13 ms·
The EU's new Cyber Resilience Act is about to tell us how to code
- Fiahil 4y agoConsidering the pile of untested and mostly garbage devices and software produced by some companies, this is amazing ! For those who will not bother reading the article : > I think having a CRA is long overdue, but I hope we can get to something that doesn’t further clamp down on innovation in Europe. GDPR had the same warning label, and yet, today, it's wholeheartedly accepted as a great improvement over the previous status quo.
- fidgewidge 4y agoBy who? The people I know who have had to deal with GDPR still regard it as a disastrous piece of legislation, a textbook example of how not to write civilized law. It's achieved nothing obvious or concrete, and meanwhile many Americans now perceive the EU as using privacy legislation to extort massive fines from them. Fines that are levied regardless of how much effort they put into compliance.
- Scandiravian 4y agoI'm going to stay sceptical of this proposal until some precedence on how it will be used by EU courts exists With that said, I think this is overall a step in the right direction. Security is in many places still a secondary concern, so regulation is in my opinion needed to improve the status quo
- MrBuddyCasino 4y agoWe got vastly better at security over the last three decades. Windows SMB shares completely open to the internet, networked code written in C without sanitisers, widely exploitable bugs in OSes - none of this is a regular occurrence anymore. There is no need to have bureaucrats get involved and line the pockets of "auditors" with ultimately useless checkbox exercises. We've seen all of this before, it never turns out as planned.
- Scandiravian 4y agoAt the same time, the amount of software running on devices around the world has also grown and attackers have gotten better tools 30 years ago the electronic warfare was not seen as much of a security risk. Today these kinds of attacks against critical infrastructure are regular occurrences This has become a very real safety risk for citizens and needs to be addressed
- MrBuddyCasino 4y agoThere are already regulations for important infrastructure such as powerplants, or safety criteria machinery such as planes and medical devices. We don’t need this kind of red tape in e-commerce startups.
- Quanttek 4y agoI honestly think this is good. Almost every other engineering profession needs to adhere to a variety of standards and is subject to certifications and review, except for software engineers. it is kinda weird that a ventilator needs to go through a wide variety of regulatory checks but the software systems that control power in the hospital do not, even if they would allow hackers to shut down electricity to all ventilators. A lot of the author's criticism is centered on the lack of a designated standards body and software standards. That seems slightly unfair, given the fact that this is still a draft law, so obviously it is still waiting to be implemented and further specified through a standardization process. In general, it should be seen as a positive when a law doesn't set out specific requirements - which might be out of date - a few years later - but rather leaves it up to a body filled with industry representatives and experts to figure out the exact standards.
- Idiot_in_Vain 4y agoThe problem is certifications, standards, reviews are strong barriers to entry and destroy competition and startup opportunities. EU already lacks big tech compared to US, China and Russia. EU can easily regulate that to write software one needs to have a masters degree in CS.
- MrBuddyCasino 4y agoOr, you know, simply fine companies that have data breaches. They will figure out how to secure their systems on their own if sufficiently motivated. No need for heavy handed bureaucracy and red tape.
- Idiot_in_Vain 4y agoOr they will pay the hackers and try to keep the breach a secret...
- bryanrasmussen 4y agothat's against the GDPR.
