Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

21–30 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#21

Since this regulation is happening, necessary and welcome, it's good to see some of the most respected FOSS groups taking the lead. Hopefully many others representing smaller development communities will join the Eclipse initiative. I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as…

> Joe Hacker also needs a seat at this table.

Any suggestions on organizations? These come to mind, but there must be others.

Free Software Foundation, https://www.fsf.org/

NLnet, https://nlnet.nl/project

SPI, https://www.spi-inc.org/projects

Software Conservancy, https://sfconservancy.org

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#22
post #14

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

> "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. >…

> I disagree. It stops new connectors being introduced (because you will still have to provide USB-C).

And just like with the predecessor Micro-USB: nothing stops the EU Parliament from adopting new legislation to update to new technologies. Unlike the US Congress, the EU Parliament is still able to regularly pass new laws.

> There is little gain: essentially slightly lower sales of charger cables.

No charger included means thinner packaging of products like laptops and phones and thus better transport efficiency (you can store more products in one container), less e-waste from chargers and cables that end up in the "never used" bin, and an easier time for consumers: no need to carry half a bag worth of power bricks, a single Anker dual-port power supply is all I need when going on vacation - it powers our laptops, phones, Switch, everything.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#23

Meanwhile, US reduced funding for the NVD database that the software world depends upon for vulnerability analysis, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing…

Part of the problem is people who write up CVEs simply to get them on their resume. ("Curriculum Vitae Enhancement"?)

The SQLite maintainers refuse to engage with the CVE process, partially for this reason:

"While the original idea being CVEs is sound, the current processes for creating and managing CVEs are inadequate. There are countless grey-hat hackers running fuzzers against a wide-variety of open-source software products (SQLite as well as many others) and writing up CVEs against any problems they find. The grey-hats are rewarded, sometimes with prestige and sometimes financially, by the number and severity of the CVEs they write. This incentive results in a proliferation of CVEs which are often not well-vetted and which can have exaggerated impact claims. The quality-control procedures for CVEs are unable to cope with this flood of inputs, making it difficult to correct exaggerated, misleading, omitted, or inaccurate claims."

- https://www.sqlite.org/cves.html

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#25
post #23

Meanwhile, US reduced funding for the NVD database that the software world depends upon for vulnerability analysis, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing…

Part of the problem is people who write up CVEs simply to get them on their resume. ("Curriculum Vitae Enhancement"?) The SQLite maintainers refuse to engage with the CVE process, partially for this reason: "While the original idea being CVEs is sound, the current processes for creating and managing CVEs are inadequate. There are countless grey-hat hackers running fuzzers against a wide-variety of open-source softwar…

[deleted]

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#26
post #23

Meanwhile, US reduced funding for the NVD database that the software world depends upon for vulnerability analysis, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing…

Part of the problem is people who write up CVEs simply to get them on their resume. ("Curriculum Vitae Enhancement"?) The SQLite maintainers refuse to engage with the CVE process, partially for this reason: "While the original idea being CVEs is sound, the current processes for creating and managing CVEs are inadequate. There are countless grey-hat hackers running fuzzers against a wide-variety of open-source softwar…

> CVEs which are often not well-vetted and which can have exaggerated impact claims

Hence the Yocto letter calling for approved tools to help the OSS community decentralize vetting.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#27

Earlier quoted context omitted.

CRA applies to all companies, Fedramp applies to just government. All major governments have policies like this, its an issue when government tries to over regulate private matters. What government regulates inside its own workforce, is absolutely upto them. But government shouldnt interfere so much into private matters.

But this is not a private matter. The costs of poor cybersecurity are born mostly not by the people producing the "bad" software but by their consumers. In the end we have law enforcement dealing with ransomware attacks, cybercrime etc. and this will never fully go away but some products don't even apply basic security principles and therefore distribute the cost of this amongst everyone. Yay, they get to produce che…

> I'd rather have securer products to get started with and then take it from there.

