13 ms·
Debian Statement on the Cyber Resilience Act
- Karellen 3y agoMaybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)
- froh 3y agothere is insightful discussion right on lwn. I think changing the URL is cutting that out.
- ajdude 3y agoIdeally[1] this thread would link to the original source, and then in the comments we would link to the second hand source that includes interesting or insightful discussion. https://news.ycombinator.com/item?id=38726890 https://news.ycombinator.com/item?id=38726890
- justin66 3y ago[flagged]
- pjmlp 3y agoSmall businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.
- whalesalad 3y agoSo why pile on even more? Terrible justification tbh. It’s hard for a small business or indie developer. The odds are against you.
- pjmlp 3y agoJust like in any business.
- SOLAR_FIELDS 3y agoI’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software
- zmgsabst 3y agoWhat’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?
- giantg2 3y agoStandardized food safety practices, pre-approved and comparatively trivial recipes, state/county inspections, etc. None of which apply to software. One is fairly trivial and standardized. The other is massively complex, rapidly changing, and unable to be boiled down to a standard set of trivial procedures. And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damaging if a malicious actor takes advantage of it.
- beedeebeedee 3y ago> Standardized food safety practices Food safety practices only became standardized after regulation was enacted. > pre-approved and comparatively trivial recipes That sounds like most software development. I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is hazardous to public safety, unlike food production which reached that a long time ago.
- giantg2 3y ago"Food safety practices only became standardized after regulation was enacted." Because you actually can standardize them. Software isn't so simple. "> pre-approved and comparatively trivial recipes That sounds like most software development." Lol no that does not. Why wouldn't high school graduates or drop outs work in software instead of at fast food? The number of languages, frameworks, patterns, etc are much more complex than basic sanitation and time/temp/acidity.
- zajio1am 3y ago> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation between number of customers and liability, and liability cannot be really priced-in.
- charcircuit 3y agoIt can be priced in you just change the minimum price from $0 to how much liability would cost you.
- zajio1am 3y agoIf every user has to pay the minimum price then the software would not be free software, by definition.
- throwaway231228 3y agoNo. https://www.gnu.org/philosophy/free-sw.en.html https://www.gnu.org/philosophy/free-sw.en.html
- zaphar 3y agoThe minimum price for the software can't be changed. It's open source. Once it's out you can't undo it. You will have users paying $0 to use it for what amounts to forever.
- throwaway231228 3y agoIt would be a huge gamble if the "0$ version" (e.g. GitHub repo) gets more popular that anticipated and the one with the bigger price tag not growing accordingly and the whole risk calculation falls apart. There is always the possibility to only offer the priced version, even if it is free software. Someone else could of course redistribute it and then it would be their responsibility. That would be a less convenient world. An open question certainly also is, when it becomes a product? Source Code alone (inredients)? Or executable form (usable)?
- miohtama 3y ago[flagged]
- gunapologist99 3y agoIt should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.
- LadyCailin 3y agoI don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognizes that consumers in general are more protected that businesses. I much rather this than the capitalist hellhole that the US is turning into.
- friend_and_foe 3y agoPretending for a second that I don't outright reject your premise (that there is no inherent right to do business)... You can't just label everything as "doing business" and then regulate it all. If I make something interesting and give everyone in the world the blueprints so they can make one themselves that's not "doing business".
- pbhjpbhj 3y agoIIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and deserves substantial consideration. It is difficult to draw the line here, much more difficult than it seems at first, in my personal opinion.
- jurynulifcation 3y agoI see no considerations for why my giving away stuff for free impacting other people's business means that my ability to freely give ought to be regulated. It is my property. I should be free to freely give of it. If that destroys a business then that kinda sucks, but why does it matter to my ability to engage in consensual non-monetary transactions with my property?
- candiddevmike 3y agoWhat about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
- ManBeardPc 3y agoBig parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Eclipse Foundation on YouTube for infos.
- jahav 3y agoThere is some hope for individual developers in EP amended version https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COMMITTEES/ITRE/DV/2023/07-19/11-CA_CRA_EN.pdf https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COM... article 10c: > Developers contributing individually to free and open-source projects should not be subject to obligations pursuant to this Regulation. Actually it’s an improved version. Hopefully it will make it through consolidation with EC version.
- ManBeardPc 3y agoThank you for providing that, didn't knew about that amended version. This only includes individual developers though and if you are employed this is already a problem again: (10a) "[...]Similarly, where the main contributors to free and open-source projects are developers employed by commercial entities and when such developers or the employer can exercise control as to which modifications are accepted in the code base, the project should generally be considered to be of a commercial nature." A small step in the right direction, but not quite there yet. Companies that want to just release (old) projects would also be more hesitant now. Recurring donations from companies would also contaminate the project.
