This reminds me of the Gaia-X / IDSA certification and approval framework blanketing the whole software industry in the EU. I am not sure yet what to think about it.
On one side, it looks a bit like proprietary software vendors trying to cut out SMEs who can match the quality with the same open-source software the big players use, but have no funds to go through the certification. The really funny part of this legislation is: the big players who can afford certification will be able to use ANY open-source component for free but the people who built it will have a tough time to go to the market because they will require the funds they don't necessarily have. Crazy situation.
On the other hand, if this is applied to everyone, well, it will get rolled into the cost of providing a service. You want to buy this from me? Sure, I'll charge you for compliance report.
The really funny part of the "Call for evidence for an impact assessment - Ares(2022)1955751" document (section C.) from https://ec.europa.eu/info/law/better-regulation/have-your-sa... reads:
> The initiative is expected to have positive economic impacts.
That section completely misses to mention that increased compliance cost will inevitably lead to increased software and services pricing, thus will lead to decreased competitiveness of European SMEs on the international market.
Hot take: I can see two options to cripple this: 1) Drown the legislator in compliance requests for minor code. 2) Dual-licensing: AGPLv3 + commercial license.
Emphasis on "proposed", the current edited title sounds like it's already in effect.
So yes, this is something to be concerned about.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
The EU is most concerned about "Class II software". The stuff that runs industry.
[1] https://acronisscs.com/blog-open-source-backdoors-in-the-wil...
[2] https://www.zdnet.com/article/open-source-software-how-many-...
No there was not!
Someone in 2003 submitted a patch. To the wrong repo. The patch was looked at anyway and rejected for this reason. It was never merged. No machine ever had this bug.
Make no mistake this will just be used to implement those backdoors.
If the EU is so concerned about cyber security they should:
1) provide A LOT of funding and support for Linux / BSD and other operating systems and flavors for testing, hardening, and rapid patch rollout
2) provide infrastructure to support such activities
3) use open source software actively in government with a focus on providing feedback and patches from government IT back to the mainline projects
A founding tenet of security is that open systems and techniques are the ones that will be most battle tested and therefore resilient.
Alas open source has terrible lobbying, so the closed source vendors can lobby politicians and policy to go the opposite way: prescribe closed source solutions and additional onus on open source.
If first world economies were serious about cyberdefense and hardening, there would be 10 billion dollars annually invested into the foundations of open source software: Linux/BSD, databases, webservers, browsers, programming languages, etc. The militaries alone should be dedicating this level of funding to defend our infrastructure, economies, and whatever technological edge we have over China.
And the EU in particular should like Linux: it originated there, and has strong roots throughout the EU, and most importantly isn't controlled by a major US corporation (unlike Apple/Microsoft) and therefore indirectly controlled by the US government.
was it ever proven somehow ? I know that it seems like an axiom here on HN but I doubt anyone did tried to check it.
The negative effects seem pretty intended to me. The legislators are aware of open source software and have an exception for non-commercial activities, but intentionally penalize OSS related to commercial activities, by leaving them out of that exception.
And, at this point, I don't believe that these legislators are so stupid that they can't see the consequences of their proposals. They probably just don't care about the negative consequences, or the "negative consequences" (negative for us) are actually what they're striving for.
So for your Python software you are fine either just providing the software alone, without an interpreter, having the customer get a Python-standard-compliant (if there were such a thing...) interpreter for themselves. Or you could provide a CE-certified Python interpreter that you got somewhere else along with your software, provided you do not change the interpreter you got and the interaction between your software and the interpreter is standard, run-of-the-mill, unsurprising normal use as intended and certified.
1) commendable, but
2) the EU shooting in its foot, because
3) large rich American closed source companies will very happy to comply
4) where will they find all the auditors to check the zillion of small open source projects inside node_modules for a commercial project? And who's going to pay them? Again, closed source companies are very happy.
edit: apparently there is a similar bill in the US. So that does sound like regulatory capture.
If the Commission was proposing a law mandating that cars have seat-belts, people would be jumping in to shout "Europe is destroying free enterprise, they're trying to destroy small car-makers!"
Seriously, when you look at the list of concerned software, you have password managers, operating systems, certificate infrastructure, remote access software, industrial IoT, etc. For any software in these categories, it's not completely insane to think that "This software is provided as-is with no warranty whatsoever, good luck!" doesn't quite cut it.
