EU's Cyber Resilience Act contains a poison pill
theregister.com
theregister.com
> In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.
From context it reads like open source is excluded unless the company developing software is selling services in the EU, in which case I don't see why open source software would need to be treated any differently from closed source software.
I think it's very valid to object to the lack of a definition of what "free and open source" means (free as in speech or free as in mattress, for one). However, that doesn't seem to be the part that most of these companies object to.
"If we post the source, we don't have to follow the CRA" would probably just lead to source dumps of crapware so that the law can be ignored. The cynic in me says that many of these objections are from people who don't want to be forced to patch the software they sell.
Luckily, this is just a proposal for now. I see a lot of things I like in this proposal. Putting pressure on manufacturers to patch their shitty hardware might finally do something about the botnets of media players and security cameras that plague the modern internet.
You know, how with FLOSS software (IIRC) you MUST provide the source on request, but CAN demand to be paid for the inconvenience (hosting, bandwidth, shipping physical storage...)
Seems like this wouldn't be an issue, but it would still be nice that this situation had been covered by the law.
P.S.: GPL :
https://www.gnu.org/philosophy/selling.html
"Distributing free software is an opportunity to raise funds for development. Don't waste it!"
OS :
"The license shall not restrict any party from selling or giving away the software [...]" (Emphasis mine, literally the first non-fluff phrase !)
The payment you can demand under GPL explicitly isn't allowed to be a money maker. It's to cover the costs only. I wouldn't classify that as commercial and I'm not aware of any laws that would.
That seems extremely ambiguous to me. What does "software developed or supplied outside the course of a commercial activity" mean. Is it all of the piece of software? What if you pay me to develop and submit some patches to a gnu project? That means that, at least in part, the project was not developed wholly "outside the course of a commercial activity".
What about if I have a free and open source project, then you come along and pay me to make some changes you need. Is the whole project now covered by such a law?
The law is not geared towards "just putting some software on a server and calling it open source" which is what most projects do. It is geared as far as I understand towards bad IOT devices, among others. People sell them and know outright that there are existing vulnerabilities, and that rightfully should be illegal.
I think (maybe after some adjustments) this will be a boon to open source. Because every company shipping a program or a physical product with some GPL or MIT source inside will now be forced to bring it up to good quality before making money out of it. And at least in case of GPL, it is likely it will be contributed back to upstream. (I personally prefer upstreaming all open source code even when not required to share it, because you don't have the burden of maintaining a fork, and you have a better relationship with the developers in case you need to incorporate new features.)
As someone with lots of software publicly available with permissive licenses I absolutely do not want to participate in letting the "courts decide". If this was going through I would be strongly considering adding a banner saying that this software is not for EU consumers with the alternative being denying the fact that I am aware that EU people were using the software.
I am happy to provide my software as-is with no warranty. But if there is a chance that I am somehow on the hook for any guarantees about that software I'm out. It is just too much risk for very little gain.
This should be incorporated in the license.
The alternative would be a (paid) support contract for EU customers.
If you're just making your code available for no charge and not selling the product, the obligations don't even apply under the current proposal.
Sadly, we'll have to wait for the courts to settle the first cases.
I imagine such a contract would be fabulously expensive. Typically, FLOSS software with support contracts is for relatively complex software; the organisation offering support is often not the organisation that develops it.
If offering support on FLOSS software exposes you to legal liability, then you need insurance, and insurers aren't going to have the expertise to price the risk. So premiums will be top-dollar.
I think the (misguided) intention is to strongly favour commercial software production over one-man-and-his-dog FLOSS developers.
If you're selling support licenses to the EU for your open source software then you're on the hook for patching them, but you'd probably already be for other reasons.
> it hinges on whether offering open source software on GitHub is considered a product in the sense of the law.
I assume Github and friends are much more concerned with being on the hook for selling these products (i.e. through Copilot). Github does sell you software that happens to make open source code available, and that seems like a much more vague situation.
What difference does it make... If small developers and software businesses risk thousands of euros of fines, decided arbitrarily by the courts based on civil minimum and maximum limits, open source and small software in the Eu will die and the only ones to benefit from this will be the larger software companies that can afford the fines - who will be scooping up all the users of these open source projects and small developers - like the German software businesses who back the current German government and the German contingent in Euparl.
