Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

31–40 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#31

Since this regulation is happening, necessary and welcome, it's good to see some of the most respected FOSS groups taking the lead. Hopefully many others representing smaller development communities will join the Eclipse initiative. I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as…

> Joe Hacker also needs a seat at this table. Any suggestions on organizations? These come to mind, but there must be others. Free Software Foundation, https://www.fsf.org/ NLnet, https://nlnet.nl/project SPI, https://www.spi-inc.org/projects Software Conservancy, https://sfconservancy.org

There's no shortage of EU-based NGOs focusing on tech advocacy. Any of these would fit right in: https://edri.org/about-us/our-network/?organisations-status=...

Whether they'd have something to contribute with their resources is a completely different question.

A bit of a tangent: FSF has a separate legal entity within the EU (https://fsfe.org/) which is (IMHO) way better at advocating than its American counterpart. There's also FSFI (India) and FSFLA (Latin America), but I'm unfamiliar with their work.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#32

Earlier quoted context omitted.

> I'd rather have securer products to get started with and then take it from there. Look forward to great American, Chinese and Korean software and hardware, who’ll invest 100% of their funds into innovation and growth, while EU startups keep paying for Open Source software security and subsidising this security advantage for the whole world. The non-EU companies will grow big and then buy out the EU companies, while…

You present one possible outcome but it is far from certain. Another possible scenario is that companies investing in these principles will be way ahead when similar regulation will pop up _everywhere_ else. You also present your opinion as a factual statement: "Laws like these need to be..." -> No, they don't as can be seen by GDPR, CRA and others. I am personally affected by the CRA, I have a startup here in Europe…

> No, they don't as can be seen by GDPR, CRA and others.

You’re optimism is great, tbh I am extremely cynical.

But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML.

Europe has far higher education outcomes for its young graduates, than both America and India. There is almost no student debt in most major EU countries.

Yet why is it that not just America, even India a significantly poorer country, with worse infrastructure, bad quality colleges which forces their brightest minds to come to EU, America and Australia to study in higher education.

And YET they do better than Europe when it comes to Tech ? Why ? It’s not just cheap labour, other places have even cheaper labour and more lax regulations.

I’m just saying the reality, I love your optimism, but I wish EU bureaucrats were actually that effective. GDPR just allows non-EU companies to grow big in their domestic markets and then they think about regulations more and enter the EU market. While EU companies have to think of laws from the beginning.

Security isn’t some black magic science which can be an intellectual secret, or give bleeding edge. It’s grunt work mostly, and gets postponed to invest in more profit generating parts of the business. If non-EU businesses think they are losing money due to lax security, they’ll flip the game, but this law doesnt do that, non-EU companies just first expand in their large domestic markets and then think about the rest later once they have more money to think of it.

Consumer will definitely win from CRA, just like they did with GDPR, USB-C just in the short term. It’ll just continue forcing EU pioneers to move to America to start their business.

I hope you are right and I am wrong, it would be great if a region like EU can prove that one can be great innovators while also being heavily regulated and pro-consumer in the long term.

It just hasn’t happened yet, and continues to go the opposite direction. Now ASML is threatening to move elsewhere too (albeit for different reason).

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#33

Am I getting older? On a modern display... reading that text is awful. Had to zoom it to 150%. At 'default' it's damn near 'fuzzy' looking. Apache, omg, use a readable font and size for goodness sake.

That’s what reader mode is for (I had the same reaction).

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#34

Since this regulation is happening, necessary and welcome, it's good to see some of the most respected FOSS groups taking the lead. Hopefully many others representing smaller development communities will join the Eclipse initiative. I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as…

> I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as BigFOSS

While names cited are associated to long-standing well-recognized projects, it strikes me at odd to include Rust Foundation here. Not only the language itself is still relatively new and used in few real life projects, but the foundation is very new (2021).

Moreover, looking at its last annual report, it spent half of it's budget (1.5M$) on "membership & admin". It seems like the true action of this foundation is to beg money from big corps and give it to a few selected members.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#35

Am I getting older? On a modern display... reading that text is awful. Had to zoom it to 150%. At 'default' it's damn near 'fuzzy' looking. Apache, omg, use a readable font and size for goodness sake.

