5 ms·
I honestly think this is good. Almost every other engineering profession needs to adhere to a variety of standards and is subject to certifications and review,
by Quanttek 4y ago
I honestly think this is good. Almost every other engineering profession needs to adhere to a variety of standards and is subject to certifications and review, except for software engineers. it is kinda weird that a ventilator needs to go through a wide variety of regulatory checks but the software systems that control power in the hospital do not, even if they would allow hackers to shut down electricity to all ventilators.
A lot of the author's criticism is centered on the lack of a designated standards body and software standards. That seems slightly unfair, given the fact that this is still a draft law, so obviously it is still waiting to be implemented and further specified through a standardization process. In general, it should be seen as a positive when a law doesn't set out specific requirements - which might be out of date - a few years later - but rather leaves it up to a body filled with industry representatives and experts to figure out the exact standards.
- Idiot_in_Vain 4y agoThe problem is certifications, standards, reviews are strong barriers to entry and destroy competition and startup opportunities. EU already lacks big tech compared to US, China and Russia. EU can easily regulate that to write software one needs to have a masters degree in CS.
- MrBuddyCasino 4y agoOr, you know, simply fine companies that have data breaches. They will figure out how to secure their systems on their own if sufficiently motivated. No need for heavy handed bureaucracy and red tape.
- Idiot_in_Vain 4y agoOr they will pay the hackers and try to keep the breach a secret...
- bryanrasmussen 4y agothat's against the GDPR.
- aww_dang 4y agoMy preference here would be for civil actions for damages rather than fines paid to bureaucrats.
- MrBuddyCasino 4y agoI have no idea why this got downvoted.
- Scandiravian 4y agoI think that would hurt startups much more. It will require that the degrees are accredited, which is a lot of work for both the institution that provides certification and for people applying Secondly, a large percentage of developers do not have a CS degree. There's also a significant number of educations that are not specified as a CS degree, but still teach people skills with the aim of them entering the workforce to work as developers It's also unclear how domains where software is developed as a tool, but isn't a primary focus (i.e. bioinformatics)
- dmitriid 4y ago> EU already lacks big tech compared to US, China and Russia US has next to zero privacy protections, and unlimited investor money with zero expectations for a company to ever turn profitable. E.g. all of YCombinator's "top companies" lose hundreds of millions and billions dollars a year. China and Russia have cheap labor and yes, zero privacy. Edit: the same people who clamor for Russia and China-style big companies will immediately shout for government to step in if any company ever gets to the size and influence of Yandex or AliBaba.
- Idiot_in_Vain 4y agoI love privacy, but the majority of people in the world seem not to understand it's importance. No, there are no "zero expectations for a company to ever turn profitable". If you ever tried to get investor money you'll know how hard is to prove to them you have a good path to profitability. Even if all of YCombinat companies except one lose hundreds of millions, the last one can turn into a Facebook, worth hundreds of billions.
- dmitriid 4y ago> No, there are no "zero expectations for a company to ever turn profitable". If you ever tried to get investor money you'll know how hard is to prove to them you have a good path to profitability. And yet, YCombinator's top companies lose billions for years and keep getting the money. What's the "proven path to profitability"? The flimsy belief that "just wait a bit and we'll have a next Facebook?" Most of the companies that get mentioned as "big innovative companies" in HN threads have been around for 5+ or even 10+ years, lost incalculable amounts of money, never turned a profit, and we're led to believe that there's an expectation to turn a profit in any of these scenarios.
- Idiot_in_Vain 4y agodmitriid, you seem to not understand the simple fact that if one of a hundred startups an investor financed turns into a big success he can make big profits overall, despite 99% of the companies lost him money.
- DyslexicAtheist 4y agoit is a nightmare for us big companies to be compliant exactly because we have millions of lines of code that we now are expected to clean up, or remove decades of security debt. from where I sit being a start-up, or SME that can make quick decisions and consolidate their security debt is a lot easier on them and worse for us big guys. I don't want to use a phrase as "level the playing field" but the upcoming expectations of RED and CRA means most of us are praying this isn't enforced as quickly as it is written into law. I'm totally rooting for this because its the only thing that will improve security.
- Attrecomet 4y agoAll the extra red tape and auditing doesn't come for free, so startups and SMEs without huge amounts of cash somehow lying around will struggle. Also, nothing about compliance is actually about "consolidating security debt" or "quick decisions". It's about paying someone to go through checklists and, like a reviewer of a scientific paper, find something, anything, no matter how inane, to criticize, before handing you a certification. Any slightly unconventional new idea to improve security in your product will be suffocated beneath the blanket of compliance. > I'm totally rooting for this because its the only thing that will improve security. So does the author. Well, they strongly endorse a sensible version without the vague phrases and open-source-killing blanket statements, and without brain-dead sentences like "your product must be un-DDoS-able". I do wonder, though, why you're rooting for legislation that would kill any open source project that might, conceivably, be used in a commercial setting?
- DyslexicAtheist 4y agoit is in fact only US companies that have been screaming loudest against better security baselines in IoT. every on of the EU member companies is welcoming this (along with RED coming in 2024) ... for US companies it presents an additional cost or even barrier of entry because they don't need to implement the same security controls in products sold back in the US.
- piperswe 4y ago> regulate that to write software one needs to have a masters degree in CS It's already hard enough to hire software engineers, how hard would it be after further restricting to only software engineers with a relevant masters? I know I'd be entirely forced out of the field, and would have to undertake a 4 year course (abroad, because here it would be 6 years) to be eligible for employment again, if that happened in my country.
