Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.
I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software
Debian Statement on the Cyber Resilience Act
11–20 of 160 posts
Re: Debian Statement on the Cyber Resilience Act
#12Re: Debian Statement on the Cyber Resilience Act
#13Earlier quoted context omitted.
I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software
What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?
And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damaging if a malicious actor takes advantage of it.
Re: Debian Statement on the Cyber Resilience Act
#14What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
Re: Debian Statement on the Cyber Resilience Act
#15[flagged]
Now, if folks want regulation, introduce the Certified Professional Software Engineer. (Pay commensurate with tort, of course.)
Re: Debian Statement on the Cyber Resilience Act
#16Maybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)
Re: Debian Statement on the Cyber Resilience Act
#17[flagged]
Re: Debian Statement on the Cyber Resilience Act
#18It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.
Re: Debian Statement on the Cyber Resilience Act
#19What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
Linux, World Wide Web… not worth the risk.
So I am making something in my free time, as a hobby, no monetary gain and suddenly I can easily get sued to oblivion. I need to at least buy insurance. My library is used left and right in commercial activity.
The impact assessment for CRA is a total lie. It assumes 100% decrease in cyber damages and laughably low compliance cost and very small amount of impacted entities (only companies, not individuals and each company makes one product).
TBF, version amended by EP explicitly excludes individual developers, hopefully it makes it through trialogue.
Edit: basically imagine authors of log4j. Remember that security flaw that impacted half the internet? That is what’s called liability. Did they use ‘ apply effective and regular tests and reviews of the security of the product with digital elements;’? Better make it industrial grade product, with no money, in their free time.
Re: Debian Statement on the Cyber Resilience Act
#20What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
we do not need regulation limiting distribution of volunteer work.
and the vague language for the delineation line is what's problematic with this proposal.
volunteers have no resources (time, money) to defend themselves or their products against false accusations of lack of compliance. likewise companies that happen to provide foss components might be approached about compliance even for their github content.