Open-source software vs. the proposed Cyber Resilience Act
blog.nlnetlabs.nl
blog.nlnetlabs.nl
This reminds me of the Gaia-X / IDSA certification and approval framework blanketing the whole software industry in the EU. I am not sure yet what to think about it.
On one side, it looks a bit like proprietary software vendors trying to cut out SMEs who can match the quality with the same open-source software the big players use, but have no funds to go through the certification. The really funny part of this legislation is: the big players who can afford certification will be able to use ANY open-source component for free but the people who built it will have a tough time to go to the market because they will require the funds they don't necessarily have. Crazy situation.
On the other hand, if this is applied to everyone, well, it will get rolled into the cost of providing a service. You want to buy this from me? Sure, I'll charge you for compliance report.
The really funny part of the "Call for evidence for an impact assessment - Ares(2022)1955751" document (section C.) from https://ec.europa.eu/info/law/better-regulation/have-your-sa... reads:
> The initiative is expected to have positive economic impacts.
That section completely misses to mention that increased compliance cost will inevitably lead to increased software and services pricing, thus will lead to decreased competitiveness of European SMEs on the international market.
Hot take: I can see two options to cripple this: 1) Drown the legislator in compliance requests for minor code. 2) Dual-licensing: AGPLv3 + commercial license.
Note that there are tons of CE certification. For radio cert for instance they don't need to open the box.
Emphasis on "proposed", the current edited title sounds like it's already in effect.
So yes, this is something to be concerned about.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Parliamentary committees are where the true work is done both in the US and the EU, so there is always value in attracting attention to their work in progress.
Finally, many drafts may not go anywhere but they are often used as a foundation for future legislation which does go through.
It's really easy to make an argument for almost anything being somehow within HN's rubric or important in some way. These arguments are often true! But that also tells you they aren't useful criteria for deciding what works and doesn't on the forum since if you accepted them all, everything is good for the forum.
Repetition and repetition-generation is HN-bad. Another example are software release posts. Those are super HN-y by topic but the bulk of them are also not great HN posts and routinely get downweighted because they tend to produce the same generic discussions which are fine in general but not (for HN purposes) at the release cadence of most active software projects.
So what mods could demand is a submission statement with a quote/source describing the momentum or the viability of the discussed regulation . In the EU when it's at the public consultation or commission adoption stage it's already serious enough, in the US you want to some evidence the bill won't just die in the next chamber.
That’s just the messageboard version of ‘ur mom’. Ur mom is a slippery slope and a strawman!
Second, you're the one not addressing my actual points but I'm supposed to be the one who's dismissive and immature?
You can just search for proposed bill, draft eu, and such. There's plenty evidence that the argument such submissions are offtopic is false.
You then insinuate that this would lead to a load of overly similar submissions and conversations by comparing legislation to software releases. How's that not a slippery slope? Where will all those tech bills suddenly come from?
Besides, I'm not arguing for more of the same but simply against the notion that early stage submissions are not appropriate for HN. This would not bring any major changes to the queue.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
The EU is most concerned about "Class II software". The stuff that runs industry.
[1] https://acronisscs.com/blog-open-source-backdoors-in-the-wil...
[2] https://www.zdnet.com/article/open-source-software-how-many-...
No there was not!
Someone in 2003 submitted a patch. To the wrong repo. The patch was looked at anyway and rejected for this reason. It was never merged. No machine ever had this bug.
Make no mistake this will just be used to implement those backdoors.
If the EU is so concerned about cyber security they should:
1) provide A LOT of funding and support for Linux / BSD and other operating systems and flavors for testing, hardening, and rapid patch rollout
2) provide infrastructure to support such activities
3) use open source software actively in government with a focus on providing feedback and patches from government IT back to the mainline projects
A founding tenet of security is that open systems and techniques are the ones that will be most battle tested and therefore resilient.
Alas open source has terrible lobbying, so the closed source vendors can lobby politicians and policy to go the opposite way: prescribe closed source solutions and additional onus on open source.
