Live data from Hacker News

Debian Statement on the Cyber Resilience Act

lwn.net

91–100 of 160 posts

Re: Debian Statement on the Cyber Resilience Act

#91
post #76

Earlier quoted context omitted.

If this isn’t done extremely carefully and with deep understanding of the industry, software will get 10X as expensive and innovation will halt due to liability concerns. It’ll turn into the aerospace industry where “if it hasn’t flown, it can’t fly.” This is among other things why we still burn leaded gas in small planes. Replacing it is easy, but the cost of certifying any kind of new design is insane. I’ve always…

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

As with anything, professional licensure can make things better or worse.

What tends to happen with professional licensing is that barriers to entry are erected, reducing the supply of labour and artificially increasing the price of labour for existing software engineers.

See cosmetology licenses for example: it is ludicrous that it is illegal to shampoo someone's hair in New York without completing a 1,000 hour course of study or having 5 years (!!!) of experience [1]. Yeah, sure, you shouldn't be spreading diseases or anything, but this is far, far beyond that.

A less ridiculous example: doctors. In the US, there is a hilariously restrictive number of residency places available, and this number is set by the government and backed by the American Medical Association. This inflates doctors' wages and makes it much harder to become a doctor than is necessary. There's a strong case for licensing doctors, but the particular way it's done in the US is obviously suboptimal.

My point is that yes, politicians writing regulations wrong will hurt the industry, but strangling the industry by limiting the number of software engineers can also cause harm.

I believe you know this already ("my proposal isn't perfect") so don't take this as an argument, I'm just making the possible downsides explicit and adding some detail.

[1]: https://dos.ny.gov/cosmetology

Re: Debian Statement on the Cyber Resilience Act

#92
post #91

Earlier quoted context omitted.

All of what you said is true. That is why I want the industry to self-regulate with professional licensure first . If we let politicians do it, they'll do it wrong. If we do it first, and push hard to have politicians adopt our system when they've decided that regulation will happen, then we have a chance that it won't be awful. As for consultants, yes, that could be a problem. However, I think professional licensure…

As with anything, professional licensure can make things better or worse. What tends to happen with professional licensing is that barriers to entry are erected, reducing the supply of labour and artificially increasing the price of labour for existing software engineers. See cosmetology licenses for example: it is ludicrous that it is illegal to shampoo someone's hair in New York without completing a 1,000 hour cour…

> I believe you know this already ("my proposal isn't perfect") so don't take this as an argument...

Yes, I do, and I agree. This could go horribly wrong.

Re: Debian Statement on the Cyber Resilience Act

#93

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

I don’t know what this act specifically covers, but if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down. That applies no matter my revenue stream size (or even if it was zero!) So I don’t find your argument particularly compelling. There is no inherent right to do business, if doing that business is harmful in some way. The E.U. rightly recognize…

> if I were a small business that sold (unintentionally) poisonous cookies to my neighbors, I ought very well to be shut down

That depends a lot on the circumstances. If a malicious, sophisticated, actor broke into your shop and poisoned your dough, which resulted in you selling poisonous cookies, should you be liable because your security systems weren't good enough to stop the poisoner?

Re: Debian Statement on the Cyber Resilience Act

#94
post #32

> It's very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout. Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303) Can someone explain to me what in the statement from Debian is "anarco-capitalist FUD"? I find it quite reasonable overall.

https://www.debian.org/vote/2023/vote_002?#proposerb is the person who posted that (and whose proposal came second).

Re: Debian Statement on the Cyber Resilience Act

#95
post #45

Earlier quoted context omitted.

"Food safety practices only became standardized after regulation was enacted." Because you actually can standardize them. Software isn't so simple. "> pre-approved and comparatively trivial recipes That sounds like most software development." Lol no that does not. Why wouldn't high school graduates or drop outs work in software instead of at fast food? The number of languages, frameworks, patterns, etc are much more…

> Because you actually can standardize them. Software isn't so simple. It isn't simple due to choice, not due to the nature of software. Software is relatively simple compared to other meat-space engineering disciplines. Software engineering is an relatively immature engineering discipline, but it is implicated in enough safety critical systems these days that it is about time to start maturing. It will be painful bu…

> Software is relatively simple compared to other meat-space engineering disciplines.

On what basis do you make this claim? If you do the same degree of optimization in software that is routinely applied in physical engineering disciplines that have some of most complex system dynamics problems, such as chemical engineering, the dynamics of software systems are qualitatively much more complex. We expect chemical engineering to design systems that asymptotically approach theoretically optimal efficiency along multiple dimensions. In software we rarely see anything approaching similar optimality except for small and exquisitely engineered components that are beyond the ken of most software engineers. In large software systems, the design problem is so complex that computational optimization to the degree we see in physical engineering is completely intractable, so similar approaches do not apply.