Note how the draft is designed to exclude the software that these major software companies are mooching off of - like Linux. Its basically exclude what you benefit from, kill who eat into your profit margins and be happy - total American corporate style legislation...
How can arbitrary fines that will be decided by the judge and that can reach up to hundreds of thousands of euros from a few thousand euros per violation be a boon to open source...
Open source already has a problem funding itself. The funding comes from major corporate donors, who naturally decide the direction of the large projects they fund. The only Open source segment that successfully funds itself through its community members, users is WordPress, which remained free of corporate domination for a very long time as a result.
With this law, any small time open source software producer and any small time private software producer risk themselves and their livelihood for producing software, based on ambiguous rules. Which would make it very difficult and risky for small time projects or companies to produce software in Europe, and as a result benefit the big companies that can actually afford those fines.
This looks like a law crafted by the large German software business that currently dominates the German govt. and Euparl to hamper small time software for their own benefit. When the small open source projects and private software developers close up shop, the software and SaaS of these large businesses will scoop up their users.
To the contrary of being a boon to Open source, this may be the biggest, most well-coordinated attack against Open source in decades...
Look what happened to the Amiga, and former propietary software companies with in-home rewritting refusing to co-operate with standards. If they want to be the next idio... dumb CEO's trying to not be lynched form the share holders, I'm totally fine. They... won't.
Note how the legislation is drafted to exclude the large open source projects that these companies mooch off of - like Linux. Both the large software companies and the projects that they sponsor can afford the fines.
But smaller software producers and open source projects that fund themselves through their users cant. So basically the law will kill smaller software producers and let the larger ones scoop everyone into their profitable SaaSes and installable software...
That's how it looks to me too.
Have you ever seen the decisions made by boomer judges in bumfuck German courts? What a dream for troll litigators.
https://www.quad9.net/news/press/quad9-s-opinion-of-the-rece...
I can safely say that I don't now the answer to the question and therefore I cannot draw conclusions as far reaching as the article author does. Effectively, the CRA is going to impose certain security standard on software products. People in medical, automotive, aviation, military fields were already subject to certain security standards, so GitHub's claim regarding unobtainability is demonstrably misleading if not outright false, depending on definitions of safety/security standards.
As it pertains to open source, it all depends on whether mere publication of open source software would be considered product release. I can agree with the author here that clarification may be needed. An important note here is that such regulation (OS is not affected) would have tremendous effect on open source. The companies using open source software in products would essentially be forced to either take open source under their belt with proper controls in place or be effectively forced to properly support open source development by at least providing security oversight. Sincerely, I have no idea what effect that would have as a whole.
While also GitHub seems to have done a decent job during the consultation, I'd take the genuinity of their position with a grain of salt due to the CoPilot fiasco. In fact, they are saying that "open source licenses disclaim all warranty, making explicit the expectation that any entity seeking to use or integrate the open source software bears responsibility to ensure its compliance with relevant laws". The pot calling the kettle black.
https://ec.europa.eu/info/law/better-regulation/have-your-sa...
Looks like he has lobbying experience :)
Chill? More like obliterate. If this bill goes through, almost every single open source repo is going to necessarily end up with a banner saying:
"MIT licensed ex EU. If you are an EU entity or intend to use this software in any way that may result in an EU entity coming into any contact (even indirectly) with this software, you are excluded from all rights granted under this license and prohibited from using any code provided here."
That would be immoral and entirely unenforceable.
They're not idiots.
Maybe it's a bad law. It could be. But this FUD distracts from a real discussion about its merits and flaws.
https://en.wikipedia.org/wiki/Max_Schrems#Schrems_I
But enforcement has been slow-moving :
"German state of Hesse has banned the use of Microsoft 365 in its schools (2022)" :
https://news.ycombinator.com/item?id=33741537
Also there's an even more recent precedent with the new directive about the obligations of content displayers (typically regarding copyright takedown requests) : in the end the directive is at least somewhat accommodating for the small/new/nonprofit displayers.
More: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
If EU’s intention really is to assert a level playing field, then they just achieve the opposite.
To even pretend otherwise is idiotic. Regulation benefits mainly big incumbents, this has always been so and should be known by everyone who is even remotely interested in this topic.
This is a gross overgeneralization.
There are many examples of regulations explicitly intended to increase competition.
It could very well be that this specific law does benefit big incumbents more.
