Live data from Hacker News

No cyber resilience without open source sustainability

github.blog

31–40 of 74 posts

Re: No cyber resilience without open source sustainability

#31

Earlier quoted context omitted.

I don't think this legislation will affect hobby projects. The problem is that whether the project is hobby or not is judged from the side of the consumer, i.e. if the software is usable "in the course of a commercial activity" (for the user). I agree that this creates a certain amount of stress, esp. for individual devs, but I think it was necessary to make sure that projects like k8s, kafka, and other OSS projects…

I probably missed it (or it's in one of the many documents on the ITRE page) but in the quoted Recital (10) on the Github Blog I'm not seeing a disctintion with regards to the use of a product. Commercial or not (within the context of the CRA) seems to be based on the development structure and the offering of related services. For example they explicitely allow for a dristributed model where "no single commercial ent…

The full draft is under https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-... , the body starts from page 14.

Upd: the amendment from 18.4.2023 is available under https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52...

Re: No cyber resilience without open source sustainability

#32
post #19

TL;DR The EU is working on the Cyber Resilience Act (CRA) which will be voted on the 19th of July. The current wording makes it look like it will affect open source projects that receice donations; which have contribution from corporate developers; and might break coordinated vulnerability disclousure. If you live in the EC area, there's a link on the blog to contact to MEP. The blog also links to other posts from OS…

I have not yet fully made up my mind, but notice that there is a lot of nuance in the actual text. For example "Accepting donations without the intention of making a profit should not count as a commercial activity, unless such donations are made by commercial entities and are recurring in nature".

That doesn't sound like nuance, just a quagmire of uncertainty. That means that if I have a Patreon account, and any business decides to fund me for a couple of months (let's say, for the duration of a Summer of Code), my project is now commercial? Is it only commercial during those months? Will such a donation affect all projects I'm working on at the same time?

Re: No cyber resilience without open source sustainability

#34

This is exactly why my FOSS licenses have a provision making them null and void if there is any legal duty for the programmer to the user. It is also one part of why I don't want to deal with Europe.

In this case I would assume it's void almost anywhere because I don't know of a single place in the world that does not require developers to avoid putting intentionally malicious software into their foss with the ultimate goal to harm users.

That requirement is something you usually can't waive with a LICENSE file either.

Re: No cyber resilience without open source sustainability

#35
German here, trying not to sound too polemic:

Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, this looks so much like an attack by enterprises against startup competition who cannot afford legal insecurities/legal departments/security certifications, that I can barely understand such a governmental interference without thinking about bad actors.

Re: No cyber resilience without open source sustainability

#36

Earlier quoted context omitted.

I probably missed it (or it's in one of the many documents on the ITRE page) but in the quoted Recital (10) on the Github Blog I'm not seeing a disctintion with regards to the use of a product. Commercial or not (within the context of the CRA) seems to be based on the development structure and the offering of related services. For example they explicitely allow for a dristributed model where "no single commercial ent…

The full draft is under https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-... , the body starts from page 14. Upd: the amendment from 18.4.2023 is available under https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52...

Thank you very much.

That seems to be the original draft of the Commission before the considerable changes added since then by the several committees

Re: No cyber resilience without open source sustainability

#37

I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction . Products aren’t commercial by themselves. Selling them is. Distributing the thing for free? Not commercial. Selling support? Commercial, you must provide guarantees even if upstream does not. Selling something that uses non-commercial FOSS softw…

Exactly this. To extend this further, the requirement should actually be on the receiver of the transaction to verify their dependencys are fit for purpose either by consuming a guarantee from upstream or by providing the guarantee if upstream does not.

This is what literally every other industry does. They vet that their dependencys meet their requirements. It is literally ridiculous that this most basic of practices is still not standard in software development.

It is insane to burden OSS developers by requiring them to assert commercial guarantees because the lazy bums who want to use their software for free can not even be bothered to check if it actually meets their needs.

Re: No cyber resilience without open source sustainability

#38
post #18

Earlier quoted context omitted.

Do you know if the requirement is: * that a project is developed AND supplied commercially? * or rather that a project is developed OR supplied commercially? For example if I write an experimental project at work which might have vulnerabilities (developed commercially), which my employer has no intention of selling yet ( not supplied commercially), should I still follow the CRA processes in case someone reports a vu…

I was on the Eclipse Foundation call a few days ago regarding this topic and they said there was a well-established 3-part test for this in the EU courts. But I don't think I managed to take a screenshot, sorry. Here is a snippet from the EU Blue Guide linked the from the Eclipse blog post: "Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered…

That roughly tracks with my gut reaction from reading what appears to be the current draft: if you're doing any sort of formalized release process, you're probably at the point where you're doing commercial activity. By the time you're supporting old versions of the software, and cutting new point releases, you're almost definitely in commercial activity land.

Definitely it looks like a higher bar than GitHub is implying--I don't see any indication that merely soliciting donations would qualify for commercial activity.

Re: No cyber resilience without open source sustainability

#39
So if a company decides to open source some of their internal software and periodically release updates they'd be liable now? I don't see how that would not outright kill 99.9% of the open source released by companies. Most companies only do so nowadays because engineers push for it and not any tangible benefit so no reason to allow it anymore given the risk.

edit: That'd mean no Hadoop, Envoy, Finagle, React, GraphQL, StatsD, Airflow, etc.

Re: No cyber resilience without open source sustainability

#40

German here, trying not to sound too polemic: Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, this looks so much like an attack by enterprises against startup competition who cannot afford legal insecurities/legal departments/security certifications, that I can barely understand such a governmental interference without thinking about bad actors.

I believe the EU is not “attacking”. It’s generally the EU’s insecurity over anything technical, as there is no good homegrown ecosystem for software, AI, etc. Brussels thinks it can fix this by regulating large American enterprises and making them dance on its music.

Also, generally politicals want to control everything and do not see the harmful side effects of regulation. You are not going to get re-elected by de-regulation. “Think of the children” and any AI, cryptocurrency etc. doomsday porn is sure way to get headlines and get your name out in the press.

The root cause of the problem of why the EU lacks software startups and AI startups compared to the US and China remains unaddresed.

In the end the result is that more and more business is infeasible in the EU, for both EU citizens and foreigners and will just move to elsewhere.

Post reply on HN