If first world economies were serious about cyberdefense and hardening, there would be 10 billion dollars annually invested into the foundations of open source software: Linux/BSD, databases, webservers, browsers, programming languages, etc. The militaries alone should be dedicating this level of funding to defend our infrastructure, economies, and whatever technological edge we have over China.
And the EU in particular should like Linux: it originated there, and has strong roots throughout the EU, and most importantly isn't controlled by a major US corporation (unlike Apple/Microsoft) and therefore indirectly controlled by the US government.
was it ever proven somehow ? I know that it seems like an axiom here on HN but I doubt anyone did tried to check it.
But really, just the language thing is enough to make the comparison silly.
About that..
If something isn't popular enough to pass muster for the majority of people and the majority of states, it should stay a state law instead of a federal one.
The negative effects seem pretty intended to me. The legislators are aware of open source software and have an exception for non-commercial activities, but intentionally penalize OSS related to commercial activities, by leaving them out of that exception.
And, at this point, I don't believe that these legislators are so stupid that they can't see the consequences of their proposals. They probably just don't care about the negative consequences, or the "negative consequences" (negative for us) are actually what they're striving for.
So for your Python software you are fine either just providing the software alone, without an interpreter, having the customer get a Python-standard-compliant (if there were such a thing...) interpreter for themselves. Or you could provide a CE-certified Python interpreter that you got somewhere else along with your software, provided you do not change the interpreter you got and the interaction between your software and the interpreter is standard, run-of-the-mill, unsurprising normal use as intended and certified.
1) commendable, but
2) the EU shooting in its foot, because
3) large rich American closed source companies will very happy to comply
4) where will they find all the auditors to check the zillion of small open source projects inside node_modules for a commercial project? And who's going to pay them? Again, closed source companies are very happy.
That might be true for the lawmakers. But as it is, there will be unintended consequences:
First, what the article criticizes: Open-Source development might be discouraged because the exemption isn't clear and encompassing enough. Compliance is enough of a burden to stop any "halfway commercial" OSS developments in the EU, with a very wide interpretation of "halfway commercial".
Second, there will be the ambulance chasing kind of lawyers profiting from any kind of ambiguity by sending expensive warning letters ("Abmahnungen"). Those scumbag lawyers definitely want to chase open source developers and everybody else without a big legal team who provides them with an opportunity...
And experience shows that lawmakers have always been unable or unwilling to write laws with the necessary clarity and non-ambiguity.
"The developer of this software attests that it does not and will not comply with the EU CRA, and may not be used as critical infrastructure within the European Union. Any entity incorporating this software in products sold in the European Union agrees to perform all required compliance, and hold the developer harmless. Any compliance failure shall terminate all licensing of this software to all involved parties."
What that does to [vendors in] the EU would be interesting to see.
The big problem imho is for EU-resident OSS developers.
Yet open source developers are subject to the regulation.
edit: apparently there is a similar bill in the US. So that does sound like regulatory capture.
If the Commission was proposing a law mandating that cars have seat-belts, people would be jumping in to shout "Europe is destroying free enterprise, they're trying to destroy small car-makers!"
Seriously, when you look at the list of concerned software, you have password managers, operating systems, certificate infrastructure, remote access software, industrial IoT, etc. For any software in these categories, it's not completely insane to think that "This software is provided as-is with no warranty whatsoever, good luck!" doesn't quite cut it.
And yes, open-source is concerned as well, when it's part of a commercial activity. Again, if you're being paid to provide software, it seems fair to say you're leaving the "lobbyist" category and entering the "paid professional" category and you have to worry about security requirements. Especially given that, outside of the critical projects mentioned above, you're allowed to display the CE mark if you self-audit.
Are there deeper discussions to be had here, concerns to be addressed, etc? Absolutely. I think a critical point is how "commercial activity" is defined. A threshold of gross revenue could be an interesting solution.
