FOSS could be an unintended victim of EU crusade to make software more secure
theregister.com
theregister.com
This seems sort of reasonable. If you charge for tech support, you have a business. I’m all for not making it harder for people who are actually just sharing their hobby projects, but a project that makes money isn’t a hobby anymore.
I mean we wouldn’t want to leave a gap large enough to send Android through, right?
The Register appears to have bought into the FUD being spewed by a bunch of people being paid a lot of money to run “non-profits”.
Businesses like Litesspeed can sell their product as a certified one and sell that as a feature.
If I am distributing a product based on Linux, it is my job to ensure that I use Linux in a secure way, to the extent required by contracts between me and my customers, and by local regulations. I can either take on this work myself, or pay IBM RedHat or SUSE or whoever else to take on some of the responsibility.
How else would this work?
Using a "standard" kernel, keeping it up to date, etc. is due diligence but WAY cheaper and easier to do then any form of certification.
Software certification especially wrt. to security is and always has been a mostly a scam.
It also is a _major_ driving factor(1) for insecure software not getting fixed. Because it's "certified" but the security fix is not. (1: in certain industries)
we can't even do that reliably for very well understood mass production processes of "simple" physical goods ( Which is why you make systems which in presence of defects still yield acceptable results.). The goal you are listing is not something which can be reached through laws like this _at all_!!!.
Outside of clear negligence and potentially hurting FOSS it will not lead to a major increase in security in it's current form and can easily have the opposite effect too due to companies "hiding there code" to avoid problems when people find issues and potentially use all kinds of questionable means to try to prevent people from doing independent security research on their products.
If past experiences around e.g. government projects with similar requirements are anything to go by certification is not in any way a reliable form of security, especially for mass products.
In my experience the overlap between competent security researchers and people doing the certification for most (not all) for-hire security review companies is rather small.
For example the amount of peace makers which can be hacked even through such medical devices have extreme strict certification requirements far beyond what can be applied to most software is still pretty high.
I have seen cases of really big (and supposedly competent) software consulting companies certifying something as secure which most 3 semester or so bachelor students could have told you is clearly not secure.
Don't get me wrong, there is a problem with negligence and having a law/regulation which reduces that is by itself a good thing.
But the issues the software industries has are much more deep rooted then such negligence (else we wouldn't also see such issues en-mass in cases where no such negligence was done). You could even say they are fundamentally rooted in human nature and society ;-)
Worse if such a regulation is not done well it might more lead to a game of shifting blame then people actually trying to fix things.
With the current writing it might be that a distributor different from the commercial entity might be liable for vulnerabilities and reporting.
https://blog.sonatype.com/eu-cyber-resilience-act-good-for-s...
To me it sounds like the "software is delivered as is" clause would nullify that.
What I see emerging is a dual license system where you can buy a supported version that's compliant with whatever European law or get the one hosted on an American mirror (where thankfully European law doesn't apply).
True. I should have said "distribute". But the point holds.
Could be an unintended side benefit given that as it stands FOSS is basically free labor for SaaS with the latter delivering a user experience that is significantly less open and free than the old closed source paradigm FOSS intended to replace.
FOSS + SaaS = less freedom than old closed source.
It's specifically an important feature of libre software that others are free to resell or to make money from support of your own software : this is seen as a good thing because distribution (and support) are not free for the distributor (though I guess much less relevant in a world with widespread high speed Internet and peer to peer distribution software ?) (and supporter).
Because there isn't a difference.
I may generally prefer permissive licenses but I certainly don't see how the GPL, for example, doesn't enable access to source code--though it may sometimes discourage participation in development.
But nobody taught me this definition. Not sure where I got it. So I could very well be wrong.
Nope. That's free as in free beer.
free/libre software / open source software is free as in free speech (and often as in free beer but not always)
some people use the French/Spanish word libre in English to avoid this exact confusion caused by the world free having both meanings.
free software and open source software are defined by the FSF and the OSI, respectively, but the definition are equivalent and designate the same set of software, essentially.
The distinction is really much more about philosophical objectives and marketing than it is about anything material.
Another thing I’m wondering about is academic code. Hypothetically the code I wrote for my thesis is available online and I was paid to write it, I guess, or at least it is part of the research I was given a stipend to do. (Happily, it has nothing to do with security!).
Nobody is making any money off it. Hypothetically it could be seen as something that is there to add (very marginal!) value to my resume or to the university by showing off research chops… I dunno. If we had a law like this in the US, I wonder if it could stay up. I guess universities would end up with an additional CYA administrative step before posting code, and a big disclaimer in all their licenses.
If you directly or indirectly (support contracts) sell some software sure it should apply, but the regulation isn't well defined (in it's draft state) and includes much more.
