TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Debian Statement on the Cyber Resilience Act

183 pointsby diyftwover 1 year ago

17 comments

gavinhowardover 1 year ago
I believe our industry needs regulations and liability, but the CRA could be dangerous. (See my comment at [1].)<p>There is a better way [2], but I don&#x27;t know how we would convince politicians that there is a better way.<p>[1]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38788919">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38788919</a><p>[2]: <a href="https:&#x2F;&#x2F;gavinhoward.com&#x2F;2023&#x2F;11&#x2F;how-to-fund-foss-save-it-from-the-cra-and-improve-cybersecurity&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gavinhoward.com&#x2F;2023&#x2F;11&#x2F;how-to-fund-foss-save-it-fro...</a>
评论 #38789571 未加载
评论 #38795357 未加载
hgs3over 1 year ago
&gt; CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA.<p>Isn&#x27;t that the idea? If you can&#x27;t innovate, litigate - see regulatory capture [1].<p>We hold the power, not the EU. Debian, FOSS developers, and small businesses world-wide should block EU IP addresses. No more Linux, no more Python, no more nothing. When the EU&#x27;s digital infrastructure begins crumbling they&#x27;ll change their tune.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Regulatory_capture" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Regulatory_capture</a>
评论 #38791260 未加载
hcfmanover 1 year ago
And don&#x27;t skip over the part where they want developers to report any zero day&#x27;s you discover to them within 24 hours so they can use them as exploits against innocent civilians not involved in any crime. And yes, the Netherlands changed the law recently so they can do this and without requiring any judge involved. And yes, they are allowed to hack people not involved with any crime as well. As well as changing the law in 2020 so all of government, including their prosecutors may law in court under oath and not be held liable.<p>And then they want other people to be accountable, how about government be accountable first.
评论 #38799699 未加载
63over 1 year ago
A lot of folks seem very angry about this and are making some broad statements with no specific citations. Can someone please give me a specific quote from the bill and explain how that will for sure be detrimental to open source projects?
评论 #38788919 未加载
评论 #38788957 未加载
评论 #38790518 未加载
hcfmanover 1 year ago
It’s time for governments to have more responsibility. The cyber resilience acts pushes 15,000,000 euros penalty to software developers. How much liability does government have for anything bad they do ? First it’s extremely difficult to get to them to be responsible for anything. Then in the Netherlands any liability would be a pittance. Nothing like 15,000,000 euros.
Karellenover 1 year ago
Maybe change the link to the actual result, rather than 2nd-hand reporting?<p><a href="https:&#x2F;&#x2F;www.debian.org&#x2F;vote&#x2F;2023&#x2F;vote_002#statistics" rel="nofollow">https:&#x2F;&#x2F;www.debian.org&#x2F;vote&#x2F;2023&#x2F;vote_002#statistics</a><p>(No matter how good LWN&#x27;s original journalism is, this is just a news link that does little more than link to the source itself)
评论 #38788650 未加载
hcfmanover 1 year ago
It’s time for everyone to put a clause in their licenses banning direct and transient free use of their software for governments.<p>I have two projects and added such a clause in protest.
nparafeover 1 year ago
The Debian team announcement is on the right track. Asking freelancers and free software groups to face the same measures and fines as big tech companies is unfair competition. The E.U. of course, was never friendly to free software[1]. The bureaucratic and neoliberal extremists that are in the lobby of Brussels will always try to destroy free and independent creation.<p>[1]: <a href="https:&#x2F;&#x2F;totsipaki.net&#x2F;ikiwiki&#x2F;nparafe&#x2F;posts_en&#x2F;posts&#x2F;Can_European_union_save_free_software&#x2F;" rel="nofollow">https:&#x2F;&#x2F;totsipaki.net&#x2F;ikiwiki&#x2F;nparafe&#x2F;posts_en&#x2F;posts&#x2F;Can_Eur...</a>
jocodaover 1 year ago
Given that this will affect costs by one, maybe two orders of magnitude, why would any developer want to do business with the EU.<p>Is disqualifying EU users even possible?
评论 #38792451 未加载
teerayover 1 year ago
Obviously it wouldn’t work for a project as large as Debian, but I wonder if there is some exclusion clause that can be inserted that forbids all users that would be covered under the Cyber Resilience Act from using the software?
评论 #38789271 未加载
评论 #38789354 未加载
评论 #38789819 未加载
评论 #38793755 未加载
评论 #38792464 未加载
omgmajkover 1 year ago
&gt; It&#x27;s very unfortunate to see such anarco-capitalist FUD being voted as the preferred option, on such a low turnout.<p>Posted Dec 27, 2023 19:32 UTC (Wed) by bluca (subscriber, #118303)<p>Can someone explain to me what in the statement from Debian is &quot;anarco-capitalist FUD&quot;? I find it quite reasonable overall.
评论 #38789522 未加载
评论 #38790132 未加载
评论 #38788965 未加载
gunapologist99over 1 year ago
It should be obvious to everyone by now that the European Union doesn&#x27;t actually care about developers or small businesses at all.
评论 #38790332 未加载
评论 #38788471 未加载
评论 #38788531 未加载
评论 #38788675 未加载
ImmutiableTruthover 1 year ago
This makes a lot of sense if you follow judgements internationally.<p>Last year in the UK the creator of BitCoin won a multi-billion pound judgement against usurper &quot;open source&quot; developers who refused to alter the protocol to allow him to recover coins a hacker took from him.<p>Developers have a duty of care to their users which no license can remove even if they are communists calling themselves &quot;open source&quot;. You either make good software and comply with your duty or you will be ruined. That is the law.
评论 #38792477 未加载
评论 #38874911 未加载
pjmlpover 1 year ago
Small businesses and solo-entrepreneurs have to deal with liability and permits all the time in other fields, even actual street bazaars for that matter, exception being when there is some &quot;flexibility&quot; between the laws and how they happen to be applied.
评论 #38789322 未加载
评论 #38788476 未加载
评论 #38789607 未加载
candiddevmikeover 1 year ago
What about the CRA is so bad? The requirements seem like common sense. Can anyone point out something specific that seems overly onourous? Debian couldn&#x27;t...<p>Our industry desperately needs better regulations, IMO.
评论 #38788636 未加载
评论 #38788717 未加载
评论 #38788756 未加载
评论 #38789377 未加载
评论 #38788697 未加载
评论 #38789428 未加载
hcfmanover 1 year ago
Additionally, there&#x27;s nothing wrong with what we have now. So there are some security flaws. But we have really fancy mobile phones and an amazing Internet.<p>Now rewind to 1990 or so. Add a Cyber resilience act. At best we maybe have a phone about as advanced as an old Nokia. But yeah, maybe hardly any cyber security flaws because the Internet would hardly function.<p>Instead of thanking all of the millions of developers who contributed to this, they proceed to kick them in the teeth and enact laws to steal from them in principle by raising the cost of entry.
charcircuitover 1 year ago
&gt;CRA will force many small enterprises and most probably all self employed developers out of business because they simply cannot fulfill the requirements imposed by CRA. Debian and other Linux distributions depend on their work.<p>If Debian depends on people&#x27;s work so badly maybe they should pay for it.