zlacker

[return to "Open source liability is coming"]
1. theLim+45[view] [source] 2023-12-29 18:31:53
>>daniel+(OP)
This is ridiculous, all blame/liability should lie with either the provider of commercial software who chooses to rely on open source software or the end user for relying on free/open source software.

I personally will not allow people in the EU to use any software I write going forward, I imagine other open source developers will take these steps as well.

◧◩
2. galdor+V6[view] [source] 2023-12-29 18:41:32
>>theLim+45
It seems the author is refering to the EU Cybersecurity Act that should be voted early 2024.

The last draft clearly excludes open source software as long as there is no commercial activity associated. If voted in this state, it won't affect the vast majority of developers releasing some code under an Open Source license. But it will wipe out all small businesses: if you're a solo company selling support or feature development on some Open Source software you wrote, paperwork and liability are just not worth it.

And good luck selling anything relying on existing Open Source libraries, because you're now liable for them too. Given the cost of a security audit, you may as well stop trying and just sell SaaS (which is explicitely excluded from the bill, funny).

Larger companies of course won't care and will continue shipping buggy software riddled with security holes because they can afford the paperwork and absorb the legal risk.

◧◩◪
3. Kon-Pe+Wc[view] [source] 2023-12-29 19:09:30
>>galdor+V6
> as long as there is no commercial activity associated

My recollection, from previous discussion on HN, is that the definition of "commercial activity" is far more broad than the open source community would like it to be. And by "open source community", I mean the people that run various foundations and non-profits and things like that.

I don't think that throwing up a virtual tip jar on your Github page counts, but offering paid support would. If you collect telemetry and then sell "usage insights" that would also count as commercial activity. Advertising on the download page is commercial activity. If you have a Patreon account? I actually don't know about that. Anyone know?

◧◩◪◨
4. galdor+8j[view] [source] 2023-12-29 19:46:01
>>Kon-Pe+Wc
Correct. I would be perfectly fine with some amount of control and liability proportional to the size of the company, excluding tiny ones as it is often the case.

With this new act, even selling 100€/month of support for a piece of software you are contributing to makes you subject to the full force of the bill (and the full force includes scary numbers, millions, with zero information on how precise amounts will be calculated).

We can only hope that it is not voted in this sorry state.

[go to top]