Proposal to shift responsibility for errors in open-source code

James Bottomley from IBM Research, who is responsible for the SCSI and PA-RISC subsystems in the Linux kernel and previously led the technical committee at the Linux Foundation, has proposed a potential solution to the issue of possibly holding open source developers accountable for bugs in code or improper remediation of vulnerabilities.

The idea is to shift the legal liability for errors in the source code from developers of open projects to suppliers of end commercial products based on that code, meaning to transfer responsibility from those who create the code to those who profit from it. For example, if a company uses third-party open code in its product and a bug/vulnerability in that code causes harm to a user, then in such a situation the producer of the commercial software product supplied to the user should be liable and compensate for the damage, not the developer of the open library.

The transfer of responsibility is proposed to be implemented through attaching a clause to the license stating the agreement to compensate for damages and protect development participants from any legal claims in case of full or partial use of the provided source code under this license as a component or product in jurisdictions imposing additional maintenance obligations on software products.

In current practice, it is sufficient to have a warning in the license stating 'AS IS', which declares that the developer is not responsible for errors, makes no guarantees of code performance, and has no obligations to resolve issues, while the consumer agrees to use the code at their own risk. The lack of guarantees from developers has fostered the development of a business model based on paid technical support, which dominated the early stages of the open source ecosystem.

As open source continues to penetrate the industry and corporate interest in its use grows, the concept of influencing development through nonprofit funds has emerged — a fund is created based on a large project, receiving funding for development from major companies, which in return are given the opportunity to join the supervisory technical council and participate in collective decision-making on further development. The emergence of funds has transformed the perception of open projects, which are now seen as a tool for advancing the technology industry rather than a chaotic refuge for volunteers. The perception of responsibility for issues in open source has also changed — instead of protecting individual developers, the clause about the absence of obligations is now viewed as a way for large companies creating open products to evade responsibility.

The situation regarding the abandonment of obligations may change if the Cyber Resilience Act, a proposed law in the European Union, is adopted. This act imposes certain responsibilities on software manufacturers who fail to adequately address security and quickly rectify vulnerabilities throughout the product lifecycle. The bill affects commercial software manufacturers and, judging by the ongoing work, will provide a special exemption for software under open licenses, but there are no guarantees that in the future a similar law will be enacted somewhere without such exemptions.

As an example of the risks associated with developers' liability, a lawsuit initiated in the UK is mentioned, in which the company Tulip Trading, having lost bitcoins worth about $4 billion in a hack, is demanding that Bitcoin system developers make changes to the blockchain code to recover the lost amount. The lawsuit is filed against the code developers rather than the operators of the Bitcoin network. The court of first instance denied the claim based on a disclaimer in the license, but the case continued in the appeals court, which, it seems, will also reject the claim, this time due to Tulip Trading's inability to prove ownership of the bitcoins in the claimed amount.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster