Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

41–50 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#41
post #17
post #8

Earlier quoted context omitted.

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

It doesn't only cover pure hobby projects:

> (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature.

> (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity.

> (10c).. for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives.

See https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#42
post #18
post #13

Earlier quoted context omitted.

> If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. USB-C is a clusterfuck of a connector, and I'm not just talking about the various voltages and how using the wrong cable can fry your equipment. I'm talking about the physical connector itself. See, the USB-C port has a shroud around the outside and a "tongue" in the middle where all the cont…

I don't have an opinion on this. The female plug always holds the power and the male taps into it. Doing it the other way around is unusual, you get a naked male plug with power on it just dangling around.

While true for clear one way connections, usbc is bi-directional or symmetrical.

1 Either side may provide power.

2 usbc power delivery requires a fancy communication and management chip, and there is no power until after a handshake has been negotiated.

So in that case a lightning style cable could be ok. (besides, even with plain usb2, lightening already existed for years without a problem)

But while lightning-style may be good, F lightening specifically. The design was good for the reasons stated. Put the weak points in the more disposable part of the system. But for standards purposes I am not interested in any good design that anyone owns.

All in all, lightning is not good. If it's good but you can't use it, then it's not good.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#43

Earlier quoted context omitted.

You present one possible outcome but it is far from certain. Another possible scenario is that companies investing in these principles will be way ahead when similar regulation will pop up _everywhere_ else. You also present your opinion as a factual statement: "Laws like these need to be..." -> No, they don't as can be seen by GDPR, CRA and others. I am personally affected by the CRA, I have a startup here in Europe…

> No, they don't as can be seen by GDPR, CRA and others. You’re optimism is great, tbh I am extremely cynical. But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML. Europe has far higher education outcomes for its young graduates, than both America and India. There is almost no student debt in most maj…

" But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML. " You are aware that big corp from Silicon Valley have big offices in Europe ? E. g. Apple in Munich?

" even India a significantly poorer country, [..] And YET they do better than Europe when it comes to Tech ? Why " citation needed

" GDPR just allows non-EU companies to grow big in their domestic markets " Local business in Germany complain about bureaucratic laws. But no one ever about GDPR. Its just a non-issue outside of AdTech.

" Consumer will definitely win from CRA, just like they did with GDPR, USB-C just in the short term. It’ll just continue forcing EU pioneers to move to America to start their business. " Currently according to State of European Tech 2023 more people move from the US to Europe than vice versa.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#44

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

The EU's approach is the result of the industry not advancing enough to self-regulate. Legislation is required to outline the lines we can no longer afford to cross, and we can't turn normal people into tiny cash cows to make the already rich even richer.

Both GDPR, DSA, DMA and related policy have been a win for consumers and normal people using electronic services (which is practically everyone). I expect the CRA to bring much needed awareness regarding security and that it's no longer OK to just put together something with spit and chewing gum and let people submit their personal data into it!

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#45
My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devices, while providing no way for the customer to take ownership of the device back, so that they can run their own software.

I really hope that we eventually get a mandate so that every device, that requires an internet connection for any and all features, will also have to allow the customer to overwrite and use their own software in case they have to make any software/security repairs themselves.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#46

Am I getting older? On a modern display... reading that text is awful. Had to zoom it to 150%. At 'default' it's damn near 'fuzzy' looking. Apache, omg, use a readable font and size for goodness sake.

That’s what reader mode is for (I had the same reaction).

At this stage there's only a few websites where I'd like reader mode off, really. It removes a lot of advertising, bypasses cookie modals, doesn't execute a lot of javascript, etc etc.

