Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

141–150 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#141

Earlier quoted context omitted.

> Software is relatively simple compared to other meat-space engineering disciplines. On what basis do you make this claim? If you do the same degree of optimization in software that is routinely applied in physical engineering disciplines that have some of most complex system dynamics problems, such as chemical engineering, the dynamics of software systems are qualitatively much more complex. We expect chemical engi…

I wasn't really thinking "complexity" in terms of formal academic problem scope, but more so "complexity" in the surface of how it interacts with the rest of the world, which is more along the lines of what would be relevant to a regulator. A regulator doesn't really care about the internal complexities of an LLM and whether or not that is more difficult than cracking petroleum. They care more about how those things…

> A regulator doesn't really care about the internal complexities

Seems like you are over simplifying the process and goals of those creating new regulations and law makers often have to care about the internal complexities because they care about the consequences new regulations will have.

When a law maker is making regulations for an industry they should care about the internal complexities since that determines the long term effects of the regulation. Law makes should care if new regulations kill small businesses or, in an extreme case that is not happening with the CRA, kills of an industry, since that effects the economy of the the country they are law makers for in addition to directly impact people represented by those law makers.

Re: Debian Statement on the Cyber Resilience Act

#142
post #102

Earlier quoted context omitted.

> ...for software that human lives depend on. who decides, and how?

For every other technology regulated this way, this is determined at the end application. How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you.

> How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you.

To make an analogy to the physical world. We have a company, B, that makes bolts, they publishes the characteristics of that bolt but do not certify it for any particular use.

Company C makes cars and decides to use bolts form company B. It turns out that is not a good choice since company B bolts do not have the characteristics that are need to use in a car.

The CRA from the a simple reading used in the discussions here[1], holds company B responsible for company C using the bolts in a way where peoples lives depend on it.

This sort of reuse can be much more common in software than it is bolts for example and just like company B did not control how company C used their product after buying it open source developers do not control how others use there software but CRA might make them liable for it.

This does not make sense to me, company C should be liable for their choice of bolt, company B should be liable for any false or incorrect claims for the characteristics of their bolt. Company B should not be held liable for the misuse of their bolt by company C which is what the CRA seems to do.

[1] https://news.ycombinator.com/item?id=38788919

Re: Debian Statement on the Cyber Resilience Act

#143
post #138

Earlier quoted context omitted.

"Deliberately excluded" is a pretty strong statement for a law that speaks of: > commercial activity, whether in return for payment or free of charge That definitely includes people like me who thought signing up for GitHub Sponsors was a good idea. What's the worst that could happen, right? For all I know it could include projects that accept donations too. Is writing a book about the project or offering screencasts…

Just like in similar complaints around GDPR, turns out that in practice the bar for these things in EU is much higher than what US lawyers are used to and scaremonger about.

Feel free to test those particular limits if you'd like. I'm not interested in that.

Re: Debian Statement on the Cyber Resilience Act

#144

Earlier quoted context omitted.

The AMA doesn’t require perfection, yet a doctor has to pay six-figure liability insurance premiums for the risk of harming a small fraction of his patients. I don’t have faith that this would be run more practically.

We have that problem in the medical world, but for some reason, we don't have it in the engineering world. Why? I don't know. Is the medical world just messed up? Or is there something wrong with licensure?

I think it’s because civil and mechanical engineering weren’t invented from scratch in living memory. We already have some safe, conservative materials and designs for them to reuse.

Our profession is still in a very early stage, sort of like the era of barbers performing surgery.

Re: Debian Statement on the Cyber Resilience Act

#145
post #76

Earlier quoted context omitted.

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

For non safety critical software, this would be absolutely unacceptable to me. We don't want any more gatekeepers who get to control who can participate or not in the industry.

Such gatekeeping almost always ends up preventing new innovative entrants from coming in. It protects those who have the certification from competition. Thus leading to stagnation in the industry.

Re: Debian Statement on the Cyber Resilience Act

#147
post #125

And don't skip over the part where they want developers to report any zero day's you discover to them within 24 hours so they can use them as exploits against innocent civilians not involved in any crime. And yes, the Netherlands changed the law recently so they can do this and without requiring any judge involved. And yes, they are allowed to hack people not involved with any crime as well. As well as changing the l…

i won't do it. and since they dont know i know of a security problem... nothing they can do about that.

Re: Debian Statement on the Cyber Resilience Act

#148

Earlier quoted context omitted.

I wasn't really thinking "complexity" in terms of formal academic problem scope, but more so "complexity" in the surface of how it interacts with the rest of the world, which is more along the lines of what would be relevant to a regulator. A regulator doesn't really care about the internal complexities of an LLM and whether or not that is more difficult than cracking petroleum. They care more about how those things…

> A regulator doesn't really care about the internal complexities Seems like you are over simplifying the process and goals of those creating new regulations and law makers often have to care about the internal complexities because they care about the consequences new regulations will have. When a law maker is making regulations for an industry they should care about the internal complexities since that determines th…

No, they really don't give a hoot. They have an end goal they're trying to accomplish, and that's their priority.

They will seek feedback from industry experts to determine if their rules should be refined, which is what is happening. The details of any internal complexity of an industry is entirely delegated.

Re: Debian Statement on the Cyber Resilience Act

#149

Earlier quoted context omitted.

For every other technology regulated this way, this is determined at the end application. How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you.

> How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you. To make an analogy to the physical world. We have a company, B, that makes bolts, they publishes the characteristics of that bolt but do not certify it for any particular use. Company C makes cars and decides to use bolts form company B. It turns out that is not…

> company C should be liable for their choice of bolt, company B should be liable for any false or incorrect claims for the characteristics of their bolt

I agree with what you're saying. I don't have enough of knowledge of EU law or the full text of the CRA to make a judgement about it specifically. I was just sharing my point of view on software regulation generally.

> Company B should not be held liable for the misuse of their bolt by company C

Putting aside this specific analogy, but on this topic: I do generally think that implied warranties are a good thing, and I don't think it should be legal to disclaim them in all scenarios. Most other professionals are held to professional liability standards, and it is expected that they follow certain basic standards when they practice.

Consider basic best practices, like testing and documentation. It probably is fine if a hobby video game developer doesn't do these things, but if you are putting out software that claims to be intended for "enterprise" or "commercial" use, it is certainly reasonable for others to expect that this software is "fit for this particular purpose", and was built with good software engineering methodology.

I do think it shouldn't be permissible to hide behind a shrink-wrap liability disclaimer when publishing software claimed to be of "commercial" or "enterprise" quality that doesn't even meet basic standard of rigor.

What software really needs right now is a standardized way to measure development quality, and some legal guardrails around standards for dependency management.

Re: Debian Statement on the Cyber Resilience Act

#150
post #130
post #121

Earlier quoted context omitted.

Every small developer should now start to ban government use. Even if they are not affected the law. To associate consequences to actions. They will never learn otherwise.

Two points: 1) this means MIT, Apache and many other licenses are dead in EU. 2) Laws override licenses, so the government can just make a law to ignore the 'no government use' clause.

That would be theft
Post reply on HN