The EU proposed CRA law may have unintended consequence for the Python ecosystem
pyfound.blogspot.com
pyfound.blogspot.com
> 10) In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.
Yeah, it could be even clearer (but laws tend to not want to enumerate everything that is obvious or they'd become books), but it feels somewhat exaggerated. Or is the actual fear that commercial support services by the authors could trigger liability? As far as I understand, that has been a preferred way to get paid and remain not-liable for the original product.
One case that could potentially become problematic is OSS developers who have Patreon subscribers or similar, where those subscribers could conceivably pass on liability claims.
[1] https://www.internetsociety.org/blog/2022/10/the-eus-propose..., via another comment here: https://news.ycombinator.com/item?id=35525876
[A previous version of this comment mentioned BIND, because I confused ISOC and ISC.]
Otherwise why would I pay for support if I could just self-host? They can strictly define the parts they are willing to support, though.
The word you were looking for is "support".
If there is something wrong with the "supported" open-source software, then you may expect a certain level of "support". Full-stop.
That generally entails an SLA that says your issue will be reacted to within N-time of opening the issue, which might be nuanced by the tier-level of support purchased. That you are provided access to documentation, or even the source code itself. You might be provided with best-effort support by an agent, which is limited to resolving documented defects, or configuration, or acknowledging standing-bugs which cannot be resolved.
What you cannot expect is the software is updated in accordance with the support incident. For that, send patches, or pay somebody to send patches.
He doesn't update his version of your software and this leads to a security issue.
Are you liable?
I feel people really try to pick the worst possible interpretation of these laws just so they can hate on the EU.
What is software in this case? The open source software you developed as such or only the Installations you sold support for?
This part isn't clear enough to confirm you assumption.
It could mean the software instance installed by your support customer, it could mean the software as such you intend to sell support for, no matter if you are really get paid for support or not.
Sadly, with these laws, we'll have to wait for some case law to be certain of the liabilities to serving Europeans customers.
I had a similar reaction to the whole thing about some new anti-Tiktok law in the US potentially banning a whole bunch of other things, but nobody is actually sure. Like, is it a weird idea of mine that you should define your laws based on what you want them to do and then test them to make sure they are right before they actually, you know, become laws? How can no one know what the law will actually do until the law is actually enforced?
If I wrote software like this I would be instantly fired. Can somebody please explain?
I’m not sure this is a good metaphor, but I think the main thrust should be true: the whole thing is adversarial like you’ve never seen, and that’s not at all the best way to establish truth, just the best you can do without trust assumptions. (Law : science and engineering :: democracy : benevolent dictatorship.)
For example, in the US, you have y things like https://en.m.wikipedia.org/wiki/Office_of_the_Legislative_Co... which helps the house draft bills.
If aerospace engineers built airplanes the way you (or me) code, they'd be in prison.
I don't think software developers have any right to criticise - we are the clowns of engineering world.
The software around me fails all the time, coffe machine refuses to make coffee becauae there is no wifi, toyota has spaghetti code controlling the accelerator, average home router has over 9000 securiry holes.
Even if you look at our industry standards, the HTTP standard has flaws allowing Request Smuggling, JSON standard is not compatiable with javascript, and Javascript itself...oof...
Really? I don't recall anyone going to prison for the 737 MAX. Not even the engineers reviewing the code written by the offshored 9$/h programmers Boeing hired...
> the HTTP standard has flaws allowing Request Smuggling
As if the building code didn't too change over time.
That doesn't mean they will always get it right, but it's often screwed up more by the legislators than the attorneys.
Laws that are so vague that they don't give notice to someone of what conduct is proscribed are not valid in the US.
Additionally, in the US, laws found to be unconstitutional are void ab initio. They are not struck down. They are declared never to have been valid in the first place.
(Though, like anything, perfect consistency is not a goal of the legal system, so you will see this screwed up at times as well)
I'm not sure how much I'm allowed to share but it'll be public at some point in April I believe.
Also, many open source projects have very complex authorship, good luck digging which company is responsable to do the audit.
Also, basically your favourite cloud provider could host your favourite open source database, but the authors providing hosting would be liable. Because "This Regulation does not regulate services, such as Software-as-a-Service (SaaS)"
Oh shit, this is huge. I wonder if it applies retroactively for code in the wild, as an open source contributor you can't recollect you code back.
There's people like me, who moved from the UK to Germany as a direct reaction to Brexit. I don't have a Boolean heaven-or-hell (Devon-or-Hull?) attitude to any of this — Brexit itself was stupid, but not (yet) the worst thing the Westminster government did to United Kingdom people. Sure, a repeat of the Potato Famine may happen, but probably not.
Then you've got people who have made it part of their identity. On both sides, they're never going to admit the possibility of Team Them making the slightest of mistakes.
For example, the specific mistake of the government passing a law that allowed a regional ambulance service to find out the preceding 6 months of internet domains accessed by any person, without any need for a warrant; something that was obviously not compatible with the Human Rights obligations but which the government passed anyway, and as that government was loudly conflating the EU with the human rights courts, I just assumed they'd force it into effect regardless of any objection I could bring, when they actually managed to leave the EU.
https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016
"Less bad" isn't automatically perfect (the topic of this discussion may be an example of such an imperfection), but it is less bad.
