{"id":12491,"date":"2023-05-11T15:30:00","date_gmt":"2023-05-11T13:30:00","guid":{"rendered":"http:\/\/plus.maciejpiasecki.info\/index.php\/2023\/05\/11\/the-cyber-resilience-act-introduces-uncertainty-and-risk-leaving-open-source-projects-confused\/"},"modified":"2023-05-11T22:07:42","modified_gmt":"2023-05-11T20:07:42","slug":"the-cyber-resilience-act-introduces-uncertainty-and-risk-leaving-open-source-projects-confused","status":"publish","type":"post","link":"https:\/\/plus.maciejpiasecki.info\/index.php\/2023\/05\/11\/the-cyber-resilience-act-introduces-uncertainty-and-risk-leaving-open-source-projects-confused\/","title":{"rendered":"The Cyber Resilience Act introduces uncertainty and risk leaving Open Source projects confused"},"content":{"rendered":"<p>What might happen if the uncertainty persists around who is held responsible under the Cyber Resilience Act (CRA)? The global Open Source community is averse to legal risks and generally lacks access to counsel, so it\u2019s very possible offers of source code will simply be withdrawn rather than seeking to resolve the uncertainty.<br \/>\nThe CRA rightly addresses the need for commercial suppliers to protect their customers from exploits and cyber attacks. But legislators have exposed the open development of software itself to the regulations rather than just the for-profit use of Open Source artifacts in the marketplace. They are\u00a0incorrectly\u00a0assuming that Dirk Riehle\u2019s terminology calling single-company projects \u201ccommercial Open Source\u201d means it\u2019s possible to use the \u201ccommerciality\u201d of an application to distinguish single-company activity from community projects, and by using the\u00a0concepts of proprietary software\u00a0to then define boundaries.<br \/>\nThere will be no escape from this for European projects like\u00a0the Eclipse Foundation, but projects outside Europe \u2014 especially smaller projects \u2014 may just decide to erect geo-blocks and not deliver their work to European IP addresses. CRA-motivated geo-blocks start with needing to seek legal advice because it\u2019s so confusing\/unclear, only then to be told \u201cmaybe,\u201d leaving you to make the decision on your own.<br \/>\nOne response when I raised this was to say that the European Union is a massive and valuable market, and projects would not risk being excluded from it by geo-blocking. But this argument ignores the fact that just because Alice deploys some code profitably in Europe, it doesn\u2019t mean\u00a0Bob in Nebraska\u00a0who wrote the code will share in the profit, whether he\u2019s in business or not where he lives. Open Source licenses do not create a relationship in which financial reward is guaranteed.<br \/>\nGeo-blocks have happened before. Many small global publications\u00a0block access from the EU\u00a0rather than resolve legal uncertainties with GDPR. But the risk of CRA-related geo-blocks is much more consequential because reading those sites is optional whereas much Open Source software maintained internationally is woven into the fabric of Europe\u2019s infrastructure.<br \/>\nIn addition, those avoiding evaluating their GDPR responsibilities (or evading them after evaluating them) are likely to fear compliance will impact the benefit they gain from surveillance advertising, while for Open Source developers the perceived risk is of being the target of a punitive bureaucracy for failing to complete paperwork that adds nothing to their work.<br \/>\nIf the confusion persists, Open Source projects will need to thoughtfully consider how to proceed. Disentangling dependencies that choose to pragmatically block Europe will be traumatic; should they be forked or substituted? Things could get very messy. Let\u2019s hope the co-legislators see sense, finally\u00a0talk to the Open Source community\u00a0and address the issues.<br \/>\nThis article first appeared on Webmink in Draft.<br \/>\nImage created by Simon Phipps featured on Webmink in Draft.<br \/>\nThe post &lt;span class=&#8217;p-name&#8217;&gt;The Cyber Resilience Act introduces uncertainty and risk leaving Open Source projects confused&lt;\/span&gt; appeared first on Voices of Open Source.&#013;<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/plus.maciejpiasecki.info\/wp-content\/uploads\/2023\/05\/b9b32e0991793bd5.png\" width=\"930\" height=\"706\">&#013;<br \/>\nSource: opensource.org&#013;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What might happen if the uncertainty persists around who is held responsible under the Cyber Resilience Act (CRA)? The global [&hellip;]<\/p>\n","protected":false},"author":48,"featured_media":12492,"comment_status":"false","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-12491","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mp"],"_links":{"self":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/comments?post=12491"}],"version-history":[{"count":1,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12491\/revisions"}],"predecessor-version":[{"id":12493,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/12491\/revisions\/12493"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media\/12492"}],"wp:attachment":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media?parent=12491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/categories?post=12491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/tags?post=12491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}