8 ms·
No cyber resilience without open source sustainability
- AugustoCAS 3y agoTL;DR The EU is working on the Cyber Resilience Act (CRA) which will be voted on the 19th of July. The current wording makes it look like it will affect open source projects that receice donations; which have contribution from corporate developers; and might break coordinated vulnerability disclousure. If you live in the EC area, there's a link on the blog to contact to MEP. The blog also links to other posts from OSS organisations sharing the same concer. * https://blogs.eclipse.org/post/mike-milinkovich/european-cyber-resilience-act-potential-impact-eclipse-foundation https://blogs.eclipse.org/post/mike-milinkovich/european-cyb... * https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-law-may-have.html https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-la... * https://blog.opensource.org/the-ultimate-list-of-reactions-to-the-cyber-resilience-act/ https://blog.opensource.org/the-ultimate-list-of-reactions-t...
- smarx007 3y agoPlease take time to understand CRA (not from the vendor point of view) before contacting MEPs: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act https://digital-strategy.ec.europa.eu/en/policies/cyber-resi...
- bonzini 3y agoI have not yet fully made up my mind, but notice that there is a lot of nuance in the actual text. For example "Accepting donations without the intention of making a profit should not count as a commercial activity, unless such donations are made by commercial entities and are recurring in nature".
- tremon 3y agoThat doesn't sound like nuance, just a quagmire of uncertainty. That means that if I have a Patreon account, and any business decides to fund me for a couple of months (let's say, for the duration of a Summer of Code), my project is now commercial? Is it only commercial during those months? Will such a donation affect all projects I'm working on at the same time?
- thayne 3y agoOr what if a business funds you for like $5 a month? Are you then required to comply with the regulations?
- WhereIsTheTruth 3y agoDonations are often, if not most of the times, ways for companies to avoid having to pay taxes I wonder if this is precisely their motivation ;)
- cmdli 3y agoDo you have any examples?
- Mystery-Machine 3y agoLike...80% of big companies? You really should have heard of this practice by this age...
- smarx007 3y agoThis is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specifically: most EU businesses rely on open-source software in prod (Linux, Nginx, OpenJDK etc.). Vulns in the software including those in OSS amount to 5.5 trillion EUR losses every year [1] (edit: quite a wild projection, disputed, see the thread below). CRA wants to ensure that if a business (especially an SME w/o a dedicated itsec team) sees software online, which looks usable "in the course of a commercial activity" and receives regular releases, that its last release is reasonably free from known significant vulnerabilities. Please note that https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-law-may-have.html https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-la... is no longer valid as amendments were made to specifically exclude PyPi, Git and other hosting platforms from any liability. I also expect a positive outcome from all this. Companies (at least, in EU) will begin requiring their dependencies to be CRA-compliant some time in the future and it will open up a path for devs to get paid for the extra burden. Finally, this is a wake-up call for all software developers to consider what needs to be changed in development practices before we can proudly call ourselves software ENGINEERS. [1]: https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-34e9-11ed-9c68-01aa75ed71a1.0001.02/DOC_1&format=PDF https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-...
- smarx007 3y agoNow, to some controversial things: do I think it's good if RedHat is legally forced by CRA to close down CentOS Stream if they decide not to deliver all security fixes they apply to RHEL? Yes, I do. This legislation will kill the practice of funding OSS projects by providing enterprise versions where many CVE fixes are only available in the enterprise versions. To that, I say: good riddance. The last thing we need is OSS software that is regularly released and is intentionally missing important security fixes.
- 3y ago
- loup-vaillant 3y agoI find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction. Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS software under the hood? Commercial again, even if upstream is not. Receiving donations? Shouldn’t matter as far as I can tell. That being said, I can see donations being used as a loophole to bypass regulation. Maybe they’re trying to close that loophole.
- sam_lowry_ 3y agoYou give EU bureaucrats too much credit. Incompetence, lack of involvement and a general feeling of doing fake work reign there.
- mordae 3y ago> I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction. I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way. There were more landmines in the original draft. Like the requirement for any known-vulnerable device not be put on the market. Well guess what? All those phones and laptops sitting on the shelves are having exploits discovered every month. Red Hat chimed in; apparently they have potential vulnerabilities on containers they publish sometimes in 15 minutes. Potential. How exactly are they supposed to act? The legislation just plain sucked and now it's being "fixed" behind closed doors.