Look forward to great American, Chinese and Korean software and hardware, who’ll invest 100% of their funds into innovation and growth, while EU startups keep paying for Open Source software security and subsidising this security advantage for the whole world.

The non-EU companies will grow big and then buy out the EU companies, while EU citizens will be left with wonder why all the major high paying tech and R&D jobs are all outside EU.

Laws like these need to be agreed upon, by all major countries together. No one country should pass policies like this which just sabotages their own people’s innovative dreams.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#28
In case anyone is interested: The EU did publish the draft "standardization request" recently https://ec.europa.eu/docsroom/documents/58974

This is the request which will allow the three european standardization organizations (CEN, CENELEC, ETSI) to draft the required 41 standards for the Cyber Resilience Act (CRA). See page 17 and following for the list.

To participate in the standardization you have to be part of a "national body" and they will "send" you to participate in EU standardization. I know no one from my FOSS circles who has any experience there, as most relevant standards for us are written outside of these organizations (W3C, IETF etc.)

So we're currently trying to get an official seat at the table via the established ways (e.g. DIN in Germany, https://standards.cencenelec.eu/dyn/www/f?p=CEN:5 see this for your own country).

If you are interested in this please send me an email, we're trying to put together a guide on how to engage in "official" standardization efforts as Open Source people.

The effort from this blog post is (amongst other things) trying to establish a whole new way of engaging with the EU. We need both approaches.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#29

Earlier quoted context omitted.

But this is not a private matter. The costs of poor cybersecurity are born mostly not by the people producing the "bad" software but by their consumers. In the end we have law enforcement dealing with ransomware attacks, cybercrime etc. and this will never fully go away but some products don't even apply basic security principles and therefore distribute the cost of this amongst everyone. Yay, they get to produce che…

> I'd rather have securer products to get started with and then take it from there. Look forward to great American, Chinese and Korean software and hardware, who’ll invest 100% of their funds into innovation and growth, while EU startups keep paying for Open Source software security and subsidising this security advantage for the whole world. The non-EU companies will grow big and then buy out the EU companies, while…

You present one possible outcome but it is far from certain.

Another possible scenario is that companies investing in these principles will be way ahead when similar regulation will pop up _everywhere_ else.

You also present your opinion as a factual statement: "Laws like these need to be..." -> No, they don't as can be seen by GDPR, CRA and others.

I am personally affected by the CRA, I have a startup here in Europe and I see this as a great chance for EU, FOSS and Software Development in general.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#30

Earlier quoted context omitted.

CRA applies to all companies, Fedramp applies to just government. All major governments have policies like this, its an issue when government tries to over regulate private matters. What government regulates inside its own workforce, is absolutely upto them. But government shouldnt interfere so much into private matters.

But this is not a private matter. The costs of poor cybersecurity are born mostly not by the people producing the "bad" software but by their consumers. In the end we have law enforcement dealing with ransomware attacks, cybercrime etc. and this will never fully go away but some products don't even apply basic security principles and therefore distribute the cost of this amongst everyone. Yay, they get to produce che…

There's a technical existence proof of a secure architecture for problematic IoT hardware, from Microsoft (of all places) Azure Sphere, with a Mediatek MCU based on Pluton (from Xbox and Ryzen). It has hardware separation of security-critical software (Linux Kernel) from IoT application software, allowing each to be updated independently, even if the device vendor goes out of business or cannot afford to invest in security in the first place.

If the security properties of the Azure Sphere design could be generalized beyond Microsoft/AMD/Mediatek by Arm or RISC-V, so that OSS software like Debian or Zephyr could be used in the security-critical hardware compartment, we could have a vendor-neutral starting point for sustainable, low-cost, networked devices sold and supportable by multiple vendors.

https://www.platformsecuritysummit.com/2019/speaker/seay

Further down the road, CHERI capabilities may be a silver bullet, but we're still years away from affordable hardware.

Post reply on HN