Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

101–110 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#101
The Debian team announcement is on the right track. Asking freelancers and free software groups to face the same measures and fines as big tech companies is unfair competition. The E.U. of course, was never friendly to free software[1]. The bureaucratic and neoliberal extremists that are in the lobby of Brussels will always try to destroy free and independent creation.

[1]: https://totsipaki.net/ikiwiki/nparafe/posts_en/posts/Can_Eur...

Re: Debian Statement on the Cyber Resilience Act

#102

Earlier quoted context omitted.

It’s probable to make the case that some forms of software are simple enough to regulate. How many Supabase style crud apps have been made in our lifetimes (not shading Supabase, they’re just automating the commonalities here)

All software is simple enough to regulate. You don't have to micromanage every single line someone writes to regulate something. The way most professional regulations work is that someone writes down the safety practices that should be done, and then the law requires people to do those things. For example, one might require some software to undergo various degrees of planning, testing, analysis, support, documentatio…

> ...for software that human lives depend on.

who decides, and how?

Re: Debian Statement on the Cyber Resilience Act

#103
post #76

Earlier quoted context omitted.

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

Some of the best developers I know are self taught. Professional licensure makes it illegal for them to practice, or at least relegates them to low end work. It further cements the requirement that someone go deeply into debt to purchase the right to work from a university.

It also creates artificial scarcity which will easily 10X costs.

Dealing with security problems is much cheaper.

Re: Debian Statement on the Cyber Resilience Act

#105
This makes a lot of sense if you follow judgements internationally.

Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him.

Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You either make good software and comply with your duty or you will be ruined. That is the law.

Re: Debian Statement on the Cyber Resilience Act

#106
post #100

> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1]. We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing.…

Blocking EU IPs would go against the open source definition and the Debian social contract; discrimination against groups of people.

Re: Debian Statement on the Cyber Resilience Act

#107
post #106
post #100

> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1]. We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing.…

Blocking EU IPs would go against the open source definition and the Debian social contract; discrimination against groups of people.

No, it would not.

Both are concerned with non-discriminatory _licensing._ That would remain the case.

Neither of those documents obligate anyone to provide the specific service of providing downloads to anyone else, or providing any act of distribution at all.

Nevertheless, not being able to access the Debian servers would be most unfortunate.

Re: Debian Statement on the Cyber Resilience Act

#108
post #12

[flagged]

A 12 year old who read a book on coding is now a professional? Standards really have fallen.

If that 12-year-old's code ends up in infrastructure that government or business depends on, it should be subject to these regulations.

Re: Debian Statement on the Cyber Resilience Act

#109

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

Whats really funny is seeing the 180 flip. The EU was, and is depending on the post here, God's gift to men when it was crushing big bads like Apple and Google. Now it should be obvious to me that they hate the little guy? The 180 is a little funny, you gotta admit.

In reality they just think that you shouldn't skirt responsibility because you're "small". And the rest of it is just developers refusing to take responsibility on a level of a market salat seller.

Re: Debian Statement on the Cyber Resilience Act

#110

Earlier quoted context omitted.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

Many of us are not "doing business" at all. Programming is my hobby. I cannot justify publishing my projects if doing that could get me sued. I already have enough liability at work.

Good thing publishing your projects is deliberately excluded so you're FUDing.
Post reply on HN