[HN Gopher] Filezilla blocks download for EU users
       ___________________________________________________________________
        
       Filezilla blocks download for EU users
        
       Author : pseudotrash
       Score  : 63 points
       Date   : 2023-07-19 09:18 UTC (13 hours ago)
        
 (HTM) web link (filezilla-project.org)
 (TXT) w3m dump (filezilla-project.org)
        
       | petre wrote:
       | We'll just get it off torrents with malware embedded. Very cyber
       | resilient.
        
       | antiloper wrote:
       | [flagged]
        
         | pwdisswordfishc wrote:
         | You're confusing EU for Facebook.
        
         | aredox wrote:
         | Are you talking about the EU or all the GAFA you all work
         | for/with/dream to join/exit to?
        
           | perceptronas wrote:
           | Didn't we read about EU trying to put backdoors in E2E
           | messaging apps like two months ago? I think parent comment
           | has at least some truth to the claims
        
             | aredox wrote:
             | Ha, you mean the backdoors (and frontdoors) the GAFA and
             | many other top players in the web ecosystem already have
             | everywhere, so much that the US government just has to buy
             | commercially available data to spy on its citizens -
             | without having to change laws to do it by itself?
        
       | 2Gkashmiri wrote:
       | is there a explainer of what the legislation is supposed to do
       | and how does it harm foss?
       | 
       | i have had trouble with understanding the push for EVERYONE doing
       | https even in localhost because "security". boo.
       | 
       | i live in a place where by law ISPs need to have DPI. they can
       | access any communication regardless of SSL or https or anything
       | in between so why should i bother with the added nonsense of
       | "much security" when it is not supposed to even work?
       | 
       | i understand there are attempts to make https to be as
       | transparent when it works but why should that not be restricted
       | to banking transactions or login pages and payment links? again,
       | DPI.
       | 
       | now this cyber resillience act which i am assuming wants to
       | "security".
       | 
       | what kind of security?
        
         | unmole wrote:
         | > i live in a place where by law ISPs need to have DPI.
         | 
         | Which law? I know ISPs in India are mandated to record session
         | information but I haven't heard of DPI being mandatory.
         | 
         | > they can access any communication regardless of SSL or https
         | or anything in between
         | 
         | No, DPI can't magically break encryption. Your ISP can't access
         | encrypted content.
        
           | autoexec wrote:
           | > No, DPI can't magically break encryption. Your ISP can't
           | access encrypted content.
           | 
           | they can if they require you to install a certificate and
           | they man in the middle everything.
        
             | unmole wrote:
             | > they can if they require you to install a certificate and
             | they man in the middle everything.
             | 
             | Not exactly relevant because no ISP outside Kazakhstan is
             | doing that.
        
               | mistrial9 wrote:
               | you should ask before making that statement -- I suspect
               | you will be surprised at the answers
        
             | Dah00n wrote:
             | I don't know how the US ISPs run things but this doesn't
             | happen in the EU.
        
               | hellojesus wrote:
               | Nobody in the US would comply with forced root CAs. It
               | breaks 4A.
        
               | autoexec wrote:
               | And nobody in the US could ever break that and get away
               | with it! _N_ ot one _S_ ingle _A_ merican!
        
         | pseudotrash wrote:
         | This post by the The Apache Software Foundation is fairly
         | complete:
         | 
         | > And what makes matters worse is that the type of open source
         | organizations most affected are also exactly those that, today,
         | tend to have very mature security processes, with
         | vulnerabilities getting triaged, fixed, and disclosed
         | responsibly with CVEs to match. While it generally is further
         | downstream; with the companies that place the product on the
         | market -- that the CRA needs to drive significant improvement.
         | It now risks doing the reverse.
         | 
         | But all organizations (ECLIPSE, LINUX, ...) raised alarms
         | 
         | https://news.apache.org/foundation/entry/save-open-source-th...
         | 
         | Edit:
         | https://nitter.kavin.rocks/search?f=tweets&q=cyber+Resilienc...
        
           | raverbashing wrote:
           | Very good description, and if the protections from OSS are
           | not enough I expect more noise in the next weeks/months
           | 
           | > There is of course an elephant in the room: the well-oiled
           | mechanism that "The internet treats censorship as a
           | malfunction and routes around it" (John Perry Barlow).
           | 
           | The parliament position reads:
           | 
           | > Only free and open-source software made available on the
           | market in the course of a commercial activity should be
           | covered by this Regulation
           | 
           | > Whether a free and open- source product has been made
           | available as part of a commercial activity should be assessed
           | on a product-by-product basis, looking at both the
           | development model and the supply phase of the free and open-
           | source product with digital elements.
           | 
           | > (10a) For example, a fully decentralised development model,
           | where no single commercial entity exercises control over what
           | is accepted into the project's code base, should be taken as
           | an indication that the product has been developed in a non-
           | commercial setting.
        
           | fsflover wrote:
           | The corresponding HN submission:
           | https://news.ycombinator.com/item?id=36783445
        
       | psychphysic wrote:
       | Well they're not wrong, despite being quite questionable
       | themselves.
        
