Software that supports your body should always respect your freedom
fsf.org
fsf.org
(Consider the inverse: Parts of your own body are not your property but are merely licensed to you, and the license can be modified or withdrawn at the pleasure of the licensor)
Legislation might be required.
(edit: this would not be without precedent. Copyright and Patents are very limited when it comes to life essentials in general, such as recipes for food or designs for clothing.)
I’ve got bad news unfortunately. Bodily autonomy has never really been all that free in practice for the last few thousand years at least. We’re making some progress at least.
In the context of the repeal of Roe V Wade....
Definitely required.
I don't know anything about law, but it looks like in jurisdictions where this clause doesn't apply, signing a separate contract wouldn't help either: https://law.stackexchange.com/questions/1410/do-warranty-dis...
This has been pretty much a cyberpunk trope since Neuromancer. Nice job making the dystopia reality, capitalism.
It should be illegal to sell software that someones life depends upon without giving the user the right to inspect and modify the code.
In some (western) countries, your body is your personal private property, and you have the freedom and ultimate authority over how to use and abuse it, or anything on or in it. (you are still advised to treat your most precious property wisely, obviously)
In other (western) countries/subcommunities people feel that obligations to your community are stronger.
People from these different cultures can get into some pretty hefty discussions when it comes to things like abortion, drugs, euthansia, or -here- implants.
That is not obviously true.
I feel I belong to my family and my community.
True. But neither is the other position
If you want to risk your life you can do it but no one should be compelled to help you.
And surely they could hire experts to do the job.
2. It's not as if the people who depend on the medical devices have to take the word of the community of people who will mod the devices over the word of the FDA.
> Homebrew modifications of that software, even in the name of “freedom”, risks the patient’s life and health and should be illegal if uncertified.
The official modifications of that software — in the name of "profit" — are currently risking the patient’s life and health, and therefore should also be illegal by your logic.Surely you must also support effective (ie harsh/deterrent) prosecution and punishment for these crimes as well, correct?
I think this is the key part of the comment - yes, uncertified changes by anyone could feasibly be illegal. The FDA or similar should probably do code reviews.
What if you fix a bug in your own pacemaker? Would it be ok to:
a) Fine you?
b) Jail you?
c) Force you to revert the change? (plausibly leading to death in an extreme case)
[edit: I do agree that there's a chance that making a 'fix' to your own pacemaker might also make it worse. In which case, who do we trust more? The person on the ground with a stake in the matter (however misinformed), or $government_official with no stake in the matter (however well informed).
I think it's tricky! ]
People have a right, albeit not enshrined in law, to do stupid things that might kill them - at least as long as they don't then ask someone else to save them.
Yes, bad software modifications are bad and should be punished wherever they arise.
Homebrew modifications make it way easier for bad stuff to happen, and make it harder to punish.
That almost never happens. Software sux.
> This is a huge straw man/whataboutism that contributes nothing to the discussion.
It's a countervailing concern, not a strawman. > bad software modifications... should be punished wherever they arise
Corporations are currently unpunished (per TFA) when they alter software in a way that risks patient safety, and they have already caused documented harm to patients. This is a shocking failure of federal oversight, but the captured FDA will (by design) never fix it. Oops.In light of the real harm caused by this neverending policy failure, the Library of Congress is morally and ethically obligated to permit fair use exemption. Individuals and homebrew communities must be unshackled to protect patients from the real (not hypothetical!), documented, and widespread harm caused by corporate-sponsored attacks on US medical infrastructure.
No, that's not an exaggeration.
Given the current anti-patient landscape, the protections of open source far outweigh any risk.
To achieve that, the max acceleration must be quite low (software controlled), and the whole experience is sluggish, like trying to steer a car by pulling on rubber bands attached to the wheel.
From the moment I found a way to overcome this, I never went back. I know that I can hurt myself if I do something stupid, but I prefer this hypothetical risk instead of cursing 100 times a day because I cannot move how I want. It has been 10 years and I never got hurt.
I understand that such "high" risk device cannot be sold, but forbidding someone to change this is like inflicting a second handicap on him.
And don't tell me that SaaS is an integral part of the business model for medical device companies. There's no world in which they can't figure out how to turn a profit without charging a monthly fee to use your tens of thousands of dollars eyeball.
Sure, in this case. But that means that the rule we're considering actually needs a big asterisk next to it, something like "when the software in question isn't the primary product." That sounds like a thorny regulatory question, and any answer to that question other than "I know it when I see it" probably has big loopholes. This might be unnecessary nitpicking on my part if we're just shooting the breeze about companies we don't like, but if we're actually interested in writing laws, this is a common failure mode. Maybe _the_ common failure mode.
On the other hand, "so you would prefer it not be developed" is a less-than-entirely-charitable way of making this point. Of course @mbakke would _not_ prefer that, and it might avoid an unnecessary round of back-and-forth to make a reasonable guess about what they would prefer and work from there :)
I was also given a proprietary box that sits at home, reads data from it and sends it to my cardiologist over a cellular network, on demand. As part of periodic remote checkups I'm supposed to sit next to it, press the button, which causes it to read data and send any abnormal heart rhythms it detected (via cellular network), whether it treated it (via a shock, in which case I would have known anyway) or whether the abnormal rhythm resolved itself with no treatment (in which case it's worth it that they check out what it picked up). I have to do this about 2-4 times a year.
Every time I hit the button I'm charged $200. Even if there are ZERO events. 90%+ of the time there are zero events.
There is NO interface provided to me where I can read the data directly. There is no way for me to read the device on my own, see zero events, and inform my cardiologist that there are no events and that there is nothing new to diagnose.
