[HN Gopher] Save Open Source /-/ the Impending Tragedy of the Cy...
___________________________________________________________________
Save Open Source /-/ the Impending Tragedy of the Cyber Resilience
Act
Author : pseudotrash
Score : 89 points
Date : 2023-07-19 08:22 UTC (14 hours ago)
(HTM) web link (news.apache.org)
(TXT) w3m dump (news.apache.org)
| joshuaissac wrote:
| > EU lawmakers also realise that open source is often 95% or more
| of the software stack on which a typical European Small and
| Medium Enterprises (SME) operates or is licenced.
|
| > it is that entire stack which the SME, as the party that places
| it on the market, is liable for.
|
| > policy makers assume that these process improvements [...] are
| costly; on the order of 25% more in cost overhead
|
| > for most European SMEs this extra effort over the full 100%
| would be several times their engineering effort and hence would
| not be feasible
|
| > certifying the 5 or 10% of the code they build on top of the
| open source stack is a lot more achievable.
|
| From what I understand of what the Apache Foundation has written,
| what the CRA does is to take the certification obligation from
| the entity that takes the open source products and profits from
| it, and push it on to the entity that produced the open source
| software.
|
| So if I have a business that uses a tech stack built on top of
| Rocky Linux, for example, I only have to certify the part of the
| stack that I built, and I can push the liability for the rest of
| the stack to the Rocky Linux vendor, even if I never bought a
| support contract.
| michaelmrose wrote:
| What's stopping Rocky Linux from stating that its products are
| not certified for usage in Europe and having a third party that
| specializes in certification handle that aspect for a
| percentage of revenue from support contracts for European
| markets with the net effect being that near zero such
| foundations end up based in Europe and European companies
| experience it as licenses being 10% more expensive with smaller
| set products available.
|
| For open source libraries which presently are 100% free have
| the certification company charge companies who want to use
| those libraries to audit and certify them and pass a
| substantial amount of the cost on to the authors of those
| libraries.
| rad_gruchalski wrote:
| If the legislator is so concerned that some random open
| source project with enough luck to become a foundation of
| something the EU relies on may be used to weaken its
| security... then why not just ... I don't know ... not use it
| and develop their own? It doesn't fit in my brain.
| marcosdumay wrote:
| Well, the blog repeats and clarify that this is indeed the
| legislators idea, and they won't change their minds.
|
| It's not clear to me how much knowledge the author has about
| the legislators opinion, but it's a very damning piece of text.
|
| Pushing for the obligatory enforcement of unknown rules,
| extending the corporations embodiment into every action of
| their employees, and granting legislative power to private
| standard bodies are all very anti-democratic decisions.
| bbarnett wrote:
| _Pushing for the obligatory enforcement of unknown rules,
| extending the corporations embodiment into every action of
| their employees, and granting legislative power to private
| standard bodies are all very anti-democratic decisions_
|
| I agree. But at the same time, this might indicate something.
|
| Frustration.
|
| Try to build a bridge, a building, a factory, and see how far
| one gets, without a lot of clear cut rules being followed.
|
| Then look at ... say, Debian. Where every _single piece of
| software_ follows guidelines, or it 's in non-free.
|
| Then look at the node ecosystem, where no one audits
| anything, or even cares if they're literally infringing, who
| wrote it, etc.
|
| No one even checks, if any of the 25,000 packages, have just
| been replaced by malware, or if the license has changed.
|
| And beyond _that_ , we have endless orgs running code on
| deprecated compilers (eg php5), with no security updates.
|
| These things are _absurd_ , but we accept it, merely because
| prefer greed over security, safety, sustainability of code.
|
| So, some of it may be frustration. I'm frustrated with it!
|
| It doesn't make it right, but....
| PaulDavisThe1st wrote:
| > Then look at ... say, Debian. Where every single piece of
| software follows guidelines, or it's in non-free.
|
| Debian rules are not about software functionality or
| implementation.
| marcosdumay wrote:
| Well, reacting to an emotion is a pretty bad thing for a
| legislative body to do. What is it, some tribal government
| where a trio of elders command everybody?
|
| I do agree that the situation is dire, and we should do
| something. Up to now, that something is almost completely
| on the "research" area and almost not on the "legislate"
| area, but some exceptions may already apply. Acting on
| those exceptions would be a good thing, but this is really
| not some "hey, this small action is proven to help" kind of
| law. Laws like that one always lead to less secure software
| and broken markets.
