|
|
Log in / Subscribe / Register

Bottomley: Solving the Looming Developer Liability Problem

Bottomley: Solving the Looming Developer Liability Problem

Posted Dec 14, 2023 13:53 UTC (Thu) by Wol (subscriber, #4433)
In reply to: Bottomley: Solving the Looming Developer Liability Problem by pizza
Parent article: Bottomley: Solving the Looming Developer Liability Problem

> In other words, a whole lot of additional regulation to ... accomplish nothing. Heck, if anyhting, it will make it _easier_ for pure software "products" to avoid liability.

Only if the supplier is not benefitting from the supply. So if I go and buy Microsoft Word from Currys, then Currys will make sure Microsoft signs a contract indemnifying Currys from CRA liability - because there most definitely is liability.

But if I download a load of games I don't pay for onto my phone from the Apple or Google store, then Apple or Google have a CRA obligation to "fix any known bugs" BECAUSE THEY BENEFIT FROM THE ADVERTISING. In practice, this will mean that they then demand from their suppliers (the games writers) that the games are secure, on pain of being kicked off the store.

This actually is probably a good analogy to forges - think of a market or a boot fair. If the market place is charging stall holders for the privilege of having a stall, then they have an obligation to make sure the stall holders are legal and above board. A boot fair charging £10 a pitch to any and everybody who turns up has a far lower duty of care, although they can't turn a blind eye to something illegal.

Plus "pure software products" don't seem to be the target of the CRA anyway. If it's a "pure software product", the CUSTOMER can choose whether they want it or not - if they don't they just don't buy it. But if I buy a smart doorbell, I don't have a choice about the quality of the software that comes with it. The purpose of the CRA is to make sure I don't face a choice of "insecure crap, insecure crap or insecure crap", because I want a physical item called a doorbell.

The whole point of this legislation is to TURN OFF COMMERCIAL DISTRIBUTION CHANNELS to suppliers who aren't prepared to stand by their product. And if those channels are non-commercial, run by volunteers, don't charge, whatever whatever then they are outside the scope of the CRA. And even if those channels ARE RUN by a commercial entity, if they are run as a public service and there is no easily traceable source of income to said commercial entity, then that's still outside the scope of the CRA. Which is why downloading Chrome from Google's own servers is exempt. If the recipient doesn't click on ads, if the recipient runs ad-blockers, heck if the recipient even JUST IGNORES ads, then Google don't benefit from that download.

As for "lots of additional regulation", how does that describe one line in a contract "I will make sure that my products are kept up to date with all known security fixes, and will be made available to you to pass on to anyone who bought it from you".

Cheers,
Wol


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds