Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

41–50 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#41
post #40

Earlier quoted context omitted.

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

TBF there is a lot of things “free of charge” connected to commercial activity, e.g. Android, .NET Core, MongoDb, ElasticSearch, even RedHat with Linux … I understand need to somehow include them, but the line should be at the for-profit companies and exclude non profits and individual developers. How to formulate it without easy loopholes is no easy task.

Oh, I agree completely.

We do need something like the CRA; we just need to make sure that it doesn't destroy our shining City of Open Source.

Re: Debian Statement on the Cyber Resilience Act

#42
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

The fact that I had to read this far in to determine that a) this is an EU law (I think?) and b) still have no idea what this (proposed?) law is/does is frustrating to me. This link could have used some context. I don't have an issue with clicking the link, but from there?

Re: Debian Statement on the Cyber Resilience Act

#43

Earlier quoted context omitted.

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and…

I see no considerations for why my giving away stuff for free impacting other people's business means that my ability to freely give ought to be regulated. It is my property. I should be free to freely give of it. If that destroys a business then that kinda sucks, but why does it matter to my ability to engage in consensual non-monetary transactions with my property?

I think that's the opinion of the person replying to you as well.

They're just using that as support for why they disagree with the EU rules, since it can be considered "commercial" even if you're making no money, just because someone is losing money.

Re: Debian Statement on the Cyber Resilience Act

#44
post #12

[flagged]

Professional accountability would be saying that companies like Riot can't deploy root-level code with no oversight onto millions of machines "for competitive integrity", not taking down git repos because they don't meet some regulations around security.

Re: Debian Statement on the Cyber Resilience Act

#45
post #13

Earlier quoted context omitted.

Standardized food safety practices, pre-approved and comparatively trivial recipes, state/county inspections, etc. None of which apply to software. One is fairly trivial and standardized. The other is massively complex, rapidly changing, and unable to be boiled down to a standard set of trivial procedures. And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damagin…

> Standardized food safety practices Food safety practices only became standardized after regulation was enacted. > pre-approved and comparatively trivial recipes That sounds like most software development. I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is ha…

"Food safety practices only became standardized after regulation was enacted."

Because you actually can standardize them. Software isn't so simple.

"> pre-approved and comparatively trivial recipes

That sounds like most software development."

Lol no that does not. Why wouldn't high school graduates or drop outs work in software instead of at fast food? The number of languages, frameworks, patterns, etc are much more complex than basic sanitation and time/temp/acidity.

Re: Debian Statement on the Cyber Resilience Act

#46
post #16
post #5

Maybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)

there is insightful discussion right on lwn. I think changing the URL is cutting that out.

Ideally[1] this thread would link to the original source, and then in the comments we would link to the second hand source that includes interesting or insightful discussion.

https://news.ycombinator.com/item?id=38726890

Re: Debian Statement on the Cyber Resilience Act

#47
post #30

Earlier quoted context omitted.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

There is some hope for individual developers in EP amended version https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COM... article 10c: > Developers contributing individually to free and open-source projects should not be subject to obligations pursuant to this Regulation. Actually it’s an improved version. Hopefully it will make it through consolidation with EC version.

Thank you for providing that, didn't knew about that amended version. This only includes individual developers though and if you are employed this is already a problem again: (10a) "[...]Similarly, where the main contributors to free and open-source projects are developers employed by commercial entities and when such developers or the employer can exercise control as to which modifications are accepted in the code base, the project should generally be considered to be of a commercial nature." A small step in the right direction, but not quite there yet. Companies that want to just release (old) projects would also be more hesitant now. Recurring donations from companies would also contaminate the project.

Re: Debian Statement on the Cyber Resilience Act

#48
post #39
post #20

Earlier quoted context omitted.

there needs to be regulation of for profit services, so when you _buy_ software, there is a baseline that you can rely on, as a buyer. we do not need regulation limiting distribution of volunteer work. and the vague language for the delineation line is what's problematic with this proposal. volunteers have no resources (time, money) to defend themselves or their products against false accusations of lack of complianc…

The problem with giving a pass to volunteer work and not to commercial activity is that there is a lot of potential for loopholes. Like by having a nonprofit tied to a for-profit company. Getting the spirit of the law into writing is tricky, and it will most likely improve over time. Closing loopholes and making exceptions when merited.

Also many non-profits are big enough that you should absolutely apply rules to them. Think of Mozilla... It has very big and expensive products. And somehow just because they are non-profit and open source they should get away with murder...

Re: Debian Statement on the Cyber Resilience Act

#50
post #40

Earlier quoted context omitted.

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

TBF there is a lot of things “free of charge” connected to commercial activity, e.g. Android, .NET Core, MongoDb, ElasticSearch, even RedHat with Linux … I understand need to somehow include them, but the line should be at the for-profit companies and exclude non profits and individual developers. How to formulate it without easy loopholes is no easy task.

The trick of course will be to have the software offered as a paid product by a non-profit, while having a for-profit outfit develop the software as a custom/consulting engagement for the non-profit. You can thank me later.
Post reply on HN