- EGreg 4y agohttps://eclipse-foundation.blog/2023/02/23/cyber-resilience-act-good-intentions-and-unintended-consequences/ https://eclipse-foundation.blog/2023/02/23/cyber-resilience-... As many well-known open source foundations have warned, this will bring unintended consequences. This means Europe will cut itself off from a lot of software as an unintended consequence. The whole point of open source software, a lot of the time, is that contributions are done incrementally by people without the means to certify this software to the level they want. Given enough time and distribution, open source software often becomes much more resilient than its closed counterparts, not due to any government regulations, but because it is run in so many environments and there are so many critical eyes on the project, able to submit a patch. In fact, most of the infrastructure on the Internet runs on open source software. That said, the package managers we use do have a problem — they rely on packages maintained by individual developers, and gradually update hundreds of versions, opposed to, say, the way operating systems are released. Commercial releases like RedHat etc. can be certified! They should go after companies that make actual promises. Having said that, a robust process in place for peer review in open source projects is good, same as in science or Wikipedia. For the longest time, software development has grown by leaps and bounds, and software security is hardly the most costly thing to society. Proprietary software behind large Big Tech companies externalizes cost to society. Consider how the world looked for instance before the open Web: we had AOL, MSN, etc. and everyone had to pay to play. Yes, it’s easy to regulate, but also increases the dependency on giant, centralized corporations and governments. Many people felt that networked software and technology empowers people and frees people up to organize in ways that don’t rely on institutions. For example: E-Mail vs the post office The Web vs newspapers, radio Ethereum vs banks, corporations Now you will only be able to run things approved by the government. Because people won’t be able to develop or update anything else. MY BIGGEST WORRY IS THAT THEY WILL REPURPOSE AND EXPAND THIS LICENSING REGIME TO EXCLUDE SOFTWARE THEY DON’T LIKE, SUCH AS FILE SHARING SOFTWARE OR END-TO-END ENCRYPTED MESSAGING SOFTWARE BECAUSE THEY WILL SAY THE “SECURITY” OF THE STATE WILL BE COMPROMISED. Once you have an effective licensing regime in place, you tighten the noose. They are doing this with rolling out DIGITAL IDs for everyone too… https://m.youtube.com/watch?v=uwRSzNTp2ko https://m.youtube.com/watch?v=uwRSzNTp2ko It’s a process that can take 10 years but you’re like the proverbial frogs in the pot.
- 4y ago
- yrdmb 4y agoWhy not just set a centralized repository of "industry best practices" and have the law require programmers follow it. If they codify the best practices into law, then they have to change and update the law every time there is an update to the best practices.
- PartiallyTyped 4y agoA collection of government __enforced__ libraries does not sound good to me, for obvious reasons, unless I misunderstood your idea.
- flangola7 4y agoI would trust it more than whatever corporate nonsense private sector would come up with
- mrguyorama 4y agoPeople out here saying they would hate to let the government dictate what libraries their software uses and then turn around and NPM install 2 gigs of dependencies that they can't even name.
- drexlspivey 4y agolibcompliance v2.0 was released. All corporations are required to upgrade by March 31. All requests to download older versions will be prosecuted.
- agilob 4y ago> have the law require programmers follow it Because that would create a certified profession like doctors and lawyer have to be and that would be bad for 98% of coders out there who don't know the difference between compiler and interpreter.
- bitwize 4y agoHave you considered that we certify doctors and lawyers for good reasons and that maybe we should certify software engineers for the same reasons? "But muh startups, muh innovations!" If the price we have to pay for some fucking accountability in the field is no more techbro startups the contribute to the ruin of society, good. The certification requirements would be doing their jobs.
- _vbnz 4y agoMore useless bureaucracy that will harm start-ups (and side-projects becoming proto-startups). I don't understand why people want more bureaucracy, it never works out well. Now the established companies like SAP will just pay expensive lawyers to check boxes for the certification, and European startups will face another massive obstacle (just like the GDPR, Cookie law, etc.) A better law would be pushing for repairability - ban locked down bootloaders and closed firmware, force published schematics, component lists and replacements, open bootloaders, etc. - this would help solve a lot of electronic waste and also drive a new sector for startups.
- mikestew 4y agoI don't understand why people want more bureaucracy, it never works out well. I don't think I even need to list counter-examples to falsify this statement. Sure, we all remember examples of bureaucracy gone wrong, and get amnesia when we step onto an airplane. As to the topic at hand, I dunno, a mostly-unregulated industry as it is now has such egregious examples that I'd be willing to see how this goes.
- _vbnz 4y agoThat's nice, but my side-project isn't a passenger airline. This will just kill innovation and startups in the EU. It's already a nightmare of bureaucracy for taxes and permits, etc.
- Attrecomet 4y agoFirst we're all akin to lawyers and doctors, now each software developer is effectively working to build an airplane... Everyone here seems to forget that we regulate these industries so finely because they are in a uniquely dangerous position to harm people, and act as if this is a blanket statement that's true for any kind of software development. This is most definitely not true, and we should think hard and long before regulating a thriving industry out of the world in order to feel superior to all those rubes over there obviously doing it wrong. Regulation is a necessary evil, not a positive good in itself.
- photon12 4y ago
- MrBuddyCasino 4y agoSo they decided to clamp down one of the last fields of business where there still is some dynamism left. This will probably turn out to be the same well-intended but ultimately stupid thing they did with the GDPR, giving more power to big corporations and adding yet another bureaucratic hoop to jump through for small companies. Tired of clicking those cookie consent banners yet? The UK was right to exit the EU.