Are these deeper discussion happening in this thread? No. It's all "Europe hates innovation" and "I hate the EC and cookie banners so much!" Most commenters seem to automatically assume that any level of regulation is automatically going to drown small businesses and favor FAANG-scale corporations, which is more extreme than even the article calling out the regulation.
No one cares if you improve anything. They just care if you make a mistake. This attitude is a disaster.
And PoignardAzure, yes, I do believe seatbelts and motorcycle helmets should be optional. If you die because you're too cool for them, you die - simple as that.
For more context, a "critical" product cannot be self-assessed. He would have to hire the auditor.
> developers of critical products may not perform self-assessment and need to involve third-party auditors
Anyway, where this will become sort of an issue in regards to open source software and actual development, as the article points out, is when too many companies rely on the same business critical piece of software. I'm not sure I agree that this will be such a big issue, however, as most organisations that I know of tend to in-source the most vital open source projects exactly because it's too dangerous to rely on some random person.
We've done this our selves. We needed an ODATA package for TypeScript projects, and while there were a few options out there, none of them were great. Some of them would've been "good enough", sort of, but they were either maintained by one or two people or not at all. So instead of using these, we wrote our own. Which is frankly how I suspect a lot of Open Source projects happen, because while you can use GORM as your GO ORM and where we could have used one of these packages and even made it better, it was simply easier to make our own.
The CRA doesn't really change this, however, at least not if you're already taking security seriously.
I personally think the only area that will actually be interesting to follow the CRA on is what the EU intended to do with all the public sector smartphone Apps. Here in Denmark we can have things like our drivers licence in apps, but these apps are only available through either Google or Apple, and those aren't European companies. :p For everything else, I think this will mostly be bureaucracy, bureaucracy, bureaucracy, which is sort of fine, because as the GDPR has shown us, not every organisation can be trusted to do security that impacts the EU.
Edit: It made me thinking, how would legislator ensure legislation is implemented? Would they start requiring escrow so they can check by themselves if software is developed to the correct security standard?
However, if you build security critical software and get paid to do so it‘s not entirely unreasonable to require some sort of certification. You can‘t just build medical devices for money either without some sort of regulation. Or produce food for money. Or repair cars for money.
"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, ...... "
It is on the user (or a third party certification authority) to accept any liability for the quality of the software.
> Limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable
If so, I'd expect it to summarily obliterate the OSS world.
This would, however, not remain true if you're actually dealing with your users in a way that establishes mutual obligations (be careful you don't fall into a contract unawares!) Providing support for pay would do it, for example.
Libc, clang/gcc, whatever. Needs to be audited.
Perhaps they require the “integrator” to perform the audit or maybe the fact someone provides software which can be useful in critical environments is enough to signal an implied warranty and they are on the hook for compliance. Nobody knows until it all goes through costly legal procedures where everyone is trying to cover their asses and pass the buck.
I’m waiting for the day where FLOSS devs are greeted at EU airports by process servers because they released some software while in college and it got used in some critical software.
However, that declaration of purpose of course binds all other users/distributors of Linux, if they should dare to use or bundle it as a desktop, server or mobile operating system, they are doing so outside the original certification and need to have the required audit for critical software performed.
That, as far as I read it, also means that something like GCC, which is unambiguously a compiler, isn't critical and need not be audited, only self-certified, even if used to compile a critical software component.
The problem lies, among other things, in the fact that a business activity might be assumed even if one does not explicitly receive money for the software directly, but indirectly. For example via donations, ads on the download Web-site, using it for self-promotion, paid consultancy, selling tutorials, ...
secondary self-promotion, donations and ads are imho not "providing goods in a business-related context". Paid consultancy and selling tutorials might be though, But I assume that judges will rule on that if it comes to it and I assume that they will set some monetary boundary to which this still counts as "outside the course of commercial activity".
