Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

131–140 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#131
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

Won't work as the CRA overrides any license (this is explicitly written).

Re: Debian Statement on the Cyber Resilience Act

#132
post #103

Earlier quoted context omitted.

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

Some of the best developers I know are self taught. Professional licensure makes it illegal for them to practice, or at least relegates them to low end work. It further cements the requirement that someone go deeply into debt to purchase the right to work from a university. It also creates artificial scarcity which will easily 10X costs. Dealing with security problems is much cheaper.

Not every developer needs the certification under my plan. And getting it is an apprenticeship, not education.

Re: Debian Statement on the Cyber Resilience Act

#133
post #102

Earlier quoted context omitted.

All software is simple enough to regulate. You don't have to micromanage every single line someone writes to regulate something. The way most professional regulations work is that someone writes down the safety practices that should be done, and then the law requires people to do those things. For example, one might require some software to undergo various degrees of planning, testing, analysis, support, documentatio…

> ...for software that human lives depend on. who decides, and how?

For every other technology regulated this way, this is determined at the end application.

How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you.

Re: Debian Statement on the Cyber Resilience Act

#134
post #57

Earlier quoted context omitted.

Likely not. A license can not override legislation. Like creative-commons cannot be used to give away moral rights at least if not some of the copy rights too.

But we are not talking about overriding legislation. The question is, can GPL4 say "you cannot use or distribute this software" if there is a legal risk to the creator?

A license could say that, however, the creator would still have legal risk in the case that someone broke the license. "My customer broke the license terms" is not a defense to breaking a law.

Re: Debian Statement on the Cyber Resilience Act

#135
post #48
post #39

Earlier quoted context omitted.

The problem with giving a pass to volunteer work and not to commercial activity is that there is a lot of potential for loopholes. Like by having a nonprofit tied to a for-profit company. Getting the spirit of the law into writing is tricky, and it will most likely improve over time. Closing loopholes and making exceptions when merited.

Also many non-profits are big enough that you should absolutely apply rules to them. Think of Mozilla... It has very big and expensive products. And somehow just because they are non-profit and open source they should get away with murder...

well you could easily put regulations on whatever is delivered to paying customers.

so if you do pay for software you know which cybersecurity scrutiny is in place --- while no cost software comes at no warranties whatsoever.

Re: Debian Statement on the Cyber Resilience Act

#136

I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

FYI, there will be a FOSDEM devroom specifically on the European Legislative Landscape, where a number of people involved in drafting this and similar regulations are expected to be present.

The deadline for submitting presentation proposals has passed, but the schedule should be available shortly at https://fosdem.org/2024/schedule/track/eu-policy/

Re: Debian Statement on the Cyber Resilience Act

#137

Earlier quoted context omitted.

I think that liability shouldn't require perfection, just close enough as long as the criteria is objective. I personally think that any criteria that SQLite and Curl can't pass is too strict.

The AMA doesn’t require perfection, yet a doctor has to pay six-figure liability insurance premiums for the risk of harming a small fraction of his patients. I don’t have faith that this would be run more practically.

We have that problem in the medical world, but for some reason, we don't have it in the engineering world.

Why? I don't know. Is the medical world just messed up? Or is there something wrong with licensure?

Re: Debian Statement on the Cyber Resilience Act

#138
post #110

Earlier quoted context omitted.

Good thing publishing your projects is deliberately excluded so you're FUDing.

"Deliberately excluded" is a pretty strong statement for a law that speaks of: > commercial activity, whether in return for payment or free of charge That definitely includes people like me who thought signing up for GitHub Sponsors was a good idea. What's the worst that could happen, right? For all I know it could include projects that accept donations too. Is writing a book about the project or offering screencasts…

Just like in similar complaints around GDPR, turns out that in practice the bar for these things in EU is much higher than what US lawyers are used to and scaremonger about.

Re: Debian Statement on the Cyber Resilience Act

#139
post #136

I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

FYI, there will be a FOSDEM devroom specifically on the European Legislative Landscape, where a number of people involved in drafting this and similar regulations are expected to be present. The deadline for submitting presentation proposals has passed, but the schedule should be available shortly at https://fosdem.org/2024/schedule/track/eu-policy/

Oh, no...My post came out before the deadline, but I didn't know...

Well, I sent an email with the link; that is all I can do.

Re: Debian Statement on the Cyber Resilience Act

#140

Earlier quoted context omitted.

It can be priced in you just change the minimum price from $0 to how much liability would cost you.

It would be a huge gamble if the "0$ version" (e.g. GitHub repo) gets more popular that anticipated and the one with the bigger price tag not growing accordingly and the whole risk calculation falls apart. There is always the possibility to only offer the priced version, even if it is free software. Someone else could of course redistribute it and then it would be their responsibility. That would be a less convenient…

> There is always the possibility to only offer the priced version, even if it is free software. Someone else could of course redistribute it and then it would be their responsibility.

I thought the CRA would make the original distributor responsible for what they distributed. So A distributed to B and B redistributes to C, A is still has responsibilities to C. B might also have be in trouble when something goes wrong but B redistributing does not shield A to my understanding.

Post reply on HN