Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

31–40 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#31

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

But if they don't include free/OSS projects, then commercial companies sponsoring FLOSS is an obvious way to launder liability, is it not?

Re: Debian Statement on the Cyber Resilience Act

#32
> It's very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout.

Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303)

Can someone explain to me what in the statement from Debian is "anarco-capitalist FUD"? I find it quite reasonable overall.

Re: Debian Statement on the Cyber Resilience Act

#33
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

I'm using [1].

Page 15:

> In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.

This sounds sane-ish, but it the key is that it says Open Source Software is not exempted if it is part of commercial activity.

So what is commercial activity?

Page 34:

> 'making available on the market' means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge

That "free of charge" connected with "commercial activity" is what has people up in arms.

Does it include free stuff like Debian? Does it include donation-based FOSS like Zig?

These are the things that worry people.

[1]: https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-...

Re: Debian Statement on the Cyber Resilience Act

#34
I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].)

There is a better way [2], but I don't know how we would convince politicians that there is a better way.

[1]: https://news.ycombinator.com/item?id=38788919

[2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

Re: Debian Statement on the Cyber Resilience Act

#35
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

You are asking how requiring open source with no money to satisfy plethora of regulations along with legal liability (I.e. making it a commercial grade) makes it less likely for open source be made?

Ask log4j or OpenSSL.

Go read this: https://blogs.eclipse.org/post/mike-milinkovich/european-cyb...

Re: Debian Statement on the Cyber Resilience Act

#36
post #32

> It's very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout. Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303) Can someone explain to me what in the statement from Debian is "anarco-capitalist FUD"? I find it quite reasonable overall.

There is a reasonable argument that the Debian project has an anarco-capitalist philosophy, so really the only question is whether it is FUD or not. I suspect not though - regulation has a strong track record of taking out smaller players.

Re: Debian Statement on the Cyber Resilience Act

#38

Earlier quoted context omitted.

Pretending for a second that I don't outright reject your premise (that there is no inherent right to do business)... You can't just label everything as "doing business" and then regulate it all. If I make something interesting and give everyone in the world the blueprints so they can make one themselves that's not "doing business".

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and…

I see no considerations for why my giving away stuff for free impacting other people's business means that my ability to freely give ought to be regulated. It is my property. I should be free to freely give of it. If that destroys a business then that kinda sucks, but why does it matter to my ability to engage in consensual non-monetary transactions with my property?

Re: Debian Statement on the Cyber Resilience Act

#39
post #20

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

there needs to be regulation of for profit services, so when you _buy_ software, there is a baseline that you can rely on, as a buyer. we do not need regulation limiting distribution of volunteer work. and the vague language for the delineation line is what's problematic with this proposal. volunteers have no resources (time, money) to defend themselves or their products against false accusations of lack of complianc…

The problem with giving a pass to volunteer work and not to commercial activity is that there is a lot of potential for loopholes. Like by having a nonprofit tied to a for-profit company.

Getting the spirit of the law into writing is tricky, and it will most likely improve over time. Closing loopholes and making exceptions when merited.

Re: Debian Statement on the Cyber Resilience Act

#40
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

TBF there is a lot of things “free of charge” connected to commercial activity, e.g. Android, .NET Core, MongoDb, ElasticSearch, even RedHat with Linux …

I understand need to somehow include them, but the line should be at the for-profit companies and exclude non profits and individual developers.

How to formulate it without easy loopholes is no easy task.

Post reply on HN