• argv_minus_one@beehaw.org
    link
    fedilink
    English
    arrow-up
    34
    arrow-down
    1
    ·
    2 years ago

    The EU Cyber Resilience Act will effectively make open-source software illegal, and that sure as hell isn’t pro-consumer. Neither is all the spooky surveillance and crippled cryptography they keep trying to mandate.

    • Nioxic@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 years ago

      How exactly is open source illegal?

      I mean… lol

      How are they even gonna enforce that?

      • Zpiritual@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 years ago

        Probably the same way they’ll enforce their upcoming ban on encryption (yes really).

        Fines, gigantic fines since people seem to love those.

    • xradeon@lemmy.one
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 years ago

      Really? According to this site they claim that “The Cyber Resilience Act should only apply to free open-source software that is developed or supplied in the course of commercial activity.” While that could be a broad scope, I don’t think it applies to most FOSS. Linux is really the big thing I see it applying to and Linux is very Cyber secure, so I don’t really see issues there.

      Are there other parts of the law that ban FOSS? Or is that site too pro EU and glosses over the bad parts?

      • argv_minus_one@beehaw.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        2 years ago

        According to this site they claim that “The Cyber Resilience Act should only apply to free open-source software that is developed or supplied in the course of commercial activity.”

        Almost all FOSS development happens as part of a commercial activity.

        The most obvious example is of course corporate sponsorship of FOSS projects, but even things like pull requests submitted to FOSS libraries by corporate employees qualify as “develop[ment] in the course of commercial activity”.

        Linux is really the big thing I see it applying to and Linux is very Cyber secure, so I don’t really see issues there.

        Linux does not and cannot comply with the demands of the Cyber Resilience Act. For example, the Act demands automatic update installation, which within a kernel is infeasible and unsafe. Linux will be illegal in the EU.

        Furthermore, no company in its right mind is going to sponsor, or allow its employees to contribute to, any FOSS project if doing so creates the risk of fines. All corporate sponsorship of and contribution to FOSS projects—which, once again, is responsible for almost all FOSS development—will completely and instantly disappear in the EU, severely damaging the worldwide FOSS movement.

        Needless to say, this proposal is catastrophically bad.