This is an overused excuse that does not actually justify nearly as much as what it's used for.
Also, online services suffer leaks and outtages and 3-letter/police pressure that I have no control or knowledge of that self owned self hosted software does not.
None of the excuses for rent hell are actually valid. They are just the excuses used to sell the idea.
The fact that services have their own problems does not mean there is no such thing as a valid service, or that the security update issue is not a real thing, it just means that this security update issue is just a thing like a lot of other things, that only really necessarily applies in certain cases, and doesn't apply everywhere, and doesn't override all other concerns, and there are other equally valid issues that are addressed by the opposite sort of model. Ie, it's nothing special and does not excuse or trump anything else.
If spftware industry is a joke and can't sort out it's own mess, its on us, not the consumer
In the United States, the landmark product liability case was Escola v. Coca-Cola Bottling Co.. In the majority decision, one of the judges wrote:
> Even if there is no negligence, however, public policy demands that responsibility be fixed wherever it will most effectively reduce the hazards to life and health inherent in defective products that reach the market. It is evident that the manufacturer can anticipate some hazards and guard against the recurrence of others, as the public cannot. Those who suffer injury from defective products are unprepared to meet its consequences. The cost of an injury and the loss of time or health may be an overwhelming misfortune to the person injured, and a needless one, for the risk of injury can be insured by the manufacturer and distributed among the public as a cost of doing business. It is to the public interest to discourage the marketing of products having defects that are a menace to the public. If such products nevertheless find their way into the market it is to the public interest to place the responsibility for whatever injury they may cause upon the manufacturer, who, even if he is not negligent in the manufacture of the product, is responsible for its reaching the market. However intermittently such injuries may occur and however haphazardly they may strike, the risk of their occurrence is a constant risk and a general one. Against such a risk there should be general and constant protection and the manufacturer is best situated to afford such protection.
There are some things to unpack here.
First, as a software developer, you are supposedly the expert and are in a far better position to evaluate your software and its potential hazards. Your customers are neither required to be experts in your software or how it might harm them, and realistically have no way to properly assess it no matter their skill level, so the responsibility falls on you.
Second, it is in the public interest to dissuade software developers from releasing faulty, broken, dangerous, etc software to the public. If a law which makes you responsible for the results of your software's failing makes you think twice about selling it, then that is a benefit to the public. If you aren't confident enough that you can accept the liability, why should your customers.
https://en.wikipedia.org/wiki/Escola_v._Coca-Cola_Bottling_C....
Consider the example of a music player that was mentioned in another comment upstream in this thread. Suppose a company sells music player software that turns out to have a RCE vulnerability when run on a maliciously crafted .mp3 file. Should they be liable?
It's helpful to consider a physical product analogy: imagine the company sold a cassette player instead. Now, let's say that someone designs a malicious tape that is lined with noxious chemicals, which when played in the cassette player causes it to catch on fire and explode. Would anyone regard the cassette maker as liable if this caused someone to die or a house to burn down?
In the Escola v. Coca-Cola Bottling Co. case that you cite, a key phrase from the majority opinion is:
> Upon an examination of the record, the evidence appears sufficient to support a reasonable inference that the bottle here involved was not damaged by any extraneous force after delivery to the restaurant by defendant.
In other words, there was no 3rd party malicious use or manipulation of the bottle: it exploded during "normal" use. If the bottle had exploded because some 3rd party had deliberately weakened the bottle, or added extra pressure before giving it to the waitress, there's no way Coca-Cola would have been liable.
With respect, a malicious tape lined with noxious chemicals is not analogous to a maliciously crafted .mp3 file for several reasons. First a tape lined with noxious chemicals is dangerous unto itself.
Second, it is not reasonably foreseeable that a tape deck would be used to play a chemically sabotaged tape. If there were millions of tapes in circulation that could cause a tape deck to self-combust, the manufacturer would be (at least partly) liable for that foreseeable outcome. They would be required to take steps to ameliorate that possible outcome.
It is now reasonably foreseeable that software designed to open arbitrary files may be subject to a maliciously crafted attack.
Should medicine manufacturers be liable if someone circumvents their tamper-proof seals and laces them with a poison?
Should berry growers be liable if someone inserts needles into foods that are sold at supermarkets?
All of these are crimes that are either widespread or famous from media scares that happened in the past, and thus foreseeable going ahead, but I think liability would still be limited because the resulting harms are caused by a 3rd party criminal act.
This is an interesting hypothetical, but I don't see the relevance.
> Should medicine manufacturers be liable if someone circumvents their tamper-proof seals and laces them with a poison?
Yes, and they are.
> Should berry growers be liable if someone inserts needles into foods that are sold at supermarkets?
The retailer should be, and is.
> This is an interesting hypothetical, but I don't see the relevance
That's your willing ignorance, and on the 2nd point too.