- DisjointedHunt 4y agoThe EUs biggest export is bureaucratic idiocy.
- Idiot_in_Vain 4y agoYou are mostly right, but the UK was extremely stupid to exit EU. They lost free access to their biggest market. And they made it harder and more expensive for their biggest suppliers to sell to them.
- MrBuddyCasino 4y agoI used to think that too, I don't believe it anymore. It will become increasingly painful to exit the EU, but there are long-term gains to be had.
- ta1243 4y agoAll EU states, including the UK, agreed with the GDPR, with the exception of Austria who didn't think it went far enough. The democratically elected EU Parliament also agreed to it.
- Idiot_in_Vain 4y agoOh yeah, it caused a million problems for people and businesses, but in the far far future the NHS will get 300 trilion pounds a week... Used to work in the Department for International Trade - not a single one of their international trade experts tought Brexit is even remotely a good idea, long, medium of short term.
- amadeuspagel 4y agoRob Graham on the National Cybersecurity Strategy: https://twitter.com/ErrataRob/status/1631368039668252672 https://twitter.com/ErrataRob/status/1631368039668252672
- vsareto 4y agoHow does he simultaneously believe "only the top 1% do Agile well" and "Software development practices have steadily improved year by year without government help."? A lot of the industry is self-regulating. Self-regulation is more vulnerable to corruption than government regulation. Most startup self-regulation is essentially "does it work? did you get paid/acquired?". If so, you did the software right.
- livealight 4y agoThis exact same sentiment came through in the National Cyber Security Strategy the US released. It describes a minimum acceptable level of software development, called safe harbours, based on e.g. the NIST Secure Development Standards. Whether we like it or not, it seems legislation is forming on how to code and ship software. https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/ https://www.whitehouse.gov/briefing-room/statements-releases...
- xiphias2 4y agoIf I remember correctly, it says that memory unsafety is not tolerated anymore, which is far the most important issue we have. The ,,rewrite in Rust'' crowd was mocked here, but there are just too many cyber attacks with growing damage and targeting politicians in power that memory unsafe code shouldn't be accepted anymore.
- mrguyorama 4y agoOh no! People expect us to do our jobs well and have absolute minimum legal standards and expectations of outcome? What a horror! What if we write code full of bugs, fail to write good unit tests, fail to do any manual dev testing, fail to find those bugs in QA (because we fired all of them or don't let them have any power to stop broken stuff from being pushed out), fail to find those bugs in integration testing, fail to have robust systems that can tolerate that kind of bug, and then people actually hold us accountable for that POS? Gosh, can you imagine if other industries had to deal with such oppressive requirements, like if the local taco truck had to abide by some minimum standards of food safety, or if engineers would be held accountable for a bad bridge, or if accountants were expected to actually do their job correctly? What a terrible world that would be.
- s1k3s 4y agoYou didn't read the article, right? Go check it out, it brings up some good points. There's definitely stuff in that Act that's more than "absolute minimum legal standards", some even impossible to achieve.
- DyslexicAtheist 4y agocan you paste one that you feel goes beyond minimum or even "impossible"? otherwise this comment is just he said she said.
- s1k3s 4y agoYeah, literally the entire 2nd half of the article. Go read it, I'm not your tldr bot.
- DyslexicAtheist 4y agoI'm deeply familiar with the actual draft proposal of the law and no person working in security would consider these outrageous. this shit really is just best practice and good security hygiene. refusing to quote what you mean is bad faith. and you're not really contributing to the conversation
- winter_blue 4y agoI would love legislation that mandated static typing for large/public companies (or any companies that took federal funding, etc). I think dynamic typing is one of the worst software engineering practices in common use today, and I'd like to see it go into the trash heap of history. It's already happening with the massive adoption of Mypy/Pyre, the JS -> TS switch, etc.; but if we can use the power of government / the force of law to hurry up the extinction of dynamic typing as an industry practice, that would be a huge huge thing. The next step after it would be requiring the nullability be an explicit part of the type (like in Kotlin, TypeScript, etc), or mandating the use of Optionals everywhere that nullability is needed in languages like Java. The death of dynamic typing and default-nullability would probably save the industry society billions of dollars in the long run.
