5 ms·
I am not a lawyer (very definitely not) and may have missed context and or other paragraphs but the directive says "(14) Free and open-source software, whereby
by arlcode 2y ago
I am not a lawyer (very definitely not) and may have missed context and or other paragraphs but the directive says
"(14) Free and open-source software, whereby the source code is openly shared and users can
freely access, use, modify and redistribute the software or modified versions thereof, can
contribute to research and innovation on the market. Such software is subject to licences
that allow anyone the freedom to run, copy, distribute, study, change and improve the
software. In order not to hamper innovation or research, this Directive should not apply to
free and open-source software developed or supplied outside the course of a commercial
activity, since products so developed or supplied are by definition not placed on the
market. Developing or contributing to such software should not be understood as making it
available on the market. Providing such software on open repositories should not be
considered as making it available on the market, unless that occurs in the course of a
commercial activity. In principle, the supply of free and open-source software by
non-profit organisations should not be considered as taking place in a business-related
context, unless such supply occurs in the course of a commercial activity. However, where
software is supplied in exchange for a price, or for personal data used other than
exclusively for improving the security, compatibility or interoperability of the software,
and is therefore supplied in the course of a commercial activity, this Directive should
apply"
see also the following recitals.
I think this sounds pretty sensible. If you want to build a business you are responsible for defects in your wares. If you are gifting software you not "selling".
- amelius 2y agoMaybe we will now see companies that will absorb the liability, e.g. reselling a FOSS package with a different license slapped on.
- arlcode 2y agoCombined with the EU Cyber Resilliance Act they would be required to report security issues back to the original project.
- keikobadthebad 2y agoBut in FOSS the original project is not under any requirement to care, and may use a license that explicitly disclaims caring. Maybe it means the original project will get forked (or perhaps helped) if it doesn't take care of everything itself.
- spwa4 2y agoSo in order to use any open-source software you must commit to fix security bugs and accept liability? And software users will actually do this? It would raise the cost of open source software a lot if you do this, and the cost of all other software. This seems very unlikely to actually happen. By which I mean, government and commercial users seem to me very, very unlikely to be willing to pay for this when they could just as well just use software from outside the EU, and this will just really suck for EU software developers and companies.
- arlcode 2y agoNot to use it but to sell it comercially (apparently except for "proffesional use" in the current iteration). And that isn't really that outlandish as you make it (maybe inadvertently) sound. If a wheel falls off of your car because the foundry that made the steels of the screws got their recipe wrong, initally the whole liabilty is on the car manufaturer and they got to fixt that. For you as a customer it stops there. The manufacturer may (if their contract permits) try to get some money back from screw factory and they in turn from the steel mill etc. If someone goes bankrupt along the supply chain, tough luck for the one up chain. So car manufacturers (and their suppliers) are really motivated to QA their parts because recalls are expensive and they may not even get back everything or anything. You can't blame the universe for putting the wrong ore composition into the ground. You can only blame the people who failed to do proper checks on the way. Software may follow a similar trajectory with Open source being the ore in the ground. You must take reasonable (see directive) steps to prevent that (e.g. good development practices, updates, react to CVEs etc). It's really nothing fundamentally new.
- 2y ago
- keikobadthebad 2y agoIt's possible... but if it's open-ended what you're supposed to solve (eg, "security") it seems hard to be confident you won't be run into the ground trying to satisfy unlimited demands.
- keikobadthebad 2y agoThanks. It seems to beg the question for how long should there be some implied requirement to fix things, if you were just paid to work on a FOSS project (and what was paid for is available under a liberal license). IOW if I got paid for some work on an existing project under a liberal license, what would I be getting myself into? (I assume the answer is 'nothing' if it happened before this directive, but if it happened after?)
- arlcode 2y agoI am certain there are already established practices for "freelancer" liability since this kind of employment happens a lot in other industries. However I'd be cautious when it comes to these finer details. It's where business liability insurances and lawyers a wise investment.
- deleted 2y ago[deleted]
- keikobadthebad 2y agoToday it really boils down to the buyer accepts the work (usually work done in the period) as reasonable and pays for it, or not. Sometimes there are contractual requirements to make good on bugs afterwards on your own time. But often the hirer accepts the risk of bugs needing solving. This sounds like there might be extra requirements for an unending? unspecified? period, I don't see how anyone can make a living if so.
- arlcode 2y agoThis kind of liability is not new Europe. In fact it applies to a lot of products. Therefore similar (though obviously not identical) questions are already settled law. As a layman it may be similar to the questions of how long a manufacturer can be held responsible for material fatique under regular use?
- spwa4 2y agoYou don't know. The EU "makes laws", it is then to be interpreted by the member states into actual laws and then interpreted again by the judges of those member states. So you don't know. However, I highly doubt that EU citizens and companies will now suddenly be willing to pay for liability insurance for people they buy software from (and that will be more expensive the smaller the developer and/or company is)
- zaroth 2y agoThis is obviously a completely useless carve out. The EU will define something as commercial based on even having paid support or enterprise features, so if there’s any company behind the open source code at all, you can be sued by your free users picking it up and misusing it. So this seems like a really great way to stop any software from being released into Europe.
- pjmlp 2y agoAs if US and Commonwealth countries aren't also doing the same.
- zaroth 2y agoTFA specifically states that US has gone in a totally different direction than the EU on this?
- beej71 2y agoI was wondering if the EU decides to do this first, maybe it'll be such a fiasco even the US will be sensible enough to not follow in their footsteps.
- pjmlp 2y agoHere are some news then, https://www.cisa.gov/cybersecurity-performance-goals https://www.cisa.gov/cybersecurity-performance-goals https://cybersecurity-centre.europa.eu/news/cisa-and-enisa-enhance-their-cooperation-2023-12-08_en https://cybersecurity-centre.europa.eu/news/cisa-and-enisa-e... https://www.cisa.gov/news-events/news/cisa-and-fbi-release-product-security-bad-practices-public-comment https://www.cisa.gov/news-events/news/cisa-and-fbi-release-p... https://www.whitehouse.gov/oncd/briefing-room/2024/03/27/readout-software-liability-symposium/ https://www.whitehouse.gov/oncd/briefing-room/2024/03/27/rea...
- deleted 2y ago[deleted]
- rstuart4133 2y ago
- woodruffw 2y agoThis is better than blanket liability for unpaid maintainers, but it's unclear how it relates to OSS activities not "on the market" per se but nonetheless connected to the larger software market. Two examples come to mind: donations to OSS maintainers, and OSS maintainers who provide consulting services instead of selling software. The former is arguably covered by donations not being "sales," but some projects/groups do provide invoices (with no particular obligations) to make donations fit into the sale-shaped financial slot that most companies understand.
- Y_Y 2y agoIf you got the software itself without paying, then you aren't really paying for the software. If you buy consulting or warm fuzzies later then that's something different.
- woodruffw 2y ago> If you buy consulting or warm fuzzies later then that's something different. I happen to agree, but the law itself doesn't make that clear. That's what matters.
- dotancohen 2y ago> However, where software is supplied in exchange for a price, or for personal data used other than exclusively for improving the security, compatibility or interoperability of the software I'm really glad that the legislation treats the exploitation of private information as a price.
- paiute 2y agoSo sell the service and not the product.