> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways.
When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them.
> - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review libraries.
Yes.
> - What happens if that library is openssl and almost all webservers on the internet are vulnerable?
Everyone deploying it is liable.
> - What happens if the library is used in an insecure way? For example, if you seed openssl or libressl with weak random numbers, it is possible to attack algorithms provided by the library.
The company doing so is liable.
> - On the contrary, if the author of a library is liable, what's going to happen if I use a library of a company and build something vulnerable with it intentionally?
You are liable.
As in, the person who produces the product is liable for what they put in the product.
But, as I said elsewhere, this is all off the cuff and relies on a way to properly classify software, which is extremely hard.
But yeah, to your points, none of those feel hard to deal with at all.
I'm not a lawyer. This is not an area I'm so familiar with. But we already have some controls for CC info, and extending those further would be hard but a good start. This situation is extremely out of hand, whether I have the solution today or not.