- jraines 4y agoCome and take i[null pointer exception]
- ftrobro 4y ago> The death of dynamic typing and default-nullability would probably save the industry society billions of dollars in the long run. I'm not sure a ban on software coded using PHP, plain Javascript, legacy Python, C/C++ or assembler would be cheap for "society"...
- continuational 4y agoI don't think it's enough. Java without null would still have Log4Shell. The current model where any piece of code can do anything it likes needs to be abandoned before we can expect any kind of security from our systems.
- ahtihn 4y agoThis is never going to happen. Do you forbid shell scripting? What about turing-complete configuration formats? How do you define static typing? Is TS `Any` allowed? Is C# `dynamic` allowed? Are you allowed to use reflection? How are you going to enforce this at scale?
- Kototama 4y ago
- gpvos 4y ago> (k) ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic updates and the notification of available updates to users. jwz was wrong: instead of being able to send mail, all software will now include its own networked update mechanism.
- raverbashing 4y ago> "where applicable"
- nivenkos 4y agoSeriously - this is the package manager's job. Unfortunately the EU has no understanding of technology, and is just trying to regulate to protect the establishment aristocrats from disruption.
- j-pb 4y agoIt'd be funny to see C, C++, Java, PHP and friends outlawed. Learning Rust, Ada or FP now seems like a good way to have job security in the EU in a couple years. But who am I kidding, it'll be mandatory Java, Waterfall, and a metric ton of "Requirements analysis" documents for everybody.
- throw_m239339 4y agoWho's going to pay to ensure Rust's web stack compliance? Do you really think that companies will magically start using Rust instead of C++ just because it's deemed it "safer"? No Microsoft, IBM or whatever will come with its own version of Rust, pay 100 millions for compliance reviews and this is what other companies will be forced to use, not Rust, of course companies will have to pay millions in license cost to use Microsoft's Rust. How can anybody here not see where this is going and what is going to happen? We'll be back to the 80's/90's IT era where free software was deemed a legal liability. This isn't scare mongering, this is precisely what is going to happen. Who was in their 20's in the 80's here, working in IT? Not a lot of people it seems...
- scoutt 4y agoAlso, who would update their compiler version every week or at every iteration? They will be stuck using a version from 10 years ago because it’s the one that was certified. Not even mention all the crates that need to be certified too.
- llanowarelves 4y agoFollow it up with Python, Ruby, and friends being carbon credit taxed out of use by the eco-friendly energy laws.
- BeFlatXIII 4y agoWhy Java in the list of obviously-bad languages? IIRC, Java doesn't do manual memory management nor is it full of old insecure implementations kept merely not to break existing code.
- 4y ago
- raverbashing 4y agoIt's a good (and very nuanced) read But again, it seems people are overreacting (not the author). Yes, I think the warnings are valid, especially for the perception You might go and check how many companies did get those 10Mi euro "scary" GDPR fines before panicking again. Did any of the 'we value your privacy (not)' popups get big fines? > Products with digital elements shall be delivered without any known exploitable vulnerabilities; This sound more like the equivalent of not releasing a Digital Ford Pinto than an Inquisition tribunal on open source developers > In terms of liabilities, it is not clear where those lie. Are the opportunities for that ’exhausted’ (a legal term) when you hit the vendor who marketed the product? Or could the author of an open source security library be exposed to bugs shipped by a vendor of IP cameras? > We really should know, but it appears that we don’t. Yeah this seems to be the main detail
- fidgewidge 4y ago> You might go and check how many companies did get those 10Mi euro "scary" GDPR fines before panicking again The EU has levied over 2.7 BILLION euros worth of GDPR fines in the past 5 years alone, and possibly much more as not all fines are made public. It is distributed over more than 1,500 separate fines. That is a staggering amount of money that went straight into its own treasury based on the enforcement of a very vague law, for example the top category of fine is "Non-compliance with general data processing principles". More relevant to the CRA, there have been over 375 million EUR worth of fines for "Insufficient technical and organisational measures to ensure information security". There's background to all this. The EU is incredibly hungry for money which it can then use to expand its own power. Historically it was restrained by the member states refusal to give it more, as they were wary of exactly that outcome. In recent years the Commission has found ways around the treaties to unlock new revenue sources, specifically: - Megafines that are impossible to avoid. How much money do you think the big tech firms spent on GDPR compliance? A massive effort. All for nothing because the EU can simply declare your efforts "inadequate" in their subjective estimation and please hand over a few hundred million more. - Issuing debt. This is a plain-as-day treaty violation but the EU does not have the rule of law, so the institutions and member states just ignore it. Dystopically the EU Council website was even updated after they started doing this to remove the references to Commission debt issuance being illegal. You do not want to hand these people even more ways to tax the software industry, because they will use it regardless of what the written rules appear to say.