- gavinhoward 3y agoThis is exactly why my FOSS licenses have a provision making them null and void if there is any legal duty for the programmer to the user. It is also one part of why I don't want to deal with Europe.
- arlcode 3y agoIn this case I would assume it's void almost anywhere because I don't know of a single place in the world that does not require developers to avoid putting intentionally malicious software into their foss with the ultimate goal to harm users. That requirement is something you usually can't waive with a LICENSE file either.
- gavinhoward 3y agoFair. In truth, I worded it wrong in my first comment. Suffice to say that I am paying a lawyer right now to avoid problems like that. Of course, the usual typical legal duties will still exist. But anything beyond that, such as fuduciary duty, will not exist.
- renegat0x0 3y agoI have already stored some links about this act. As it is written in the register "The road to hell is paved with good intentions". https://www.internetsociety.org/blog/2022/10/the-eus-proposed-cyber-resilience-act-will-damage-the-open-source-ecosystem/ https://www.internetsociety.org/blog/2022/10/the-eus-propose... https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/ https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-... https://blog.opensource.org/what-is-the-cyber-resilience-act-and-why-its-important-for-open-source/ https://blog.opensource.org/what-is-the-cyber-resilience-act... https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-software-could-have-dire-impact-on-open-source/ https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-sof... https://berthub.eu/articles/posts/eu-cra-secure-coding-solution/ https://berthub.eu/articles/posts/eu-cra-secure-coding-solut... https://www.theregister.com/2023/05/12/eu_cyber_resilience_act/ https://www.theregister.com/2023/05/12/eu_cyber_resilience_a...
- jauer 3y agoWouldn't this lead to the EU not being able to use most F/OSS software through conflict with common warranty/merchantability license clauses?
- nforgerit 3y agoGerman here, trying not to sound too polemic: Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, this looks so much like an attack by enterprises against startup competition who cannot afford legal insecurities/legal departments/security certifications, that I can barely understand such a governmental interference without thinking about bad actors.
- miohtama 3y agoI believe the EU is not “attacking”. It’s generally the EU’s insecurity over anything technical, as there is no good homegrown ecosystem for software, AI, etc. Brussels thinks it can fix this by regulating large American enterprises and making them dance on its music. Also, generally politicals want to control everything and do not see the harmful side effects of regulation. You are not going to get re-elected by de-regulation. “Think of the children” and any AI, cryptocurrency etc. doomsday porn is sure way to get headlines and get your name out in the press. The root cause of the problem of why the EU lacks software startups and AI startups compared to the US and China remains unaddresed. In the end the result is that more and more business is infeasible in the EU, for both EU citizens and foreigners and will just move to elsewhere.
- loup-vaillant 3y agoI’ve skimmed over a previous version of this proposed law. And while we moan here about who this applies to, we ignore what is being required. From what I’ve read, the requirements looked eminently reasonable. To the point where not following them right now is kind of unethical. Even if you’re an unpaid open source hobby project. In some domains this is widely understood: I myself have been heavily criticised for having released a cryptographic library, even though I took every precaution I possibly could. While I do think much of this criticism was unfounded knee-jerk reactions, the idea behind it, that it is serious stuff, is actually good. Thing is, security products aren’t the only "serious stuff" out there. Anything that parses untrusted input (any reader, any network server…) can have serious vulnerabilities, and as such is kind of serious too. Thus, my opinion here is that pretty much any published software should follow this regulation, even if it isn’t bound by it.
- marcinzm 3y agoSo if a company decides to open source some of their internal software and periodically release updates they'd be liable now? I don't see how that would not outright kill 99.9% of the open source released by companies. Most companies only do so nowadays because engineers push for it and not any tangible benefit so no reason to allow it anymore given the risk. edit: That'd mean no Hadoop, Envoy, Finagle, React, GraphQL, StatsD, Airflow, etc.
- nforgerit 3y agoI think in the future I'm gonna open my sources as science fiction literature with "hypothetical" installation notes. Prose is not yet prohibited, is it?
- megous 3y agoIs it too hard to link to the actual proposed regulation, instead of just to some blogs?