In chemical engineering, the measure of system complexity is roughly the size of the system of differential equations the govern the total dynamics of the system. Computers then solve for the system, which can be computationally intensive. We do this routinely, with some caveats. An optimal design is not computable but we can get asymptotically close via approximation.

In software engineering, the equivalent would be formal optimization and verification of the entire program. The complexity of doing this for non-trivial software is completely intractable. Software has so many degrees of freedom compared to physical systems that they aren’t even the same class of problem. It is arguable if it is even possible in theory to achieve similar degrees of design robustness and efficiency that we see in physical engineering systems.

Unlike physical engineering, where a computer takes a set of equations and constraints, crunches numbers, and produces an approximately optimal design, no such thing is possible in software.

Re: Debian Statement on the Cyber Resilience Act

#96

Earlier quoted context omitted.

Pretending for a second that I don't outright reject your premise (that there is no inherent right to do business)... You can't just label everything as "doing business" and then regulate it all. If I make something interesting and give everyone in the world the blueprints so they can make one themselves that's not "doing business".

IIRC in USA trademark legislation "doing business" has been defined by caselaw as encompassing acts which would harm another person's business such as giving things away for free. So, if one gives away LibreProgram and that takes significant market share away from ClosedProgram sellers then I am "doing business". Much as I ardently support FOSS (and similar: open hardware, say) I also think this idea has some use and…

This is very analogous to Wickard v Filbern [1] which basically says that intrastate commerce is interstate commerce if that commerce affects interstate commerce. It is very much absurd on it's face and a thinly veiled power grab by the federal government. It's like saying my breathing affects the air quality and so I must be cognizant of others when I breathe.

I don't find the idea useful to anyone but the unscrupulous. I find it very easy to draw the line. If I design something and publish it and people find it useful and put it to use that's clearly not commerce, that's just creativity.

[1] https://en.m.wikipedia.org/wiki/Wickard_v._Filburn

Re: Debian Statement on the Cyber Resilience Act

#97

It should be obvious to everyone by now that the European Union doesn't actually care about developers or small businesses at all.

Whats really funny is seeing the 180 flip. The EU was, and is depending on the post here, God's gift to men when it was crushing big bads like Apple and Google. Now it should be obvious to me that they hate the little guy? The 180 is a little funny, you gotta admit.

Re: Debian Statement on the Cyber Resilience Act

#98

Earlier quoted context omitted.

> Because you actually can standardize them. Software isn't so simple. It isn't simple due to choice, not due to the nature of software. Software is relatively simple compared to other meat-space engineering disciplines. Software engineering is an relatively immature engineering discipline, but it is implicated in enough safety critical systems these days that it is about time to start maturing. It will be painful bu…

> Software is relatively simple compared to other meat-space engineering disciplines. On what basis do you make this claim? If you do the same degree of optimization in software that is routinely applied in physical engineering disciplines that have some of most complex system dynamics problems, such as chemical engineering, the dynamics of software systems are qualitatively much more complex. We expect chemical engi…

I wasn't really thinking "complexity" in terms of formal academic problem scope, but more so "complexity" in the surface of how it interacts with the rest of the world, which is more along the lines of what would be relevant to a regulator.

A regulator doesn't really care about the internal complexities of an LLM and whether or not that is more difficult than cracking petroleum. They care more about how those things interact with the rest of the world. Software is pretty limited in how it interacts with the rest of the world.

Re: Debian Statement on the Cyber Resilience Act

#99
post #24

A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

> Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?

The entire point of the CRA is to make "manufacturers" liable for the quality of the software they produce, in a similar manner to how car manufactures were held liable for the Takata air bags. But who is the manufacturer. In the Takata case it was the car manufacturers the car owners held liable. This LWN comment spells how how difficult it is for software: https://lwn.net/Articles/956218/

One sentence from that highlights hints at the problem:

> the CRA's explicit statement that things qualify whether or they are provided gratis.

The CRA as it stands doesn't draw the line in a way that clearly exempts a bunch of high schoolers uploading their code to github, possibly because no one has figured out how to do it in a way that doesn't also give Google Chrome & Android a free pass.

To put it another way, you've asked an impossible question. You can't point to the faulty clause that exempts open source, because it doesn't exist.

Re: Debian Statement on the Cyber Resilience Act

#100
> CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA.

Isn't that the idea? If you can't innovate, litigate - see regulatory capture [1].

We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing. When the EU's digital infrastructure begins crumbling they'll change their tune.

[1] https://en.wikipedia.org/wiki/Regulatory_capture

Post reply on HN