This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…
>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.
No cyber resilience without open source sustainability
11–20 of 74 posts
Re: No cyber resilience without open source sustainability
#12This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…
>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.
Re: No cyber resilience without open source sustainability
#13Earlier quoted context omitted.
>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.
The figure is an estimate of the global cost, not just EU. And I recall seeing a figure of 300B USD per year just on system integration projects (i.e., just plumbing). Compared to that, the figure looks believable.
Re: No cyber resilience without open source sustainability
#14This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…
> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.
Re: No cyber resilience without open source sustainability
#15Earlier quoted context omitted.
The figure is an estimate of the global cost, not just EU. And I recall seeing a figure of 300B USD per year just on system integration projects (i.e., just plumbing). Compared to that, the figure looks believable.
That's more than the worldwide spending on IT per year.
UPD: here is the original source for the figure https://cybersecurityventures.com/cybercrime-damages-6-trill... That report includes the cybersec costs as well as says that it was a 120B market in 2017 and made a projection that it would be worth 1T+ by 2021. Would be interested to see how those projections fared if anyone has better stats.
Re: No cyber resilience without open source sustainability
#16Earlier quoted context omitted.
> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.
I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…
Have you seen the dependency trees for commercial software? I'd be surprised if there's any non-trivial OSS project that hasn't been used as part of commercial activity.
Re: No cyber resilience without open source sustainability
#17It is also one part of why I don't want to deal with Europe.
Re: No cyber resilience without open source sustainability
#18Earlier quoted context omitted.
> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.
I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…
* that a project is developed AND supplied commercially?
* or rather that a project is developed OR supplied commercially?
For example if I write an experimental project at work which might have vulnerabilities (developed commercially), which my employer has no intention of selling yet (not supplied commercially), should I still follow the CRA processes in case someone reports a vulnerability? What if someone else decides to take my toy project and put it into their product?
Re: No cyber resilience without open source sustainability
#19TL;DR The EU is working on the Cyber Resilience Act (CRA) which will be voted on the 19th of July. The current wording makes it look like it will affect open source projects that receice donations; which have contribution from corporate developers; and might break coordinated vulnerability disclousure. If you live in the EC area, there's a link on the blog to contact to MEP. The blog also links to other posts from OS…
Re: No cyber resilience without open source sustainability
#20Earlier quoted context omitted.
That's more than the worldwide spending on IT per year.
Haha! I dug a bit deeper and the figure seems to be a 2019 projection: https://ai-watch.ec.europa.eu/publications/cybersecurity-our... UPD: here is the original source for the figure https://cybersecurityventures.com/cybercrime-damages-6-trill... That report includes the cybersec costs as well as says that it was a 120B market in 2017 and made a projection that it would be worth 1T+ by 2021. Would be interested to se…
In other words it's the most aggressive projection (ie: most sources note it as such) based on the most liberal definition possible of impact from a throwaway slide by a CEO. Then it's listed as the actual number and not a historical projection from half a decade ago.
https://www.smartcompany.com.au/technology/complacency-over-...