Live data from Hacker News

Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

news.apache.org

1–10 of 76 posts

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#2
This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone.

It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else.

That way EU bureaucrats will stop trying to be the World Police without paying the price that USA has to pay to keep its global influence (like funding military of other nations while americans die in hospitals, in homelessness , intentionally making american exports disadvantageous just to keep its global reserve currency status, etc).

It is absolutely insane to me how EU thinks it can decide what charging port everyone should use USB-C , cookie banners for everyone, GDPR nightmare for everyone, and now this new government rule on opensource contributors to software being held liable for security breaches.

Absolutely crazy. They just want free lunch while trying to control everyone and everything.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#3

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

I won't bother addressing most of the nonsense you've written. I'll just say that the US has FedRAMP (https://en.wikipedia.org/wiki/FedRAMP) and EO 14028 (https://www.federalregister.gov/documents/2021/05/17/2021-10...). So if you imagine that this is somehow an EU-specific thing and doesn't affect the US, you're very wrong. Not to mention NIST and FIPS and CISA.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#4
post #3

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

I won't bother addressing most of the nonsense you've written. I'll just say that the US has FedRAMP ( https://en.wikipedia.org/wiki/FedRAMP ) and EO 14028 ( https://www.federalregister.gov/documents/2021/05/17/2021-10... ). So if you imagine that this is somehow an EU-specific thing and doesn't affect the US, you're very wrong. Not to mention NIST and FIPS and CISA.

CRA applies to all companies, Fedramp applies to just government.

All major governments have policies like this, its an issue when government tries to over regulate private matters.

What government regulates inside its own workforce, is absolutely upto them. But government shouldnt interfere so much into private matters.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#5

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

"USB-C" -> Good for consumer, I believe.

"cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner.

"GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-data/europes-hidden-security-cri... ).

"now this new government rule on opensource contributors to software being held liable for security breaches." -> Indeed, that's problematic, specially the way this was (not) discussed with the open source sector. Cf. https://cnll.fr/news/la-france-doit-prot%C3%A9ger-sa-fili%C3... and https://cnll.fr/news/declaration-cra-cyber-resilience-act/ (two texts that I wrote, in French, last year).

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#6
I guess the foundations are hyped because CRA basically forces companies to pay for security of OS projects (which the foundations try to be the main receiver of the money) But in the end the OS ecosystem becomes much more secure.

Otherwise all the SV dudes complaining about the over burocratics: How to improve Software security? Only alternative I can think of, is the goverment pays for the security. For me thats a worser solution.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#7

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

"USB-C" -> Good for consumer, I believe. "cookie banners for everyone" -> cookie banners only if your website is using cookies in a way that needs a cookie banner. There are plenty of sites or web analytics technologies that don't mandate the use of a cookie banner. "GDPR nightmare for everyone" -> only for companies that intend touse personal data in non-ethical ways (cf. for instance: https://www.iccl.ie/digital-da…

"USB-C" -> Good for consumer, I believe

With the same logic EU had tried to make Micro USB mandatory for everyone, it was a very poorly executed charging port which would break often and easily.

If it was made industry standard back then, USB-C would have probably never come along or would have taken much much longer.

The road to hell is paved with good intention, I doubt any decent government (which EU is) would pass laws that is bad for its people in short term.

It’s just that these burden some regulations backfire in the long term.

The problems with GDPR and Cookie Banner are well documented, it puts EU startups at a disadvantage because of having to pass all regulations before they can innovate and get up from the ground. Regulations like this should not apply to startups, the harm done to economy is far more than harm done to the public.

Or else , EU citizens will forever be left using American Software, driving Japanese cars (EU car makers are in decline), use Chinese and American Robots (Largest German Robot company (KUKA Robotics) sold to China), use Chinese Solar Panels, Korean Phones, etc.

I get what you’re saying, it all sounds sweet and good on paper.

But it ends up being a race where brilliant european minds are running with 20kg weights on their shoes, while other major nations are supplying stimulants for their innovators to win the gold medal.

It’s just the reality of what’s happening, if it continues EU will die a slow and painful death (Saying the truth as a well wisher for europe, they are pro-consumer in great many ways, but they are over regulating and hurting their next generation)

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#8

This just further incentivises over-regulatory EU to keep making burdensome regulation that slows down innovation for everyone. It is better for open source projects to just pass a license claiming, software is not available for free in EU and to make EU companies pay sky high fees to use the software that is freely available for everyone else. That way EU bureaucrats will stop trying to be the World Police without p…

CRA requires integrators of open source components to perform their own due diligence. Open Source contributors are not held liable for security breaches. In fact this regulation will probably increase investment in open source projects because companies are obliged to share vulnerabilities they have discovered including any relevant patches they might have developed.[1]

[1] https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#9
I'm thinking about Maw Gergel's Isopropyl book, and how in the 1960'sthey basically threw dangerous chemical waste out the window or buried it after a fire, scarring a kid.

That's the state of our industry today. In some ways, Open source seems among the better students of the class. In other ways, Open source is like a million people each contributing a few parts to a society critical factory, nobody noticing how big we grew. Of course that makes people uneasy.

I think something like this is unavoidable. How to get the max impact with minimal overhead is the most important discussion now, so I applaud apache's initiative.

Re: Open Source Community Unites to Build EU CRA-Compliant Cybersecurity Processes

#10
Since this regulation is happening, necessary and welcome, it's good to see some of the most respected FOSS groups taking the lead. Hopefully many others representing smaller development communities will join the Eclipse initiative. I would characterise "Apache Software Foundation, Blender Foundation, OpenSSL Software Foundation, PHP Foundation, Python Software Foundation, Rust Foundation, and Eclipse Foundation" as BigFOSS. :) Joe Hacker also needs a seat at this table.

> establishment of common specifications for secure software > development based on existing open source best practices.

The problem with "best practices" is that there are always better practices. Hopefully this group don't ossify around "best practices" that are already out of date but become research focused. To be blunt, a problem is not that "best practices" are never followed, but that we have about 30 years of technical security debt to catch up with.

This foundation is also going to be a money pit, because it needs to help other developers. It cannot rule, dictate or enforce anything. Since most European devs are going to want to join in, it's going to be paying out for conferences, education, development grants and T-shirts. It'll need a pipeline of money from EU and commerce - and there's the danger of corruption.

Post reply on HN