Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

61–70 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#61

Earlier quoted context omitted.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

But if they don't include free/OSS projects, then commercial companies sponsoring FLOSS is an obvious way to launder liability, is it not?

Sure, that is something that has to be avoided. The problem is that "commercial" is so broadly defined that basically everyone is covered, even non-profit organizations or single developers. A lot of those that want to release open-source stuff suddenly have to comply with all the requirements, which means having to spend a lot of time or money that non-commercial entities often don't have. This effectively kills nearly all of open-source in the EU. A sibling response mentions some improvements, but it still contains stuff like: (10a) "[...]Similarly, where the main contributors to free and open-source projects are developers employed by commercial entities and when such developers or the employer can exercise control as to which modifications are accepted in the code base, the project should generally be considered to be of a commercial nature."

Re: Debian Statement on the Cyber Resilience Act

#62

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

There's nothing wrong with it at first glance. It's high time they start adding some liability to these corporations because way too many of them just don't give a shit.

They just need to clarify some points. They need to explicitly make an exception for free and open source software developers. Because free and open source software development will be killed if they don't. Can you imagine getting sued because someone had problems with the free software you published on GitHub? The sustainability of free software development is questionable enough as it is. If publishing a project exposes me to that kind of risk I'll simply not publish.

Re: Debian Statement on the Cyber Resilience Act

#63
post #30

Earlier quoted context omitted.

There is some hope for individual developers in EP amended version https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COM... article 10c: > Developers contributing individually to free and open-source projects should not be subject to obligations pursuant to this Regulation. Actually it’s an improved version. Hopefully it will make it through consolidation with EC version.

Thank you for providing that, didn't knew about that amended version. This only includes individual developers though and if you are employed this is already a problem again: (10a) "[...]Similarly, where the main contributors to free and open-source projects are developers employed by commercial entities and when such developers or the employer can exercise control as to which modifications are accepted in the code b…

That is one of them, here is the second version with different amendedments by European Council: https://data.consilium.europa.eu/doc/document/ST-11726-2023-...

They are now hashing out a final consolidated version in a trialogue.

Re: Debian Statement on the Cyber Resilience Act

#64
post #25

Earlier quoted context omitted.

> it’s called professional accountability Professional does for money, by definition. That doesn’t apply for most open source. RedHat employee contributing to Linux kernel is an exception, not a rule.

That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.

> The majority of open source contributions are people making commits while at their paid jobs.

Do you have any evidence to back up this seemingly wildly speculative assertion?

And, even if it were true, "while at their paid jobs" doesn't mean at all they're getting paid as developers at all, let alone as developers on those projects that they are contributing to.

Re: Debian Statement on the Cyber Resilience Act

#65

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

> Our industry desperately needs better regulations, IMO.

Can you explain how you believe better regulations would improve software (assuming you're talking about software)?

Re: Debian Statement on the Cyber Resilience Act

#66

Earlier quoted context omitted.

That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.

> The majority of open source contributions are people making commits while at their paid jobs. Do you have any evidence to back up this seemingly wildly speculative assertion? And, even if it were true, "while at their paid jobs" doesn't mean at all they're getting paid as developers at all, let alone as developers on those projects that they are contributing to.

Here's one example:

> By studying the Linux Kernel, we document that commercial participation outweighs volunteer participation substantially

https://journals.aom.org/doi/abs/10.5465/AMPROC.2023.17240ab...

Also, empirically, many of the most popular open source projects are published by commercial companies, who hire developers to maintain them. If you review the commit history for these projects, you will see that many of them are, unsurprisingly, employees.

https://airtable.com/appiS6H4nkeXdyO89/shrATIy7RIOheo3gF/tbl...

There is inevitable overlap of commercial activity with popular open source software. Either it was a commercial piece of software to begin with, or because it is popular, it now has commercial value and garners commercial attention. Something like React falls into the former, and something like Linux falls into the latter.

There's a lot of community open source software too, but it trends towards smaller hobby projects with few users.

Re: Debian Statement on the Cyber Resilience Act

#67

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

Many of us are not "doing business" at all. Programming is my hobby. I cannot justify publishing my projects if doing that could get me sued. I already have enough liability at work.

Re: Debian Statement on the Cyber Resilience Act

#68
post #12

[flagged]

> It's called professional accountability.

Programming is not my profession though, it's my hobby. I chose to pursue another profession specifically so I could keep programming as a hobby. By all means hold the corporations accountable but please leave people like me out of it.

Re: Debian Statement on the Cyber Resilience Act

#69
post #16
post #5

Maybe change the link to the actual result, rather than 2nd-hand reporting? https://www.debian.org/vote/2023/vote_002#statistics (No matter how good LWN's original journalism is, this is just a news link that does little more than link to the source itself)

there is insightful discussion right on lwn. I think changing the URL is cutting that out.

[flagged]

Re: Debian Statement on the Cyber Resilience Act

#70
post #2

Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.

> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation b…

It can be priced in you just change the minimum price from $0 to how much liability would cost you.
Post reply on HN