So if you have a permanent Website of your open-source product to promote some other product or service, or ask for donations or put ads on the site, you intent to make a profit out of your open-source product. (Almost?) every possible answer to the question: "How can I generate revenue with my open source project?" describes a business related context.
> In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. [..]
> Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context.
> Open-source software is provided both within and outside of business related contexts. And the 'occasional supplies' exception in this quote seems to be of limited use to projects society comes to depend on. Would you consider an open-source operating system (MINIX) that has been freely available for 35 years an 'occasional supply'? What does its integration in all Intel processors since 2015 mean for being 'goods' outside a 'business related context'? How about the BIND project, a staple of open-source core Internet infrastructure shipping for 40 years?
This feels like a huge issue to me and that's before considering how most OSS we use everyday is worked on by full-time employees as a part of their jobs.
If someone uses TerminatorOS and you did not sell it to them, they will be responsible for its use, you are fine.
If you start terminator.io, a startup that sells TerminatorOS powered drones that shoot you in the face, you are not fine and need to comply.
In the same way, if BIND starts BIND.io to sell Bind-as-a-Service, then they'll have to be compliant. If BIND is found to be ran at 90% by AWS with AWS paid employees, they won't need to be compliant. Otherwise, you'll be fine.
Source: this is not the US, European law takes context into account.
It's really the same thing as selling non certified products in Europe. If you are a registered EU business, you have to sell CE certified products, so we know that you're not going to burn my house down. If i buy from alibaba an LED strip that draws 500W and ends up burning my house down, it'll be my fault, the seller was in China and i knew what i was getting into.
> open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation.
You take an upstream, free, non-commercial product and you SUPPLY it as part of the solution. You are responsible for the conformity.
Donors get “perks” for the donations, so the receiver is essentially selling these perks and services.
At what point am I responsible for every single module I’ve ever produced because I received X000€ in donations this year?
Therefore I would consider any kind of open source contribution by an IT professional a commercial activity. Only if the open source contribution is strictly a hobby and your normal job involves nothing IT-like at all you'd maybe be safe.
As always, talks to your tax accountant about your specific case, this is not legal or tax advice, …
all legislation is designed for Mittelstand (medium sized german companies)
tax, privacy, communications, employment, now software
this was seen with the VAT changes: it was raised that this would badly affect small companies, so they passed the legislation then penciled a meeting in for 3 years time to maybe think about small companies
in general: if you're a small company: fuck you
I don't remember how many DAYS we've collectively lost in all the apps we're making, to make sure we comply with GDPR instead of focusing on productivity.
If you're not located in the EU, what can they really do even if you do have paying clients in the EU?
I could instead not push it back, which is less immediate risk
As highlighted in the article, "commercial activity" is what triggers the legislation, not profit, and it's a broader concept.
Note also this section on page 34:
‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
Take what I’m saying with a huge grain of salt, cause I’m also not a OSS contributor nor do I work with tech-related legislation.
If these big corporations were paying up the fair share of profit generated by the open source software they use, I am sure the developers behind it would have funds essential to ensure the security of the software they make.
That being said, even if above was not feasible (shame!), then it should be up to corporation using the software to ensure it is secure (and possibly contributing any fixes back to the software).
(i) it is designed to run with elevated privilege or manage privileges; (ii) it has direct or privileged access to networking or computing resources; (iii) it is designed to control access to data or operational technology; (iv) it performs a function critical to trust, in particular security functions such as network control, endpoint security, and network protection. (b) the intended use in sensitive environments, including in industrial settings[...]
There's a clear distinction here between what the EU labels 'critical products' and non-critical software. Seeing the increasingly insecure global situation, the importance of software in infrastructure and the potential threats I think it's wild that something like this hasn't passed a decade ago. Digital infrastructure needs to be as secure as physical infrastructure.
I wonder what would happen if some Heartbleed-esque bug that went undiscovered for years took out a huge chunk of a nation's electricity grid in a military conflict. What the EU needs in addition is if course also more funding for software security, but they're already doing a halfway decent job. If you didn't know, if you fix open source bugs in the EU you can get paid for doing just that: https://ec.europa.eu/info/news/european-commissions-open-sou...