|
| And anyway, no legislative body anywhere should even think
| on doing any of the things I listed on that paragraph. Any
| of that is already enough to dismiss the entire thing (IMO,
| it's enough to dismiss the entire body too and call for
| replacement) even if the actual rules would improve
| software security.
| veave wrote:
| [flagged]
| flangola7 wrote:
| Are you kidding? HN hates regulations of any kind.
| Dah00n wrote:
| Go back to Reddit.
| jauntywundrkind wrote:
| This definitely brings out the Accelerationist in me.
|
| Keep making more changes, more regulation Europe. It'll make an
| interesting story one day. But only after extreme turmoil &
| chaos. After the dust settles.
|
| And I don't think these attempts to regulate the planet, to
| impose your will & shift so much burden onto those doing & making
| & creating is going to work as you hope. I don't think it will
| give your societies the safety you think you can demand, and I
| think the difficulties you are creating are going to cause great
| suffering for your nations.
|
| I respect your desire for a better more sensible world but
| forever more layering in more and more constraints & burdens on
| the active agents in your systems has such unfathomable costs.
|
| And you don't have the right. You don't get to tell the entire
| world how to behave. There are impossible asks, utterly
| ridiculous, and you make them against everyone. You already have
| your foot on the floor, speeding us so quickly to breaking.
| notquitehuman wrote:
| I don't think IBM could have come up with a better marketing plan
| for Enterprise Open Source. Unless this is exactly that.
| Dah00n wrote:
| Ever law like this is the doom of XYZ and a week later it isn't.
| Just like this one.
| racked wrote:
| They all ought to band together and block EU countries from
| downloading their software until the regulation is changed. Let's
| see what happens.
| Dah00n wrote:
| Using open source as a political weapon is much worse than
| this. Banning patches from Russian developers have already been
| seen. It is not the spirit most open source software developers
| would want to go, I'm sure. At least I would never lift a
| finger to patch anything that took part in something like you
| mentioned or as insane as sanctioning russian developers (or
| some other country/race/gender/etc.)
|
| It is a slippery slope and in no time it would spread to
| banning Chinese patches and developers, with people getting
| riled up by people from .gov mails and next up Muslims and on
| and on.
|
| Besides, show me one of those "all" you mentioned that has the
| right to do so. Do you think open source is American? It could
| just as well be they all ban the US. Just... don't.
| NegativeK wrote:
| What will you tell open source developers who live in the EU?
| orclev wrote:
| Don't need to actually block EU downloads, just state that no
| open source software is certified for commercial usage in the
| EU. Any company that ignores that is now in violation of this
| law and that's their problem. The EU will need to decide if
| they want to allow their businesses to continue benefiting
| from open source software or fix this law.
|
| The interesting question is really what happens when
| commercial software companies outside the EU that use open
| source libraries decide they don't want to deal with this
| headache _also_ start refusing to certify their software for
| use in the EU and stop doing business there.
| Dah00n wrote:
| That's not possible with GPL etc. code. Especially since
| most repos are not even in the US and you can't change the
| license.
| orclev wrote:
| Why not? Nothing in the GPL says you need to certify your
| code for commercial usage in the EU.
|
| Edit: In fact, reading the GPL it looks like it might
| implicitly already preclude usage in the EU under this
| law. There's this section right here:
| 11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE
| IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED
| BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN
| WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
| PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND,
| EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED
| TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
| FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE
| QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU.
| SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST
| OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
| 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR
| AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY
| OTHER PARTY WHO MAY MODIFY AND/OR REDISTRIBUTE THE
| PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES,
| INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR
| CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY
| TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
| DATA OR DATA BEING RENDERED INACCURATE OR LOSSES
| SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE
| PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH
| HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY
| OF SUCH DAMAGES.
|
| That seems to suggest that any cost associated with
| certifying for commercial usage in the EU would fall on
| the company using the GPL licensed code, not the
| developers of the licensed code. Certifying the code for
| commercial usage under the EU law I would argue would be
| a warranty, one explicitly declaimed already by the GPL.
| grobmeier wrote:
| Not sure what he would tell me, but I would go on vacation
| for some time.
| rad_gruchalski wrote:
| Time to start planning because the draft has been accepted.
| pxeger1 wrote:
| From what I can tell, it sounds like the lawmakers have the right
| intentions here. So I'm not too worried that this law will get
| passed in its current problematic state. Am I naive?
| rad_gruchalski wrote:
| Are you naive? Difficult to judge. Who knows, maybe they have a
| good intent. The execution is bad. This will put so much legal
| burden on anyone who contributes AND accepts contributions.