- AstralStorm 4y agoYou wish the masters would teach you anything about these new regulations. Universities lag 10 years or more behind the research edge in teaching, if not more...
- Atlas22 4y agoWell as someone that has had the "joy" of implementing a lot of the ones that exist in the US: SOC*, HIPAA, HITRUST, PCI-DSS, a handful of DoD ones. I think if they seriously taught them in schools it would cause a lot change of majors when students realize what an absolute clown car of regulation they are getting themselves into. Its also probably the most boring subject availible.
- MrQuimico 4y agoSomething to keep in mind is that this is about certification of products, not people. This is not a regulation for the profession of Software Developer, but a regulation for software products. The EU knows very well that it needs more people from all backgrounds writing and understanding software, not less. As it is, I think this is going to be very similar to what is already required for some specific industries like healthcare or finance. Startups that want to operate in these industries already need to go through some certification processes of their products and services. Most startups will probably fall under the "low risk status" category until they are a big enough. If self-assessment is anything similar to what it is already required for things like PCI DSS or GDPR, then most small companies will be fine until they are big enough to care. And by the way, there is no easy way for the EU to regulate that to write software you need a specific degree.
- yencabulator 4y agoComputer science is not the same as software development (or "engineering").
- 3836293648 4y agoHonestly, you should. Europe isn't America. We have free education here. If you leave academia and enter the workforce willingly at a lower level than society offers you for free, should you really get to do the work you refused to train for?
- throw_m239339 4y ago> I honestly think this is good There is absolutely nothing good with that. > but the software systems that control power in the hospital do not, even if they would allow hackers to shut down electricity for all ventilators This is straight out false. > Almost every other engineering profession needs to adhere to a variety of standards and is subject to certifications and review, except for software engineers. This isn't a engineer certification process to begin with. This is just government overreach and regulatory capture which is going to siffle innovation because of all the legal liability created by the EU. This will burden open source projects with bureaucracy and effectively kill open source in Europe. Apple, Microsoft, they have the money to comply to all that garbage, and it will also put a huge legal burden on independent developers. Big consultancies are Big Tech are the only one happy to get rid of all the competition. Imagine if all EU startups, the little that EU has, were forced to run their whole stack products from corporations that have the means to comply to all these regulations, do you really think that any of these startups would use open source projects like Linux, PHP, Ruby, Python, framework X or Z that didn't pay for a compliance review at first place? Startups are a thing because entrepreneurs don't have to pay big bucks to Microsoft, Accenture, Cap Gemini, ... This is a bureaucratic Diktat under pretense of "cyber security".
- rollcat 4y agoThe problem is the runaway complexity of modern computing. If you want review and certification, you have to wade through millions of lines of code, even for projects with a well defined "contact surface", like an OS kernel. "Traditional" engineering never had to deal with this much complexity. We make do, because our tooling (which itself suffers from said complexity) is somewhat decent at catching many classes of problems before they cause IRL harm: a compiler is somewhat likely to yell at you before you push the broken code to production, CI makes sure you actually ran the tests, etc. Working *on* these tools also requires a broadly similar skillset as working *with* them, whereas e.g. an architect needs an incredibly different skillset from someone building CAD software. So the tools get "better", so the software can continue growing more complex. So all of this (and much more) effectively lets us get away with much more complexity, and I think it's the crucial bit that people calling for more regulation miss. I am a software development professional, 15 years in the industry. I am scared shitless with how all of my tools, libraries, "supply chain" - are so complex, indecipherable, opaque, impossible to understand. I've been working on this one project for over 4 years now, and I'm yet finding bugs that were introduced 3 years ago. How can *you*, as an independent outside reviewer, help me in any capacity, if it takes several months just to onboard someone, and additional domain expert knowledge (video delivery) to fully understand? If you can do it, well, I'm gonna hire you to work for me instead. But if you can't understand it - what are you certifying? That it didn't break in your lab? We already run a staging system - thanks for double-checking, I guess?
- unity1001 4y ago> Almost every other engineering profession needs to adhere to a variety of standards and is subject to certifications and review, except for software engineers Every other engineering profession has actual physical phenomenon that governs them, leading to concrete standards that can be applied. Software doesnt. Debates on whether OOP or functional being 'the thing', client-side vs server-side delivery, typing or not typing, TDD or not and many more are still ongoing without any objective resolution. No side of any specific debate can objectively demonstrate their argument. Its all based on preference and biases. Even the concept of 'good practices' in any given field changes every 2 years. In this environment, attempting to bring concrete standards in software like other engineering fields would just end up in whichever group getting the upper hand in the regulatory body or political parties enforcing their own paradigm on everyone else, at the cost of innovation and productivity. ... This is before the fact that German business interests dominate the Euparl at this moment, and this law seems to have been crafted to cater to their interests - crippling and pushing out Open Source and private small software producers by ambiguous, brutal fines that they can never afford but the big business can. The users of these Open Source and private small software producers will have to go and become the users of the software and SaaS of these big corporations when those Open Source and small private software producers are bankrupt or pushed out. The biggest and most evil attack on Open Source in decades.
- krona 4y agoAnd if the compiler of your ${favourite_lang} doesn't conform to these hypothetical arbitrary standards (Or maybe it does but Deloitte doesn't have a sales rep in ${compiler_dev_home_country} allowing them to buy the certification software? What then?