If spftware industry is a joke and can't sort out it's own mess, its on us, not the consumer
In the United States, the landmark product liability case was Escola v. Coca-Cola Bottling Co.. In the majority decision, one of the judges wrote:
> Even if there is no negligence, however, public policy demands that responsibility be fixed wherever it will most effectively reduce the hazards to life and health inherent in defective products that reach the market. It is evident that the manufacturer can anticipate some hazards and guard against the recurrence of others, as the public cannot. Those who suffer injury from defective products are unprepared to meet its consequences. The cost of an injury and the loss of time or health may be an overwhelming misfortune to the person injured, and a needless one, for the risk of injury can be insured by the manufacturer and distributed among the public as a cost of doing business. It is to the public interest to discourage the marketing of products having defects that are a menace to the public. If such products nevertheless find their way into the market it is to the public interest to place the responsibility for whatever injury they may cause upon the manufacturer, who, even if he is not negligent in the manufacture of the product, is responsible for its reaching the market. However intermittently such injuries may occur and however haphazardly they may strike, the risk of their occurrence is a constant risk and a general one. Against such a risk there should be general and constant protection and the manufacturer is best situated to afford such protection.
There are some things to unpack here.
First, as a software developer, you are supposedly the expert and are in a far better position to evaluate your software and its potential hazards. Your customers are neither required to be experts in your software or how it might harm them, and realistically have no way to properly assess it no matter their skill level, so the responsibility falls on you.
Second, it is in the public interest to dissuade software developers from releasing faulty, broken, dangerous, etc software to the public. If a law which makes you responsible for the results of your software's failing makes you think twice about selling it, then that is a benefit to the public. If you aren't confident enough that you can accept the liability, why should your customers.
https://en.wikipedia.org/wiki/Escola_v._Coca-Cola_Bottling_C....
Consider the example of a music player that was mentioned in another comment upstream in this thread. Suppose a company sells music player software that turns out to have a RCE vulnerability when run on a maliciously crafted .mp3 file. Should they be liable?
It's helpful to consider a physical product analogy: imagine the company sold a cassette player instead. Now, let's say that someone designs a malicious tape that is lined with noxious chemicals, which when played in the cassette player causes it to catch on fire and explode. Would anyone regard the cassette maker as liable if this caused someone to die or a house to burn down?
In the Escola v. Coca-Cola Bottling Co. case that you cite, a key phrase from the majority opinion is:
> Upon an examination of the record, the evidence appears sufficient to support a reasonable inference that the bottle here involved was not damaged by any extraneous force after delivery to the restaurant by defendant.
In other words, there was no 3rd party malicious use or manipulation of the bottle: it exploded during "normal" use. If the bottle had exploded because some 3rd party had deliberately weakened the bottle, or added extra pressure before giving it to the waitress, there's no way Coca-Cola would have been liable.
With respect, a malicious tape lined with noxious chemicals is not analogous to a maliciously crafted .mp3 file for several reasons. First a tape lined with noxious chemicals is dangerous unto itself.
Second, it is not reasonably foreseeable that a tape deck would be used to play a chemically sabotaged tape. If there were millions of tapes in circulation that could cause a tape deck to self-combust, the manufacturer would be (at least partly) liable for that foreseeable outcome. They would be required to take steps to ameliorate that possible outcome.
It is now reasonably foreseeable that software designed to open arbitrary files may be subject to a maliciously crafted attack.
Should medicine manufacturers be liable if someone circumvents their tamper-proof seals and laces them with a poison?
Should berry growers be liable if someone inserts needles into foods that are sold at supermarkets?
All of these are crimes that are either widespread or famous from media scares that happened in the past, and thus foreseeable going ahead, but I think liability would still be limited because the resulting harms are caused by a 3rd party criminal act.
This is an interesting hypothetical, but I don't see the relevance.
> Should medicine manufacturers be liable if someone circumvents their tamper-proof seals and laces them with a poison?
Yes, and they are.
> Should berry growers be liable if someone inserts needles into foods that are sold at supermarkets?
The retailer should be, and is.
> This is an interesting hypothetical, but I don't see the relevance
That's your willing ignorance, and on the 2nd point too.
If by my second point, you're referring to circumventing the tamper-proof seal on medications, then maybe you'd like to expand? Manufacturers, retailers, and medical staff are (jointly) responsible for medications for their entire life cycle. A retailer who sells a poisoned medication is absolutely liable, as is the manufacturer who produced a fallible tamper-proof seal (which is worse than no seal at all).
Feel free to elaborate on why you think I'm wilfully ignorant.