| This isn't going to strengthen OSS in the EU. When this comes
| into effect, any company attempting to contribute back will
| have to answer a question: do we want to throw those devs under
| the legislative bus?
|
| From the other perspective: am I going to accept a contribution
| from anyone who may be remotely connected to any company in the
| EU? Well, nope. I don't want to deal with that stuff in my
| private time just because some EU bureaucrat decided that
| accepting a contribution from a corporate contributor is now
| legally speaking a "commercial activity".
|
| They will now hold a huge fat stick but there's no carrot. So
| when it's a commercial activity, can I have benefits like any
| other commercial entity? Say, claim VAT back?
| PartiallyTyped wrote:
| My first thought in reading this is that it guts PostgreSQL and
| similar projects, and proprietary vendors like Oracle will make
| bank.
|
| Unless EU itself employs developers to contribute to OSS and
| ensure verification, this will only do harm.
| EMIRELADERO wrote:
| What is it about this law that will make FOSS mantainers'
| lives unduly difficult? Are the requirement ridiculous? To me
| it just seems like they need to be more proactive and careful
| with publishing releases if they're aware of CVEs affecting
| the component.
| AugustoCAS wrote:
| [dead]
| rad_gruchalski wrote:
| The CRA draft has been accepted. I submitted this a couple of
| hours ago: https://news.ycombinator.com/item?id=36790228.
| whartung wrote:
| > And it is that entire stack which the SME, as the party that
| places it on the market, is liable for.
|
| This has been a nit of mine as others cry out how I'm a "NIH"
| curmudgeon for not importing some library because I need, oh,
| "upshiftFirstCharacter" or some other thing.
|
| Like many, I do incorporate other projects into my own. But,
| also, I tend to just write my own stuff for "little things", even
| when they creep into "big" things, as many are wont to do.
|
| And the canard I hoist when challenged on this stuff, I simply
| point out "We may only being using a a small piece of it, but
| we're responsible for all of it." And point to the trail of jars
| that simple utility is dragging with it.
|
| There's a lot of pressure for things to have fewer and fewer
| dependencies. As a Java developer, I strive to rely as much as
| practical on the JDK and the utilities they provide.
|
| My code is as imperfect as anyone else's. But I watch threads on
| forums about "how can I do XXX" and what they really mean is
| "what package do I need to do XXX" rather than just, you know,
| "doing it". It's a spectrum of complexity, but if I can get away
| with a simple BlockingQueue instead of loading in some off the
| shelf behemoth for a simple twixt threads queue, I'm going to do
| that. Use the stuff I have until it fails before I drag and drop
| some onerous jar and a boat of dependencies to do the same thing.
| "This has monitoring and plugins and ...!" "Do we need that?"
| "...Maybe?" "Well lets wait and see, shall we?"
| michaelmrose wrote:
| What are the implications if an open source library is simply
| maintained in the US and consumed in the EU?
|
| Does the EU company then need to handle the details of certifying
| it? Do you end up with an entire industry around companies
| "importing" open source libraries into essentially a library of
| usable verified things that companies are then allowed to
| consume?
|
| Does this end up with EU companies using out of date things
| because it requires certification? How do you avoid it either
| becoming a rubber stamp with a fee attached or EU industry being
| behind insofar as its ability to use technology.
|
| EG a US developer can use A B or C whereas EU dev can only use a
| 2 year old version of A which may be less secure for lack of
| improvements on further versions rather than more secure.
| Essentially a certified predictable level of inferiority.
|
| > Some of the obligations are virtually impossible to meet: for
| example there is an obligation to "deliver a product without
| known exploitable vulnerabilities".
|
| Is it possible we actually CAN meet something a lot closer to
| that? There isn't infinite ways to use something and if the use
| is novel and out of scope of the library itself wouldn't that be
| something out of scope and part of the companies job to certify?
|
| Consider languages and technology that obviate or drastically
| decrease entire classes of bugs from memory safe langues, to
| comprehensive testing, to static analysis, to more secure OS like
| seL4.
| marcosdumay wrote:
| > EG a US developer can use A B or C whereas EU dev can only
| use a 2 year old version of A which may be less secure for lack
| of improvements on further versions rather than more secure.
|
| That has been the natural consequence of every past effort to
| legislate security all over the world.
|
| The fact that this one seems less attached to reality than the
| normal only reinforces that, so I'd expecting nothing else from
| it.
___________________________________________________________________
(page generated 2023-07-19 23:02 UTC)