Earlier quoted context omitted.
Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…
But if they don't include free/OSS projects, then commercial companies sponsoring FLOSS is an obvious way to launder liability, is it not?
Debian Statement on the Cyber Resilience Act
61–70 of 160 posts
Re: Debian Statement on the Cyber Resilience Act
#62What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
They just need to clarify some points. They need to explicitly make an exception for free and open source software developers. Because free and open source software development will be killed if they don't. Can you imagine getting sued because someone had problems with the free software you published on GitHub? The sustainability of free software development is questionable enough as it is. If publishing a project exposes me to that kind of risk I'll simply not publish.
Re: Debian Statement on the Cyber Resilience Act
#63Earlier quoted context omitted.
There is some hope for individual developers in EP amended version https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COM... article 10c: > Developers contributing individually to free and open-source projects should not be subject to obligations pursuant to this Regulation. Actually it’s an improved version. Hopefully it will make it through consolidation with EC version.
Thank you for providing that, didn't knew about that amended version. This only includes individual developers though and if you are employed this is already a problem again: (10a) "[...]Similarly, where the main contributors to free and open-source projects are developers employed by commercial entities and when such developers or the employer can exercise control as to which modifications are accepted in the code b…
They are now hashing out a final consolidated version in a trialogue.
Re: Debian Statement on the Cyber Resilience Act
#64Earlier quoted context omitted.
> it’s called professional accountability Professional does for money, by definition. That doesn’t apply for most open source. RedHat employee contributing to Linux kernel is an exception, not a rule.
That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.
Do you have any evidence to back up this seemingly wildly speculative assertion?
And, even if it were true, "while at their paid jobs" doesn't mean at all they're getting paid as developers at all, let alone as developers on those projects that they are contributing to.
Re: Debian Statement on the Cyber Resilience Act
#65What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.
Can you explain how you believe better regulations would improve software (assuming you're talking about software)?
Re: Debian Statement on the Cyber Resilience Act
#66Earlier quoted context omitted.
That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.
> The majority of open source contributions are people making commits while at their paid jobs. Do you have any evidence to back up this seemingly wildly speculative assertion? And, even if it were true, "while at their paid jobs" doesn't mean at all they're getting paid as developers at all, let alone as developers on those projects that they are contributing to.
> By studying the Linux Kernel, we document that commercial participation outweighs volunteer participation substantially
https://journals.aom.org/doi/abs/10.5465/AMPROC.2023.17240ab...
Also, empirically, many of the most popular open source projects are published by commercial companies, who hire developers to maintain them. If you review the commit history for these projects, you will see that many of them are, unsurprisingly, employees.
https://airtable.com/appiS6H4nkeXdyO89/shrATIy7RIOheo3gF/tbl...
There is inevitable overlap of commercial activity with popular open source software. Either it was a commercial piece of software to begin with, or because it is popular, it now has commercial value and garners commercial attention. Something like React falls into the former, and something like Linux falls into the latter.
There's a lot of community open source software too, but it trends towards smaller hobby projects with few users.
Re: Debian Statement on the Cyber Resilience Act
#67It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.
I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…
Re: Debian Statement on the Cyber Resilience Act
#68[flagged]
Programming is not my profession though, it's my hobby. I chose to pursue another profession specifically so I could keep programming as a hobby. By all means hold the corporations accountable but please leave people like me out of it.
Re: Debian Statement on the Cyber Resilience Act
#69Maybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)
there is insightful discussion right on lwn. I think changing the URL is cutting that out.
Re: Debian Statement on the Cyber Resilience Act
#70Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.
> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation b…