And yes, open-source is concerned as well, when it's part of a commercial activity. Again, if you're being paid to provide software, it seems fair to say you're leaving the "lobbyist" category and entering the "paid professional" category and you have to worry about security requirements. Especially given that, outside of the critical projects mentioned above, you're allowed to display the CE mark if you self-audit.
Are there deeper discussions to be had here, concerns to be addressed, etc? Absolutely. I think a critical point is how "commercial activity" is defined. A threshold of gross revenue could be an interesting solution.
Are these deeper discussion happening in this thread? No. It's all "Europe hates innovation" and "I hate the EC and cookie banners so much!" Most commenters seem to automatically assume that any level of regulation is automatically going to drown small businesses and favor FAANG-scale corporations, which is more extreme than even the article calling out the regulation.
No one cares if you improve anything. They just care if you make a mistake. This attitude is a disaster.
And PoignardAzure, yes, I do believe seatbelts and motorcycle helmets should be optional. If you die because you're too cool for them, you die - simple as that.
For more context, a "critical" product cannot be self-assessed. He would have to hire the auditor.
Edit: It made me thinking, how would legislator ensure legislation is implemented? Would they start requiring escrow so they can check by themselves if software is developed to the correct security standard?
If these big corporations were paying up the fair share of profit generated by the open source software they use, I am sure the developers behind it would have funds essential to ensure the security of the software they make.
That being said, even if above was not feasible (shame!), then it should be up to corporation using the software to ensure it is secure (and possibly contributing any fixes back to the software).
(i) it is designed to run with elevated privilege or manage privileges; (ii) it has direct or privileged access to networking or computing resources; (iii) it is designed to control access to data or operational technology; (iv) it performs a function critical to trust, in particular security functions such as network control, endpoint security, and network protection. (b) the intended use in sensitive environments, including in industrial settings[...]
There's a clear distinction here between what the EU labels 'critical products' and non-critical software. Seeing the increasingly insecure global situation, the importance of software in infrastructure and the potential threats I think it's wild that something like this hasn't passed a decade ago. Digital infrastructure needs to be as secure as physical infrastructure.
I wonder what would happen if some Heartbleed-esque bug that went undiscovered for years took out a huge chunk of a nation's electricity grid in a military conflict. What the EU needs in addition is if course also more funding for software security, but they're already doing a halfway decent job. If you didn't know, if you fix open source bugs in the EU you can get paid for doing just that: https://ec.europa.eu/info/news/european-commissions-open-sou...
"outside the course of a commercial activity should not be covered by this Regulation" Is this kind of wording normal In EU laws? Why use "Should" in the law, since we are in the middle of defining what is going to happen shouldn't it be "is"?
Instead we just get more bureaucratic anti-innovation makework - just like the Link Tax, Cookie law and GDPR, etc.
OSS developers who don’t charge for the software have no obligations. If their software is used in a commercial product, the seller of that product is responsible.
On the "bright side", this will realistically be impossible to enforce. Any national court who deems such industry important will probably use a local constitutional amendment to reinforce that CODE easily falls under freedom of expression, just like any other craft.
EU showing once again how desperate it is for money. Let's strangle out all our industries until nobody can make anything anymore: See agriculture, energy, manufacturing, and "now" even a bigger range of the IT spectrum.
Why they just don't release a law that forbids people from making bugs?
What happens when/if core technologies like SSL, BIND, and even the Linux kernel fail to meet these requirements? Will EU entities have to stop using noncompliant open source software? As someone who is not a fan of bureaucracy, the consequences of this could be almost hilarious.
Edit: TFA is writing about this as legislation to be concerned about. I'd wonder if the best response to this is malicious compliance: "sorry $EU_ENTITY, we never certified, so you can't use our tech that happens to be fundamental to the security/networking/OS stack."
"(13) In order not to hamper innovation or research, this Directive should not apply to free and open-source software developed or supplied outside the course of a commercial activity. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. However where software is supplied in exchange for a price or personal data is used other than exclusively for improving the security, compatibility or interoperability of the software, and is therefore supplied in the course of a commercial activity, the Directive should apply."