Live data from Hacker News

The EU Open Source Strategy

digital-strategy.ec.europa.eu

151–160 of 167 posts

Re: The EU Open Source Strategy

#151

Earlier quoted context omitted.

You know what happened at Google after Operation Aurora and they went full bore on security (BeyondCorp and all that)? They started phasing out Windows laptops for employees immediately. I'm honestly having trouble taking you seriously, Windows has always been at the butt of security jokes, I guess you maybe didn't grow up with winnuke etc? But maybe you could elaborate a bit more concretely about what kind of intra-…

I worked at Google on post-Aurora endpoints security. Windows laptops are alive and well at Google. Linux laptops have had one foot in the grave for a while now (it's a bummer). Google historically made gLinux work only with enormous investments in customised distros and D&R. > But maybe you could elaborate a bit more concretely about what kind of intra-host security boundaries are missing - no boundaries between app…

> Unless you count ChromeOS/Android which are not really OSS

Wouldn't ChromiumOS and AOSP count? Though I read a lot of people generally complaining about secure boot on desktop (for reasons I honestly don't understand: secure boot seems to be part of the Android security model, and it seems valuable to me).

Re: The EU Open Source Strategy

#152
post #106

Earlier quoted context omitted.

- digital services act mandates interoperability in chat, but apparently companies can put require obnoxious terms for interoperating parties such as sharing their users IP addresses - which service is going to agree to that if a very large portion of the alternatives target people not wanting to share data with Facebook? - pay "ridiculous price" or accept ads & tracking instead of allowing to disable tracking

NOYB have raised a complaint on the second one for a publisher in the Nordics. https://noyb.eu/en/nordic-media-giant-schibsted-switches-pay...

Cool? So one down, how many to go? Why don't they get the same level of scrutiny as, say, Facebook?

Re: The EU Open Source Strategy

#153
post #145

Earlier quoted context omitted.

Look if everyone agrees the outcome of the law has been incredibly annoying, then that is ultimately down to the law and/or its enforcement. The point of the law is to provide incentives to self-interested actors for good behaviour. I see a lot of complacency in these threads, combined with a lot of frankly absurd posturing, like if anybody is against the GDPR, they must’ve been brainwashed by Elon Musk. No! People d…

> People dislike it because they dislike its practical effects, and frankly the EU should take responsibility for that and try to fix it. What’s to fix? A business needs a legitimate reason to process personal data, people need to be sufficiently informed about how their data will be processed. These are not impossible obstacles. Anyone who claims otherwise is acting in bad faith because they know that people would n…

> What’s to fix?

Is this not your own comment, from just a few hours ago, visible on the same viewport as this one?

https://news.ycombinator.com/item?id=48445299

Why is it that so many years later, so many companies are still not compliant? That seems like a major problem to fix.

You are replying to a comment complaining about the annoyance for users that the law has created. When will that be fixed?

Why is it that all of the enforcement effort been so unevenly directed specifically at non-European companies?

This subthread started with the statement "True but it also reflects that the EU has indeed destroyed most goodwill towards it in the last decade regarding most things digital."

I think maybe you don't understand that the level of goodwill destroyed really is on par with the level of goodwill towards American that Trump has destroyed. Yes, it is really that bad. Yes, it is something that needs to be fixed.

Re: The EU Open Source Strategy

#154

Earlier quoted context omitted.

> People dislike it because they dislike its practical effects, and frankly the EU should take responsibility for that and try to fix it. What’s to fix? A business needs a legitimate reason to process personal data, people need to be sufficiently informed about how their data will be processed. These are not impossible obstacles. Anyone who claims otherwise is acting in bad faith because they know that people would n…

> What’s to fix? Is this not your own comment, from just a few hours ago, visible on the same viewport as this one? https://news.ycombinator.com/item?id=48445299 Why is it that so many years later, so many companies are still not compliant? That seems like a major problem to fix. You are replying to a comment complaining about the annoyance for users that the law has created. When will that be fixed? Why is it that a…

> Why is it that all of the enforcement effort been so unevenly directed specifically at non-European companies?

Do you have any evidence of that?

> You are replying to a comment complaining about the annoyance for users that the law has created. When will that be fixed?

The law isn’t about fixing an annoyance to users. If you’re annoyed by bad UX, tell your boss to cut that shit out because they’re probably part of the problem too.

What I struggle to understand is you’d rather have your privacy right absolutely derailed just so you have a couple things less to click. Wild.

Re: The EU Open Source Strategy

#155
post #83

Earlier quoted context omitted.

If your friends have never said “man I hate these cookie popups”, they sound like a highly selected group.

Don't be silly, the legislation doesn't state that websites have to show cookie popups. It's rather where the term malicious compliance enters the picture, a compliance incentivized by the financial interests of the biggest advertising businesses the world has ever seen.

