Live data from Hacker News

No cyber resilience without open source sustainability

github.blog

21–30 of 74 posts

Re: No cyber resilience without open source sustainability

#21

I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…

You give EU bureaucrats too much credit. Incompetence, lack of involvement and a general feeling of doing fake work reign there.

Re: No cyber resilience without open source sustainability

#22
post #8
post #6

This is very good that we have so many experts/vendors expressing their opinion (read: fears on how it will affect them). However, I welcome everyone to read https://digital-strategy.ec.europa.eu/en/policies/cyber-resi... and understand why CRA was created, what it tries to solve, and most importantly, why EU legislators INTENTIONALLY decided to make open-source part of the regulation. Regarding the OSS more specific…

Now, to some controversial things: do I think it's good if RedHat is legally forced by CRA to close down CentOS Stream if they decide not to deliver all security fixes they apply to RHEL? Yes, I do. This legislation will kill the practice of funding OSS projects by providing enterprise versions where many CVE fixes are only available in the enterprise versions. To that, I say: good riddance. The last thing we need is…

CVE fixes should not be available in RHEL only. If they are it's a bug. Of course RHEL might fix it with a backport whereas CentOS Stream might fix it with a new upstream version, but the fix should be there.

Re: No cyber resilience without open source sustainability

#23
post #18

Earlier quoted context omitted.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…

Do you know if the requirement is: * that a project is developed AND supplied commercially? * or rather that a project is developed OR supplied commercially? For example if I write an experimental project at work which might have vulnerabilities (developed commercially), which my employer has no intention of selling yet ( not supplied commercially), should I still follow the CRA processes in case someone reports a vu…

I was on the Eclipse Foundation call a few days ago regarding this topic and they said there was a well-established 3-part test for this in the EU courts. But I don't think I managed to take a screenshot, sorry.

Here is a snippet from the EU Blue Guide linked the from the Eclipse blog post:

"Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context."

I would consider GCC or React to fit this definition, while a hobby project like https://github.com/rui314/chibicc not to fit it.

Edit: I don't think you would have any obligations under CRA unless you make a project release available, whether commercially or on Github. The 3-part test I mentioned above only kicks in when there is a release of some sort in the first place.

Re: No cyber resilience without open source sustainability

#24
post #10

Earlier quoted context omitted.

> it will open up a path for devs to get paid for the extra burden. The thing is, being paid for an extra burden doesn't make it any less of an imposition on devs limited energy. Basically, if you want to accept donations so people can show their appreciation for what you share freely with the world, you open yourself up to demands that you do work that you don't enjoy on a hobby. That's really shit.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…

I probably missed it (or it's in one of the many documents on the ITRE page) but in the quoted Recital (10) on the Github Blog I'm not seeing a disctintion with regards to the use of a product.

Commercial or not (within the context of the CRA) seems to be based on the development structure and the offering of related services. For example they explicitely allow for a dristributed model where "no single commercial entity" has full control.

I'm not doubting that what you said is true, I'm interested to learn more, because in general this directive seems to be a big step in the right direction.

Do you happen to have a link to where I can read the current ITRE draft in it's enterity?

Re: No cyber resilience without open source sustainability

#25

I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…

> I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction.

I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way.

There were more landmines in the original draft. Like the requirement for any known-vulnerable device not be put on the market. Well guess what? All those phones and laptops sitting on the shelves are having exploits discovered every month.

Red Hat chimed in; apparently they have potential vulnerabilities on containers they publish sometimes in 15 minutes. Potential. How exactly are they supposed to act?

The legislation just plain sucked and now it's being "fixed" behind closed doors.

Re: No cyber resilience without open source sustainability

#26
post #4

Donations are often, if not most of the times, ways for companies to avoid having to pay taxes I wonder if this is precisely their motivation ;)

Do you have any examples?

Like...80% of big companies? You really should have heard of this practice by this age...

Re: No cyber resilience without open source sustainability

#27
post #22
post #8

Earlier quoted context omitted.

Now, to some controversial things: do I think it's good if RedHat is legally forced by CRA to close down CentOS Stream if they decide not to deliver all security fixes they apply to RHEL? Yes, I do. This legislation will kill the practice of funding OSS projects by providing enterprise versions where many CVE fixes are only available in the enterprise versions. To that, I say: good riddance. The last thing we need is…

CVE fixes should not be available in RHEL only. If they are it's a bug. Of course RHEL might fix it with a backport whereas CentOS Stream might fix it with a new upstream version, but the fix should be there.

Yes, sorry, I didn't make it clear that I was speaking of a purely hypothetical speculation that if RH ever decided to do this yet keep releasing CentOS Stream or Fedora, it would not be legal under CRA.

Re: No cyber resilience without open source sustainability

#28
post #25

I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…

> I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction. I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way. There were more landmines in the original draft. Like the r…

I'm pretty sure at least some of the lobbyists who wrote this were aware of the negative effects on FLOSS software.

Re: No cyber resilience without open source sustainability

#29
I have already stored some links about this act. As it is written in the register "The road to hell is paved with good intentions".

https://www.internetsociety.org/blog/2022/10/the-eus-propose...

https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-...

https://blog.opensource.org/what-is-the-cyber-resilience-act...

https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-sof...

https://berthub.eu/articles/posts/eu-cra-secure-coding-solut...

https://www.theregister.com/2023/05/12/eu_cyber_resilience_a...

Re: No cyber resilience without open source sustainability

#30

I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…

The reason is to make sure that all software that a normal run-the-mill business may use in the "in the course of a commercial activity" and receives regular releases, is reasonably free from known significant vulnerabilities (the last release, at least). Would it be reasonable to use Nginx "in the course of a commercial activity"? Yes, it would. Thus, EU wants to ensure that if you as an SME install Nginx and keep it updated, it's reasonably free from CVEs (e.g. that Nginx Plus does not contain CVE fixes that were not released in the latest versions of the OSS version of Nginx).

Bottom line: the criteria is written from the viewpoint of a software user, not the developer or vendor.

Post reply on HN