Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

11–20 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#11
post #2

Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.

I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software

What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?

Re: Debian Statement on the Cyber Resilience Act

#13

Earlier quoted context omitted.

I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software

What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?

Standardized food safety practices, pre-approved and comparatively trivial recipes, state/county inspections, etc. None of which apply to software. One is fairly trivial and standardized. The other is massively complex, rapidly changing, and unable to be boiled down to a standard set of trivial procedures.

And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damaging if a malicious actor takes advantage of it.

Re: Debian Statement on the Cyber Resilience Act

#14

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Eclipse Foundation on YouTube for infos.

Re: Debian Statement on the Cyber Resilience Act

#16
post #5

Maybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)

there is insightful discussion right on lwn. I think changing the URL is cutting that out.

Re: Debian Statement on the Cyber Resilience Act

#19

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

To put it bluntly, it means a significant risk when creating any open source project. It’s a common knowledge that there is no money in open source, but suddenly I am liable. Half of open source licenses is disclaimer of liability. Also a lot of other yet to be defined requirements (harmonised regulations it is called I believe).

Linux, World Wide Web… not worth the risk.

So I am making something in my free time, as a hobby, no monetary gain and suddenly I can easily get sued to oblivion. I need to at least buy insurance. My library is used left and right in commercial activity.

The impact assessment for CRA is a total lie. It assumes 100% decrease in cyber damages and laughably low compliance cost and very small amount of impacted entities (only companies, not individuals and each company makes one product).

TBF, version amended by EP explicitly excludes individual developers, hopefully it makes it through trialogue.

Edit: basically imagine authors of log4j. Remember that security flaw that impacted half the internet? That is what’s called liability. Did they use ‘ apply effective and regular tests and reviews of the security of the product with digital elements;’? Better make it industrial grade product, with no money, in their free time.

Re: Debian Statement on the Cyber Resilience Act

#20

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

there needs to be regulation of for profit services, so when you _buy_ software, there is a baseline that you can rely on, as a buyer.

we do not need regulation limiting distribution of volunteer work.

and the vague language for the delineation line is what's problematic with this proposal.

volunteers have no resources (time, money) to defend themselves or their products against false accusations of lack of compliance. likewise companies that happen to provide foss components might be approached about compliance even for their github content.

Post reply on HN