Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

61–70 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#61
post #18

Earlier quoted context omitted.

I don't have an opinion on this. The female plug always holds the power and the male taps into it. Doing it the other way around is unusual, you get a naked male plug with power on it just dangling around.

While true for clear one way connections, usbc is bi-directional or symmetrical. 1 Either side may provide power. 2 usbc power delivery requires a fancy communication and management chip, and there is no power until after a handshake has been negotiated. So in that case a lightning style cable could be ok. (besides, even with plain usb2, lightening already existed for years without a problem) But while lightning-styl…

I cant help but think we are stuck with excuses not to have simple replaceable batteries.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#62
post #17

Earlier quoted context omitted.

That exemption only covers non-commercial open source. Anyone who monetises the open source project (e.g. by offering related consultancy or hosting business, or offering the code under a commercial license as well) is still liable. It only covers pure hobby projects by pure hobby developers.

If I offer a product under both open source and commercial license, and then someone uses an open source version without paying me anything, neither for the license nor consultancy, am I liable for damages?

As far as I can see you are. You are developing it with a view to making a profit:

https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#63
post #55
post #41

Earlier quoted context omitted.

It doesn't only cover pure hobby projects: > (10c) the mere fact that an open-source software product receives financial support by manufacturers or that manufacturers contribute to the development of such a product should not in itself determine that the activity is of commercial nature. > (10) Accepting donations without the intention of making a profit should not be considered to be a commercial activity. > (10c).…

To be clear "related consultancy or hosting business" is still commercial. The notion of "accepting donations without the intention of making a profit" seems insane, too.

The idea is that you can accept donations to cover the costs, but not beyond that.

So an organisation can pay developers to work on it, cover hosting costs etc. but they have to be careful not to accept donations for more than that. A non-profit can accept more provided it is used for the right objects.

I have no idea (neither does the author of the article) where that leaves an individual developer who accepts donations to cover the value of their time.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#64
post #39
post #14

Earlier quoted context omitted.

> "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. >…

> You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. It's not a burden to have to do common sense things. Is it a burden not to leave medical or private or fi…

> It's not a burden to have to do common sense things

It depends on your scale. Suppose I ran a small website that provided news and articles and forums about some small hobby that I am into. Maybe 100 users worldwide. I include articles about European things related to that hobby, written specifically to better serve the European visitors to my site.

The only personal information I store is IP addresses in my Apache logs.

Such a site could be run for less than $100/year in hosting costs.

If my processing of personal information counts as "occasional" then as far as I can tell GDPR imposes no burden on me, other than having to deal with it when someone requests that I remove their personal information.

If my processing does not count as "occasional" then under Article 27 I would need to appoint a representative in the Union that people and regulators could contact when they have GDPR related matters involving me.

There are companies that provide "in-Union GDPR representative as a service" but the least expensive I've seen is around €100. If I had to use such a service I'd be at least doubling my costs which would probably push the costs past what I'd be willing to do for a hobby site that is not monetized.

Would my processing be "occasional"? The recital for Article 27 doesn't provide any guidance on what "occasional" means.

One the one hand one might argue that a low traffic site is almost by definition "occasional" in everything it does. On the other hand one might argue that my site is processing IP addresses on every single request it processes and that something that happens 100% of the time surely can't be "occasional".

At some point this issue will arise and the GDPR regulators in some member state will issue a ruling that clarifies it, and if we are lucky no other member state's regulators will issue a ruling that goes the other way.

Even if it is eventually decided that processing such as mine is definitely "occasional" the fact that I have to think about it in the first place is somewhat burdensome.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#65

Am I getting older? On a modern display... reading that text is awful. Had to zoom it to 150%. At 'default' it's damn near 'fuzzy' looking. Apache, omg, use a readable font and size for goodness sake.

If something is less readable on your modern display than on an older display then the problem is with your modern display not the website.

In other words: Turn on display scaling instead of expecting every website to increase the font size.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#67
post #13

Earlier quoted context omitted.

