Live data from Hacker News

France Endorses UN Open Source Principles

social.numerique.gouv.fr

211–220 of 232 posts

Re: France Endorses UN Open Source Principles

#211

Earlier quoted context omitted.

So insurance did not offer much before the CRA. They will probably develop this market but it is gonna cost a lot probably and will be complex and imperfect. Of course an LLC ultimately protect you but you have just multiplied by 10 or 100 the risk of blowing up your livelihood and the one of your employees. Those regulations are just a nightmare, with "no-fault" liability, a simplified the burden of proof for the cl…

Have you talked to an insurer? Business insurance requires a customized quote. You didn't really answer the question. Do you have a specific risk in mind, or are you only worried about the risk of a random fuckup which all businesses face?

Yes so the problem is this is not about random f-up, the CRA is full of buzzwords concepts like "Cyber security by design", "Cyber security by default" "according to risks" which will be evaluated by the courts if you end up there.

Every software you provide have to be secure and if not you are liable for damage. So this is not just a random f-up, and we know how hard security really is in practice.

I also know that when you are a provider of a software most vulnerabilities and risks are usually requested/created by the client who usually exercise pressure on you (especially if you are a small actor). It is often done in a sneaky manner, putting the provider in an impossible situation. You will need to document this the best you can because now you are liable big time.

EDIT: What I mean is I understand they did that to force big manufacturers of IoT device to care more about security. But if you are now a small provider setting up some customized software you fall under the same rules.

Re: France Endorses UN Open Source Principles

#212

Earlier quoted context omitted.

Now look at Outlook. Or Skype. And 15 years ago, we just used Office files in a Dropbox folder. It solved all of our collaboration issues.

> And 15 years ago, we just used Office files in a Dropbox folder. It solved all of our collaboration issues. No, it did not. I worked through that. Someone had to be in charge of the master version of all documents and ensure modifications were properly merged and not done simultaneously. Getting to the final version of anything was deeply annoying. Now everyone can just work on the shared document. You see modifica…

I agree that the collaborative tools in the current office are better. It's just that they are not that _much_ better than before to justify all the negatives.

Re: France Endorses UN Open Source Principles

#213

Earlier quoted context omitted.

Have you talked to an insurer? Business insurance requires a customized quote. You didn't really answer the question. Do you have a specific risk in mind, or are you only worried about the risk of a random fuckup which all businesses face?

Yes so the problem is this is not about random f-up, the CRA is full of buzzwords concepts like "Cyber security by design", "Cyber security by default" "according to risks" which will be evaluated by the courts if you end up there. Every software you provide have to be secure and if not you are liable for damage. So this is not just a random f-up, and we know how hard security really is in practice. I also know that…

So in other words if you provide someone software and it sets their business on fire, you're liable to repay the value of the business you set on fire. Yes, this is how all business relations work. If I sell someone a mango that sets their business on fire I'm liable for that too. Not unique to software. No difference if it's a mango full of genetically modified bacteria that spontaneously combust after a certain time passes, or a server that sends network signals to turn the heating up to 1000 degrees. And in both cases the solution is don't do that.

So I want to know what specific risks you're worried about that are not present in literally 100% of business interactions. Or do you expect software to be exempt from the general principles of liability?

Re: France Endorses UN Open Source Principles

#214
post #187

Earlier quoted context omitted.

What sort of issues? They are just providing funding for open source, personally I would prefer that sort of funding to corporate funding.

A GmbH is s for-profit company. They have a managing director, shareholders, … ultimately it’s a for—profit org established on an insider-level knowledge and good luck creating a competitive business to the one of those players. Case in point: Bundesanzeiger Verlag GmbH.

Some links for other folks looking at this:

https://www.sovereign.tech/legal https://www.sovereign.tech/faq https://www.sprind.org/ https://de.wikipedia.org/wiki/Bundesagentur_f%C3%BCr_Sprungi...

I guess the government wouldn't fund more than one such org, even if the additional ones were non-profit instead.

At least NLnet (similar org from .nl) is a registered charity. IIRC its funds are from the EU level though.

https://nlnet.nl/

What happened with Bundesanzeiger Verlag GmbH?

Re: France Endorses UN Open Source Principles

#215
post #31

As an American, this sort of brings back into question for me thoughts of, "What should constitute a public utility in a Capitalism society?" Upon doing some cursory research (so cursory that I'm afraid to provide links), it occurs to me that I was maybe under a false impression that there _are_ any nationwide public utilities in the first place. We basically have: * The Federal Reserve * The Interstate Highway Syste…

> Did I leave anything major out? You've limited your list to federal services. But state and local governments provide plenty more "public utility in a Capitalism society", don't they? Schools, fire protection, police for example.

