5 ms·
CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fa
by Lariscus 2y ago
CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1]
[1] https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-for-open-source/ https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
- graemep 2y agoThat exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.
- Sukera 2y agoIt doesn't only cover pure hobby projects: > (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. > (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity. > (10c).. for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives. See https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-for-open-source/ https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
- temac 2y agoTo be clear "related consultancy or hosting business" is still commercial. The notion of "accepting donations without the intention of making a profit" seems insane, too.
- graemep 2y agoThe idea is that you can accept donations to cover the costs, but not beyond that. So an organisation can pay developers to work on it, cover hosting costs etc. but they have to be careful not to accept donations for more than that. A non-profit can accept more provided it is used for the right objects. I have no idea (neither does the author of the article) where that leaves an individual developer who accepts donations to cover the value of their time.
- graemep 2y agoMore than hobby, you are correct. I should have said "completely unrelated to commercial activity" That is still a problem: https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-for-open-source/#things-that-are-commercial https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f... > the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. That just means that a business can donate to a non-profit project. Such a business would still need to not profit from the project in anyway. Why would a business help develop something it does not profit from? > for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives So again, an organisation can, provided it no profit. These are very narrow exemptions.
- bdd8f1df777b 2y agoIf I offer a product under both open source and commercial license, and then someone uses an open source version without paying me anything, neither for the license nor consultancy, am I liable for damages?
- teitoklien 2y agoThis is just the final draft, this was not their intention before. They wanted to hold opensource devs legally liable before. Only after several months of backlash, lobbying and bad PR, they changed it into that. They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only EU businesses pay for it. Laws like this should only be applied to billion dollar companies not small businesses or startups. It just hurts EU innovators while benefiting everyone else. Laws don’t matter, they almost always sound sweet in decent governments like EU. What effects those laws cause in the real world when accounting for all players in the market matter a lot more. And this law will yet again benefit non-EU startups while hurting EU startups.
- sofixa 2y ago> They wanted to hold opensource devs legally liable before No, the legislators hadn't considered open source software at the early stages. Once that gap was realised, there were negotiations and exceptions were carved out. > It just hurts EU innovators while benefiting everyone else Believe it or not, but the EU's higher priority is EU people and consumers, not startups. It will be possible to run a startup under CRA, just as it is now possible under GDPR.
- Lariscus 2y agoI recommend actually reading the CRA[1] the requirements for non-critical software are easy to follow. If your product does not fall into the categories described in Annex III you are making non-critical software. The requirements are described in Annex IV, V and VI. You must do a conformity assessment and provide a declaration of conformity. For non-critical software you can do the assessment yourself see the first five points in Annex VI. The only thing that maybe requires a bit of effort is that you must write some technical documentation including a cybersecurity risk assessment. For critical software the process is more involved because it requires certification by a "notified body". If a startup in the EU fails because they have to write a bit of documentation once in a while they deserve to fail. Also if a startup wants to create security relevant software I expect that they follow some security standard and the CRA makes sure of that. None of these requirements are something only a billion dollar company can do. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52022PC0454 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...