"USB-C" -> Good for consumer, I believe With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily. If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. The road to hell is paved with good intention, I doubt any decent government (which EU is) would pas…

> If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer. USB-C is a clusterfuck of a connector, and I'm not just talking about the various voltages and how using the wrong cable can fry your equipment. I'm talking about the physical connector itself. See, the USB-C port has a shroud around the outside and a "tongue" in the middle where all the cont…

MicroUSB was even worse though in my experience - I managed to break the charging port on ALL my MicroUSB phones after enough time but my USB C phones so far have not yet encountered that failure mode.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#68
post #15

Earlier quoted context omitted.

> It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. I have been wondering whether it would be possible to a add a limitation of liability in line with GPL3 7 a) that allows "Disclaiming warranty or limiting liability differently from the terms of sect…

No matter what that it is not possible to override the law with a license. Of course if it is outside your local jurisdiction you can ignore but you don't need a license text for that. If it applies to you it does so regardless of your license. A court would simply rule the terms illegal. But as others said this will (arguabely) only apply to real commercial activy and in that realm you (usually9 cannot dislaim liabi…

> No matter what that it is not possible to override the law with a license.

That is not what I am suggesting. I am wondering about ways to not allow people to redistribute in ways that increases your liability. i.e. the law would apply, but the people using it in the way that exposes you to liability would be in breach of copyright.

Sadly, looking more closely at the wording, this cannot be done in a GPL comaptible way. maybe we need new licenses to cover this.

> but as others said this will (arguably) only apply to real commercial activy

Aguably? maybe, but we need certainty. It does look as though a lot of smaller projects and developers will be at risk here if (for example) they dual license with a paid for version available, or sell support of consultancy services.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#69
post #64
post #39

Earlier quoted context omitted.

> You do not understand GDPR. It is a burden even for businesses or non-profits that keep a minimal amount of data and do not trade it. As with all Eu regulation it is designed around big business. It actually helps the like of FB because they are more able to push people into agreeing to let them use their data. It's not a burden to have to do common sense things. Is it a burden not to leave medical or private or fi…

> It's not a burden to have to do common sense things It depends on your scale. Suppose I ran a small website that provided news and articles and forums about some small hobby that I am into. Maybe 100 users worldwide. I include articles about European things related to that hobby, written specifically to better serve the European visitors to my site. The only personal information I store is IP addresses in my Apache…

Surely the basis for the processing matters? If you're storing IP addresses in your access logs, you're presumably doing this for security reasons? And presumably you periodically purge old data? If so, that's a legitimate interest, no consent required.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#70
post #69
post #64

Earlier quoted context omitted.

> It's not a burden to have to do common sense things It depends on your scale. Suppose I ran a small website that provided news and articles and forums about some small hobby that I am into. Maybe 100 users worldwide. I include articles about European things related to that hobby, written specifically to better serve the European visitors to my site. The only personal information I store is IP addresses in my Apache…

Surely the basis for the processing matters? If you're storing IP addresses in your access logs, you're presumably doing this for security reasons? And presumably you periodically purge old data? If so, that's a legitimate interest, no consent required.

It's not a consent problem. Even if you have consent, or some other legal justification for what you are doing with user data, users need to contact you if they want to exercise some of their GDPR rights such as the right to have their data deleted.

Article 27 is about requiring that you at least support one specific method of contact: a representative in the Union. It applies if your site is covered by GDPR and is not in the Union.

There's an exception for sites whose processing of personal data is occasional, does not include certain particularly sensitive kinds of data (e.g., genetic data, health data, criminal conviction records), and is unlikely to pose a risk to the rights and freedoms of natural persons.

There's some commentary here [1] about Article 27. It says that

> The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both provide a contact point for data subjects and ensure that there is legal accountability for processing activities by mandating the appointment of a representative.

I see that page also has something to say about what "occasional" mean:

> The term "occasional" has been interpreted by the WP29 to mean processing that is not carried out regularly and that falls outside of the scope of the regular activities of the controller or processor. Similarly, Millard and Kamarinou have interpreted the term "occasional" to mean "non-systematic" processing, or in other words, processing that happens on an ad hoc and infrequent basis and not in a regular way

It sounds like automatically logging all visits to your web server in the Apache logs would not be "occasional".

[1] https://gdprhub.eu/Article_27_GDPR

Post reply on HN