Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

151–160 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#151

Earlier quoted context omitted.

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and…

This is very analogous to Wickard v Filbern [1] which basically says that intrastate commerce is interstate commerce if that commerce affects interstate commerce. It is very much absurd on it's face and a thinly veiled power grab by the federal government. It's like saying my breathing affects the air quality and so I must be cognizant of others when I breathe. I don't find the idea useful to anyone but the unscrupul…

Commerce and business activity are different though. Commerce is business activity directly relating to financial recompense.

MS give away a browser with their OS, that's still business activity but not directly commerce, IMO.

Re: Debian Statement on the Cyber Resilience Act

#152

Earlier quoted context omitted.

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and…

I see no considerations for why my giving away stuff for free impacting other people's business means that my ability to freely give ought to be regulated. It is my property. I should be free to freely give of it. If that destroys a business then that kinda sucks, but why does it matter to my ability to engage in consensual non-monetary transactions with my property?

It can be like the Uber model, no? A company undercuts the market, in this case we're talking about giving product away for free, then when no one else exists in the market they have monopoly control.

Now, you say "but I'm not doing that", however the law needs to account for those who would use the freedom to create something and give it away in order to manipulate the market. It happens.

So in my opinion, whilst I absolutely want to ensure FOSS projects can operate, I also want to ensure large companies can't simply release a product as OSS destroy the market and once captured then only update their commercial offerings, for example. So, it needs a bit of thought.

Re: Debian Statement on the Cyber Resilience Act

#153
post #131
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

Won't work as the CRA overrides any license (this is explicitly written).

How can that be though? If there are users using your software where their nation imposes requirements you don’t want to deal with, you should be able to bar those users from using your software. Licensing is typically that mechanism.

Think if it were something else as an exercise: say some nation implemented rules requiring you to pay $10k USD/year to that government as some nonsense open-source fee. Common sense says you should be able to say, in response, “well, then I guess I’m cutting that country off.” If the rule making country shouts “no takebacks!” and supersedes licensing, then wouldn’t that impinge on sovereignty?

Re: Debian Statement on the Cyber Resilience Act

#154

This makes a lot of sense if you follow judgements internationally. Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You eith…

Hi craig wright, how are things?

[flagged]

Re: Debian Statement on the Cyber Resilience Act

#155
post #103

Earlier quoted context omitted.

Some of the best developers I know are self taught. Professional licensure makes it illegal for them to practice, or at least relegates them to low end work. It further cements the requirement that someone go deeply into debt to purchase the right to work from a university. It also creates artificial scarcity which will easily 10X costs. Dealing with security problems is much cheaper.

Not every developer needs the certification under my plan. And getting it is an apprenticeship, not education.

In practice you’ll get a certification mill industry that charges lots of money to certify you. Whether it’s inside or outside universities, it will be pay to play. Developers will spend the first N years of their career paying for their taxi medallion.

If you can’t tell I am deeply and profoundly cynical of systems like this. They always turn into rent extraction schemes for bureaucrats, consultants, etc.

Re: Debian Statement on the Cyber Resilience Act

#156

Earlier quoted context omitted.

> A regulator doesn't really care about the internal complexities Seems like you are over simplifying the process and goals of those creating new regulations and law makers often have to care about the internal complexities because they care about the consequences new regulations will have. When a law maker is making regulations for an industry they should care about the internal complexities since that determines th…

No, they really don't give a hoot. They have an end goal they're trying to accomplish, and that's their priority. They will seek feedback from industry experts to determine if their rules should be refined, which is what is happening. The details of any internal complexity of an industry is entirely delegated.

> They will seek feedback from industry experts to determine if their rules should be refined, which is what is happening. The details of any internal complexity of an industry is entirely delegated.

We may be working with different definitions here. If they did not care they would not delegate away the details of the internal complexity.

Re: Debian Statement on the Cyber Resilience Act

#157

Earlier quoted context omitted.

> How does someone know that a particular application is something lives depend on? Either your lawyer, insurance company, or regulator explicitly tells you. To make an analogy to the physical world. We have a company, B, that makes bolts, they publishes the characteristics of that bolt but do not certify it for any particular use. Company C makes cars and decides to use bolts form company B. It turns out that is not…

> company C should be liable for their choice of bolt, company B should be liable for any false or incorrect claims for the characteristics of their bolt I agree with what you're saying. I don't have enough of knowledge of EU law or the full text of the CRA to make a judgement about it specifically. I was just sharing my point of view on software regulation generally. > Company B should not be held liable for the mis…

> I do think it shouldn't be permissible to hide behind a shrink-wrap liability disclaimer when publishing software claimed to be of "commercial" or "enterprise" quality that doesn't even meet basic standard of rigor.

I am not sure that "commercial" or "enterprise" implies anything in terms of quality or should. "enterprise" for example is defined as "Enterprise software, or enterprise application software, is computer software used by organizations rather than individual users." by the following aws page[1].

Aerospace software already has to follow aerospace regulations, medical software already has to meet medical regulations.

Holding a company responsible for selling software with implicit claims but a liability disclaimer makes sense to me. Clarity in contracts, advertisements, terms of service, and similar makes sense. The CRA currently seem to to hold non commercial entities or individuals who are not making claims and explicitly going out of their way to disclaim liability responsible. That does not make sense to me and seems counter productive to the goal of safe software as well as a productive economy.

[1] https://aws.amazon.com/what-is/enterprise-software/

Re: Debian Statement on the Cyber Resilience Act

#158

This makes a lot of sense if you follow judgements internationally. Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You eith…

[flagged]

Re: Debian Statement on the Cyber Resilience Act

#159
post #158

This makes a lot of sense if you follow judgements internationally. Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper "open source" developers who refused to alter the protocol to allow him to recover coins a hacker took from him. Developers have a duty of care to their users which no license can remove even if they are communists calling themselves "open source". You eith…

[flagged]

[flagged]
Post reply on HN