The sensible approach to so called critical infrastructure would be to just make a company provide free service for a number of days for every hour/day of downtime for preventable errors. Like say the power went out for an hour, you get 100kW of free electricity. You didn't have natural gas for 1 hour, you get 100cm of gas for free. And I find this approach better than having some random person from a government agency with a clipboard and a checklist fining you because you don't have antivirus on your phone or some other stupid thing like this.
If there's a sophisticated cyber attack, then the utilities get to walk away scot-free. Just like the insurance company waives all liabilities in case of unforeseen circumstances like war & stuff.
Sure, but what does “direct” mean in this context?
My little IRC client library or a device driver in the kernel?
Either one could be used in an exploit chain to take down the EU power grid. Theoretically, of course, because I don’t actually have an IRC lib and I don’t think it would be used to control a power grid if I did…at least I would hope so.
"outside the course of a commercial activity should not be covered by this Regulation" Is this kind of wording normal In EU laws? Why use "Should" in the law, since we are in the middle of defining what is going to happen shouldn't it be "is"?
Instead we just get more bureaucratic anti-innovation makework - just like the Link Tax, Cookie law and GDPR, etc.
A fund sounds like a great idea as well, but who would decide who gets the money? You don't want overseas companies syphoning the fund because they have 0.01% of their userbase in the EU.
Overall, as others have stated: how unreasonable is it if you create a 'critical' product, and you make money off of it, to invest some of that money to show it is secure.
I suppose it depends on how many hurdles you want to place in front of innovation.
I learned after driving a cab for nine years just how little I can live off of and if I cut out the luxuries (like hot water) it was surprisingly little.
Now suppose I were able to get people to pay me peanuts (through donations for the sake of the argument) to maintain some critical software because, you know, “someone has to do it and this guy will work for peanuts”, just how many luxuries am I expected to do without to comply with some overbearing regulation?
That's a weirdly specific hypothetical.
In this situation, we're assuming the regulation is morally responsible for you living an austere life and not, like... you for choosing to pick the job instead of other better-paid software jobs, or the software users for not being willing to pay for critical software they depend on? And the regulation is therefore immoral if it costs any non-zero amount to anybody to comply with it, even if that amount is low?
Either they take absolutely no compensation or they are responsible for (probably costly because government) compliance measures if some bureaucrat finds the project “critical” without them intentionally producing “critical software”.
The typical software you need to google in the context of an audit is "Excel" for the endless fill-me-in lists of compliance b.s. your auditor will make you fill in...
OSS developers who don’t charge for the software have no obligations. If their software is used in a commercial product, the seller of that product is responsible.
I’m not getting an auditor over to audit my $20 program.
Self-assesment is an option. The problem is that now you're responsible for the bugs, no matter whether the user uses it for securing his cafe or bank...
> For the purposes of this Regulation, the following definitions apply: (1) ‘product with digital elements’ means any software or hardware product and its remote data processing solutions, including software or hardware components to be placed on the market separately
https://ec.europa.eu/newsroom/dae/redirection/document/89543
On the "bright side", this will realistically be impossible to enforce. Any national court who deems such industry important will probably use a local constitutional amendment to reinforce that CODE easily falls under freedom of expression, just like any other craft.
EU showing once again how desperate it is for money. Let's strangle out all our industries until nobody can make anything anymore: See agriculture, energy, manufacturing, and "now" even a bigger range of the IT spectrum.
if you're in the EU then EU legislation overrides any local law
The European Green Taxonomy is a brillant exemple. It’s both complicated, costly and a poor way to achieve the goals it wants to achieve.
At this point, I have to assume it’s voluntary self-sabotage.
That’s what they do all day long themselves after all. It’d be reasonable to think that everyone has as much free time on their hands, right?