If by my second point, you're referring to circumventing the tamper-proof seal on medications, then maybe you'd like to expand? Manufacturers, retailers, and medical staff are (jointly) responsible for medications for their entire life cycle. A retailer who sells a poisoned medication is absolutely liable, as is the manufacturer who produced a fallible tamper-proof seal (which is worse than no seal at all).
Feel free to elaborate on why you think I'm wilfully ignorant.
Although, I think some companies use recalls in a dark pattern, specifically baby product companies.
The EU's Safety Gate programme documents safety recalls all the time, and it's common to get an email (for bigger purchases) or see recall notices at the entrance or checkouts at retailers. Retailers of safety-critical products (medical equipment, lifejackets, climbing gear, etc) will often insist on a phone number or email address in case of recall.
Incidentally, perhaps you can eventually be paid back for your stroller or crib if you do keep the receipt and watch the lists.
Thrift stores will have to check recall lists of donated items and discard the ones that are recalled, or there might be some legal exposure.
If the lobby of your building has a fancy chair in it, the furniture company isn't going to expect $10 a month forever to keep using it, and on the flip side, if the furniture turns out to be accidentally made of asbestos, it's the furniture company's responsibility to do something about that, regardless of the fact that you're not paying them every month.
Is there a version of the concierge that's a one time purchase? Probably not a good one? The fee your paying is for 1. continued incentive to continue doing a good job and 2. Training and improvements to the staff.
Is there a version of the chair that should be a recurring fee? Maybe if the chair company comes and swaps out the chair every month, but then you're not paying for the chair, you're paying for the chair service. Should the apartment building have the expectation that under a flat fee the fabric in the chair is going to get upgraded to fit new styles and tastes? No, that's never a expectation when you buy furniture. The only case where the manufacturer would be beholden to you would be if there is some gross defect in the product or if there was some negligence on their part that could lead to injury.
Realistically there's not going to be an issue where a chair lets robbers in, but if you bought a door lock for example, and the lock failed when someone tapped it, you're not SOL because your not paying a subscription to the lock maker, they're liable for their defective product.
There's absolutely cases where software should be a subscription model and there's absolutely cases where it shouldn't be.
I don't need any features that have been added to Adobe Premiere since 2013. I don't want or need updates--my copy of CS6 still works. I'm not getting a CC subscription.
If I needed software to help with accessibility compliance, I would absolutely be willing to pay a monthly fee because the standards change and information becomes out of date quickly. It would be an unreasonable expectation that a lump sum I paid in 2013 would still have my websites up to code today.
--
Forgive typos, on my phone.
My thoughts on this:
1. How long would it take a team of 4 people to build this with just the features I need for a single user?
2. How much would it cost to contract a team to build that (ball bark)?
If it can be done on a single person's salary, I'm not paying a monthly subscription, no matter how inexpensive. I'm also not contracting that work either, but I might be tempted to compete with them if my employer let me (they won't).
Only certain things make sense as a subscription, and those are things that have an infinite (or practically infinite) cost to the consumer, thus they should have an amortized infinite cost.
Do you think there's a case where something might have an infinite cost to the consumer but a finite cost to the company? Ie a solution to some recurring problem that, without the software or service the customer would endlessly pay for, but with the software or service would not incur the recurring cost--and in that situation, do you think it would be fair for the company to charge a recurring fee given that it's not costing them to continually develop it? So the customer is saving money compared to before they had the software but it's not supplementing a cost of development?
Now you’ve set yourself up for a community to grow: core devs you pay, customers that contribute code and help diagnose bugs, customers that pay you only for support, and customers that pay you to do everything.
I did this once, and the support-only customers were the most interesting. They helped locate latent race conditions that only appeared on underpowered hardware, but could happen on over-subscribed machines (like the hosted version), and so much more.
I never got any contributions on the code side, but one guy randomly took over responding to issues without being asked to. By the time I got to them, it would be ready to close or I would have enough information to address it immediately.
If you are going this route, just be aware that companies *will* eventually replace you with a home-grown solution. Even if it takes years. So ask yourself if you want to be the solution everyone goes to, you need an FOSS solution to give people. Otherwise, you’ll be replaced with the other ones, eventually.
IOW, if a company like auth0 were to have an open source server, they’d be killing it everywhere. Five or six years ago. By now, there’s enough free (as in free speech) solutions out there that they will probably never be the default solution, just one that you pay for for a little while until you figure out how or have the time to host your own.
@d13 What if the house magically changed shape so the chair couldn't be used any more in that house? Suddenly one day you'll need to sit on the floor and eat, until you had gotten new chairs, for the new shape of the house
Who would you sue (the house or the chair company or no one?)
Or instead, when the house changes shape randomly and whenever, what about paying the chair company for upgrading your chairs to match the new shape of the house (and you'd never have to cook and eat on the floor)
(It makes little sense, I think, to compare software with chairs and houses. Unless the houses are magical as per above)