       | kevincox wrote:
       | I see that the Linux Foundation has posted a blog opposed to
       | this. I wonder if they could single-handedly destroy this
       | legislation by revoking the license for Linux in the EU.
       | 
       | Of course this would be difficult because existing contributions
       | can't be relicensed. But they could maybe start accepting new
       | patches with a non-Eurpoe license. Or does the GPL prevent this
       | as they are building on GPL code and need the same license? I
       | double the EU would be ok with running on outdated Linux or
       | trying to maintain their own.
        
         | perceptronas wrote:
         | My gut feeling is that EU wouldn't cave and would be OK on
         | running on outdated Linux. There is really no citizen influence
         | on block wide policies so I doubt a protests would work or that
         | any majority of non-technical people would care.
        
         | joshuaissac wrote:
         | They cannot revoke the licence under the GPL. If new patches
         | are under a non-Europe licence, then they cannot be combined
         | and redistributed with the existing GPLv2 codebase.
         | 
         | There is a provision in section 8 of the GPLv2 that allows
         | excluding certain countries, but it can only be activated in
         | the face of copyright or patent restrictions on the
         | distribution of the software. IANAL, but one approach to
         | activate this provision might be to implement a patented
         | technique within the kernel, for which the patent licence only
         | allows implementations outside the EU.
        
         | peddling-brink wrote:
         | Microsoft would be thrilled.
        
       | gndk wrote:
       | I just downloaded an update through my already installed client.
       | I'm in Germany, so obviously the block is not working.
        
         | orangepurple wrote:
         | File sharing program with dwindling userbase embargoes itself
         | in EU political protest; fails
        
       | justinclift wrote:
       | That is _incredibly rich_ coming from __FileZilla__, one of the
       | few OSS projects that accepts money from _malware makers_ to
       | catch out unwary windows users.
       | 
       | I wonder if they're actually more worried about having the EU go
       | after them legally if some EU member loses data or money directly
       | because of that malware?
        
         | jdboyd wrote:
         | It may be rich coming from them, but it doesn't mean they are
         | wrong in this case.
        
         | TedDoesntTalk wrote:
         | > money from malware makers to catch out unwary windows users.
         | 
         | As an active user of FileZilla, can you elaborate on this? Any
         | links or sources where I can read about it? Thank you.
        
           | speps wrote:
           | The default download link installs malware/adware alongside
           | FileZilla. If you go to the actual downloads page, you get
           | the vanilla version.
        
       | pseudotrash wrote:
       | TLDR: In protest of the Cyber Resilience Act. FOSS projects have
       | been raising alarms for a while. Today ITRE voted. Now it's game
       | over for FOSS in Europe
        
         | jeroenhd wrote:
         | The CRA isn't law yet.
         | 
         | Also, I don't see the problem myself:
         | 
         | > In order not to hamper innovation or research, free and open-
         | source software developed or supplied outside the course of a
         | commercial activity should not be covered by this Regulation.
         | This is in particular the case for software, including its
         | source code and modified versions, that is openly shared and
         | freely accessible, usable, modifiable and redistributable. In
         | the context of software, a commercial activity might be
         | characterized not only by charging a price for a product, but
         | also by charging a price for technical support services, by
         | providing a software platform through which the manufacturer
         | monetises other services, or by the use of personal data for
         | reasons other than exclusively for improving the security,
         | compatibility or interoperability of the software.
         | 
         | I'm not sure where people get the idea that donations are
         | considered commercial activity. Support subscriptions and such
         | make you liable (but I don't see why that would be a problem).
         | Ubuntus's Snap store is a platform through which the
         | manufacturer monetises other services. Half open source (i.e.
         | FileZilla Pro) also counts as closed source software, of
         | course.
         | 
         | Most of the protests seem to come from people who operate a
         | business that sells their open source software and wants to
         | remain off the hook to get an advantage over their closed
         | source competition.
        
         | Dah00n wrote:
         | No it isn't. These kind of laws and doom saying is repeated
         | again and again. Wait a week and see. Nothing changed.
        
         | rs999gti wrote:
         | > it's game over for FOSS in Europe
         | 
         | You mean the European Union. The rest of the world will be
         | fine.
        
       | [deleted]
        
       | veave wrote:
       | [flagged]
        
         | Proven wrote:
         | [dead]
        
         | davidebaldini wrote:
         | Regulations become unpalatable when they hit too close to home.
        
       | rs999gti wrote:
       | > The CRA goes against this principle by imposing unavoidable
       | liability on producers of free software, requiring them to make
       | their development, testing, and documentation activities much
       | harder and complex.
       | 
       | If the EU wants this, they should use part of their budget to
       | fund it.
       | 
       | This is the same argument for businesses using FOSS, if you want
       | support, pay for it, otherwise you get what you pay for.
        
         | tough wrote:
         | EU does fund a lot of FOSS
        
       | gumballindie wrote:
       | Unpopular thought, but eu's CRA may reduce open source software
       | availability, increasing scarcity and thus leading to a potential
       | indie market. Software is one of the few industries where people
       | have freely made the product of their labor available in large
       | quantity, dramatically reducing their prospect of earning
       | independently just by writing software. The more indie software
       | makers the more proper engineering can be done - as opposed to
       | simply giving it for free to corporations.
        
       | badrabbit wrote:
       | The filezilla installer will install adware on a windows PC if
       | you leave the default options (as of 1-2yrs ago)
        
       ___________________________________________________________________
       (page generated 2023-07-19 23:02 UTC)