Yeah I did. I realize that each state and municipality has the ability to do this. But they aren’t countries. Is it fair to compare e.g. one cherry-picked state to France? I thought maybe it wasn’t, but you certainly have a point.

Re: France Endorses UN Open Source Principles

#216

Earlier quoted context omitted.

Have you talked to an insurer? Business insurance requires a customized quote. You didn't really answer the question. Do you have a specific risk in mind, or are you only worried about the risk of a random fuckup which all businesses face?

Yes so the problem is this is not about random f-up, the CRA is full of buzzwords concepts like "Cyber security by design", "Cyber security by default" "according to risks" which will be evaluated by the courts if you end up there. Every software you provide have to be secure and if not you are liable for damage. So this is not just a random f-up, and we know how hard security really is in practice. I also know that…

Open source software is unsecure. It's neither secure or insecure. Securing something means implementing policies like SSO and ACLs. That's not open source's job. Open source gives you a tool and it's your responsibility to secure the thing. It's not the responsibility of open source developers. It can't be. What they strive to do is to not ship something that's known to be insecure.

Re: France Endorses UN Open Source Principles

#217
post #150

Earlier quoted context omitted.

[flagged]

I'm not sure if this is satire, but if it isn't you can look over for some history you may have never heard of. https://en.wikipedia.org/wiki/Nazi_human_experimentation

Well the recent human experimentation was unleashed on the whole world.

Re: France Endorses UN Open Source Principles

#218

Earlier quoted context omitted.

There is nothing fascist there. That's the core regalian powers at the heart of the state. Basically, a state is there to ensure laws can be voted, that they are fairly enforced and that things can stay that way. This notably means that people are safe in the broadest sense. They are not going to be mugged, murdered or dispossessed. That also means that the state has the mean to stay a state without becoming part of…

You're only outing yourself more and more. > If the French felt a bit less entitled and a bit more grateful, the country wouldn't be in the sorry state it's currently in. Oh please. The French are doing far better than we (the US) are. Precisely because their electorate has made their aristocracy rightly fearful of them. Chopping off their heads tends to do that.

> Oh please. The French are doing far better than we (the US) are.

I’m French.

The French hasn’t chopped the head of their aristocracy. Despite going through five republics, two monarchies and two empires in the last two hundred years, the country has very much de facto recreated an aristocracy. It’s one of the most unequal when it comes to social mobility in the whole OECD. Ever heard of Bourdieu?

What France has is a lot of redistribution so its Gini coefficient is quite low and a very generous through currently financially unsustainable safety net. Public services are also working fairly well even if it used to be better. That’s why I hate how ungrateful most French are. People have no interest in maintaining and protecting what they have. They prefer whining constantly while waiting for other people to do the work. That’s how you end up with the far right and the far left at 30% despite them only peddling non sense.

I’m not really interested in commenting further on your weird fascist obsession. I think it would be good for the discussion if you brushed up on what is both fascism and a state however.

Re: France Endorses UN Open Source Principles

#220

Earlier quoted context omitted.

Yes so the problem is this is not about random f-up, the CRA is full of buzzwords concepts like "Cyber security by design", "Cyber security by default" "according to risks" which will be evaluated by the courts if you end up there. Every software you provide have to be secure and if not you are liable for damage. So this is not just a random f-up, and we know how hard security really is in practice. I also know that…

So in other words if you provide someone software and it sets their business on fire, you're liable to repay the value of the business you set on fire. Yes, this is how all business relations work. If I sell someone a mango that sets their business on fire I'm liable for that too. Not unique to software. No difference if it's a mango full of genetically modified bacteria that spontaneously combust after a certain tim…

> Or do you expect software to be exempt from the general principles of liability?

Yes.

Have you read the EULA of most of the software you use ?

Any of the open source licenses ?

And this is why the computer world is almost the only thing that really progressed in the last decades.

Because we could take that risk because in most cases nobody was gonna die (medical devices or the ABS in your car are a separate category with other rules).

You do not realize how free from regulations computers have been and this is why you are on HN and probably work in this industry.

We ended up with a fairly acceptable ecosystem where you can either keep your ISP provided router, buy a very suspicious one on Aliexpress, or Nitrokey, Turris (both EU companies) or one with OpenBSD.

Bad regulations will make the last 3 options disappear. That is the sad reality.

Post reply on HN