Wow. And people voted in favor of that?
No wonder we're flooded with resumes from the UK over here...
First it was fonts and cookies, now this; I don't want to see where this jaw-dropping progression ends up.
In 2016 I thought Britain was absolutely mad, but they're starting to look smarter and smarter
I heard a third-hand story about a Boeing engineer held responsible for an aircraft crash in China, and the US was going to extradite him to China. He committed suicide. Don't know if it was true, although it was a Boeing employee who told me about it, and she certainly thought it was true.
But big players (who were consulting politicians when GDPR regulations were written) only won from GDPR, they don't need to show the cookies banner all the time on their platforms and still have a lot of power over your private data.
Certification of software is always expensive, so expect new open source licenses: "Open source as usual, but if you are from EU, you are not allowed to use that code".
Or expect Amazon to take an open source product, close source their fork, do certification and provide SAAS.
Again, there are companies who can do some commercial support for their code, but they are really could not be interested in adopting all the EU regulations.
And how about Linux, or Android... or iOS, they contain open source software as well. Could you go after some random kernel developer for a bug that affects Android?
This hasn't been tought through in any way, the ramifications could be enormous.
But it never happens. The only example is Google leaving China because of authoritarianism. And now they are back.
Maybe it can happen to a tiny country. But do you actually imagine that the entire 17 trillion economy of EU will be left without software?
Companies do not 'just quit' huge markets. They don't leave money on the table.
And here we are not talking about "basic decency" or taxes. The audit requirements by the new EU law are extremely expensive. They assume that every software developer is BigCo. I don't see that the EU is requesting every tabloid article to be fully audited to remove false claims or that each medical decision must be audited. The requirement is disproportional.
The regulatory burden is so disproportionate that only a few large companies can operate following all the regulations and arbitrary rules set by the Europeans unelected bureaucrats. In turn, large companies raise their prices, but it doesn't matter because they are the only game in town left since smaller companies simply can't compete.
So the European consumer ends up paying for all the extra compliance through less competition while the bureaucrats pat themselves on the back and politicians keep getting "big victory" against the "evil foreing tech giants".
Being blocked from PyPi and npm would probably catapult EU software quality ahead of America... and without them hosting it on GitHub to feed into our LLMs to circumvent their IP? Oof we'd be in trouble...
Mr Nüll
Null St
0°N, 0°E
https://en.wikipedia.org/wiki/Eduard_van_der_Nüll(I assume this is a record error) https://goo.gl/maps/fDEbp5ymtTiYPMKZA
| I call my billion-dollar mistake. It was
| the invention of the null reference in 1965.
|
| -- Tony Hoare
It might turn into a real billion-dollar mistake, not just a metaphorical one...- From the Eclipse Foundation: https://eclipse-foundation.blog/2023/01/15/european-cyber-re... and https://blogs.eclipse.org/post/mike-milinkovich/cyber-resili...
- From the Internet Society: https://www.internetsociety.org/blog/2022/10/the-eus-propose...
With more to come... This is a serious situation.
Hopefully they know what they are doing and revise the law.
I have never understood why software is some special place. Specially if entity has anyway to monetize it.
The source of the problem is a particular approach to legislation that has become popular in the EU that purports to regulate across the entire supply chain for a product. Which might make sense for production of physical items or for software developed completely from scratch 30 years ago under a waterfall model, but is strongly disconnected from the way software is currently built.
>Google wants to work with government to secure open-source software
https://blog.google/technology/safety-security/making-open-s...
https://www.techradar.com/news/white-house-calls-summit-on-o...
https://www.engadget.com/google-open-source-private-public-p...
And 2 years since:
>If your open-source software project is considered "critical", you could be facing a lot more work and responsibility in the future. But for now, it's just some ideas from a few of Google's top engineers.
https://www.zdnet.com/article/open-source-google-wants-new-r...
But the python licence explicitly says:
PSF is making Python 3.11.3 available to Licensee on an "AS IS" basis. PSF MAKES NO REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED. BY WAY OF EXAMPLE, BUT NOT LIMITATION, PSF MAKES NO AND DISCLAIMS ANY REPRESENTATION OR WARRANTY OF MERCHANTABILITY OR FITNESS FOR ANY PARTICULAR PURPOSE OR THAT THE USE OF PYTHON 3.11.3 WILL NOT INFRINGE ANY THIRD PARTY RIGHTS.
So it's not sold to you, and not distributed with any implied level of quality or guaranted service.
That is an incorrect expectation. Even in the American legal system "I said don't do that" is not a shield against liability. In the EU framework a new law can pretty much create any new liability they want, so a disclaimer absolutely could be rendered meaningless.
Also IANAL. As someone offering open source software for free, what shields you against liability in the American system?
If you sell rope with no label for anything whatsoever, and people use it to do rock climbing and die, I doubt you will lose in court.
Yet again, IANAL at all.
1) very large corporations
2) who use a lot of components they don’t make
This seems almost designed as protectionist legislation for dinosaur companies unable to manage their software dependencies at any level of competence.
