zlacker

[return to "Open source liability is coming"]
1. sevagh+F6[view] [source] 2023-12-29 18:40:30
>>daniel+(OP)
I find this article and the reactions here confusing. This seems to me like unequivocally a good thing for open-source devs.

Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so harm to our customers is not our fault!"

◧◩
2. omnico+98[view] [source] 2023-12-29 18:46:10
>>sevagh+F6
The article is misleading unless you read the whole thing and the reactions are standard knee-jerk ones from HN users that didn't need to read past "EU" to assume the worst possible misinterpretation.
◧◩◪
3. sevagh+J9[view] [source] 2023-12-29 18:53:00
>>omnico+98
Yes, the author of the article is all over the place

>But what if you’re just part of a collaborative open source project, give away your app, or if there’s open source code in the product you put on the market? Who gets blamed when open source might be the heart of the problem?

Every other sentence is dripping in "sympathy for open-source creators", but buried in the subtext is "sympathy for the innocent commercial vendors who decided to rely on open-source projects."

>So, how is open-source software implicated? If a commercial software product causes harm, whoever put the software on the market will soon be strictly liable.

Good!

>You will need to prove that your code wasn’t to blame to escape the costs. But what if you’ve embedded open-source code, used open-source tools, or called open-source APIs? Under the pending rules, you’d be liable for any errors in those sources as well, regardless of whether you directly contributed or not.

Better! Now a big evil company _can't_ pass the buck to the unpaid hobby project creator!

◧◩◪◨
4. curt15+3k[view] [source] 2023-12-29 19:50:09
>>sevagh+J9
So can we expect popular yet understaffed open source software -- like OpenSSL -- to get a lot of paid code review or patches?
◧◩◪◨⬒
5. mistri+AB[view] [source] 2023-12-29 21:36:48
>>curt15+3k
expect new, certified companies with security and finance, to become the officially required caretakers along with many fees; expect new monetized systems to distribute security patches passed through new bureaucracies, with logging of the government ID of all recipients; expect the restriction of new security patches to authorized users only.
[go to top]