- bitwize 3y ago[flagged]
- turtleyacht 3y agoNo--see licensing terms. As well, the software used is chosen by the implementors. Now, if folks want regulation, introduce the Certified Professional Software Engineer. (Pay commensurate with tort, of course.)
- deleted 3y ago[deleted]
- jahav 3y ago> it’s called professional accountability Professional does for money, by definition. That doesn’t apply for most open source. RedHat employee contributing to Linux kernel is an exception, not a rule.
- kube-system 3y agoThat is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.
- gunapologist99 3y ago> The majority of open source contributions are people making commits while at their paid jobs. Do you have any evidence to back up this seemingly wildly speculative assertion? And, even if it were true, "while at their paid jobs" doesn't mean at all they're getting paid as developers at all, let alone as developers on those projects that they are contributing to.
- kube-system 3y agoHere's one example: > By studying the Linux Kernel, we document that commercial participation outweighs volunteer participation substantially https://journals.aom.org/doi/abs/10.5465/AMPROC.2023.17240abstract https://journals.aom.org/doi/abs/10.5465/AMPROC.2023.17240ab... Also, empirically, many of the most popular open source projects are published by commercial companies, who hire developers to maintain them. If you review the commit history for these projects, you will see that many of them are, unsurprisingly, employees. https://airtable.com/appiS6H4nkeXdyO89/shrATIy7RIOheo3gF/tblNI7bNzsCDdhYCD?backgroundColor=green&viewControls=on https://airtable.com/appiS6H4nkeXdyO89/shrATIy7RIOheo3gF/tbl... There is inevitable overlap of commercial activity with popular open source software. Either it was a commercial piece of software to begin with, or because it is popular, it now has commercial value and garners commercial attention. Something like React falls into the former, and something like Linux falls into the latter. There's a lot of community open source software too, but it trends towards smaller hobby projects with few users.
- 63 3y agoA lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?
- gavinhoward 3y agoI'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software. This sounds sane-ish, but it the key is that it says Open Source Software is not exempted if it is part of commercial activity. So what is commercial activity? Page 34: > 'making available on the market' means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge That "free of charge" connected with "commercial activity" is what has people up in arms. Does it include free stuff like Debian? Does it include donation-based FOSS like Zig? These are the things that worry people. [1]: https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-34e9-11ed-9c68-01aa75ed71a1.0001.02/DOC_1&format=PDF https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-...
- jahav 3y agoTBF there is a lot of things “free of charge” connected to commercial activity, e.g. Android, .NET Core, MongoDb, ElasticSearch, even RedHat with Linux … I understand need to somehow include them, but the line should be at the for-profit companies and exclude non profits and individual developers. How to formulate it without easy loopholes is no easy task.
- omgmajk 3y ago> It's very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout. Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303) Can someone explain to me what in the statement from Debian is "anarco-capitalist FUD"? I find it quite reasonable overall.
- roenxi 3y agoThere is a reasonable argument that the Debian project has an anarco-capitalist philosophy, so really the only question is whether it is FUD or not. I suspect not though - regulation has a strong track record of taking out smaller players.
- dec0dedab0de 3y agoI also think Debian’s statement seems reasonable. I think the commenter is suggesting that solo developers should not be able to hide behind a “buyer beware” philosophy when they use and contribute to foss libraries. Meaning that it doesn’t matter if smaller development shops are forced to merge with larger vendors, if it is for the greater good. At least that’s how I read it.
- aragilar 3y agohttps://www.debian.org/vote/2023/vote_002?#proposerb https://www.debian.org/vote/2023/vote_002?#proposerb is the person who posted that (and whose proposal came second).
- gavinhoward 3y agoI believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-from-the-cra-and-improve-cybersecurity/ https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...
- api 3y agoIf this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always just been against any such regulation because I have zero confidence our technically ignorant politicians can do it well. I also think it’s likely to be sabotaged by consultants and big tech monopolists who see an opportunity to lock out competitors or create gravy trains.
- gavinhoward 3y agoAll of what you said is true. That is why I want the industry to self-regulate with professional licensure first. If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure would minimize that because requiring a Professional Software Engineer (PSWE) on a project means having someone there for the long term, dedicated to the project, which is antithetical to consultants game plan to run either short projects or many projects at once. As for Big Tech monopolists, yes that could be a problem. However, I think professional licensure, with a Code of Ethics, would actually give the PSWE at such companies the ability to say no to such monopolization. And they would, if we could actually threaten loss of license. So you are correct that my proposal isn't perfect, but I do think it minimizes the risk of bad things happening among the others.
