Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

51–60 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#51
post #15

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

> It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. I have been wondering whether it would be possible to a add a limitation of liability in line with GPL3 7 a) that allows "Disclaiming warranty or limiting liability differently from the terms of sect…

No matter what that it is not possible to override the law with a license. Of course if it is outside your local jurisdiction you can ignore but you don't need a license text for that.

If it applies to you it does so regardless of your license. A court would simply rule the terms illegal.

But as others said this will (arguabely) only apply to real commercial activy and in that realm you (usually9 cannot dislaim liability anyway.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#52
post #8

Earlier quoted context omitted.

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1] [1] https://berthub.eu/articles/posts/eu-cra-w…

This is just the final draft, this was not their intention before. They wanted to hold opensource devs legally liable before. Only after several months of backlash, lobbying and bad PR, they changed it into that. They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only E…

I recommend actually reading the CRA[1] the requirements for non-critical software are easy to follow. If your product does not fall into the categories described in Annex III you are making non-critical software.

The requirements are described in Annex IV, V and VI. You must do a conformity assessment and provide a declaration of conformity. For non-critical software you can do the assessment yourself see the first five points in Annex VI. The only thing that maybe requires a bit of effort is that you must write some technical documentation including a cybersecurity risk assessment. For critical software the process is more involved because it requires certification by a "notified body".

If a startup in the EU fails because they have to write a bit of documentation once in a while they deserve to fail. Also if a startup wants to create security relevant software I expect that they follow some security standard and the CRA makes sure of that. None of these requirements are something only a billion dollar company can do.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#53
post #45

My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devices, while providing no way for the customer to take ownership of the device back, so that they can run their own software. I really hope that we eventually get a mandate so that every device, that requires an internet connection for any and all features, will…

Panic NOT :) There is still retro computing move...

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#54
post #43

Earlier quoted context omitted.

" But name one Fortune 50 tech company making great profits giving high salaries to EU devs and R&D folks that isnt relying on Government Funding from EU except SAP & ASML. " You are aware that big corp from Silicon Valley have big offices in Europe ? E. g. Apple in Munich? " even India a significantly poorer country, [..] And YET they do better than Europe when it comes to Tech ? Why " citation needed " GDPR just al…

> You are aware that big corp from Silicon Valley have big offices in Europe ? E. g. Apple in Munich? Its done for tax reasons and lobbying efforts, its used more as a weapon than for actual reasons. Apple pays an effective tax rate of 5-6% on EU revenue and profits, while EU businesses pay much higher, this scenario is constantly used by big EU businesses like Seimens to get more tax credits and public grants while…

Im sorry you didnt provide any source for your Indian claim. You deny the quality of Silicon Valley offices on their European location (which is a huge insult for their engineer working their)

Currently EU is also the #1 destination for illegal migrants and refugees. How many americans come to EU is meaningless. The net economic and strategic contributions of the ones who are leaving EU for USA vs vice versa is much more important.

"Currently EU is also the #1 destination for illegal migrants and refugees. How many americans come to EU is meaningless. The net economic and strategic contributions of the ones who are leaving EU for USA vs vice versa is much more important."

You can easily assume that legal emigration is mostly for high qualified labours (illegal US emigration is a None - Issue) so yes the economic and strategic contributions are important.

But given your missing claims I guess I opt out of the discussion.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#55
post #41
post #17

Earlier quoted context omitted.

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

It doesn't only cover pure hobby projects: > (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. > (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity. > (10c).…

To be clear "related consultancy or hosting business" is still commercial.

The notion of "accepting donations without the intention of making a profit" seems insane, too.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#56
post #53
post #45

My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devices, while providing no way for the customer to take ownership of the device back, so that they can run their own software. I really hope that we eventually get a mandate so that every device, that requires an internet connection for any and all features, will…

Panic NOT :) There is still retro computing move...

Why not both? Build an open future on the expensive lessons of past hardware.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#57

Earlier quoted context omitted.

