Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

121–130 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#121
post #104

Given that this will affect costs by one, maybe two orders of magnitude, why would any developer want to do business with the EU. Is disqualifying EU users even possible?

Every small developer should now start to ban government use. Even if they are not affected the law. To associate consequences to actions. They will never learn otherwise.

Re: Debian Statement on the Cyber Resilience Act

#122
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

Yes, but also perhaps be explicit. Ban direct and transient government use.

Re: Debian Statement on the Cyber Resilience Act

#123

This makes a lot of sense if you follow judgements internationally. Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You eith…

Hi craig wright, how are things?

Re: Debian Statement on the Cyber Resilience Act

#124
It’s time for governments to have more responsibility. The cyber resilience acts pushes 15,000,000 euros penalty to software developers. How much liability does government have for anything bad they do ? First it’s extremely difficult to get to them to be responsible for anything. Then in the Netherlands any liability would be a pittance. Nothing like 15,000,000 euros.

Re: Debian Statement on the Cyber Resilience Act

#125
And don't skip over the part where they want developers to report any zero day's you discover to them within 24 hours so they can use them as exploits against innocent civilians not involved in any crime. And yes, the Netherlands changed the law recently so they can do this and without requiring any judge involved. And yes, they are allowed to hack people not involved with any crime as well. As well as changing the law in 2020 so all of government, including their prosecutors may law in court under oath and not be held liable.

And then they want other people to be accountable, how about government be accountable first.

Re: Debian Statement on the Cyber Resilience Act

#126
Additionally, there's nothing wrong with what we have now. So there are some security flaws. But we have really fancy mobile phones and an amazing Internet.

Now rewind to 1990 or so. Add a Cyber resilience act. At best we maybe have a phone about as advanced as an old Nokia. But yeah, maybe hardly any cyber security flaws because the Internet would hardly function.

Instead of thanking all of the millions of developers who contributed to this, they proceed to kick them in the teeth and enact laws to steal from them in principle by raising the cost of entry.

Re: Debian Statement on the Cyber Resilience Act

#127
post #103

Earlier quoted context omitted.

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

Some of the best developers I know are self taught. Professional licensure makes it illegal for them to practice, or at least relegates them to low end work. It further cements the requirement that someone go deeply into debt to purchase the right to work from a university. It also creates artificial scarcity which will easily 10X costs. Dealing with security problems is much cheaper.

It also makes hiring foreign talent (where such certifications do not exist) impossible.

Re: Debian Statement on the Cyber Resilience Act

#128
post #112

Earlier quoted context omitted.

What if you needed a full commercial grade license and permit to give some home baked cookies to your co-workers? edit: Or if we go to the extreme of nothing except the action and potential for negative impact mattering then you'd need a license to give those cookies to your own kids or even yourself.

If those co-workers end up in the hospital due to those cookies, better be prepared for talking to some police officers and possible class action depending on what happens to them.

That's not the analogy here. Nothing happens. No one is hurt. Everyone loved the cookies. The government however fines you a massive amounts for just providing the cookies that may hurt them potentially but don't actually.

Re: Debian Statement on the Cyber Resilience Act

#129
post #57

Earlier quoted context omitted.

If it were a big enough problem, could GPLv4 be published (perhaps with a clause to cover this and future laws) and products encouraged to migrate to it?

Likely not. A license can not override legislation. Like creative-commons cannot be used to give away moral rights at least if not some of the copy rights too.

But we are not talking about overriding legislation. The question is, can GPL4 say "you cannot use or distribute this software" if there is a legal risk to the creator?

Re: Debian Statement on the Cyber Resilience Act

#130
post #121
post #104

Given that this will affect costs by one, maybe two orders of magnitude, why would any developer want to do business with the EU. Is disqualifying EU users even possible?

Every small developer should now start to ban government use. Even if they are not affected the law. To associate consequences to actions. They will never learn otherwise.

Two points:

1) this means MIT, Apache and many other licenses are dead in EU.

2) Laws override licenses, so the government can just make a law to ignore the 'no government use' clause.

Post reply on HN