- teeray 3y agoObviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?
- kube-system 3y agoIt could be done for some software, but some popular licenses like GPL don't allow additional restrictions on use.
- quacksilver 3y agoIf it were a big enough problem, could GPLv4 be published (perhaps with a clause to cover this and future laws) and products encouraged to migrate to it?
- Ekaros 3y agoLikely not. A license can not override legislation. Like creative-commons cannot be used to give away moral rights at least if not some of the copy rights too.
- patrakov 3y agoBut we are not talking about overriding legislation. The question is, can GPL4 say "you cannot use or distribute this software" if there is a legal risk to the creator?
- kube-system 3y agoA license could say that, however, the creator would still have legal risk in the case that someone broke the license. "My customer broke the license terms" is not a defense to breaking a law.
- Palomides 3y agono common definition of free/open source software (such as the debian free software guidelines) would permit a use restriction like that
- charcircuit 3y ago>CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Debian and other Linux distributions depend on their work. If Debian depends on people's work so badly maybe they should pay for it.
- hgs3 3y ago> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1]. We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing. When the EU's digital infrastructure begins crumbling they'll change their tune. [1] https://en.wikipedia.org/wiki/Regulatory_capture https://en.wikipedia.org/wiki/Regulatory_capture
- pabs3 3y agoBlocking EU IPs would go against the open source definition and the Debian social contract; discrimination against groups of people.
- throwaway231228 3y agoNo, it would not. Both are concerned with non-discriminatory _licensing._ That would remain the case. Neither of those documents obligate anyone to provide the specific service of providing downloads to anyone else, or providing any act of distribution at all. Nevertheless, not being able to access the Debian servers would be most unfortunate.
- pabs3 3y agoDefinitely disagree there. Debian blocking EU access would be ineffective too, there is a large network of third-party mirrors.
- nparafe 3y agoThe Debian team announcement is on the right track. Asking freelancers and free software groups to face the same measures and fines as big tech companies is unfair competition. The E.U. of course, was never friendly to free software[1]. The bureaucratic and neoliberal extremists that are in the lobby of Brussels will always try to destroy free and independent creation. [1]: https://totsipaki.net/ikiwiki/nparafe/posts_en/posts/Can_European_union_save_free_software/ https://totsipaki.net/ikiwiki/nparafe/posts_en/posts/Can_Eur...
- jocoda 3y agoGiven that this will affect costs by one, maybe two orders of magnitude, why would any developer want to do business with the EU. Is disqualifying EU users even possible?
- hcfman 3y agoEvery small developer should now start to ban government use. Even if they are not affected the law. To associate consequences to actions. They will never learn otherwise.
- ImmutiableTruth 3y agoThis makes a lot of sense if you follow judgements internationally. Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You either make good software and comply with your duty or you will be ruined. That is the law.
- cvalka 3y ago[flagged]
- ImmutiableTruth 3y ago[flagged]
- cvalka 3y ago[flagged]
- voxic11 3y agoHi craig wright, how are things?
- ImmutiableTruth 3y ago[flagged]
- hcfman 3y agoIt’s time for everyone to put a clause in their licenses banning direct and transient free use of their software for governments. I have two projects and added such a clause in protest.
- hcfman 3y agoIt’s time for governments to have more responsibility. The cyber resilience acts pushes 15,000,000 euros penalty to software developers. How much liability does government have for anything bad they do ? First it’s extremely difficult to get to them to be responsible for anything. Then in the Netherlands any liability would be a pittance. Nothing like 15,000,000 euros.
- hcfman 3y agoAnd don't skip over the part where they want developers to report any zero day's you discover to them within 24 hours so they can use them as exploits against innocent civilians not involved in any crime. And yes, the Netherlands changed the law recently so they can do this and without requiring any judge involved. And yes, they are allowed to hack people not involved with any crime as well. As well as changing the law in 2020 so all of government, including their prosecutors may law in court under oath and not be held liable. And then they want other people to be accountable, how about government be accountable first.
- 6R1M0R4CL3 3y agoi won't do it. and since they dont know i know of a security problem... nothing they can do about that.
- hcfman 3y agoAdditionally, there's nothing wrong with what we have now. So there are some security flaws. But we have really fancy mobile phones and an amazing Internet. Now rewind to 1990 or so. Add a Cyber resilience act. At best we maybe have a phone about as advanced as an old Nokia. But yeah, maybe hardly any cyber security flaws because the Internet would hardly function. Instead of thanking all of the millions of developers who contributed to this, they proceed to kick them in the teeth and enact laws to steal from them in principle by raising the cost of entry.
- 6R1M0R4CL3 3y ago[flagged]