Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

21–30 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#21

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

> but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors

bad analogies are bad

Re: Debian Statement on the Cyber Resilience Act

#22

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

> Our industry desperately needs better regulations, IMO.

Famous last words of any dying industry

Re: Debian Statement on the Cyber Resilience Act

#23

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

What if you needed a full commercial grade license and permit to give some home baked cookies to your co-workers?

edit: Or if we go to the extreme of nothing except the action and potential for negative impact mattering then you'd need a license to give those cookies to your own kids or even yourself.

Re: Debian Statement on the Cyber Resilience Act

#24
A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

Re: Debian Statement on the Cyber Resilience Act

#26

Earlier quoted context omitted.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

Pretending for a second that I don't outright reject your premise (that there is no inherent right to do business)... You can't just label everything as "doing business" and then regulate it all. If I make something interesting and give everyone in the world the blueprints so they can make one themselves that's not "doing business".

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business".

Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and deserves substantial consideration.

It is difficult to draw the line here, much more difficult than it seems at first, in my personal opinion.

Re: Debian Statement on the Cyber Resilience Act

#27
post #13

Earlier quoted context omitted.

What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?

Standardized food safety practices, pre-approved and comparatively trivial recipes, state/county inspections, etc. None of which apply to software. One is fairly trivial and standardized. The other is massively complex, rapidly changing, and unable to be boiled down to a standard set of trivial procedures. And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damagin…

> Standardized food safety practices

Food safety practices only became standardized after regulation was enacted.

> pre-approved and comparatively trivial recipes

That sounds like most software development.

I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is hazardous to public safety, unlike food production which reached that a long time ago.

Re: Debian Statement on the Cyber Resilience Act

#28

Earlier quoted context omitted.

I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software

What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?

The same difference as there is between a baker liable for flour content and you being liable for flour content when sharing some home made cookies with your co-workers.

Re: Debian Statement on the Cyber Resilience Act

#29

Earlier quoted context omitted.

I’m curious what the liability and permits being discussed are here. Because the permit required to prevent some Joe Schmoe from selling me a tainted brownie off a street cart feels a little bit different and perhaps difficult to compare to software

What’s different between a baker liable for flour content and an SDE liable for packaged library vulnerabilities?

[deleted]

Re: Debian Statement on the Cyber Resilience Act

#30

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

There is some hope for individual developers in EP amended version https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COM... article 10c: > Developers contributing individually to free and open-source projects should not be subject to obligations pursuant to this Regulation.

Actually it’s an improved version. Hopefully it will make it through consolidation with EC version.

Post reply on HN