Live data from Hacker News

No cyber resilience without open source sustainability

github.blog

11–20 of 74 posts

Re: No cyber resilience without open source sustainability

#11
post #9
post #6

This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…

>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.

The figure is an estimate of the global cost, not just EU. And I recall seeing a figure of 300B USD per year just on system integration projects (i.e., just plumbing). Compared to that, the figure looks believable.

Re: No cyber resilience without open source sustainability

#12
post #9
post #6

This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…

>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.

[deleted]

Re: No cyber resilience without open source sustainability

#13
post #9

Earlier quoted context omitted.

>OSS amount to 5.5 trillion EUR every year So the EU loses over 30% of it's total GDP to security vulnerabilities? I somehow find that figure very suspect and using clearly exaggerated numbers as justification makes me distrust the whole premise of this legislation.

The figure is an estimate of the global cost, not just EU. And I recall seeing a figure of 300B USD per year just on system integration projects (i.e., just plumbing). Compared to that, the figure looks believable.

That's more than the worldwide spending on IT per year.

Re: No cyber resilience without open source sustainability

#14
post #10
post #6

This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…

> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects consistently relied on by businesses cannot claim that the OSS version is not for commercial use. And with that run-around statement, be done with CRA "compliance".

Re: No cyber resilience without open source sustainability

#15

Earlier quoted context omitted.

The figure is an estimate of the global cost, not just EU. And I recall seeing a figure of 300B USD per year just on system integration projects (i.e., just plumbing). Compared to that, the figure looks believable.

That's more than the worldwide spending on IT per year.

Haha! I dug a bit deeper and the figure seems to be a 2019 projection: https://ai-watch.ec.europa.eu/publications/cybersecurity-our...

UPD: here is the original source for the figure https://cybersecurityventures.com/cybercrime-damages-6-trill... That report includes the cybersec costs as well as says that it was a 120B market in 2017 and made a projection that it would be worth 1T+ by 2021. Would be interested to see how those projections fared if anyone has better stats.

Re: No cyber resilience without open source sustainability

#16
post #10

Earlier quoted context omitted.

> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…

>The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user).

Have you seen the dependency trees for commercial software? I'd be surprised if there's any non-trivial OSS project that hasn't been used as part of commercial activity.

Re: No cyber resilience without open source sustainability

#18
post #10

Earlier quoted context omitted.

> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…

Do you know if the requirement is:

* that a project is developed AND supplied commercially?

* or rather that a project is developed OR supplied commercially?

For example if I write an experimental project at work which might have vulnerabilities (developed commercially), which my employer has no intention of selling yet (not supplied commercially), should I still follow the CRA processes in case someone reports a vulnerability? What if someone else decides to take my toy project and put it into their product?

Re: No cyber resilience without open source sustainability

#19

TL;DR The EU is working on the Cyber Resilience Act (CRA) which will be voted on the 19th of July. The current wording makes it look like it will affect open source projects that receice donations; which have contribution from corporate developers; and might break coordinated vulnerability disclousure. If you live in the EC area, there's a link on the blog to contact to MEP. The blog also links to other posts from OS…

I have not yet fully made up my mind, but notice that there is a lot of nuance in the actual text. For example "Accepting donations without the intention of making a profit should not count as a commercial activity, unless such donations are made by commercial entities and are recurring in nature".

Re: No cyber resilience without open source sustainability

#20

Earlier quoted context omitted.

That's more than the worldwide spending on IT per year.

Haha! I dug a bit deeper and the figure seems to be a 2019 projection: https://ai-watch.ec.europa.eu/publications/cybersecurity-our... UPD: here is the original source for the figure https://cybersecurityventures.com/cybercrime-damages-6-trill... That report includes the cybersec costs as well as says that it was a 120B market in 2017 and made a projection that it would be worth 1T+ by 2021. Would be interested to se…

So it seems to be a projection based on a presentation by the CEO of Microsoft that said the loss of potential revenue and growth is $3T in 2016 (note this is itself not actual measured impact but also a counter-factual projection).

In other words it's the most aggressive projection (ie: most sources note it as such) based on the most liberal definition possible of impact from a throwaway slide by a CEO. Then it's listed as the actual number and not a historical projection from half a decade ago.

https://www.smartcompany.com.au/technology/complacency-over-...

Post reply on HN