• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Lawsuit Raises Fear of Greater Liability Exposure for ISVs

    June 7, 2010 Alex Woodie

    The importance of software quality and the potential liability for functional flaws and security vulnerabilities was on full display last month when a judge in the United Kingdom ordered a software company to compensate a former customer for the business costs of a failed implementation of a hotel management system. The judge basically overturned the limited liability clause of the vendor’s license agreement–a move that software quality experts and industry analysts say could herald a new wave of litigation and a push to certify applications.

    The trouble for Kingsway Hall started soon after going live with Red Sky IT‘s Windows-based software in late 2006. The biggest problem was an inability for the reservation system to accurately track which of the four-star hotel’s 170 rooms were available, requiring the hotel to do this manually, which took a toll in the hotel’s revenue. Group bookings also posed a problem, as did mini bar charges. Finally, the system would freeze at least once per day on each client, which required the hotel to re-boot the clients frequently, taking up more staff time.

    In his decision, Judge Toulmin, a member of the Technology and Construction division of the Royal Courts of Justice, stated that “the system was never fit for the purpose for which it was sold,” and mandated that Red Sky IT compensate Kingsway Hall to the tune of about £111,000, or $160,000 at current conversion rates. A good percentage of this judgment was for Kingsway’s lost profits, additional staff time required to maintain room availability, and wasted expenditures related to the software, according to the written judgment, which can be read at www.bailii.org/ew/cases/EWHC/TCC/2010/965.html.

    What’s is striking about this case is that the judge basically threw out Red Sky IT’s end user license agreement (EULA). Most EULAs, including Red Sky’s, contain liability clauses that limit the damages an ISV legally must pay to cover the cost of the software and related fees. But in this case, the judge granted the plaintiff damages for lost profits and other impacts the failed hotel management system had on the hotel’s business–an unusual move that experts say could open the kimono on EULAs around the industry.

    Roger Oberg, senior vice president of marketing at Veracode, says this ruling could mark a milestone in how court’s around the world enforce EULAs.

    “It’s kind of surprising that it’s lasted this long, the blanket indemnification that we get out of our EULAs,” Oberg tells IT Jungle. “Gartner predicted this would happen in 2007. They said as organizations increasingly become reliant on commercial software for core business processes, that these complete blanket agreements of indemnification would be litigated and software companies would be held more accountable. They see this as a trend and [the Kingsway case] an indicator of the trend, and frankly so do we.”

    While the Kingsway case revolved around whether Red Sky’s software functioned as advertised, Oberg sees the issue evolving to include security, which could potentially be a much more expensive proposition.

    “Start pulling on that string and you get to a much scarier place, for customers and software suppliers,” Oberg says. “For customers, security breaches could be potentially far more damaging than failure to perform the function that software was implied to do. The damage from being egregiously hackable could determine the fate of the business.”

    Imagine, for a minute, if Microsoft could be held to account for all of the damage caused by security vulnerabilities within its products. That number–let’s call it a google for lack of a better term–would make BP’s liability exposure for the Gulf of Mexico oil spill, by comparison, look like chump change.

    Obviously, there has to be some kind of balance, Oberg says. “If every software company was held in an unlimited way liable for security breaches or functional failures, you’d shortly see a demise in the number of people writing software for commercial purposes. There has to be some point here where accountability balances with economic viability,” he says.

    For this reason, the limited liability clause in EULAs must remain, but vendors need to take additional action if this is to be the case. “I believe the industry is going to need to look to things like certifications, which suggests that they’ve applied some due diligence to the effort to make sure that the software is of sufficient quality. That’s where we come in,” Oberg says.

    Veracode is one of a handful of companies that provides security testing for other ISVs and grants its own certification mark for applications that have passed the company’s tests. The company offers three types of application testing, including static binary testing, dynamic Web application testing, and targeted penetration testing, to ensure that modern C, C++, Java, ColdFusion, PHP, and .NET applications don’t contain any of the most well-documented vulnerabilities, as well as some not-so-obvious problems.

    System i software vendors that write in RPG and COBOL are generally not as susceptible to security problems as their “open systems” brethren. (In terms of functional problems, it’s probably a wash, despite the fact that many in the AS/400 industry believe RPG to be the world’s greatest business application programming language.) There are a number of reasons for the improved security posture of the AS/400 architecture, including the closed-loop nature of i/OS security, the monolithic nature of legacy development models, and the lack of visibility that i/OS systems and applications have to the outside world.

    But as soon as i/OS ISVs start incorporating any of the above-mentioned languages into their modernized applications–especially if they’re using third-party component libraries and integrating them using service-oriented techniques–then their potential exposure suddenly jumps up a notch.

    “The court case suggests that perhaps the pendulum is swinging, and accountability may be the watch word, if you will, for software companies in the future–both for security and functional performance,” Oberg says.

    The Kingsway ruling could be an aberration. But with thousands of hungry lawyers around the world looking for any chink in the armor protecting the deep pockets of the titans of high-tech, that possibility may not be worth betting on. In any event, it’s something to keep an eye on.

    This article was corrected. Roger Oberg’s name was misspelled. IT Jungle regrets the error.



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: mtfh_rc, Volume 19, Number 21 -- June 7, 2010

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    nuBridges Eases i/OS Integration for Tokenized Data iBoost Turbo-Charges Slow i/OS Batch Jobs

    Leave a Reply Cancel reply

TFH Volume: 19 Issue: 21

This Issue Sponsored By

    Table of Contents

    • Hardware Spending to Lead the IT Recovery
    • Glass i: Windows RPG for $50, 25 Users for $250
    • Consultant Says: I See i on Blade Servers
    • As I See It: On Leadership
    • Maximum Availability Sues Vision Solutions Over Advertising Claims
    • Lawsuit Raises Fear of Greater Liability Exposure for ISVs
    • Revenues and Profits Down at BluePhoenix in Q1
    • Infor Acquires Bridgelogix for Data Collection
    • Help COMMON Europe Rank the Top i Concerns
    • Modern i Platform Relies on Skills as Much as Technology

    Content archive

    • The Four Hundred
    • Four Hundred Stuff
    • Four Hundred Guru

    Recent Posts

    • Meet The Next Gen Of IBMers Helping To Build IBM i
    • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
    • Will Independent IBM i Clouds Survive PowerVS?
    • Now, IBM Is Jacking Up Hardware Maintenance Prices
    • IBM i PTF Guide, Volume 27, Number 24
    • Big Blue Raises IBM i License Transfer Fees, Other Prices
    • Keep The IBM i Youth Movement Going With More Training, Better Tools
    • Remain Begins Migrating DevOps Tools To VS Code
    • IBM Readies LTO-10 Tape Drives And Libraries
    • IBM i PTF Guide, Volume 27, Number 23

    Subscribe

    To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

    Pages

    • About Us
    • Contact
    • Contributors
    • Four Hundred Monitor
    • IBM i PTF Guide
    • Media Kit
    • Subscribe

    Search

    Copyright © 2025 IT Jungle