Like the idea is to punish workers (skilled and unskilled) and keep the power and wealth in the hands of the aristocrats.
It’s not that I necessarily disagree. It’s just that it’s a sad state of affairs if this is the best we can do.
Even now they still punish member countries for trying to enforce their borders.
I don't see it as attractive for any for-profit investment. Maybe it's the right incubator for open source / nonprofit alternatives?
Well don't forget, it applies to non-profits too. Or an individual who makes money from it.
edit: can't reply to the reply below (too nested? IDK).
> I'm not sure I'm understanding your point... could you please elaborate?
My point is the compliance laws apply to "non-profits" (the legal entity) and individuals that make a profit from OSS. Perhaps you covered that in "for profit" but that term is often used for companies and in contrast to "non-profit"
Yeah, I hear you... the burdens are also real for non-profits and individuals. I should have said it is more about motivations. I wouldn't go into EU to complete against displaced ROW companies in the hopes of making money (personally or as a company or a VC).
But if the mission was to make the world a better place and profit wasn't important, sure. As business-unfriendly as the environment is, it is very consumer friendly, at least in intent. IMO there may be unintended consequences that harm consumers but their hearts are in the right place.
But for some reason the EU is still hooked on neoliberalism and anti-protectionism, even when it has ravaged the continent with the energy crisis and the US monopolising the Tech industry, etc. (remember that the ZX Spectrum, BBC Micro, Acorn, ARM, Linux and Nokia were all European once).
Like in this case - it'd be better to just invest directly into support for EU-based FOSS consultancies to contribute and maintain critical libraries like OpenSSL, LibreSSL, Linux, etc. - and then all EU government and industry would benefit with that, whilst keeping the jobs and investment in the EU.
They're just so short-sighted and dogmatic about neoliberalism (as well as doing whatever the US asks, regardless of the negative effect on Europe). It's no wonder we're being eclipsed by China. Just look at the GDP per capita and Productivity since 2008 - https://data.worldbank.org/indicator/NY.GDP.PCAP.CD?location...
That's how they are introducing neo-communism by the backdoor. Technically private initiative is still legal and possible, but it is not in practice.
So if you have an idea, your only option, eventually will be to get hired at one of big corporations and try to sell your idea at one of their start-up incubators.
Difference is that you'll always be a salaried worker (and remain in working class) and shareholders will profit from your idea not yourself.
(Of course, Communism as actually implemented wasn't what Communism was supposed to be, either. It was in fact just another neo-serfdom.)
Even by HN's typical standards of political discussions, this sentence is quite something. You can't actually be serious?
This bill looks pretty shit, but you're jumping from that to a conspiracy theory that just doesn't seem to match reality at all?
So the EU and it's consumer/people right's over company rights caused Russia to invade Ukraine and therefore decrease the supply of energy causing an increase in prices??? This is one of the craziest, nonsensical takes I've ever read.
The EU politicians and especially the EC members are beyond insane at this point.
We haven't intervened in Armenia or Ethiopia for example.
The EU were the ones trying to force Russia to sell gas to everyone, and not only that, but to also deliver it to specific transit routes. Like "you can't cut off Ukraine" because they're gonna freeze or something.
There's a lot of nonsense that is happening just because bureaucrats are stubborn and think the world should work how they dream it at night.
Also, part of the issue isn’t Russia raising their prices but a reduction in supply either from Russia removing a supply or countries not wanting to buy from Russia.
Despite the headline this is about all software, not just code that's developed with open source and software freedom as features.
Now could be the time that FOSS gets to put the many-eyes reasoning to the test with crowdsourced standards compliance. It could make paid jobs for open source developers as CE auditors for code. That code is currently just taken by big companies for free, plus the ingratitude of blaming developers who work for nothing when it goes wrong.
It's mostly a checklist exercise anyway. So long as there's no monetary cost to compliance it may create a cadre of OS reviewers who are skilled and prepared to do it for free for projects they support.
