7 ms·
That's apparently already changing in the EU, where software vulnerabilities mean the company is liable for damages. The only way out is to straight up not make
by NegativeK 3mo ago
That's apparently already changing in the EU, where software vulnerabilities mean the company is liable for damages. The only way out is to straight up not make any money (not just from direct sales) from the software.
- ssttoo 3mo agoIs the burden of proof on me, the developer? Do I need to prove in perpetuity that I didn’t get a job or a free flight to talk at a conference because of my free software? (Which had a flaw that hurt someone)
- deleted 3mo ago[deleted]
- NegativeK 3mo agoI have no clue. But I do think that this is a much better start than letting companies ignore the impact to software consumers or having open source devs be on the hook for volunteer work.
- 9dev 3mo agoThat is a misrepresentation. You are obligated to actually put effort into securing your products, which is the only sensible stance to take.
- NegativeK 3mo agoHow so? I'm thrilled that companies are liable for crap that ends up hurting other people. I don't think they should get an easy way out, and I also like that there's a carve out for people who aren't making money off of software (like OSS devs.)