Earlier quoted context omitted.
Saying let the courts decide when there is massive ambiguity for the small projects and developers just means that many of us (I know I will) will region block the EU until some one else deals with the court system and provides clarity for the rest us. It is way, way better for legislators to provide intent and clarity then to make things uncertain and ambiguous for the courts to decide. If they truly aren't going to…
I don't see a reason to do this (region blocking whole EU). The legislation has a very similar enforcement to GDPR – did you get a 15M USD fine for Google Analytics on your blog? What's similar is that: 1. There will be authorities overseeing this. Court action will not be the first step (Europe is not a litigious place as opposed to some other jurisdictions). 2. First step would be a corrective action to "Ensure tha…
No cyber resilience without open source sustainability
61–70 of 74 posts
Re: No cyber resilience without open source sustainability
#62German here, trying not to sound too polemic: Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, this looks so much like an attack by enterprises against startup competition who cannot afford legal insecurities/legal departments/security certifications, that I can barely understand such a governmental interference without thinking about bad actors.
In some domains this is widely understood: I myself have been heavily criticised for having released a cryptographic library, even though I took every precaution I possibly could. While I do think much of this criticism was unfounded knee-jerk reactions, the idea behind it, that it is serious stuff, is actually good.
Thing is, security products aren’t the only "serious stuff" out there. Anything that parses untrusted input (any reader, any network server…) can have serious vulnerabilities, and as such is kind of serious too. Thus, my opinion here is that pretty much any published software should follow this regulation, even if it isn’t bound by it.
Re: No cyber resilience without open source sustainability
#63Earlier quoted context omitted.
Does Nginx assert it is fit for commercial activity? If it does, then yes they should be required to meet their promises and keep it fit for commercial purposes. If it does not, then why the hell are you using it for commercial purposes? They told you it is not fit for that purpose. You do not get to demand they meet your needs because it is convenient for you cheap out by using inadequate dependencys.
As I wrote elsewhere in the thread, if EU didn't word it the way they did, most OSS projects would simply slap "not fit for commercial purposes" in the README next day after CRA became law with a smug smile. Regarding "cheaping out", I expect EU businesses to begin demanding that every dependency in their SBOM is CRA-compliant in some due time. This will most likely mean paying money. But I disagree on "by using inad…
Pretty much all software already has this in the license/EULA since forever. It's just worded slightly differently as "there's no guarantee of fitness for any purpose" and disclaimer of all warranties.
Re: No cyber resilience without open source sustainability
#64Re: No cyber resilience without open source sustainability
#65Earlier quoted context omitted.
I don't see a reason to do this (region blocking whole EU). The legislation has a very similar enforcement to GDPR – did you get a 15M USD fine for Google Analytics on your blog? What's similar is that: 1. There will be authorities overseeing this. Court action will not be the first step (Europe is not a litigious place as opposed to some other jurisdictions). 2. First step would be a corrective action to "Ensure tha…
I did not get 15M USD fine for Google Analytics on my blog. Instead, I am working for state agencies that are shy of using even locally installed Mamoto for web analytics, out of fear to collect too much PIIs because of GDPR. It is a daily tax on my mental sanity and a real problem for fellow citizens because of worsened service. GDPR had two effects on the industry in EU: 1. Chilling effect. None wants to do things…
Regarding the ad hominem part, I invite you to watch https://www.youtube.com/watch?v=Gv2I7qTux7g to understand why I think our industry needs to elevate the level of our craft. And also please take a look at the actual requirements CRA puts on devs in https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-... (pages 2 and 3 – yes, just those two pages* plus requirements on documentation on page 8, which could be a bit more annoying than the requirements on pp. 2 and 3). I hope you will find them reasonable for the most part.
Regarding GDPR, I am indeed sad that so many people interpret it incorrectly. This happens in part due to the influence of various groups, as you say. I invite you to read the blog of https://noyb.eu/en to understand the spirit of GDPR (indeed, there is a thing called "data minimization" that could be the reason you find it difficult to collect more data without a solid justification; in a fun twist, §1(3)(e) of the CRA annex also mentions data minimization) and see that the progress is made slowly yet steadily. If you noticed big websites recently show the option to deny tracking cookies directly instead of "manage cookies", you got these folks to thank ( https://noyb.eu/en/where-did-all-reject-buttons-come ). BTW, I donate to them and think they are doing awesome work.
* unless you are doing "serious stuff" (TM) as described on pages 5 and 6.
Re: No cyber resilience without open source sustainability
#66Earlier quoted context omitted.
I don't see a reason to do this (region blocking whole EU). The legislation has a very similar enforcement to GDPR – did you get a 15M USD fine for Google Analytics on your blog? What's similar is that: 1. There will be authorities overseeing this. Court action will not be the first step (Europe is not a litigious place as opposed to some other jurisdictions). 2. First step would be a corrective action to "Ensure tha…
I did not get 15M USD fine for Google Analytics on my blog. Instead, I am working for state agencies that are shy of using even locally installed Mamoto for web analytics, out of fear to collect too much PIIs because of GDPR. It is a daily tax on my mental sanity and a real problem for fellow citizens because of worsened service. GDPR had two effects on the industry in EU: 1. Chilling effect. None wants to do things…
No. Most GDPR threads on this website are full of speculation or beliefs that are backed by nothing. Most comment authors would not be able to provide a source to their claims, either with a citation from the legal text, interpretations (eg. From the EDPB, a DPA, or even the GDPRHub stuff), or actual cases. They don’t even make the effort to understand its principles (data minimization, transparency). And I don’t see how you can say that EU directives and regulations are poorly written when you don’t even take the time to read the one that may have an impact on your work. I know developpers here are not lawyers, but neither am I-but I still read the thing (and ePrivacy) so I actually know my rights, and can ask somewhat relevant questions wrt. data protection in my work.
