Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

11–20 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#11
Meanwhile, US reduced funding for the NVD database that the software world depends upon for vulnerability analysis, https://nvd.nist.gov/general/news/nvd-program-transition-ann...

  NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities submitted to the NVD and requiring analysis. This is based on a variety of factors, including an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.
March 8th analysis by Linux Foundation's OpenSSF, https://www.securityweek.com/cve-and-nvd-a-weak-and-fracture... & https://www.linkedin.com/posts/netriseinc_cve-vulnerabilitym... (graph)

> Starting February 12th, thousands of CVE IDs have been published without any record of analysis by NVD. Since the start of 2024 there have been a total of 6,171 total CVE IDs with only 3,625 being enriched by NVD. That leaves a gap of 2,546 (42%!) IDs.

Private/paid offerings? https://www.darkreading.com/vulnerabilities-threats/nist-nee...

> NIST is going to open up the program to a consortia of vetted organizations from the industry in order to deal with the backlog of vulnerabilities that need to be analyzed.. Budget cuts happening for the first time in a decade.. hopefully a pivot to a private-public sector partnership can be reached quickly to scale up the program

OSS alternative to paid offerings? April 2024 open letter from Yocto, https://github.com/yoctoproject/cve-cna-open-letter/blob/mai...

  Processes/tooling to easily allow CNAs to adopt enhancements to CVEs would also encourage improving the data, ideally as easy as something like a GitHub pull request. We, as projects that need to respond to security issues, could all do things in our own ways. Many of us have open source backgrounds and realise the power of collaboration and would much prefer to work together and build something none of us alone could achieve. We need the tools, processes and core support from the CVE project to make it happen.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#12

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

"USB-C" -> Good for consumer, I believe With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily. If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. The road to hell is paved with good intention, I doubt any decent government (which EU is) would pas…

The EU tried making micro USB mandatory only after first asking the industry to cooperate and self-standardize. Legislation was the very last thing tried.

After years of Apple stalling not cooperating, the EU got fed up, and forced them.

GDPR was similar: Only after years of abuse by adtech etc.., the regulator took action.

Maybe this is a communication mismatch between US and EU culture? EU companies tend to take the hint from the EU and do something before they are forced. US companies say: ...but there is no law forcing me? Then act surprised when said law is written.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#13

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

"USB-C" -> Good for consumer, I believe With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily. If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. The road to hell is paved with good intention, I doubt any decent government (which EU is) would pas…

> If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer.

USB-C is a clusterfuck of a connector, and I'm not just talking about the various voltages and how using the wrong cable can fry your equipment. I'm talking about the physical connector itself. See, the USB-C port has a shroud around the outside and a "tongue" in the middle where all the contacts are. The USB-C plug has a shroud which fits into the port's shroud, but inside the plug's shroud are all the contacts which align with the contacts on the tongue. This tongue is fragile, necessitating replacement of the whole port if it breaks or is otherwise damaged. If I am not very careful with my phone's USB-C connector, it can get flaky and make even charging (let alone data transfer) difficult and annoying within a year.

Do you want to see an example of a good design? Look at Apple's Lightning connector, where the fragile tongue is on the more easily replaceable plug, and the port is just the shroud. Meaning my wife just plugs or unplugs her iPhone all the time, never worrying about what kind of damage dirt or lint might cause if it gets into the port or whether inserting or removing the plug too hard might permanently harm the port. It Just Works, every time.

Mandating USB-C just made the connector situation worse for everybody. Mandating an open standard doesn't really help much if it's a shitty standard. It just squelches any improvements a company might make.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#14

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

> "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways

You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data.

> "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner.

Yes, but it does little good, and it stops end users from white-listing sites allowed to set cookies because you need to allow the cookies that track your cookie options.

> "USB-C" -> Good for consumer, I believe.

I disagree. It stops new connectors being introduced (because you will still have to provide USB-C). There is little gain: essentially slightly lower sales of charger cables.

Add to that messes like VAT MOSS which was ridiculously heavy and even lead to some small businesses stopping sales to other EU countries to avoid complying with it.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#15

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

> It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else.

I have been wondering whether it would be possible to a add a limitation of liability in line with GPL3 7 a) that allows "Disclaiming warranty or limiting liability differently from the terms of sections 15 and 16 of this License" to prevent redistribution that exposes the authors to any liability. it is definitely possible to add an indemnification clause to cover any risk under clause 7 f.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#16
post #6

I guess the foundations are hyped because CRA basically forces companies to pay for security of OS projects (which the foundations try to be the main receiver of the money) But in the end the OS ecosystem becomes much more secure. Otherwise all the SV dudes complaining about the over burocratics: How to improve Software security? Only alternative I can think of, is the goverment pays for the security. For me thats a…

"Hyped" is not the word I'd use. Most of us are or were concerned and it took a lot of long meetings to even move "us" out of the category of "software manufacturer" and into a new category of "steward" which is currently not well defined.

Also not hyped because the required standards are written at the EU level and there is no established process for foundations to participate in these standards.

So it's more like: Trying to do the best with the cards we've been dealt.

I agree wtih everything else you're saying.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#17
post #8

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable.

It only covers pure hobby projects by pure hobby developers.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#18
post #13

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily. If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. The road to hell is paved with good intention, I doubt any decent government (which EU is) would pas…

> If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. USB-C is a clusterfuck of a connector, and I'm not just talking about the various voltages and how using the wrong cable can fry your equipment. I'm talking about the physical connector itself. See, the USB-C port has a shroud around the outside and a "tongue" in the middle where all the cont…

I don't have an opinion on this. The female plug always holds the power and the male taps into it. Doing it the other way around is unusual, you get a naked male plug with power on it just dangling around.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#19
post #3

Earlier quoted context omitted.

I won't bother addressing most of the nonsense you've written. I'll just say that the US has FedRAMP ( https://en.wikipedia.org/wiki/FedRAMP ) and EO 14028 ( https://www.federalregister.gov/documents/2021/05/17/2021-10... ). So if you imagine that this is somehow an EU-specific thing and doesn't affect the US, you're very wrong. Not to mention NIST and FIPS and CISA.

CRA applies to all companies, Fedramp applies to just government. All major governments have policies like this, its an issue when government tries to over regulate private matters. What government regulates inside its own workforce, is absolutely upto them. But government shouldnt interfere so much into private matters.

But this is not a private matter.

The costs of poor cybersecurity are born mostly not by the people producing the "bad" software but by their consumers.

In the end we have law enforcement dealing with ransomware attacks, cybercrime etc. and this will never fully go away but some products don't even apply basic security principles and therefore distribute the cost of this amongst everyone. Yay, they get to produce cheap crap but at which cost?

I'd rather have securer products to get started with and then take it from there.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#20
post #8

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

This is just the final draft, this was not their intention before. They wanted to hold opensource devs legally liable before. Only after several months of backlash, lobbying and bad PR, they changed it into that.

They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only EU businesses pay for it.

Laws like this should only be applied to billion dollar companies not small businesses or startups. It just hurts EU innovators while benefiting everyone else.

Laws don’t matter, they almost always sound sweet in decent governments like EU. What effects those laws cause in the real world when accounting for all players in the market matter a lot more.

And this law will yet again benefit non-EU startups while hurting EU startups.

Post reply on HN