This remains a curious example. Nebraska is not an EU country, it's an American state. EU law doesn't apply. The Nebraska developer (or me in my state) don't need to care beyond that if enough Europeans were interested they might contribute patches to meet their own new reqs, or make requests over it, and then maintainer would need to judge if it matched/was worth it, and if not it might get forked into a CRA one, or not. Ie., just the normal open source process.
Unless someone can point to an American (Japanese/Australian/Canadian/Korean/Mexican/Chinese/Indian etc etc) law passed promising equivalence this continued notion that the EU laws are global is really weird. Certain things they've targeted at companies work, because said companies wish to have physical business within the EU, and the EU of course has jurisdiction over everyone within the EU. So the cost of not complying is the cost of losing a large chunk of business there, and since it's a huge market that's a big motivator (though not infinite, even for megacorps). But for those who don't have any physical interest, what's the issue?
It’s gate-keeping at its best. This is a blow to SMEs and a protectionist move on behalf of large enterprises.
In my head, the reasoning is the following: certification will be another bureaucratic process to follow. It will cost money, it will require human resources on both sides, it will feed some companies who don’t have to do shit to turn profit—companies started to feed on others as those who “certify”, it will most likely imply that someone from the bureaucratic machine will look into your source code -> trade secrets, anyone? Big players (not going to name them here) like companies like SA…, De… Te… have enough resources and financial backing to push through that. The point is, they cannot compete with OSS on dev pace, they found a workaround - kill OSS and impact SMEs by putting a legal barrier to entry.
On a personal note, as an EU-based person, I start getting fed up with this shit.
I guess it depends on what counts as "proof", is that clear yet? I was thinking that if certain code practices and such were enough, then maybe an EU-based dev would then contribute the changes necessary to meet that should the original maintainer(s) not be interested, or fork it to do so. The details really matter, there are certain best practices that are a perfectly good idea anyway and also don't hurt future maintainability or the like at all, so the ideal would be something that encourages making such changes and then effectively "goes away" as a concern. Removing old ciphers/hash functions completely for new products for example, government might usefully provide industry a kick in the butt there, but once someone has moved on from MD5 it's not like they'd need to think about it again.
As you say though if it instead turns into an expensive bureaucratic mess, or as bad or arguably even worse pushes anti-maintainability/security practices (which has happened! in the US there was a long period of awful anti-security password policy stuff floating around that came from outdated "best practices" reqs), then that'd be a major issue. And regulatory capture is indeed always a concern with new acts like this too.
Audits are discussed everywhere.
As a PM in a previous position, I would have loved to fix known bugs, contribute back to open source, audit things properly. But when there was no legal pressure to do so, my bosses (understandably) said: great, that software is for free, take it, don't put to much work into it, ship it.
Like it or not, open source software is part of our supply chains, and if there is no incentive to maintain it properly then that's a big problem.
Edit: there the other side of the coin. A single dev who wants to enter the market has an uphill battle. He is required to certify their own work, and provide audits of all dependencies. Good luck starting a business from your bedroom un such climate. If this is what people in the EU want, paraphrasing:
I don’t want to live on this continent anymore.
It depends, but in general there is significant, straightforward incentives to upstream most stuff. It makes things a lot cheaper over the long term for all involved, and particularly with security/stability and basic code hygiene there is basically never going to be any "special sauce" there where the company is getting some major additional value. It's all cost centers. So if an EU-based company audits and then needs to make some changes to a non-EU-based project, I'd assume by default they'd want all those changes upstreamed and made permanent since it'd reduce the burden going forward. Though again this is all highly speculative based on how it actually works. Also
>A single dev who wants to enter the market has an uphill battle. He is required to certify their own work, and provide audits of all dependencies. Good luck starting a business from your bedroom in such climate.
It is true I'm thinking of it from a non-European point of view, where it's not starting from scratch and by default it's not my problem. I'm not trying to downplay possible disincentives in those in the EU starting projects de novo. I just don't know enough about it.
Humans aren’t behaving logically. If a company A audited their dependencies, it doesn’t benefit them at all to “upstream” their audits because: 1) dependencies are already audited for that company and only new version has to be audited in the future, 2) holding an audit will be a competitive advantage because everyone else has to consume their resources to get audits in place, 3) “my people on my salary got those audits for me so if I had to pay for it, the others have to pay, why should I share that when I paid for it, it cost money and sweat, nobody’s getting it for free”.
