Live data from Hacker News

The EU Open Source Strategy

digital-strategy.ec.europa.eu

81–90 of 167 posts

Re: The EU Open Source Strategy

#81
post #65

Earlier quoted context omitted.

True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. Most EU initiatives have damaged everyday UX on the web and in tech. Yes, some malicious compliance has played a role by over-reacting to well-intended regulations. But overall the EU has brought this upon itself. This specific Open Source Strategy memo is typical. It's in fact not a s…

> Most EU initiatives have damaged everyday UX on the web and in tech. Are you really trying to suggest that GDPR and PECR are bad pieces of legislation because businesses have decided that they’d prefer to give you a bad UX?

[deleted]

Re: The EU Open Source Strategy

#82
post #35

Earlier quoted context omitted.

In what aspect does GNU/Linux not meet EU sovereignty security requirement, but two American companies do? Other than the elephant in the room that most FOSS projects are anyway sponsored by US companies, that is.

Sovereignty yes it's obviously better. I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries. Is this a worthwhile tradeoff against being tied to US tech? Yeah maybe, like I said there are no good options here, and Linux might be the least bad.

You know what happened at Google after Operation Aurora and they went full bore on security (BeyondCorp and all that)? They started phasing out Windows laptops for employees immediately.

I'm honestly having trouble taking you seriously, Windows has always been at the butt of security jokes, I guess you maybe didn't grow up with winnuke etc? But maybe you could elaborate a bit more concretely about what kind of intra-host security boundaries are missing, and why they would be required on single-user computers in this scenario?

Re: The EU Open Source Strategy

#83
post #71
post #65

Earlier quoted context omitted.

True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. Most EU initiatives have damaged everyday UX on the web and in tech. Yes, some malicious compliance has played a role by over-reacting to well-intended regulations. But overall the EU has brought this upon itself. This specific Open Source Strategy memo is typical. It's in fact not a s…

" True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. " And these criticism destroys any goodwill from me. These are non topics my among political diverse friends. Most people criticise the EU internet regulations are American cry babys. Their arguments are shallow, their knowledge about EU is low.

If your friends have never said “man I hate these cookie popups”, they sound like a highly selected group.

Re: The EU Open Source Strategy

#84
post #65

Earlier quoted context omitted.

True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. Most EU initiatives have damaged everyday UX on the web and in tech. Yes, some malicious compliance has played a role by over-reacting to well-intended regulations. But overall the EU has brought this upon itself. This specific Open Source Strategy memo is typical. It's in fact not a s…

> Most EU initiatives have damaged everyday UX on the web and in tech. Are you really trying to suggest that GDPR and PECR are bad pieces of legislation because businesses have decided that they’d prefer to give you a bad UX?

[flagged]

Re: The EU Open Source Strategy

#85
post #65

Earlier quoted context omitted.

True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital. Most EU initiatives have damaged everyday UX on the web and in tech. Yes, some malicious compliance has played a role by over-reacting to well-intended regulations. But overall the EU has brought this upon itself. This specific Open Source Strategy memo is typical. It's in fact not a s…

> Most EU initiatives have damaged everyday UX on the web and in tech. Are you really trying to suggest that GDPR and PECR are bad pieces of legislation because businesses have decided that they’d prefer to give you a bad UX?

Right. It’s the loopholes that make them bad

Re: The EU Open Source Strategy

#86

Empty words. Without changes to anti-circumvention laws, safe harbor commitments for security researchers and serious funding for foss projects nothing is going to change.

... and I'd still be very happy for them. Some money, is better than none.

Besides, supply chain payments are already a thing and help maintainers like myself already while providing security benefits for corporations.

Re: The EU Open Source Strategy

#87
post #35

Earlier quoted context omitted.

In what aspect does GNU/Linux not meet EU sovereignty security requirement, but two American companies do? Other than the elephant in the room that most FOSS projects are anyway sponsored by US companies, that is.

Sovereignty yes it's obviously better. I am just talking about the pure tech fact that GNU/Linux desktops do not have any meaningful intra-host security boundaries. Is this a worthwhile tradeoff against being tied to US tech? Yeah maybe, like I said there are no good options here, and Linux might be the least bad.

Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X"?

Secondly, are you sure that it is impossible to secure a system for a whole department? I have seen relatively big companies having an IT team managing their own Linux flavour. That is, whitelisting the packages that can be installed by the users. Given that most computer users in the administration use a handful of programs, it doesn't seem super hard to audit them?

Re: The EU Open Source Strategy

#88

I wish there was somewhere I could earnestly and intelligently have discussions about EU related tech and tech policy, but HN isn't it. As you can see already in this thread, there's 14 comments besides mine and they are 100% negative, and about 95% low effort/reactionary. Of course there's a lot to criticize and also to appreciate about the EU. But this is supposed to be a forum for intelligent, thoughtful discussio…

What points could we even discuss? It's all terribly vague and I imagine nobody here can even tell how that supposed 'strategy' is different from the one 5 years ago. And half of the things mentioned there, like the EUDI Wallet or age verification have been heavily criticised for good reasons.

If the headline was "EU invests 100B into open source to further independence from US", I imagine things would be different. But right now it's "we have intentions to have plans about tech and open source in the EU sometime in the future".

Re: The EU Open Source Strategy

#89
post #7
post #3

All great, but I would love EU and (national, local, ...) governments in the EU simply use the open source stuff already available. Often there is an 'you must open source, unless you explain why not' and then there is some faff about why they really need to be buying more stuff from Microsoft (which is more and more cloud stuff and thus under the CLOUD act etc.) Time to get rid of the 'unless' bit.

Although I usually come up negative on my The Year of Linux Desktop comments, that would already be a starting point. Unless EU citzens are able to easily walk into FNAC, Vobis, Cool Blue, MediaMarket, Carrefour, Publico,.... and come out with a laptop or desktop with e.g. SuSE Linux already set up, this will always be a niche thing from nerds assembling their own PCs, or finding their ways into Tuxedo and co. And th…

Well you can do that right now with Chrom(ium)OS.

Re: The EU Open Source Strategy

#90

I wish there was somewhere I could earnestly and intelligently have discussions about EU related tech and tech policy, but HN isn't it. As you can see already in this thread, there's 14 comments besides mine and they are 100% negative, and about 95% low effort/reactionary. Of course there's a lot to criticize and also to appreciate about the EU. But this is supposed to be a forum for intelligent, thoughtful discussio…

I guess the hate is because the EU also invented the following monstrosities: - CRA (cyber resiliency act): Manufacturers must handle and release security patches for vulnerabilities, and developers are required to report actively on exploited vulnerabilities and breaches. - PLD (Product Liability Directive): A failure to provide critical security updates or the presence of exploitable vulnerabilities can now legally…

Sounds like plausible clauses to me? Please explain why they are so toxic. What cases are there where these clauses present an unfair threat or disadvantage to a business?

In case it is unclear from my tone, I am genuinely curious.

Post reply on HN