This is just the final draft, this was not their intention before. They wanted to hold opensource devs legally liable before. Only after several months of backlash, lobbying and bad PR, they changed it into that. They will most likely bring that clause back in a few years after the current bill is passed. Once they realise that their current law is essentially subsidizing security of the whole world, by making only E…

I recommend actually reading the CRA[1] the requirements for non-critical software are easy to follow. If your product does not fall into the categories described in Annex III you are making non-critical software. The requirements are described in Annex IV, V and VI. You must do a conformity assessment and provide a declaration of conformity. For non-critical software you can do the assessment yourself see the first…

You could say all of that of other things e.g. the MDR, where the end result in practice is complete crap. The system of "notified bodies" is commercial bureaucracy with random efficiency. If an agency wants to audit me, just dot it. The FDA does, with lower delays than commercial EU notify bodies... (right now the EU is accumulating more and more years of delay on putting medical devices on the market, even locally developped)

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#58
post #45

My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devices, while providing no way for the customer to take ownership of the device back, so that they can run their own software. I really hope that we eventually get a mandate so that every device, that requires an internet connection for any and all features, will…

Strict launch integrity (unlike "secure boot") depends on a customer-defined root of trust. OpenCompute (OCP) Caliptra is an effort by hyperscalers to enforce a platform root of trust with OSS firmware, mandating dual signature by server OEM and hyperscaler customer. The platform RoT is responsible for validating device firmware and OS boot.

https://www.youtube.com/watch?v=p9PlCm4tLb8&t=2764s

> Often we see.. great security.. compromised by other great ideas for mgmt and other things.. starts to weaken its security posture.. want to keep Caliptra very clean [via OSS firmware transparency]

Separately, AMD has promised OpenSIL open firmware by 2026, https://www.phoronix.com/news/AMD-openSIL-Detailed

Isolation architectures like pKVM on Android can run banking or wallet applications in a security-controlled VM, alongside arbitrary user-defined VMs. In contested environments, both security and the freedom to innovate are necessary to survive an arms race with a competent adversary.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#59
post #47

In case anyone is interested: The EU did publish the draft "standardization request" recently https://ec.europa.eu/docsroom/documents/58974 This is the request which will allow the three european standardization organizations (CEN, CENELEC, ETSI) to draft the required 41 standards for the Cyber Resilience Act (CRA). See page 17 and following for the list. To participate in the standardization you have to be part of a…

I'd like to give my comments on the new standards, but I'm never going to be chosen to be part of an elite squad of standards-writers. Is there any chance of the standards developing more in the open, with a community in addition to the committee?

It is not so much an elite squad as more a bunch of people willing to spend the entrance fee and to commit their time. The exact requirements depend on the country you're in though. So if that is your only concern but you are willing to spend time feel free to reach out.

About your actual question: The answer is "not really" no. ETSI has a way to adopt existing standards: https://www.etsi.org/images/files/ETSI_PAS_Process_Guide.pdf But CEN and CENELEC (which are probably relevant here) do not.

The effort from the blog post is partially about a long term plan to get the EU to change this. But in the short term it'll be hard to change the rules in time for the CRA standards.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#60
post #41
post #17

Earlier quoted context omitted.

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

It doesn't only cover pure hobby projects: > (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. > (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity. > (10c).…

More than hobby, you are correct. I should have said "completely unrelated to commercial activity"

That is still a problem: https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...

> the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature.

That just means that a business can donate to a non-profit project. Such a business would still need to not profit from the project in anyway. Why would a business help develop something it does not profit from?

> for the purpose of this Regulation, the development of products qualifying as free and open-source software by not-for-profit organisations should not be considered a commercial activity as long as the organisation is set up in a way that ensures that all earnings after cost are used to achieve not-for-profit objectives

So again, an organisation can, provided it no profit.

These are very narrow exemptions.

Post reply on HN