I wonder how long before we get browsers that run in readability mode first and foremost? O:-)

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#47

In case anyone is interested: The EU did publish the draft "standardization request" recently https://ec.europa.eu/docsroom/documents/58974 This is the request which will allow the three european standardization organizations (CEN, CENELEC, ETSI) to draft the required 41 standards for the Cyber Resilience Act (CRA). See page 17 and following for the list. To participate in the standardization you have to be part of a…

I'd like to give my comments on the new standards, but I'm never going to be chosen to be part of an elite squad of standards-writers. Is there any chance of the standards developing more in the open, with a community in addition to the committee?

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#48
post #17
post #8

Earlier quoted context omitted.

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

If I offer a product under both open source and commercial license, and then someone uses an open source version without paying me anything, neither for the license nor consultancy, am I liable for damages?

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#49
post #17

Earlier quoted context omitted.

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

If I offer a product under both open source and commercial license, and then someone uses an open source version without paying me anything, neither for the license nor consultancy, am I liable for damages?

Not liable

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#50
post #43

Earlier quoted context omitted.

> No, they don't as can be seen by GDPR, CRA and others. You’re optimism is great, tbh I am extremely cynical. But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML. Europe has far higher education outcomes for its young graduates, than both America and India. There is almost no student debt in most maj…

" But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML. " You are aware that big corp from Silicon Valley have big offices in Europe ? E. g. Apple in Munich? " even India a significantly poorer country, [..] And YET they do better than Europe when it comes to Tech ? Why " citation needed " GDPR just al…

> You are aware that big corp from Silicon Valley have big offices in Europe ? E. g. Apple in Munich?

Its done for tax reasons and lobbying efforts, its used more as a weapon than for actual reasons.

Apple pays an effective tax rate of 5-6% on EU revenue and profits, while EU businesses pay much higher, this scenario is constantly used by big EU businesses like Seimens to get more tax credits and public grants while threatening germany from moving headquarters of company elsewhere. Apple having offices here pales in comparison to an EU owned tech giant granting great salaries, dividends to EU pension fund holders, instead they make American pension funds, income taxes get better, while EU companies cannot compete due to regulatory burden. Startups matter a lot, Apple started from a garage with 3 people.

China bought KUKA , the largest global robotics giant and a EU owned company, now it owns 100% has delisted the stock from EU exchange (so EU citizens with their pensions wont get the future profits and dividends generated by KUKA) AND China has said they are only committing to keeping those high tech EU jobs till 2025 after that they are moving all those jobs to Asia.

> India a significantly poorer country, [..] And YET they do better than Europe when it comes to Tech ? Why " citation needed

There are a lot of major Indian software companies paying america like salaries for their best talents (even without adjusting for purchasing power parity), most of these tech unicorns register their companies in Singapore or America so it doesnt show up, but in reality they are employing tons of Indians and driving innovation in that country. A lot of US stock exchange listed companies are in reality Indian businesses primarily employing Indians. It’s why such a small sector in terms of employment in India contributes 15% or higher in GDP growth to the 5th largest economy in the world. Even with all the disadvantages India has.

> But no one ever about GDPR. Its just a non-issue outside of AdTech.

Adtech is 98% revenue of Google and Facebook, both of them combined at their highest valuation were worth more than entire EU stock exchanges combined. Each of these “adtech companies” can buy out some of the major EU businesses in a heart beat.

I feel a lot of this feels like sports contest, you’re rooting for how team EU is so amazing, while I’m trying to show how its shooting itself in the foot.

We both want EU to win, but it’s not necessary to worship them, the policy makers are making a lot of decisions which will hurt EU for decades to come into the future.

EU has the power to be the tech and innovation capital of this world, with great colleges, minimal student debt, innovators not having to worry about outrageous healthcare costs for their family, allowing them to take more risks and going without a salary while working on their startups, yet EU continues to underperform and declines.

It’s because of government policies.

> Currently according to State of European Tech 2023 more people move from the US to Europe than vice versa.

Currently EU is also the #1 destination for illegal migrants and refugees. How many americans come to EU is meaningless. The net economic and strategic contributions of the ones who are leaving EU for USA vs vice versa is much more important.

Post reply on HN