Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

81–90 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#81

Earlier quoted context omitted.

> Because you actually can standardize them. Software isn't so simple. It isn't simple due to choice, not due to the nature of software. Software is relatively simple compared to other meat-space engineering disciplines. Software engineering is an relatively immature engineering discipline, but it is implicated in enough safety critical systems these days that it is about time to start maturing. It will be painful bu…

It’s probable to make the case that some forms of software are simple enough to regulate. How many Supabase style crud apps have been made in our lifetimes (not shading Supabase, they’re just automating the commonalities here)

All software is simple enough to regulate. You don't have to micromanage every single line someone writes to regulate something. The way most professional regulations work is that someone writes down the safety practices that should be done, and then the law requires people to do those things.

For example, one might require some software to undergo various degrees of planning, testing, analysis, support, documentation, etc.

Right now, the amount of planning, testing, analysis, support, and documentation required by law is generally zero. This might be fine for someone's hobby project, but it is not okay for software that human lives depend on.

Re: Debian Statement on the Cyber Resilience Act

#82
post #76

I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

All of what you said is true.

That is why I want the industry to self-regulate with professional licensure first.

If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful.

As for consultants, yes, that could be a problem. However, I think professional licensure would minimize that because requiring a Professional Software Engineer (PSWE) on a project means having someone there for the long term, dedicated to the project, which is antithetical to consultants game plan to run either short projects or many projects at once.

As for Big Tech monopolists, yes that could be a problem. However, I think professional licensure, with a Code of Ethics, would actually give the PSWE at such companies the ability to say no to such monopolization. And they would, if we could actually threaten loss of license.

So you are correct that my proposal isn't perfect, but I do think it minimizes the risk of bad things happening among the others.

Re: Debian Statement on the Cyber Resilience Act

#83
post #74

Earlier quoted context omitted.

That is not true. The majority of open source contributions to popular projects are people making commits while at their paid jobs.

First, I like how you included “popular” adjective. That alone disqualifies 99% of projects. These are the projects “hacked” by non-paid devs. Second, some proof would be nice. I live in .net/nugget ecosystem and other than libraries backed by MS, most popular projects are not (at least ones I know of).

The 'popular' qualifier is important, because these are the ones that important infrastructure are reliant on. These are the ones that should meet professional standards. And by most accounts, they are being developed by professionals who should be subject to such expectations.

I think it's okay if a hobby project is unsuitable or unreliable for important tasks. They should also not be used in critical infrastructure or commercial products.

Re: Debian Statement on the Cyber Resilience Act

#84

What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn't... Our industry desperately needs better regulations, IMO.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

Get ready for the next evolution of “this website is not available in your country” except it’ll be GitHub repos, huggingface models, etc. The internet became worse with the gdpr/cookie warning stuff and this will continue that trend.

Insane tbh. EU is all about safety to the extreme and it’s nauseating. Pretty soon you won’t be able to fart there without getting a permit and sign off from some kind of council.

Re: Debian Statement on the Cyber Resilience Act

#85
post #76

I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].) There is a better way [2], but I don't know how we would convince politicians that there is a better way. [1]: https://news.ycombinator.com/item?id=38788919 [2]: https://gavinhoward.com/2023/11/how-to-fund-foss-save-it-fro...

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

I think that is an odd comparison. Yes, there's parts of an industry like aerospace where innovation is slow, but then again if airplanes were build like web apps they'd get twice as heavy every year and fall out of the sky once per day.

Compared to the relatively high engineering standards and slow but at least continuous improvements in actual engineering disciplines, software is built so badly most of it should never see the light of day. If most machines we build were as insecure and crappy as software we'd have brought the Code of Hammurabi back already.

Re: Debian Statement on the Cyber Resilience Act

#86
post #76

Earlier quoted context omitted.

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

My problem with self-regulation is that time for that was 10 years ago. Maybe 20 is too much, but certainly over a decade ago... The industry had their change, they fully squandered it. Now it is time for the whip.

Re: Debian Statement on the Cyber Resilience Act

#87

Earlier quoted context omitted.

Big parts of the legislation are good and long overdue. The big problem is that this effectively also includes many free/open-source software projects, as the definition for what constitutes "commercial" or "commercial-grade" is very broad. You host a FOSS library on Github that can/is used by others? Congrats, you now have to fulfil all requirements. Look for "Update on the European Cyber Resilience Act" by the Ecli…

But if they don't include free/OSS projects, then commercial companies sponsoring FLOSS is an obvious way to launder liability, is it not?

Sounds like a feature rather than a bug!

Re: Debian Statement on the Cyber Resilience Act

#88
post #86

Earlier quoted context omitted.

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

My problem with self-regulation is that time for that was 10 years ago. Maybe 20 is too much, but certainly over a decade ago... The industry had their change, they fully squandered it. Now it is time for the whip.

And I'm afraid I agree with you.

I just hope it doesn't destroy the nice things.

If it does, well, this is why we can't have nice things.

Re: Debian Statement on the Cyber Resilience Act

#89
post #49

Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?

I'm working on licenses that do that; they become null and void if there is any duty.

Of course, an outside agreement can establish such duties.

Re: Debian Statement on the Cyber Resilience Act

#90

Earlier quoted context omitted.

> Standardized food safety practices Food safety practices only became standardized after regulation was enacted. > pre-approved and comparatively trivial recipes That sounds like most software development. I think you are unwittingly making the case that software development is a lot like food production. Software development is only beginning to get regulated because it is only now reaching the level where it is ha…

Knuth’s code has bugs. NASA’s code has bugs. I would like to think that someday our profession might be able to achieve high enough quality to survive with liability, but today nobody is close to that at all.

I think that liability shouldn't require perfection, just close enough as long as the criteria is objective.

I personally think that any criteria that SQLite and Curl can't pass is too strict.

Post reply on HN