- lxe 4y agoThere needs to be a carve-out for open source software. The difference between open source software and other industries is that OSS is not "the bridge" -- it's the "blueprint for the bridge". Until it's in the process of getting deployed, it shouldn't be subject to fines or audits.
- hummus_bae 4y ago[dead]
- kachurovskiy 4y agoThe amount of certifications to go through for a physical products is insane - here's a brief overview of just one of the standards - https://youtu.be/fL-Yz9b1eMk https://youtu.be/fL-Yz9b1eMk - frankly it's amazing (both good and bad) that to sell software you can put out almost anything and declare no liability. With CE for example you are required to accept liability. We're in the Wild West phase with software industry that sometimes reminds me of the John Brinkley radio station.
- seanw444 4y agoI hate that we feel the need to make everything boring and difficult, as though it's some sort of end-game goal to reach in every industry. Why must this be our default outlook on things?
- llanowarelves 4y agoGood to have standards, best practices, warranties, accreditations etc. But then there's a whole industries of middle-men who don't build and by most accounts don't add any value (other than keeping you out of jail due to the laws they themselves pushed) -- who love the boring and start licking their lips at the possibilities. Combine with revolving door, regulatory capture, lawfare etc to take your competitors out. So that's what this article is about. We need details to know which side of the line we're walking on. Maybe this was better not as a response to you but I already started typing it lol.
- unity1001 4y agoThe most concerted and dangerous attack on Open Source since a long while. Even as it is, it will kill a lot of Open Source projects due to the risk of not only ambiguous, but !unbounded! fines. There isnt a cap on the fines like 'X% of your revenue' like in GDPR. Not that the majority of Open Source projects have any revenue. Only the biggest ones that are like Linux etc, who are sponsored by major corporations that use them can be at ease with this law. And in that you can understand how evil this law is: Its carefully crafted to avoid risking the major software that megacorps are using. But it cripples & bankrupts all Open Source and also private small software producers. Whose users will have to turn to big corp apps and SaaS as a result. Whereas the large Open Source projects that are sponsored by corporations as a foundation will become totally beholden to those corporations as if they were external product organizations of those corporations because they cant risk funding themselves in any other way... It looks like something that is crafted by the German private interests that currently dominate the Euparl.
- Scandiravian 4y agoFrom the second sentence of the article: > Non-adherence comes with Significant Fines (15 million euros or 2.5% of annual turnover, whichever is higher) I don't know where you got the idea that this proposal suggest unbounded fines. Do you have a source for it?
- nivenkos 4y agoWhichever is higher implies no upper bound no?
- Scandiravian 4y agoNo, it implies that there's a minimum upper bound for all companies, but that it scales based on the size of the company at a certain point It can never be higher than either 15M euro or 2.5% of global annual revenue depending on the size of the company
- unity1001 4y agoAre you aware that an Open Source project with scarce revenue or small private software maker will get fined up to 15 million Euros if they found to be non-compliant, based on however the regulator interprets the legal maximum like in GDPR? Uncharacteristically outside the civil law principles that require solid, written guidelines for everything. Which Open Source software project or small software producer has the funds to fork out from tens of thousands to millions of Euros? That's as unbounded as it gets. Its a great risk to take. Solely this law going out would kill a lot of Open Source projects or move them out of the Eu. Considering how most projects are just collection of a few people without any organization and the individuals would be legally responsible, it would definitely kill any participation in an Open Source project by a Eu resident.