Let’s accept for the sake of argument that all the cookie banners are malicious compliance. Fine. Then they should change the law to stop the malicious compliance! Regulation has an outcome nobody likes. Are you gonna wait for every company to stop being “malicious”? Or are you gonna fix the law?

Re: The EU Open Source Strategy

#156
post #155

Earlier quoted context omitted.

Don't be silly, the legislation doesn't state that websites have to show cookie popups. It's rather where the term malicious compliance enters the picture, a compliance incentivized by the financial interests of the biggest advertising businesses the world has ever seen.

Let’s accept for the sake of argument that all the cookie banners are malicious compliance. Fine. Then they should change the law to stop the malicious compliance! Regulation has an outcome nobody likes. Are you gonna wait for every company to stop being “malicious”? Or are you gonna fix the law?

The latter, obviously, and that is what's happening with the Digital Omnibus.

Re: The EU Open Source Strategy

#157
post #151

Earlier quoted context omitted.

I worked at Google on post-Aurora endpoints security. Windows laptops are alive and well at Google. Linux laptops have had one foot in the grave for a while now (it's a bummer). Google historically made gLinux work only with enormous investments in customised distros and D&R. > But maybe you could elaborate a bit more concretely about what kind of intra-host security boundaries are missing - no boundaries between app…

> Unless you count ChromeOS/Android which are not really OSS Wouldn't ChromiumOS and AOSP count? Though I read a lot of people generally complaining about secure boot on desktop (for reasons I honestly don't understand: secure boot seems to be part of the Android security model, and it seems valuable to me).

It's a good technical artifact yeah but it would need to be forked and degoogled, today it is only really useful with Google services as a backend.

Also it's coupled to the device ecosystem which is organised by Google. This coupling with the HW is one of its major technical strengths though, including for the security things I'm yapping about.

So yeah I think the two options for a EuroOS are:

- Fork and degoogle ChromiumOS/AOSP

- Invest in a Silverblue/bootc/Flatpak style system and just keep filling the gaps there

Hard to say which would be the better option. Both require at least tens of millions in investment over 5+ years.

Re: The EU Open Source Strategy

#158

Earlier quoted context omitted.

I guess the hate is because the EU also invented the following monstrosities: - CRA (cyber resiliency act): Manufacturers must handle and release security patches for vulnerabilities, and developers are required to report actively on exploited vulnerabilities and breaches. - PLD (Product Liability Directive): A failure to provide critical security updates or the presence of exploitable vulnerabilities can now legally…

Sounds like plausible clauses to me? Please explain why they are so toxic. What cases are there where these clauses present an unfair threat or disadvantage to a business? In case it is unclear from my tone, I am genuinely curious.

Here it goes:

- CRA mandates vulnerability patches for products. This puts undue burden on manufacturers whose products are out of the production cycle. Basically the EU wants updates for products no longer manufactured.

- PLD requires fixes for products deemed to have critical vulnerabilities, again, if the product is not manufactured anymore, why should the manufacturer have to support who knows what old software?

Then, for OSS it is even worse: you have a pet project, you give it away for free, it has success, you want to sell a paid version of it. Automatically you're on the hook for vulnerability fixing. Which takes time. And if you're in the early stages of maybe selling a few copies here and there, the time spent fixing stuff will outweigh any winnings.

Than again with "you're on the hook if you ship commercial products using some OSS components" - either no one ships OSS packages with their commercial software given the advent of coding agents that can replicate OSS software functionality, or there will be a ton of forks, with vendors claiming they fixed the problem in their own way.

With all this said, then the EU has the nerve to come and say "use OSS" because freedom and BS.

Re: The EU Open Source Strategy

#159
post #138

Earlier quoted context omitted.

[flagged]

Interoperability is what enables consumer choice and the best product winning in the first place. Theres no choice if all your friends are on a network that's not interoperable.

Yes there is. I gave the Whatsapp example. People on different carriers and with different phones can talk to each other. How is that not interoperable?

Re: The EU Open Source Strategy

#160
post #87

Earlier quoted context omitted.

Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X"? Secondly, are you sure that it is impossible to secure a system for a whole department? I have seen relatively big companies having an IT team managing their own Linux flavour. That is, whitelisti…

> Genuinely interested: does it bring something to say "everything is crap anyway, but given that we must choose between one of them, we may as well choose the least bad" instead of "the best solution we currently have is X" Well I dunno if that's true, that's why I didn't say it. Linux _may_ be the best solution overall I am not sure. It is definitely not the best solution from a security perspective. > Secondly, ar…

> It is definitely not the best solution from a security perspective.

But that's compared to alternatives that virtually nobody uses, isn't it? No public service is using ChromeOS. In Europe they probably all use Windows, I would guess? So the question reduces to: is Linux worse than Windows in terms of security in this context?

The goal here is not to have the perfect system, rather to be sovereign. It's enough to not be significantly worse than Windows.

Post reply on HN