However, the EU would have a much more difficult time enforcing fines on entities with no European presence. In principal they could go through the international treaty system, but that would be very slow and expensive. I'm not aware of any case where they've actually successfully pursued this for non tax / copyright fines which tend to have special arrangements although I've not looked into it that much. Please let me know if anyone is aware of any precedent.
Ultimately the ability of one country to enforce fines on another relies on goodwill and diplomacy. What could the EU do to say, India, if their courts declined to enforce a $20k fine on a small developer or take 7 years to decide the matter? Even if they were technically allowed to go after sovereign Indian assets instead by a treaty or threaten sanctions, it's hard to see the diplomatic cost being worth such a small fine.
Extraterritorial jurisdiction isn't a new or unusual concept in the slightest, and I don't understand the recent trend of pretending that it's only the EU does this. The classic examples of money laundering, organised crime, sexual crimes committed against children, female genital mutilation, anti-competitive laws, etc, are so mainstream at this point that I don't think any Westerner would consider it controversial for somebody who does these acts in countries where they are less regulated to be arrested for them upon arriving in a Western country.
There's also more HN specific examples like cybercrime, with a recent example being the arrest of Marcus Hutchins. Or copyright, where anybody from countries with less strict copyright laws from the US knows what I'm talking about. Japan has strict copyright laws too, and game companies like Sega and Nintendo are notoriously protective of their IP to the point where Sega has apologised for abusing the DMCA to take down videos produced by North American and European nationals. COPPA predates the GDPR by 15 years and is applicable everywhere. The Canadian Anti-Spam Legislation regulates sending spam to Canadians. The German NetzDG will send you a strongly worded letter if you criticise Germans.
Many data protection laws also regulate how you handle data of their nationals. For example, the data protection laws India introduced in 2011, applicable to businesses that outsource operations to India, were described as much more restrictive than the EU or US counterparts. China regulates that foreign businesses doing business in China store all their data in China. South Korea has no scope on territory for their PIPA, but it's hard to tell if this applied to their 2011 legislation or just their 2020 legislation as these laws obviously aren't in English. Many newer laws are modelled after the GDPR and also have no scope on territory, e.g., Brazil, California, Russia, etc.
There's other more general examples too. Many countries criminalise taking drugs, and evidence that you've taken drugs in the past can lead to you being deported. Consumer protection laws are generally pretty strong and banks will side with consumers in issuing charge backs. Anecdotally, Steam had a no refund policy for the longest time and support staff would berate you for asking for a refund for a game that doesn't work, but they still issued refunds and now have a refund policy (even if it doesn't fully comply with local laws). America regulates exporting arms, which caused a lot of drama in the Linux scene in the early 2000s when encryption was (still is?) considered munition. Doing commerce with embargoed or sanctioned countries can land you in hot water too, it might make sense for 'bad guy' countries like China, Russia, Iran, etc, but the US and Israel stand alone in defending the embargo on Cuba. Many countries have restrictions on freedom of speech, it might not be the best idea to travel to Turkey if you publicly criticise Erdoğan. Etc.
--
None of this is to say that I agree with what the EU is doing, or that these examples are 1:1 parallels, but I think the attitude of 'these laws don't/shouldn't affect me' is naive at best, unless you plan on never leaving or doing business outside of your own country.
Rant over.
Honestly I don't understand why is it not done the same way as for other certification. You only need to have certification once you start selling your product in a regulated industry - e.g. a connected device in this case. If you use any components (hardware or software) it's your responsibility that they are either pre-certified for you (what commercial suppliers would do) or certify them yourself. This would shift responsibility from open source maintainers to where it's due.
Legal systems do not have to be coherent or logical, only actionable.
OSS is decentralized. Everyone has source access. The police will have to arrest everyone, including themselves.
"arrest everyone" is some bizarre fantasy that the legal system is both ineffective and stupid.
That's not a charitable interpretation. Try re-reading what I've written from the perspective of someone pointing out logical flaws of a proposed law.
That's what the commenter is responding to. Laws are clearly not applied logically, and while you may be able to make that argument in court, it's never clear that it will be accepted.
I don't disagree, but I'm not making a defense argument in a courtroom, I'm making a logical argument about a proposed law on a message board.
