3 ms·
It sucks they should just set up a fund for fundamental projects - Linux, LibreSSL, OpenSSL, etc. and then make companies of a certain size contribute. It could
by _vbnz 4y ago
It sucks they should just set up a fund for fundamental projects - Linux, LibreSSL, OpenSSL, etc. and then make companies of a certain size contribute. It could even be a way of boosting the European Tech industry by funding FOSS consultancies within Europe.
Instead we just get more bureaucratic anti-innovation makework - just like the Link Tax, Cookie law and GDPR, etc.
- deleted 4y ago[deleted]
- nomercy400 4y agoOr, the foundations could come together and provide a compliancy/audition foundation that does these audits, letsencrypt-style, for (nearly) free. A fund sounds like a great idea as well, but who would decide who gets the money? You don't want overseas companies syphoning the fund because they have 0.01% of their userbase in the EU. Overall, as others have stated: how unreasonable is it if you create a 'critical' product, and you make money off of it, to invest some of that money to show it is secure.
- mistrial9 4y agogoogle OSS-fuzz
- throwaway294566 4y agoThat isn't an audit. Audits are not about actually doing anything about security. Audits are about having documented procedure and properties and reviewing documentation. The typical software you need to google in the context of an audit is "Excel" for the endless fill-me-in lists of compliance b.s. your auditor will make you fill in...
- UncleEntity 4y ago> Overall, as others have stated: how unreasonable is it if you create a 'critical' product, and you make money off of it, to invest some of that money to show it is secure. I suppose it depends on how many hurdles you want to place in front of innovation. I learned after driving a cab for nine years just how little I can live off of and if I cut out the luxuries (like hot water) it was surprisingly little. Now suppose I were able to get people to pay me peanuts (through donations for the sake of the argument) to maintain some critical software because, you know, “someone has to do it and this guy will work for peanuts”, just how many luxuries am I expected to do without to comply with some overbearing regulation?
- PoignardAzur 4y ago> Now suppose I were able to get people to pay me peanuts (through donations for the sake of the argument) to maintain some critical software because, you know, “someone has to do it and this guy will work for peanuts”, just how many luxuries am I expected to do without to comply with some overbearing regulation? That's a weirdly specific hypothetical. In this situation, we're assuming the regulation is morally responsible for you living an austere life and not, like... you for choosing to pick the job instead of other better-paid software jobs, or the software users for not being willing to pay for critical software they depend on? And the regulation is therefore immoral if it costs any non-zero amount to anybody to comply with it, even if that amount is low?
- UncleEntity 4y agoWhat I’m really saying is they are pushing the burden of compliance on someone who just so happens to be professional because some people think they are providing a service they find useful enough to toss them a few bucks here and there — like a ton of FLOSS projects with a “buy me a beer” donations button. In a weirdly specific manner because once I get started on an idea it just flows. Either they take absolutely no compensation or they are responsible for (probably costly because government) compliance measures if some bureaucrat finds the project “critical” without them intentionally producing “critical software”.
- deleted 4y ago[deleted]