I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…
No cyber resilience without open source sustainability
21–30 of 74 posts
Re: No cyber resilience without open source sustainability
#22This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…
Now, to some controversial things: do I think it's good if RedHat is legally forced by CRA to close down CentOS Stream if they decide not to deliver all security fixes they apply to RHEL? Yes, I do. This legislation will kill the practice of funding OSS projects by providing enterprise versions where many CVE fixes are only available in the enterprise versions. To that, I say: good riddance. The last thing we need is…
Re: No cyber resilience without open source sustainability
#23Earlier quoted context omitted.
I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…
Do you know if the requirement is: * that a project is developed AND supplied commercially? * or rather that a project is developed OR supplied commercially? For example if I write an experimental project at work which might have vulnerabilities (developed commercially), which my employer has no intention of selling yet ( not supplied commercially), should I still follow the CRA processes in case someone reports a vu…
Here is a snippet from the EU Blue Guide linked the from the Eclipse blog post:
"Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context."
I would consider GCC or React to fit this definition, while a hobby project like https://github.com/rui314/chibicc not to fit it.
Edit: I don't think you would have any obligations under CRA unless you make a project release available, whether commercially or on Github. The 3-part test I mentioned above only kicks in when there is a release of some sort in the first place.
Re: No cyber resilience without open source sustainability
#24Earlier quoted context omitted.
> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.
I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…
Commercial or not (within the context of the CRA) seems to be based on the development structure and the offering of related services. For example they explicitely allow for a dristributed model where "no single commercial entity" has full control.
I'm not doubting that what you said is true, I'm interested to learn more, because in general this directive seems to be a big step in the right direction.
Do you happen to have a link to where I can read the current ITRE draft in it's enterity?
Re: No cyber resilience without open source sustainability
#25I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…
I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way.
There were more landmines in the original draft. Like the requirement for any known-vulnerable device not be put on the market. Well guess what? All those phones and laptops sitting on the shelves are having exploits discovered every month.
Red Hat chimed in; apparently they have potential vulnerabilities on containers they publish sometimes in 15 minutes. Potential. How exactly are they supposed to act?
The legislation just plain sucked and now it's being "fixed" behind closed doors.
Re: No cyber resilience without open source sustainability
#26Re: No cyber resilience without open source sustainability
#27Earlier quoted context omitted.
Now, to some controversial things: do I think it's good if RedHat is legally forced by CRA to close down CentOS Stream if they decide not to deliver all security fixes they apply to RHEL? Yes, I do. This legislation will kill the practice of funding OSS projects by providing enterprise versions where many CVE fixes are only available in the enterprise versions. To that, I say: good riddance. The last thing we need is…
CVE fixes should not be available in RHEL only. If they are it's a bug. Of course RHEL might fix it with a backport whereas CentOS Stream might fix it with a new upstream version, but the fix should be there.
Re: No cyber resilience without open source sustainability
#28I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…
> I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction. I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way. There were more landmines in the original draft. Like the r…
Re: No cyber resilience without open source sustainability
#29https://www.internetsociety.org/blog/2022/10/the-eus-propose...
https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-...
https://blog.opensource.org/what-is-the-cyber-resilience-act...
https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-sof...
https://berthub.eu/articles/posts/eu-cra-secure-coding-solut...
https://www.theregister.com/2023/05/12/eu_cyber_resilience_a...
Re: No cyber resilience without open source sustainability
#30I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…
Bottom line: the criteria is written from the viewpoint of a software user, not the developer or vendor.