It's text size 14px + a relative thin font + font with "serifs" + #404040; instead of black. Which is a gray which looks black but is 25% white.

I.e. thin small text of a font type which is well known to yield less good results on screens with unnecessary low contrast == bad UX.

Sadly way to many people today assume in their choices (sometimes without realizing it) everyone has mac book level HiRes OLED display and good eye sight where this should still looks quite fine (the contrast is better due to the screen, the font might lock wider due not using traditional sub pixel anti-aliasing, and the serifs aspect is less "bad" on high resolution displays).

But if you display it on a 1080p ISP display (assuming it's a decent 1080p ISP display) it will not be a very pleasant experience in a very subtle way due to lower contrast potentially thinner text and serifs in generally leading to decreased readability on non HiRes screens (hence why for years the general recommendation was not to use them for digital content).

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#36

Am I getting older? On a modern display... reading that text is awful. Had to zoom it to 150%. At 'default' it's damn near 'fuzzy' looking. Apache, omg, use a readable font and size for goodness sake.

Fine on android firefox.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#37
post #14

Earlier quoted context omitted.

> "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. >…

> I disagree. It stops new connectors being introduced (because you will still have to provide USB-C). And just like with the predecessor Micro-USB: nothing stops the EU Parliament from adopting new legislation to update to new technologies. Unlike the US Congress, the EU Parliament is still able to regularly pass new laws. > There is little gain: essentially slightly lower sales of charger cables. No charger include…

In general USB chargers work with Apple devices. You just need another cable. Cables are small, fragile (so do not last anyway) and have minimal impact on transport or waste production.

While legislation can be changed, it takes time and influence to do so. What manufacturer would introduce a new charger unless they are sure the EU would allow it? It essentially means it will only change if a big manufacturer lobbies for it BEFORE launching products, or if a standard gets established in the rest of the world before the products are launched in the EU. Not exactly encouraging innovation.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#38
post #8

Earlier quoted context omitted.

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

This is just the final draft, this was not their intention before. They wanted to hold opensource devs legally liable before. Only after several months of backlash, lobbying and bad PR, they changed it into that. They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only E…

> They wanted to hold opensource devs legally liable before

No, the legislators hadn't considered open source software at the early stages. Once that gap was realised, there were negotiations and exceptions were carved out.

> It just hurts EU innovators while benefiting everyone else

Believe it or not, but the EU's higher priority is EU people and consumers, not startups. It will be possible to run a startup under CRA, just as it is now possible under GDPR.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#39
post #14

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

> "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. >…

> You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data.

It's not a burden to have to do common sense things. Is it a burden not to leave medical or private or financial data publicly readable stored on a share everyone can access? Yes, it is, but when you have such data you also have a responsibility to protect it. Since private entities were incapable of that, GDPR tells them how they should do that. Reminder that Americans that do not have access to protections such as GDPR, have their private information leaked frequently, and abuse is rampant (any random company you interact with selling whatever they can - be it telecoms, services, up to Grindr selling HIV status).

> I disagree. It stops new connectors being introduced (because you will still have to provide USB-C). There is little gain: essentially slightly lower sales of charger cables.

There's an explicit mechanism for the connector to be refreshed periodically, so no, it doesn't.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#40
post #34

Since this regulation is happening, necessary and welcome, it's good to see some of the most respected FOSS groups taking the lead. Hopefully many others representing smaller development communities will join the Eclipse initiative. I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as…

> I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as BigFOSS While names cited are associated to long-standing well-recognized projects, it strikes me at odd to include Rust Foundation here. Not only the language itself is still relatively new and used in few real life projects, but…

Here's[0] a breakdown from the foundation on that budget category. They also commit to breaking it down better in the future:

  Salaries, benefits, payroll taxes, payroll service provider fees: $1.17m  
  Travel, event sponsorship, & support: $192k  
  Legal and Professional Fees: $66k
  Fund transfer to the Grants Program from membership fees: $40k
  Fund transfer to the Specification work from membership fees: $20k
  Marketing: $36k
  General Admin: (software, bank fees, meeting rooms, etc.) $20k
It's mostly salaries. They employ four engineers (software, security, infrastructure) that work on Rust, who they pay "at or above the average in their local market."

[0]: https://rust-lang.zulipchat.com/#narrow/stream/335408-founda...

Post reply on HN