Re: No cyber resilience without open source sustainability
#67Earlier quoted context omitted.
I've seen many things in my life I'd gladly unsee, including corp IT devs putting programs with "SNAPSHOT" (unstable) dependencies in production. But just merely having a corp use your software would not place the CRA burden on you. Your project needs to make such an impression. The most negative outcome of this legislation that I can see is that OS projects like Nix, Debian and others will start aggressively pruning…
I see you are very active on this topic. I have a question regarding an interesting point you're making: > But just merely having a corp use your software would not place the CRA burden on you. Your project needs to make such an impression. What does "needs to make such an impression" mean. Sloppy code and PRs with Fix, Fix, Fix, Another Fix commits are hobby projects? And having some integrity implies "you make an i…
Regarding the commercial activity: I found the screenshot of a 3-part test from a recent Eclipse call and I hope it's OK to post it ( https://imgur.com/a/70a6cQt ). I think it's important to understand that in a multi-part test, you typically need to seriously hit a few points to "pass" the test. Some examples of what I would consider passing each point (but not necessarily the whole test):
1. Rust with its 6-week release cadence will quite likely pass the 1 part.
2. Nginx, k8s, Ubuntu LTS will quite likely pass the part 2 of the test.
3. A project like Eclipse 4diac ( https://projects.eclipse.org/projects/iot.4diac ) would quite likely pass the 3rd part of the test. That's the part of the test that worries Github and others, because receiving money and significant contributions from corporate will contribute to scoring high on this point.
But then, Eclipse 4diac could claim that it's mainly an R&D project and thus not passing the part 2 of the test. And even part 1 of the test would be hard to establish with barely 1 release a year.
Re: No cyber resilience without open source sustainability
#68Earlier quoted context omitted.
As I wrote elsewhere in the thread, if EU didn't word it the way they did, most OSS projects would simply slap "not fit for commercial purposes" in the README next day after CRA became law with a smug smile. Regarding "cheaping out", I expect EU businesses to begin demanding that every dependency in their SBOM is CRA-compliant in some due time. This will most likely mean paying money. But I disagree on "by using inad…
>As I wrote elsewhere in the thread, if EU didn't word it the way they did, most OSS projects would simply slap "not fit for commercial purposes" in the README next day after CRA became law with a smug smile. So? Seems an amazingly cut and dry case for the EU to go after any business using software with that clause (directly or indirectly). Isn't that exactly the goal here? To prevent businesses from using this softw…
I hope you'd agree that we'd all be laughing right now if EU instead mandated businesses to use only commercial-grade software, joking about how are they going to run cloud VMs without the Linux kernel, GCC etc. EU fully understands that the world of software is thoroughly built on OSS, whether we like it or not.
It's also not a secret that many companies rely on OSS as a springboard for adoption, e.g. MongoDB. EU does not want to allow Mongo the company to avoid compliance merely by saying that their product is open-source(ish). And by the way, the regulation would require software to come with a secure by default configuration (page 2 of https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-... ), wink wink ( https://snyk.io/blog/mongodb-hack-and-secure-defaults/ ).
Re: No cyber resilience without open source sustainability
#69Earlier quoted context omitted.
> I find the criteria for inclusion a bit weird: why would any given project should be the object of regulation? The way I see it, they should rather focus on the transaction. I asked them directly. There is no direct reason whatsoever. They just rushed it and fucked up. Nobody ever thought about FLOSS besides vaguely excluding it in the "noncommercial" way. There were more landmines in the original draft. Like the r…
I'm pretty sure at least some of the lobbyists who wrote this were aware of the negative effects on FLOSS software.
Related timestamp: https://youtu.be/AmsM5_5QO5A?t=1528
Re: No cyber resilience without open source sustainability
#70Earlier quoted context omitted.
I did not get 15M USD fine for Google Analytics on my blog. Instead, I am working for state agencies that are shy of using even locally installed Mamoto for web analytics, out of fear to collect too much PIIs because of GDPR. It is a daily tax on my mental sanity and a real problem for fellow citizens because of worsened service. GDPR had two effects on the industry in EU: 1. Chilling effect. None wants to do things…
All right, now that someone downvoted you (not me), I feel a mild obligation to respond. Regarding the ad hominem part, I invite you to watch https://www.youtube.com/watch?v=Gv2I7qTux7g to understand why I think our industry needs to elevate the level of our craft. And also please take a look at the actual requirements CRA puts on devs in https://eur-lex.europa.eu/resource.html?uri=cellar:864f472b-... (pages 2 and 3…
And the "if applicable" part is kind of vague. For just one example, is it applicable for a database to have built in support for encryption at rest? Or is it sufficient to depend on the user setting up an encrypted filesystem? 1.3 is a reasonable list for a complete system, but less so for individual components. Some of those items, such as authentication, event monitoring, and high availability, are frequently "enterprise" features for open core projects. I'm not sure what the impact of that would be. Maybe companies will start including those in the opens offerings, or maybe we'll see those projects become completely proprietary.
And a lot of open source projects do the "serious stuff" described on pages 5 and 6. Some of which accept donations but have very small teams.
I don't think putting this burden entirely on the developers of open source projects is the right way to do it. I agree with the spirit of this, but think the implementation has some serious problems. I feel much the same way about GDPR.