Edit: It made me thinking, how would legislator ensure legislation is implemented? Would they start requiring escrow so they can check by themselves if software is developed to the correct security standard?
Edit: It made me thinking, how would legislator ensure legislation is implemented? Would they start requiring escrow so they can check by themselves if software is developed to the correct security standard?
However, if you build security critical software and get paid to do so it‘s not entirely unreasonable to require some sort of certification. You can‘t just build medical devices for money either without some sort of regulation. Or produce food for money. Or repair cars for money.
"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, ...... "
It is on the user (or a third party certification authority) to accept any liability for the quality of the software.
Libc, clang/gcc, whatever. Needs to be audited.
Perhaps they require the “integrator” to perform the audit or maybe the fact someone provides software which can be useful in critical environments is enough to signal an implied warranty and they are on the hook for compliance. Nobody knows until it all goes through costly legal procedures where everyone is trying to cover their asses and pass the buck.
I’m waiting for the day where FLOSS devs are greeted at EU airports by process servers because they released some software while in college and it got used in some critical software.
However, that declaration of purpose of course binds all other users/distributors of Linux, if they should dare to use or bundle it as a desktop, server or mobile operating system, they are doing so outside the original certification and need to have the required audit for critical software performed.
That, as far as I read it, also means that something like GCC, which is unambiguously a compiler, isn't critical and need not be audited, only self-certified, even if used to compile a critical software component.
> Limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable
If so, I'd expect it to summarily obliterate the OSS world.
This would, however, not remain true if you're actually dealing with your users in a way that establishes mutual obligations (be careful you don't fall into a contract unawares!) Providing support for pay would do it, for example.
The problem lies, among other things, in the fact that a business activity might be assumed even if one does not explicitly receive money for the software directly, but indirectly. For example via donations, ads on the download Web-site, using it for self-promotion, paid consultancy, selling tutorials, ...
secondary self-promotion, donations and ads are imho not "providing goods in a business-related context". Paid consultancy and selling tutorials might be though, But I assume that judges will rule on that if it comes to it and I assume that they will set some monetary boundary to which this still counts as "outside the course of commercial activity".
So if you have a permanent Website of your open-source product to promote some other product or service, or ask for donations or put ads on the site, you intent to make a profit out of your open-source product. (Almost?) every possible answer to the question: "How can I generate revenue with my open source project?" describes a business related context.
I don't remember how many DAYS we've collectively lost in all the apps we're making, to make sure we comply with GDPR instead of focusing on productivity.
all legislation is designed for Mittelstand (medium sized german companies)
tax, privacy, communications, employment, now software
this was seen with the VAT changes: it was raised that this would badly affect small companies, so they passed the legislation then penciled a meeting in for 3 years time to maybe think about small companies
in general: if you're a small company: fuck you
Donors get “perks” for the donations, so the receiver is essentially selling these perks and services.
At what point am I responsible for every single module I’ve ever produced because I received X000€ in donations this year?
As always, talks to your tax accountant about your specific case, this is not legal or tax advice, …
Therefore I would consider any kind of open source contribution by an IT professional a commercial activity. Only if the open source contribution is strictly a hobby and your normal job involves nothing IT-like at all you'd maybe be safe.
I could instead not push it back, which is less immediate risk
If you're not located in the EU, what can they really do even if you do have paying clients in the EU?
> In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. [..]
> Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context.
> Open-source software is provided both within and outside of business related contexts. And the 'occasional supplies' exception in this quote seems to be of limited use to projects society comes to depend on. Would you consider an open-source operating system (MINIX) that has been freely available for 35 years an 'occasional supply'? What does its integration in all Intel processors since 2015 mean for being 'goods' outside a 'business related context'? How about the BIND project, a staple of open-source core Internet infrastructure shipping for 40 years?
This feels like a huge issue to me and that's before considering how most OSS we use everyday is worked on by full-time employees as a part of their jobs.
If someone uses TerminatorOS and you did not sell it to them, they will be responsible for its use, you are fine.
If you start terminator.io, a startup that sells TerminatorOS powered drones that shoot you in the face, you are not fine and need to comply.
In the same way, if BIND starts BIND.io to sell Bind-as-a-Service, then they'll have to be compliant. If BIND is found to be ran at 90% by AWS with AWS paid employees, they won't need to be compliant. Otherwise, you'll be fine.
Source: this is not the US, European law takes context into account.
It's really the same thing as selling non certified products in Europe. If you are a registered EU business, you have to sell CE certified products, so we know that you're not going to burn my house down. If i buy from alibaba an LED strip that draws 500W and ends up burning my house down, it'll be my fault, the seller was in China and i knew what i was getting into.
> open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation.
You take an upstream, free, non-commercial product and you SUPPLY it as part of the solution. You are responsible for the conformity.
As highlighted in the article, "commercial activity" is what triggers the legislation, not profit, and it's a broader concept.
Note also this section on page 34:
‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
Take what I’m saying with a huge grain of salt, cause I’m also not a OSS contributor nor do I work with tech-related legislation.