem
Bottomley: Solving the Looming Developer Liability Problem
Posted Dec 14, 2023 13:29 UTC (Thu) by Wol (subscriber, #4433)In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem
> By this logic, Google Chrome is not commercial either.
AND THAT IS THE POINT!
If you download Chrome from Google's website, then you are responsible for keeping it up to date. YOU imported it into the EU (or whatever ...), YOU are liable.
If, on the other hand, you bought a phone with Chrome pre-installed, then the SHOP you bought it from is liable for making sure you have access to updates. If they can't pass that liability onto Google, or Samsung, or Apple, then they will simply refuse to stock that phone. Which will mean either (a) you will be forced to buy direct from the manufacturer's own distribution system in the EU, and it'll be the manufacturer on the hook because they're the shop you bought it from, or (b) you will have to buy it from China or wherever and just accept the fact that you have no comeback whatsoever if your £1000 i-phone or Pixel-8 or whatever dies the day after it arrives.
Not many customers will accept option (b), and it only takes one manufacturer to say "we're happy with the CRA", and the rest of them will be forced into line as that first manufacturer basically cleans up in the European market.
So no, it's not that Google Chrome is commercial or not, it's whether Google Chrome is part of a commercial product. As others have repeatedly said, it all depends on HOW you acquire whatever digital product it is. And manufacturers will be forced to provide security updates yada yada because it they don't their distribution channels will go "toooo risky, mate!", and slam the doors shut.
You're not in the EU. Your customers (to the best of my knowledge) are not in the EU. The CRA will not, CAN not, apply to you. At an absolute maximum, you may be asked to certify for the purposes of the CRA that your products are kept up to date and all known security bugs are fixed, but that's a contract matter between you and your customers. And if you have a problem with that, you're exactly the sort of supplier who shouldn't be going anywhere near anything remotely security-sensitive. Which again is the point. And if you do have a problem with that, any of your customers who supply to the EU will either have to certify it themselves (which is okay), or find another supplier who will certify their *component* products.
Cheers,
Wol
