Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

51–60 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#51
post #42

Earlier quoted context omitted.

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

The fact that I had to read this far in to determine that a) this is an EU law (I think?) and b) still have no idea what this (proposed?) law is/does is frustrating to me. This link could have used some context. I don't have an issue with clicking the link, but from there?

IANAL, so I think the best course of action would be to do a search. Plenty of lawyers have written the summarized context you seek.

Re: Debian Statement on the Cyber Resilience Act

#52
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

It could be done for some software, but some popular licenses like GPL don't allow additional restrictions on use.

Re: Debian Statement on the Cyber Resilience Act

#53
post #13

Earlier quoted context omitted.

Standardized food safety practices, pre-approved and comparatively trivial recipes, state/county inspections, etc. None of which apply to software. One is fairly trivial and standardized. The other is massively complex, rapidly changing, and unable to be boiled down to a standard set of trivial procedures. And to answer your question more directly, the flour itself causes the damage. The vulnerability is only damagin…

> Standardized food safety practices Food safety practices only became standardized after regulation was enacted. > pre-approved and comparatively trivial recipes That sounds like most software development. I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is ha…

Knuth’s code has bugs. NASA’s code has bugs. I would like to think that someday our profession might be able to achieve high enough quality to survive with liability, but today nobody is close to that at all.

Re: Debian Statement on the Cyber Resilience Act

#54
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

It could be done for some software, but some popular licenses like GPL don't allow additional restrictions on use.

If it were a big enough problem, could GPLv4 be published (perhaps with a clause to cover this and future laws) and products encouraged to migrate to it?

Re: Debian Statement on the Cyber Resilience Act

#55
post #45

Earlier quoted context omitted.

> Standardized food safety practices Food safety practices only became standardized after regulation was enacted. > pre-approved and comparatively trivial recipes That sounds like most software development. I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is ha…

"Food safety practices only became standardized after regulation was enacted." Because you actually can standardize them. Software isn't so simple. "> pre-approved and comparatively trivial recipes That sounds like most software development." Lol no that does not. Why wouldn't high school graduates or drop outs work in software instead of at fast food? The number of languages, frameworks, patterns, etc are much more…

> Because you actually can standardize them. Software isn't so simple.

It isn't simple due to choice, not due to the nature of software. Software is relatively simple compared to other meat-space engineering disciplines. Software engineering is an relatively immature engineering discipline, but it is implicated in enough safety critical systems these days that it is about time to start maturing.

It will be painful but I welcome more software regulatory standards, because it is necessary for our trade to mature.

Re: Debian Statement on the Cyber Resilience Act

#56

Earlier quoted context omitted.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

But if they don't include free/OSS projects, then commercial companies sponsoring FLOSS is an obvious way to launder liability, is it not?

Does not seem like it would, the company would still be responsible for their choice of open source software, that is how I would assume it would work at least.

Re: Debian Statement on the Cyber Resilience Act

#57

Earlier quoted context omitted.

It could be done for some software, but some popular licenses like GPL don't allow additional restrictions on use.

If it were a big enough problem, could GPLv4 be published (perhaps with a clause to cover this and future laws) and products encouraged to migrate to it?

Likely not. A license can not override legislation. Like creative-commons cannot be used to give away moral rights at least if not some of the copy rights too.

Re: Debian Statement on the Cyber Resilience Act

#58
post #25
post #12

[flagged]

> it’s called professional accountability Professional does for money, by definition. That doesn’t apply for most open source. RedHat employee contributing to Linux kernel is an exception, not a rule.

That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.

Re: Debian Statement on the Cyber Resilience Act

#59
post #2

Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.

> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields,

In other fields there is a direct relation between number of customers and liability.

But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation between number of customers and liability, and liability cannot be really priced-in.

Re: Debian Statement on the Cyber Resilience Act

#60
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

no common definition of free/open source software (such as the debian free software guidelines) would permit a use restriction like that
Post reply on HN