A lot of FOSS is based around the idea:
- provide software components as FOSS on a as is-basis, components you do not sell directly or indirectly but plan to use, or used, or planed to use until things changed etc.
- the consumer of the software (other programmers/companies) are expected to do _their own_ risk assessment, reviews etc. IF they decide to use the software (but only if, i.e. not needed for prototyping)
- if they use the software (hopefully) you get feedback from their review and assessment leading to bug fixes and improvements
- in some cases projects are evaluated by enough other parties that not everyone needs to do their risk assessment
- you don't make profit from the release, but you do get feedback which could safe cost and do get publicity and trust, so it has a commercial benefit so it's commercial in a certain way
Now you probably can already spot the problem, in many cases companies do _not_ do their do due diligence in reviewing software and blindly assume "someone" did it.
So an regulating which requires you to have made sure that someone did due diligence for all software you include in a product, including SaaS(!) is reasonable IMHO.
But because the regulation is based on the concepts/ideas of a physical supply chain it is instead requiring anyone which is publishing software components (instead of using them) to do the due diligence if it's commercial. But due to OSS leading to feedback, publicity and trust _ANY_ OSS done by a company can be classified as "commercial", even if it's a tech demo explicitly not meant to be used in production or a early pre-pre-pre release version.
Another problem is the definition of what I called due diligence but to comment on that I had to read the draft again.
So IMHO the problem is not the regulation by itself, it might even make OSS better, but the exact formulation which either show a deep missing understanding of software development or bribed politicians, probably a bit of both. Ah I mean lobby influence politicians, it's practically the same, but not legally so better clarify that.
EDIT: I.e. a lot of OSS software is more like sharing (potential prototype) technical blue prints in an informal shared development/research agreements then it is selling "parts" in a supply chain.
The example applications included in them are usually vague enough that implementing them isn't trivial. It'd be very hard to view them as anything more than pseudocode, with similar expectations of functionality.
It all depends. There are plenty of people who have hobbies and engage in some sort of low-level commerce in order to fund them. They aren't intending to profit by them (and don't), but are looking to reduce their loss.
The interesting here is: What is a product? Most open source is not. The millions of libraries are not products. A product accumulates the various aspects (cybersecurity, license, ....) into a package. If I buy the software from a vendor I will make him responsible for it. If I hack it together on my self, this duty is on me.
Open Source will survive that. But open source owners will get tons of questions and should be better be prepared to answer questions. GitLab and GitHub are already working on the consumer side with their security analysis features.
And do not think that this influence will not happen. There are reason why the non functional requirement licensing has switched to MIT from previously more LGPL constructs.
Having said all that... Yes, no one is obligated to answer.
...for appropriate pay.
The EU is basically an association for German business owners and landowners. Happy to impede technological progress if it serves their interests.
That's not true at all, and I don't see which interest there would be in hampering FOSS development.
TFA this thread is based on is low quality. It’s breathless in its criticism of the legislation but uses hyperbole instead of calmly laying out the issues.
The Maven Central guy puts it plainly - the proposed legislation doesn’t penalise OSS developers, unless they distribute software they also get a commercial benefit from. But that describes the operator of Maven Central, who publishes software and has some commercial interests tied to it. However they cannot possibly take on liability for every published package. In that case they would be left with no choice but to block EU users.
Same applies to any kind of business.
Why should FOSS be any different?
Maybe this is the culmination of the bazaar idea after all, including quickly stuffing the products back into a bag and running away from the law enforcement official between the crowd, by not having either a license or the expected quality.
Because it's not a business. Health regulations for restaurants also don't apply to your kitchen at home, even if you are inviting friends for dinner.
The "do what you want and we will punish you hard if luck strikes badly" is less predictable. It has unfair results. It leads to both excessive risk avoidance (because if you are unlucky punishment is disproportionate) and risk taking customer is unable to proactively avoid.
If you make business with said FOSS you need to provide security just like how a food truck making food from open recipes has to make sure to not poison people either.
Holly bushes grow berries that you shouldn't eat.
Should government destroy all holly bushes? No. All berries? Certainly not.
Speech is a natural right and software is speech, so it can't be meaningfully viewed any other way, unless you're mindlessly parroting representative government deliberations.
Imagine you were making cookies for your friends, and Nabisco happened to get one of the cookies somehow. Should you be responsible if they decide to use the ability, conferred from having one cookie, to create an infinite number of copies of that cookie (without checking it for defects or even really investigating it much) and start selling them across the country? I’d say probably not. But our legal framework doesn’t cover it, because physical objects don’t work like that, unlike software.