Surely, in a real security meritocracy the cruft that passes for "closed proprietary" software will soon be exposed for what it is. How long will Windows 11 last in an environment with good security culture?
Proprietary software will not only have to compete against free, it will have to compete against _good_, and certified good free and commercial FOSS. The FUD, disinformation and fearmongering of Big Tech and it's shills may end up having less impact, not more.
OTOH I doubt this will impact hobby developers and Non-Commercial FOSS that comes with liability disclaimers from the get-go. It will however, impact those who want to take that work and deploy it in critical roles for commercial gain.
Why they just don't release a law that forbids people from making bugs?
The more I think about it, isn't that literally what the law is about, lol?
What happens when/if core technologies like SSL, BIND, and even the Linux kernel fail to meet these requirements? Will EU entities have to stop using noncompliant open source software? As someone who is not a fan of bureaucracy, the consequences of this could be almost hilarious.
Edit: TFA is writing about this as legislation to be concerned about. I'd wonder if the best response to this is malicious compliance: "sorry $EU_ENTITY, we never certified, so you can't use our tech that happens to be fundamental to the security/networking/OS stack."
Enforcement of compliance would thus be via the seller, distributor, importer or producer, whichever is a EU entity and available/responsible.
Generally it would be permissible to use non-CE-certified products e.g. at home, provided you do not make them available to others, give them away or sell them. Using non-certified products can be prohibited for companies and other legal entities, usually through the safety regulations they have to obey.
What the legal consequences for a user of non-CE-certified software would be, I don't know. There will certainly be an assumption of negligence if anything goes wrong.
This was a long time coming for our entire industry- ever since internet stopped being just about kittens and porn and started handling serious money.
This is a good thing because it will force decision makers at major compabies to sober the fuck up and pay real attention to security. We still have consumer products, like phones and routers, that are being shipped with known security holes and without any updates.
The issue is pervasive throughout the industry and will take decades to resolve.
If anything, it will create a situation where e.g. OpenSSL is audited and compliant, but other newer solutions aren't so you can't use them. If "has been audited and approved" would be a good assurance the project is of good quality then that might be okay, but overall I find it's a rather weak signal.
For example Go has a boringssl build because boringssl is FIPS certified whereas the default Go crypto stuff isn't, and this matters for some people.
Details depend on the project, of course. The lesser used WolfSSL is also FIPS verified; it's clearly not impossible to do these things, it just puts additional pressure on what are often already constrained resources. I mean, the amount of general resources Linux has available compared to, say, OpenBSD is just huge.
"(13) In order not to hamper innovation or research, this Directive should not apply to free and open-source software developed or supplied outside the course of a commercial activity. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. However where software is supplied in exchange for a price or personal data is used other than exclusively for improving the security, compatibility or interoperability of the software, and is therefore supplied in the course of a commercial activity, the Directive should apply."
However, as I understand it: If it applies (e.g. commercial context) and you distribute the software or offer a product based on the software, you need to show the audit of all, not just a part (e.g. the glue code).
And, maybe since you do understand, you could explain, rather than making 10,000 of us go do the research on our own?
The fear is that they will proceed with extended definition of "commercial activity" though, out of fear of loopholes.
Here is an excerpt from the article that puts into context why this is concerning. But honestly, just read the article.
> Now, what is a commercial activity? The CRA does not define this term. However, conversations with people more knowledgeable on product legislation pointed me to the EU Blue guide to the implementation of EU product rules:
> Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context.
> This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. However where software is supplied in exchange for a price...
This says that publicly available open-source software that is not supplied in exchange of a price (as in, say, customised versions of software that are not available to general public) is exempt. It doesn't cite any other commercial activity (technical support, donations etc.) from EU Blue guide.
Who’s responsible for compliance in that case, the dev or the thousands of companies who used the library in a critical role?
I know this is supposed to fix such a situation but they aren’t going to be taking hundreds of thousands of website operators to court who used the freely provided library without auditing the code.