- kneebonian 4y agoSomething to keep in mind when comparing CS with traditional engineering: http://thecodelesscode.com/case/154 http://thecodelesscode.com/case/154 Excerpt: When they had reached the other side, Kaimu asked the first monk: “What have you learned from the bridge-builder?” The first monk said: “The determination of a true engineer is an enviable thing. But if we were to work in such an inflexible fashion, the Emperor would surely drown us in our own Waterfalls.” Kaimu asked the second monk: “What have you learned from the bridge-builder?” The second monk said: “The frugality of a true engineer is an enviable thing. But if we were to cling so hard to yesterday’s technology, the Web would not exist for another thousand years.” Kaimu asked the third monk: “What have you learned from the bridge-builder?” The third monk said: “The predictability of a true engineer’s world is an enviable thing. But ours is a world always in flux, where the laws of physics change weekly. If we did not quickly adapt to the unforeseen, the only forseeable event would be our own destruction.” The first monk asked: “Master... what has the bridge-builder learned from us?” Said Kaimu: “Nothing yet. But when I touch a lit candle to the oil I sprinkled from my lantern during our crossing, he will learn the reason to plan for the absurd, the virtue of rebuilding in stone, and the wisdom of not insulting your customers.”
- gavinhoward 4y agoI am a programmer that cares about quality software. I think we should professionalize the industry with certifications. I am also starting a business where I accept some liability for my Open Source software. So this is a good step. The only criticism I have is that the carve out for Open Source needs to be well-defined. I agree that FOSS like mine, where it's the basis of my business, should be required to be certified. That said, I'm not sure I'll be able to afford the required certification. Will Curl or SQLite? I think SQLite might, since it's already certified for flight. Curl might since it's been used in NASA flight. But in both cases, the cost of certification, if it happened, was borne by the "customer." In the case of SQLite, it was Airbus. In the case of Curl, it would've been NASA. In both cases, the original authors did enough testing to make it possible, which would be a major cost for them. I want my software to reach the same quality, but I couldn't, by myself, get it certified. It would take an outside entity that wanted my software certified for their use in Europe. Edit: I also only have a Bachelor's degree. If I needed a Master's, that would be untenable.
- aww_dang 4y agoThis thread is beginning to read like a transatlantic culture war. There's also a dichotomy between employees and entrepreneurs. This one is a bit simpler in that it can be evaluated from first principles. There are no private employees without entrepreneurship.
- kneebonian 4y agoHow it will actually go. Legislator: "I don't understand all this stuff what does pointers and registers mean?" Helpful Industry Partner (Also rep of massive corp): "Well here this is what we consider "secure development practices". Also did you know Firefox is a tool used by hackers, using Firefox is insecure. "New Bill Requires Standardization in Web Browsers to Ensure Europe's digital security and to protect the children."
- pookha 4y agoMy position is simple...An unelected and non-adjudicated EU commission bureaucrat can't micro-manage my software -- or tell me how to write it -- just like I can't open source all of their calendars and tell them how to manage their -- unlikely -- busy days and off-the-books meetings.
- xhxhxh 4y ago[flagged]
- pmontra 4y agoRegulatory capture and let all small companies and self employed people die or go to work for big companies at a fraction of the profit.
- wkat4242 4y agoI'm glad there's a carve-out for open source and homebrew stuff otherwise this would kill an entire scope of software in the EU. Obviously some student in his bedroom is not going to be thanklessly maintaining some piece of software people rely on if it comes with a huge administration burden and the possibility of mega fines. Referring to this kind of thing: https://xkcd.com/2347/ https://xkcd.com/2347/
- Attrecomet 4y agoThe carve-out of FOSS is rather weak. Anything that involves money can be a commercial activity. And suddenly some haskell core dev is on the hook because there are companies using it in prod. We can hope that it won't end that way, but there's nothing in the text suggesting that this should not happen.
- wkat4242 4y agoI think the one being on the hook then would be the company using it. Not the dev, right? If the dev is not selling it, it wouldn't be commercial from their end. But indeed, it's all very very vague.
- xhxhxh 4y agoFor the time being, the solution is simple: just market to the US and completely ignore Europe. If you get hit by a GDPR or one of these audits, do not respond until they threat, and if they do simply drop all business there. What I'm worried about is not that. As a non-European who doesn't live in Europe I'm worried about what it's happening over there. The non-elected EU bureaucrats will soon control and regulate every aspect of your lives, and I can forsee the future: cash will be banned (terrorists use it!), the internet will be severily restricted and monitored (think of the children!), hate speech laws will dictate what you can or what you cannot say (this already happens). Everything else will be done in the name of regulation for regulation's sake, banning sales of new fossil fuel cars due to "climate change" (and they will eventually ban your existing car), and so much more. I think this is the result of extended peace and prosperity, it leads to people acting weirdly and relying too much on abstractions. Weird results ensue and eventually it all crumbles under its own weight. And yes, the same will happen to the US.