In letter to EU, open source bodies say Cyber Resilience Act could have ‘chilling effect’ on software development
Reading Time: 3 minutesMore than a dozen open source industry bodies have published an open letter asking the European Commission (EC) to reconsider aspects of its proposed Cyber Resilience Act (CRA), saying it will have a ‘chilling effect’ on open source software development if implemented in its current form.
Thirteen organizations, including the Eclipse Foundation, Linux Foundation Europe, and the Open Source Initiative (OSI), also note that the Cyber Resilience Act as its written ‘poses an unnecessary economic and technological risk to the EU.’
The purpose of the letter, it seems, is for the open source community to garner a bigger say in the evolution of the CRA as it progresses through the European Parliament.
The letter reads:
Early stages
First unveiled in draft from back in September, the Cyber Resilience Act strives to codify into law best cybersecurity practices for connected products sold in the European Union. The legislation is designed to strong-arm internet-connected hardware and software makers, for example those who manufacture internet-enabled toys or ‘smart’ refrigerators, into ensuring their products are robust and kept up-to-date with the latest security updates.
Penalties for non-compliance may include fines of up to €15M, or 2.5% of global turnover.
While the Cyber Resilience Act is still in its early-stages, with nothing set to pass into actual law in the immediate future, the legislation has already set some alarm bells ringing in the open source world. It’s estimated that open source components constitute between 70-90% of most modern software products, from web browsers to servers, yet many open source projects are developed by individuals or small teams in their spare time. Thus, the CRA’s intentions of extending the CE marking self-certification system to software, whereby all software developers will have to testify that their software is ship-shape, could stifle open source development for fear of contravening the new legislation.
The draft legislation as it stands does in fact go some way toward addressing some of these concerns. It says (emphasis ours):
However, the language as it stands has prompted concerns from the open source world. While the text does seem to exempt non-commercial open source software from its scope, trying to define what is meant by ‘non-commercial’ is not a straight forward endeavor. As GitHub policy director Mike Linksvayer noted in a blog post last month, developers often ‘create and maintain open source in a variety of paid and unpaid contexts,’ which may include corporate, government, non-profit, academic, and more.
‘Non-profit organizations offer paid consulting services as technical support for their open source software,’ Linksvayer wrote. ‘And increasingly, developers receive sponsorships, grants, and other forms of financial support for their efforts. These nuances require a different exemption for open source.’
So really, it all comes down to language — clarifying that open source software developers won’t be held responsible for any security slipups of a downstream product that uses a particular component.
‘The Cyber Resilience Act can be improved by focusing on finished products,’ Linksvayer added. ‘If open source software is not offered as a paid or monetized product, it should be exempt.’
‘Chilling effect’
A growing number of proposed regulations in Europe is raising concerns across the technological landscape, with open source software a recurring theme. Indeed, the issues around the CRA are somewhat reminiscent of those facing the EU’s upcoming AI Act, which seeks to govern AI applications based on their perceived risks. GitHub CEO Thomas Dohmke recently opined that open source software developers should be exempt from the scope of that legislation when it comes into effect, as it could create burdensome legal liability for general purpose AI systems (GPAI) and give greater power to well-financed big tech companies.
As for the Cyber Resilience Act, the message from the open source software community is pretty clear — they feel that their voices are not being heard, and if changes are not made to the proposed legislation then it could have a major long-tail impact.
‘Our voices and expertise should be heard and have an opportunity to inform public authorities’ decisions,’ the letter reads. ‘If the CRA is, in fact, implemented as written, it will have a chilling effect on open source software development as a global endeavour, with the net effect of undermining the EU’s own expressed goals for innovation, digital sovereignty, and future prosperity.’
The full list of signatories includes: The Eclipse Foundation; Linux Foundation Europe; Open Source Initiative (OSI); OpenForum Europe (OFE); Associaçāo de Empresas de Software Open Source Portuguesas (ESOP); CNLL; The Document Foundation (TDF); European Open Source Software Business Associations (APELL); COSS – Finnish Centre for Open Systems and Solutions; Open Source Business Alliance (OSBA); Open Systems and Solutions (COSS); OW2, and Software Heritage Foundation.
Ref: techcrunch
MediaDownloader.net -> Free Online Video Downloader, Download Any Video From YouTube, VK, Vimeo, Twitter, Twitch, Tumblr, Tiktok, Telegram, TED, Streamable, Soundcloud, Snapchat, Share, Rumble, Reddit, PuhuTV, Pinterest, Periscope, Ok.ru, MxTakatak, Mixcloud, Mashable, LinkedIn, Likee, Kwai, Izlesene, Instagram, Imgur, IMDB, Ifunny, Gaana, Flickr, Febspot, Facebook, ESPN, Douyin, Dailymotion, Buzzfeed, BluTV, Blogger, Bitchute, Bilibili, Bandcamp, Akıllı, 9GAG