We could also look at software as more like a recipe. If Nabisco decided to copy my cookie recipe, they’d unambiguous be responsible for checking it and making sure it wasn’t actually poisonous. We also have cook books, I guess if you put a poisonous recipe in a cookbook you’d have some responsibility. But this is all manageable because cooking recipes are pretty short and easy enough to verify, and the foot-guns of the hobbyist cooking field are mostly well known.
A closer recipe analogy is probably — Nabisco probably gets their bulk supplies from a network of suppliers, who have to manage things like contamination levels and fitness for a given purpose. But now we’re hitting the point where the analogy is at least as complicated as the software supply network; I’m sure there are lots of shared responsibilities and regulations in that network, and it is all professionalized and for-profit.
It's one of the smartest laws I've seen in this area. Want to run a small coffee shack with some cakes, cookies etc? No need for a certified kitchen, "fully trained" cook, etc. The only thing you have to do is take a course that helps differentiate between refrigeration-required and no-refrigeration required food.
Interesting to think how this model would apply in the software context...
And those do apply to small stands and full kitchens. But if you want to claim they are unreasonable, then you should argue by existing ones rather then made up ones.
I did not make anything up. The New Mexico law I mentioned went into effect only a few years ago. Before that, it would be illegal to, for example, bake a cake in your home kitchen and offer it for sale. This is no longer the case.
Maybe, but remember that Ursula von der Leyen herself has been advocating for a while for EU's "digital sovereignty" (not having to depend on products and services form non-EU countries) and the easiest way to achieve that would be to heavily rely on FOSS.
But is it also the most profitable way for politicians.
Looks like everyone here has forgotten that the EU copyright stance is basically to shovel money to the US.
I really wish people here would judge politicians by the outcome of their actions and not by what they say.
https://torrentfreak.com/europes-odd-anti-piracy-stance-send...
Some proof of that would be nice. The phrase "it was even listed as one of the reasons for Brexit" sends my personal prior in the direction of it being a lie, though I am quite willing to adjust if there is some evidence.
Regulatory capture. It's very much intended by whoever really drafted that bill.
Well, I'm pretty sure that these same US software companies are still there lobbying in their own interest, in a complete absence of transparency.
Being a contributor, even to my own pet project, cannot compel me to contribute my valuable time to the project in ways that I do not so chose. And you can't compel me either to spend my money to hire some third party security firm to audit this code that isn't owned by me or anyone.
If some third party wants to compile this un-owned piece of code and sell it to another, the onus is on them to comply with security regulations.
While I'm generally a big fan of heavy regulation, there's just so much tech that doesn't matter, that we just use to make other things that don't matter easier.
I would much rather see the regulation confined to domain specific things, stuff that directly deals with finances, life safety, industrial, etc.
More like 450m
It is whether, for companies that offer paid support for FOSS, the obligations are towards the paying customers or all.
The same with FOSS which is used as a basis for commercial products. E.g. Google makes money off Android, but is AOSP with no Google stuff also covered by this law?
And how does it affect companies providing support for software they do not own? (e.g. consultancies).
GPL 3: there is no warranty for the program, to the extent permitted by applicable law. except when otherwise stated in writing the copyright holders and/or other parties provide the program “as is” without warranty of any kind, ...
BSD-3-Clause: this software is provided by the author ``as is'' and any express or implied warranties, including, but not limited to, ...
Apache 1.1: this software is provided ``as is'' and any expressed or implied * warranties, ...
Which means that the liability lies entirely with the user if they use the software for something critical.
If this push isn't stopped... we'll all be taking a crash course on microkernels and the principle of least privilege. (A long overdue crash course, but that's my opinion, and not widely shared)
The EU is probably the leading body of government trying to drive FOSS adoption.
Except those regulations hurt the little guys more than the big companies.
Even if the big companies can't buy their way out of compliance, compliance inherently costs less for them and regulatory bodies are more willing to work with a big company than a small group of hobbyists, leading to the big company being able to follow the law with nary a hiccup whereas the hobbyists get destroyed by zealous enforcement.
This is often somewhat true. However, as I have observed in several USA contexts, large organizations are often exempted (whether explicitly or not) from pesky new regulations, citing this very point. For example, I personally attended a California PUC meeting in which VZN and SBC were exempted from "lifeline" regulations that continued to be imposed (with nonzero costs) on the small CLEC that employed me. Large organizations have to keep lawyers and lobbyists employed, so they might as well keep them busy. Creating regulations and exempting themselves is common practice.
Perhaps things work differently in Europe.
In practice, a lot of companies stop growing just below the limit, and e.g. split in parts that have supplier relations to each other. No, we don't have 2000 employees. We are a group of 200 companies, owned by the same owners, and having 10 employees each.
There is also impact on worker protection. If your people go on strike, or if you want to do mass layoffs, you just dissolve a few companies.
I presume board requirements are a lot smaller for such tiny companies, too.