I hate this medical system. The device is great for saving my life but I want access to read its data without being charged.
Boston Scientific, the device maker, does not have an interface for patients, they only send data to hospitals directly.
I'm not currently willing to switch to a different ICD because Boston Scientific's ICD has successfully saved my life 3/3 times in out-of-hospital situations and 2/2 times during in-hospital testing where they induced ventricular vibrillation in controlled testing and I'd rather not risk trying something different. Insurance wouldn't pay for an extra surgery deemed unnecessary, anyway.
I could switch healthcare providers, but I'm not sure if the others in my area are better at cardiology.
Okay so having access to the data wouldn't change a thing, surely you'd be charged even more if you wanted to talk directly to the cardiologist to do a report yourself, as you said?
> inform my cardiologist that there are no events and that there is nothing new to diagnose
I wish more programmers would refuse to contribute to this kind of exploitation.
And to be clear, I wasn't saying he should have refused treatment. I was saying I wish more programmers would refuse to help develop exploitative software like this.
If you had a good doctor that liked da Vinci robotic surgery, versus another one that did raven II would that factor more than the reputation of the doctor? Programmers who make life saving software are good in my opinion, even if the company they work for wants to make money.
I think we should strive for the best features, and also be grateful for "fascist trailblazers". Shockley was known to be an awful boss but our transistors started there and we are better off for it. Body warming methods were created by Nazi scientists experimenting unethically. These are the 2nd step, at least the profiteers show it's doable and the drive for profit made it in the first place.
We do not need the monsters to make progress. Don't try to justify their inexcusable actions in some myopic utilitarian way.
Control software is much more involved topic, let me illustrate it with a scenario: one family member is non-techy but has an insulin pump, another family member is techy and likes to hack around, they made a change to the insulin pump software to "improve it", but by accident the change triggered insulin overdose at night during sleep and family member died. We have rules and regulations not just to have rules and regulations, we have rules and regulations because they are written in blood.
While advocating for ability to freely modifying any life dependant control software is a noble goal, in my opinion it's the wrong end to approach it, instead it would be more constructive if we as computer science industry figure out ways how to make software such as we don't kill people, how to "certify" it in self service fashion (validation passed == no-one will die), etc, it's no trivial and it feels this particular part of our industry is not as developed/main stream as compared to something like civil engineering. If we have easy ways to ensure that modifying software will not lead to death then it will be easier to change the legislation to enforce this freedom.
Given that, having medical software be FLOSS certainly seems like it's a necessary step. Whether that alone is also sufficient is something that might warrant further debate.
Eg. in the opposing quadrant: maybe the insulin pump has a bug, but the new fix doesn't get certified in time and now the family member dies while their kin stands by whilst wringing their hands. This bears balancing.
I think -partially- this would fall under a patient's right[1] to choose an alternative treatment option, when presented with the pros and cons. A patient should be allowed to take considered risks.
Obviously their intent, the jurisdiction, their training/knowledge, and what sort of changes they attempted would matter in terms of how they were charged, prosecuted, etc.
If the device manufacturer updates software and injures or kills someone, they're liable on a criminal and/or civil level.
Before anyone starts rambling about how "they'll just calculate out their liability vs cost of proper software engineering blah blah"...in a civil lawsuit, at least in the US, the punitive portion of damages is for the express purpose of penalizing the defendant for shitty behavior, beyond actual damages, to discourage them and others from doing such a thing again.
McDonalds was slammed hard in the infamous coffee-scald case with a huge punitive portion. Before suing, the victim asked merely for medical expenses - nothing for the (enormous) pain and suffering from her genital burns. McDonalds told her to fuck off.
The jury was (to put it mildly) enraged on a number of counts: McD's knew their coffee was served well above industry standard temperatures, knew they'd injured people, and refused a reasonable request for damages.
But the sad news is, we carry around with us portable surveillance circlets which have the ability to access our medical conditions. We give it information voluntarily, and through occasional advertorials, this practice is becoming more normalized and accepted. I'm not convinced that the convenience outweighs the trouble this is going to bring.
It allows patients to pull their complete medical history from their various healthcare institutions, and store it locally without having to worry about some corporation monetizing and data-mining their health record
If I can't find anyone willing to take the risk, I'd take a shot in reverse engineering the thing myself.
I realise that's not a normal or even reasonable response to the predicament, but I'll never have kids and I've never been very attached to my life anyway.
Apple is well known to operate with a near total disregard for the stability of third party software. I wouldn't go so far as saying that anyone who puts Apple in their tech stack for something safety critical and then blithely upgrades gets what they deserve when it breaks, but it's a damn fool thing to do, especially if they've already personally run into problems as a result before.
Bit of a misnomer.
The whole world doesn't revolve around the FSF's definitions of free/open/libre, and LibreLink is related to the FreeStyle Libre devices, that aim (marketing) at being something "so you can get back to the things that matter most".
Surely you opt into buying a non-smartphone version? They're not stable enough and will never be.
To get my UBI payments in CBDC, I was required to have a chip inserted in my hand. Little did I know that this chip also was scanned and read every time I stepped into a vehicle and from beacons all over town. How can I get this out and still get my money to live?
Apple making an update that breaks apps isn't the fault of the app developers, or the app. The measures they suggested are completely useless if nobody wants to update or make a gpl 3 or even a horrible gpl 2 app. Suppose they do, they're supposed to pay the apple fee every year and "sell" it for free?
I'm not sure what the article wants besides bad press for companies that went bankrupt?
Or you don't even have to sell the software at all. If I had a piece of software that I needed to live, if it was OSS at least I could pay a dev to maintain it so I don't die...