[1]: https://totsipaki.net/ikiwiki/nparafe/posts_en/posts/Can_Eur...
Debian Statement on the Cyber Resilience Act
101–110 of 160 posts
Re: Debian Statement on the Cyber Resilience Act
#102Earlier quoted context omitted.
It’s probable to make the case that some forms of software are simple enough to regulate. How many Supabase style crud apps have been made in our lifetimes (not shading Supabase, they’re just automating the commonalities here)
All software is simple enough to regulate. You don't have to micromanage every single line someone writes to regulate something. The way most professional regulations work is that someone writes down the safety practices that should be done, and then the law requires people to do those things. For example, one might require some software to undergo various degrees of planning, testing, analysis, support, documentatio…
who decides, and how?
Re: Debian Statement on the Cyber Resilience Act
#103Earlier quoted context omitted.
If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…
All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…
It also creates artificial scarcity which will easily 10X costs.
Dealing with security problems is much cheaper.
Re: Debian Statement on the Cyber Resilience Act
#104Is disqualifying EU users even possible?
Re: Debian Statement on the Cyber Resilience Act
#105Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him.
Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You either make good software and comply with your duty or you will be ruined. That is the law.
Re: Debian Statement on the Cyber Resilience Act
#106> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1]. We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing.…
Re: Debian Statement on the Cyber Resilience Act
#107> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1]. We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing.…
Blocking EU IPs would go against the open source definition and the Debian social contract; discrimination against groups of people.
Both are concerned with non-discriminatory _licensing._ That would remain the case.
Neither of those documents obligate anyone to provide the specific service of providing downloads to anyone else, or providing any act of distribution at all.
Nevertheless, not being able to access the Debian servers would be most unfortunate.
Re: Debian Statement on the Cyber Resilience Act
#108Re: Debian Statement on the Cyber Resilience Act
#109It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.
Whats really funny is seeing the 180 flip. The EU was, and is depending on the post here, God's gift to men when it was crushing big bads like Apple and Google. Now it should be obvious to me that they hate the little guy? The 180 is a little funny, you gotta admit.
Re: Debian Statement on the Cyber Resilience Act
#110Earlier quoted context omitted.
I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…
Many of us are not "doing business" at all. Programming is my hobby. I cannot justify publishing my projects if doing that could get me sued. I already have enough liability at work.