I agree laws are not applied logically which is why they must be scrutinized logically before they become laws.
The logical conclusion of that is that we shouldn't have any laws... Except it's not true. Of course laws are not applied strictly accordingly to the laws of logic, nothing is, but there is a relatively high degree of logic and predictability in the legal system.
That doesn't stop absurd rulings in some occasions. But from that concluding that "laws are not logical" is an overreaction.
Things may be less clear when it comes to donations, where customers don't directly purchase a service yet the developer makes a bit of money, but from the context of the proposed text I don't think that is what the law intends to cover.
Support is a gray area. Not only are there different kinds of support that have nothing to do with code, like selling training material, but there is also selling ones expertise of a codebase as a consultant without necessarily making code changes oneself. Presumably one could author a support contract to state that the code is a fork, regardless of whether there are changes or not, and that the price paid is merely a consulting fee.
If you accept the premise that OSS is decentralized, then so is the right to repair. Anyone can learn the code and charge a one-off service fee for fixing a defect. I'm not sure how liable one could be here. If you sell an annual support contact then presumably you're only on the hook for the year and not the "lifetime of the product" which is vague given the decentralized nature of OSS.
https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-la...
to wit: under a reasonable reading of the legislation, having any commercial activity (classes, conference tickets, etc) opens you to liability. Or imagine selling support.
Additionally: if open source code is included by someone besides the author into a commercially available product, it's not clear that the open source author doesn't hold liability there. Even if the author received $0, or is unaware of the use of the software he/she created.
Perhaps the most striking issue revealed by the CRA is that open source stakeholders apparently do not have their NGOs at Brussels (or Capitol for that matter). There would be all kinds of opportunities like lobbying for funding, or fighting Big Tech if that is your game, etc.
I wonder how this will affect the business model where you get updates while your subscription is active.
A "poison pill" provision or amendment is an element deliberately added to turn people who otherwise would have supported the legislation against it. The person proposing the poison pill is acting it in bad faith - they have no expectation of it passing, they might not even support the idea themselves - the only reason it's added is to make the original legislation's supporters drop their support, killing said legislation.
I don't think anyone is seriously proposing that the EU is deliberately hamstringing open source in order to kill their own cyber-security act. They've just written a bad piece of legislation.
Maybe something like "food poisoning pill"? Made with good intentions, but without proper understanding or taking proper precautions, so it becomes toxic...
This is way too fine-tuned to destroy small software segments, open source and private developers included, for the benefit of large companies that will be able to afford the potential fines.
That’s different from a poison pill amendment, where the intention isn’t to actually implement the policy, just to kill the legislation that you’re attaching it to.
The use of the term here is unfortunate because it's not a poison pill in this typical legal/contracts sense, but rather the writer's attempt to characterise the clause as a deathblow for OSS devs.
This isn't a detail; it's the whole point.
EDIT:
To better understand why these regulations are pushed forward throughout the world, read for instance Huston's elegant piece:
GDPR was so completely inconsequential for EU start up. We have to stop with this constant EU bashing. You know what EU-based start-up do to comply with GDPR ? They don't. Most of them copy paste a generic GDPR legal statement and name the CTO/CEO the DPO. And if they receive a GDPR request (it almost never happen), they just handle it manually.
Now, when you get big enough (or if you start to do really obvious egregious thing with data collection/processing) you might attract the eye of your local data protection agency. And if you really do naughty things they might, gasp, send you a letter and ask you to comply. Only repeated offender and company who really didn't care about even the most basic principle of the law end up being fined. And in most case, the fines are weeeell within reason. Or, as we say, "the cost of doing business".
The only actor who were somewhat annoyed by the GDPR were huge data hoarder.
They're called investor-state dispute settlements, and they let corporations sue governments for loss of profit from things such as environmental protection and public health laws: https://en.wikipedia.org/wiki/Investor%E2%80%93state_dispute...
Bridges can’t be downloaded from Russia, however, and requiring open source devs to carry liability insurance probably just destroys open source, so I am genuinely unsure how you solve this in practice.
But I think that is a conversation we should be having, rather than just saying that the status quo is the ideal, and allowing no room for discussion.
In the area where I live there are few privately owned parks that are open to the public and according to the owner, they can basically do what they want in one of those parks as long as they tell people that they're using everything at their own risk.