Secondly, a large percentage of developers do not have a CS degree. There's also a significant number of educations that are not specified as a CS degree, but still teach people skills with the aim of them entering the workforce to work as developers
It's also unclear how domains where software is developed as a tool, but isn't a primary focus (i.e. bioinformatics)
It's already hard enough to hire software engineers, how hard would it be after further restricting to only software engineers with a relevant masters? I know I'd be entirely forced out of the field, and would have to undertake a 4 year course (abroad, because here it would be 6 years) to be eligible for employment again, if that happened in my country.
from where I sit being a start-up, or SME that can make quick decisions and consolidate their security debt is a lot easier on them and worse for us big guys.
I don't want to use a phrase as "level the playing field" but the upcoming expectations of RED and CRA means most of us are praying this isn't enforced as quickly as it is written into law.
I'm totally rooting for this because its the only thing that will improve security.
Also, nothing about compliance is actually about "consolidating security debt" or "quick decisions". It's about paying someone to go through checklists and, like a reviewer of a scientific paper, find something, anything, no matter how inane, to criticize, before handing you a certification. Any slightly unconventional new idea to improve security in your product will be suffocated beneath the blanket of compliance.
> I'm totally rooting for this because its the only thing that will improve security.
So does the author. Well, they strongly endorse a sensible version without the vague phrases and open-source-killing blanket statements, and without brain-dead sentences like "your product must be un-DDoS-able". I do wonder, though, why you're rooting for legislation that would kill any open source project that might, conceivably, be used in a commercial setting?
As it is, I think this is going to be very similar to what is already required for some specific industries like healthcare or finance. Startups that want to operate in these industries already need to go through some certification processes of their products and services. Most startups will probably fall under the "low risk status" category until they are a big enough. If self-assessment is anything similar to what it is already required for things like PCI DSS or GDPR, then most small companies will be fine until they are big enough to care.
And by the way, there is no easy way for the EU to regulate that to write software you need a specific degree.
US has next to zero privacy protections, and unlimited investor money with zero expectations for a company to ever turn profitable. E.g. all of YCombinator's "top companies" lose hundreds of millions and billions dollars a year.
China and Russia have cheap labor and yes, zero privacy.
Edit: the same people who clamor for Russia and China-style big companies will immediately shout for government to step in if any company ever gets to the size and influence of Yandex or AliBaba.
No, there are no "zero expectations for a company to ever turn profitable". If you ever tried to get investor money you'll know how hard is to prove to them you have a good path to profitability. Even if all of YCombinat companies except one lose hundreds of millions, the last one can turn into a Facebook, worth hundreds of billions.
And yet, YCombinator's top companies lose billions for years and keep getting the money. What's the "proven path to profitability"? The flimsy belief that "just wait a bit and we'll have a next Facebook?"
Most of the companies that get mentioned as "big innovative companies" in HN threads have been around for 5+ or even 10+ years, lost incalculable amounts of money, never turned a profit, and we're led to believe that there's an expectation to turn a profit in any of these scenarios.
One in five US citizens is protected by a regulation that looks an awful lot like GDPR. And if history is any guide, it won't be long before that number gets a lot closer to 100%.
EU laws apply to all member states and even entities just dealing with EU members (which is why Privacy Shield is dead again, USA lied).
They do, in fact, when it does business in California. (Also, California is less than 1/5 of the country, so the reference is not just to California law.)
Otherwise it's illegal as due to fun laws only FED can regulate interstate commerce.
Physical presence is not a requirement for commerce clause nexus (though it definitely satisfies it.) I’m not sure it ever was viewed as a requirement outside of sales taxes, and the precedent establishing it as a requirement for sales taxes was overturned by the Supreme Court in South Dakota v. Wayfair (2018).
> Otherwise it's illegal as due to fun laws only FED can regulate interstate commerce.
The “fun law” is the Constitution's Commerce Clause, and that’s not actually how it works.