Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

71–80 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#71
post #32

> It's very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout. Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303) Can someone explain to me what in the statement from Debian is "anarco-capitalist FUD"? I find it quite reasonable overall.

I also think Debian’s statement seems reasonable. I think the commenter is suggesting that solo developers should not be able to hide behind a “buyer beware” philosophy when they use and contribute to foss libraries. Meaning that it doesn’t matter if smaller development shops are forced to merge with larger vendors, if it is for the greater good. At least that’s how I read it.

Re: Debian Statement on the Cyber Resilience Act

#72
>CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Debian and other Linux distributions depend on their work.

If Debian depends on people's work so badly maybe they should pay for it.

Re: Debian Statement on the Cyber Resilience Act

#73

Earlier quoted context omitted.

> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation b…

It can be priced in you just change the minimum price from $0 to how much liability would cost you.

If every user has to pay the minimum price then the software would not be free software, by definition.

Re: Debian Statement on the Cyber Resilience Act

#74
post #25

Earlier quoted context omitted.

> it’s called professional accountability Professional does for money, by definition. That doesn’t apply for most open source. RedHat employee contributing to Linux kernel is an exception, not a rule.

That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.

First, I like how you included “popular” adjective. That alone disqualifies 99% of projects. These are the projects “hacked” by non-paid devs.

Second, some proof would be nice. I live in .net/nugget ecosystem and other than libraries backed by MS, most popular projects are not (at least ones I know of).

Re: Debian Statement on the Cyber Resilience Act

#75
post #45

Earlier quoted context omitted.

"Food safety practices only became standardized after regulation was enacted." Because you actually can standardize them. Software isn't so simple. "> pre-approved and comparatively trivial recipes That sounds like most software development." Lol no that does not. Why wouldn't high school graduates or drop outs work in software instead of at fast food? The number of languages, frameworks, patterns, etc are much more…

> Because you actually can standardize them. Software isn't so simple. It isn't simple due to choice, not due to the nature of software. Software is relatively simple compared to other meat-space engineering disciplines. Software engineering is an relatively immature engineering discipline, but it is implicated in enough safety critical systems these days that it is about time to start maturing. It will be painful bu…

It’s probable to make the case that some forms of software are simple enough to regulate. How many Supabase style crud apps have been made in our lifetimes (not shading Supabase, they’re just automating the commonalities here)

Re: Debian Statement on the Cyber Resilience Act

#76

I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns.

It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane.

I’ve always just been against any such regulation because I have zero confidence our technically ignorant politicians can do it well.

I also think it’s likely to be sabotaged by consultants and big tech monopolists who see an opportunity to lock out competitors or create gravy trains.

Re: Debian Statement on the Cyber Resilience Act

#77

Earlier quoted context omitted.

> Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, In other fields there is a direct relation between number of customers and liability. But if i offer free software and also offer commercial support for it, and because of that i would be liable to everyone who uses that software, not just to those who pay for commercial support, then there is no relation b…

It can be priced in you just change the minimum price from $0 to how much liability would cost you.

The minimum price for the software can't be changed. It's open source. Once it's out you can't undo it. You will have users paying $0 to use it for what amounts to forever.

Re: Debian Statement on the Cyber Resilience Act

#78
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

I'm using [1]. Page 15: > In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a…

Not forgetting of course that Debian is available commercially:

Vendors of Debian Installation Media https://www.debian.org/CD/vendors/

They are hardly Adobe, but all it takes is one zealous lawyer on a crusade to force an interpretation that Debian and Adobe are equivalent organisations when it comes to the commercial production of software.

pizza points out that Commercial Activity is apparently a bit more carefully defined, in the act, than simply “money changing hands”: https://lwn.net/Articles/956191/

I’ve never been a fan of the moral position that says certain laws only apply to commercial contracts. If two parties make an agreement (get married, have a child, adopt a cat, go fishing, etc.) then they ought to be held to that agreement. Whether or not money exchanged hands seems immaterial and considering whether it did or not, when trying to decide if someone acted in the right or in the wrong, feels dirty.

Re: Debian Statement on the Cyber Resilience Act

#79
post #2

Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some "flexibility" between the laws and how they happen to be applied.

So why pile on even more? Terrible justification tbh. It’s hard for a small business or indie developer. The odds are against you.
Post reply on HN