Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

111–120 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#111
post #2

Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.

So why pile on even more? Terrible justification tbh. It’s hard for a small business or indie developer. The odds are against you.

Just like in any business.

Re: Debian Statement on the Cyber Resilience Act

#112

Earlier quoted context omitted.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

What if you needed a full commercial grade license and permit to give some home baked cookies to your co-workers? edit: Or if we go to the extreme of nothing except the action and potential for negative impact mattering then you'd need a license to give those cookies to your own kids or even yourself.

If those co-workers end up in the hospital due to those cookies, better be prepared for talking to some police officers and possible class action depending on what happens to them.

Re: Debian Statement on the Cyber Resilience Act

#113

Earlier quoted context omitted.

> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation b…

It can be priced in you just change the minimum price from $0 to how much liability would cost you.

It would be a huge gamble if the "0$ version" (e.g. GitHub repo) gets more popular that anticipated and the one with the bigger price tag not growing accordingly and the whole risk calculation falls apart.

There is always the possibility to only offer the priced version, even if it is free software. Someone else could of course redistribute it and then it would be their responsibility. That would be a less convenient world.

An open question certainly also is, when it becomes a product? Source Code alone (inredients)? Or executable form (usable)?

Re: Debian Statement on the Cyber Resilience Act

#114

Earlier quoted context omitted.

It can be priced in you just change the minimum price from $0 to how much liability would cost you.

If every user has to pay the minimum price then the software would not be free software, by definition.

No.

https://www.gnu.org/philosophy/free-sw.en.html

Re: Debian Statement on the Cyber Resilience Act

#115
post #106

Earlier quoted context omitted.

Blocking EU IPs would go against the open source definition and the Debian social contract; discrimination against groups of people.

No, it would not. Both are concerned with non-discriminatory _licensing._ That would remain the case. Neither of those documents obligate anyone to provide the specific service of providing downloads to anyone else, or providing any act of distribution at all. Nevertheless, not being able to access the Debian servers would be most unfortunate.

Definitely disagree there. Debian blocking EU access would be ineffective too, there is a large network of third-party mirrors.

Re: Debian Statement on the Cyber Resilience Act

#116

Earlier quoted context omitted.

Knuth’s code has bugs. NASA’s code has bugs. I would like to think that someday our profession might be able to achieve high enough quality to survive with liability, but today nobody is close to that at all.

I think that liability shouldn't require perfection, just close enough as long as the criteria is objective. I personally think that any criteria that SQLite and Curl can't pass is too strict.

The AMA doesn’t require perfection, yet a doctor has to pay six-figure liability insurance premiums for the risk of harming a small fraction of his patients. I don’t have faith that this would be run more practically.

Re: Debian Statement on the Cyber Resilience Act

#118
post #110

Earlier quoted context omitted.

Many of us are not "doing business" at all. Programming is my hobby. I cannot justify publishing my projects if doing that could get me sued. I already have enough liability at work.

Good thing publishing your projects is deliberately excluded so you're FUDing.

"Deliberately excluded" is a pretty strong statement for a law that speaks of:

> commercial activity, whether in return for payment or free of charge

That definitely includes people like me who thought signing up for GitHub Sponsors was a good idea. What's the worst that could happen, right? For all I know it could include projects that accept donations too. Is writing a book about the project or offering screencasts or whatever the same as offering "technical support services"? Is building a community on GitHub or Discord or whatever "providing a software platform through which the manufacturer monetises other services"? Who knows? I'm not a lawyer.

Re: Debian Statement on the Cyber Resilience Act

#119

Earlier quoted context omitted.

A 12 year old who read a book on coding is now a professional? Standards really have fallen.

If that 12-year-old's code ends up in infrastructure that government or business depends on, it should be subject to these regulations.

Should the 12 year old be liable because a billion dollar company uses his code?

Re: Debian Statement on the Cyber Resilience Act

#120
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

Gee I don’t know. Why don’t you spent 15,000 euros for a court case and find out. See the problem now ?
Post reply on HN