I don’t think the airbag vendor should be separately liable to the user since it’s the auto vendor’s responsibility to ensure that the holistic system works- even without considering the case of open source wherein there’s no contract at all between the OSS “vendor” and either the immediate “buyer” or end customer.
People can sue for pretty much anything and there's a good chance you have to (or at least should) get a lawyer if that happens. While it's arguably negligible, there is some risk in putting tools/code out there even if it's free and not warrantied.
If something warranty-worthy happened with a tire, I'd just take it to the dealer and have them deal with it.
In the EUs model of social democracy citizens does not need to bear responsibility for their actions, but it’s government’s job to enforce everything is in harmony. “Someone else” e.g. corporates are responsible for any negative outcomes. Whether or not open source, or many other Internet produced contents, fits into this model is secondary. This is also very easy for politicians to sell as the evil is always outside (US corporations, China, Russia) and there is never anything wrong with country or its citizens themselves. If people can go to Internet and hurt themselves e.g. by downloading an application or a package of course it must be someone else’s liability.
Same was with GDPR... It will benefit companies, who have money to do audits (and companies which do audits).
The FSFE has already explained to them why the liability should be shifted to the company shipping the actual product.
Does this mean the license may be invalid entirely in the EU, making it so you actually just can't use the software at all? I know that's how the GPL basically works, if you don't accept the GPL, then you simply have no license at all.
I mean one day they could also say copyleft is unreasonable and illegal, so now the GPL is just a free for all.
It’s different from if the law would say that the whole type of contract is illegal.
This sounds like more of the same. The proposed EU law applies to commercial activity, which volunteer FOSS development is not. So now we have commercial interests trying to fan the flames of another hysteria.
And last time this came up it seemed widely believe that a donation link is commercial activity.
- it only applies if you are directly selling a IT product/software to consumers.
- when you use third party components and find a security flaw in them you have to inform the third party immediately.
- in addition if you find a flaw in open source code you should send a patch if you are capable of doing so.
The responsibility lies with the commercial vendors however, not with the open source developers. What a perverse world we live in, that that can even be possible… Using our software for free and then holding us responsible… ha!
Yeah...slap in the face for open source contributions that literally chnage the world for the better.
If true, this is insane.
Although I think in many cases, the people doing this aren't aware it's happening. It's a git action kicking off some jenkins agent somewhere in a kubernetes container on a virtualized server that was set up and forgotten about based on a patchwork of online tutorials.
I expect the EU to continue to falter in cutting edge tech as a result. Software in particular.
"Citizenship of the Union is hereby established. Every person holding the nationality of a Member State shall be a citizen of the Union. Citizenship of the Union shall be additional to and not replace national citizenship."
I guess they can continue to export luxury brands and tourism.
I think Europeans tend to have an aversion to success/wealth and are scared to go out and try and build something. Just be conservative and go and work for a company that underpays. But at least you get to go on a vacation a couple times a year.
I feel like the time I've spent in Europe and the time in the USA is that Americans are optimistic that something can be done and they go out and take a risk. Europeans are skeptical of anything new. And to me it's weird because the way social safety nets tend to work in Europe, people should be taking risks left and right. And to be sure there's no lack of very talented engineers in the EU.
Is it that Europe relies so much on legacy? Their legacy colonial relationships around the world, their legacy brands, etc?
DISCLAIMER: Following text is not a program code. It does not work. Do not execute it.
And call it a day. As long as it was only brought to the market as a piece of prose, you are safe. :-)
I have actually written some Open Source licenses [1], and one different thing about these licenses is that they are null and void if the law requires the original contributors to accept any responsibility for the software unless they voluntarily accept it.
In my opinion (IANAL, but I wrote those licenses), if things passes, then anything licensed under my licenses would not be legal to use in Europe or by EU citizens.
Licenses will now need protections like this to keep FOSS alive, and places with laws like these will lose out.
By the way, my licenses are currently being checked by a lawyer. However, it may cost me more than I can spare, so I may not be able to get them fully checked.
It's a pattern of EU law makers going after the little guy: VAT MOSS, GDPR, now this. Not much of a problem if you have an accounting department next to legal department on the same floor of your corporate building. A huge burden for a small guy who only have limited number of man hours to distribute between paperwork and actual work.
It's demonstrative to read the official EU impact assessments for a lot of their recent legislation. For example, the impact assessment for the EU AI Act estimated prior-to-launch compliance costs for a small business with one AI product at €400,000. But when you look into the assessment in more detail, that estimate actually excludes legal costs (not joking here). It creates a very uneven playing field for small innovators.
Passing out poison for free doesn't go too well in real world, I don't see why software should be really different.
then you will never have bugs.
I have a couple things up on GitHub that are fit for my purpose but you probably don’t want to be using if your threat model is higher than “huh, that doesn’t work”.
I have no expectations that anyone will ever read the code much less use it but it costs exactly nothing to put it out there on the off chance it may be useful to somebody.
So, yeah, I should be responsible if someone hacks some crypto kitty clone and makes off with a billion dollars?
It's illegal to give out free poison in the real world? how do they sell it then?