FOSS could be an unintended victim of EU crusade to make software more secure
- Reference: 1675071006
- News link: https://www.theregister.co.uk/2023/01/30/opinion_eu_foss_security/
- Source link:
This is an imperfect process, as regulations always are. Companies and free market libertarians chafe at not being allowed to poison, crush or electrocute paying customers or passers-by. But it turns out a well-regulated market inspires consumer confidence, doesn't stop innovation, and adds value to entire sectors. That it annoys libertarians is just a free bonus.
The EU has now turned its attention to cybersecurity and more especially the lack thereof. It's certainly dangerous enough to merit attention. A proposed [1]Cyber Resilience Act (CRA) making its way through Brussels says that for "products with digital elements" to be allowed on the EU market, manufacturers have to demonstrate they follow best practice in four areas. These are improving the security of a product through the whole life cycle, following a coherent cybersecurity framework to measure compliance, demonstrate transparency about cybersecurity efforts, and lastly to make sure customers can use products securely.
[2]
Which sounds fair enough, considering some of the horrors visited upon us in the past – and today. Cheap "smart" electronics running out-of-date Android that nobody's patched since Noah? Phones studded with "I bring you the best wishes of the People's Liberation Army" mystery-meat bloatware? Big name, big ticket office software that keeps making headlines for all the wrong reasons? Who could argue with bringing these into line?
[3]
[4]
There are just two questions that need to be answered: will the proposed regulations do the job they set out to do, and what effect will they have on the market? Here, it's not so much the devil in the details as the entire population of all seven layers of Dante's Inferno.
The effect on the market, according to the EU's own risk assessment, will be to cost some €29 billion, but with €180-290 billion saved through not having to deal with cybersecurity incidents. Exactly what counts as "products with a digital element" has been and is furiously debated, with the CRA dividing relevant software up into two categories of different importance and excluding – at the time of writing – software-as-a-service altogether.
[5]
SaaS is [6]hotly disputed , with different EU countries taking differing stances on whether it can or should be regulated. What if a product has a chunk of software built in that talks to SaaS through an API? Will this drive more products into subscription models, taking them out of regulatory scope and into a bad revenue model for users?
But [7]FOSS is in the most danger . The underlying assumption of the regulation is that cybersecurity exists in the digital market like fire resistance does in that for soft furnishings. Putting regulatory cost burdens on a part of the market with no revenue and no gatekeeping on its distribution channels cannot work; there are no prices to increase to absorb compliance costs and no tap to turn off to keep the stuff off the market.
[8]Bill shock? The red ink of web services doesn't come out of the blue
[9]Time to study the classics: Vintage tech is the future of enterprise IT
[10]Disruptive innovation's like a party. It's always happening elsewhere
[11]Citizen Coder? Happiness Concierge? Here come 2023's business cards
And FOSS can't be outlawed. To re-engineer infrastructure and applications to exclude it would be unthinkably expensive and undoubtedly vastly destabilizing for cybersecurity resilience. To allow grandfathering – allowing pre-regulatory software components to continue to be used but demand compliance if new or updated – would freeze the sector to death. And what "cybersecurity framework" would catch the sort of errors that currently only appear after intensive analysis by the few teams of good and bad hats who are already fully employed for better or worse on a tiny percentage of extant software.
The EU as a whole, and many of its member states in particular, has been very pro-FOSS, seeing it as a way to disrupt de facto non-European software monopolies and encouraging diversity and transparency. The CRA draft even [12]exempts FOSS from compliance – but only if no commercial use is made of it, including things like technical support and as part of monetized services. That breaks so many funding models for FOSS it's not even funny.
The principle of regulating digital products to make vendors take responsibility for cybersecurity is excellent but it demands proportionality. FOSS that is absolutely free of commercial interest isn't somehow more secure than one where you can buy a support contract. A far more general exemption that recognizes the intrinsic security advantages of software that is automatically transparent makes far more sense.
[13]
The bad news is that the period for official feedback on the CRA has just closed. The good news is that [14]there's been a lot of feedback and the debate is far from over. Take the time to read a [15]solid analysis or two – and if you're sensible enough to live in a EU member state, engage your MEP. No point in having a democracy if you don't use it. ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2022/09/16/eu_cyber_resilience_act/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9ejT6QC0yvVZY61gjT45AAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9ejT6QC0yvVZY61gjT45AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9ejT6QC0yvVZY61gjT45AAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9ejT6QC0yvVZY61gjT45AAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.euractiv.com/section/cybersecurity/news/eu-council-moves-to-exclude-software-as-a-service-from-new-cybersecurity-law/
[7] https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-software-could-have-dire-impact-on-open-source/?td=rt-3a
[8] https://www.theregister.com/2023/01/23/opinion_column/
[9] https://www.theregister.com/2023/01/16/opinion_column/
[10] https://www.theregister.com/2023/01/09/opinion_column_disruption/
[11] https://www.theregister.com/2023/01/03/column_job_titles/
[12] https://blog.sonatype.com/eu-cyber-resilience-act-good-for-software-supply-chain-security-bad-for-open-source
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9ejT6QC0yvVZY61gjT45AAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13410-Cyber-resilience-act-new-cybersecurity-rules-for-digital-products-and-ancillary-services_en
[15] https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/
[16] https://whitepapers.theregister.com/
I'm not sure how it applies to Fedora either. Red Hat makes Fedora which is FOSS, but then turns it into RHEL which is commercial. So would the regulation exemption for FOSS apply to Fedora or would the fact that it's used to make RHEL mean it's ineligible? Maybe Red Hat changes enough to make them distinct but who makes that call?
Hurrah for Brexit
"and if you're sensible enough to live in a EU member state, engage your MEP. No point in having a democracy if you don't use it."
Fortunately the UK used their democracy and got out.
Re: Hurrah for Brexit
And you will be smashed and buried when trying to sling unsecured software at the remaining EU countries. Not only EU local production is covered, but imports too.
How did that exit help again?
Re: Fortunately the UK used their democracy and got out
Oh yeah, I remember that period.
All those reasoned arguments and intelligent debates. So refreshing.
Can you feel the sarcasm ?
"That breaks so many funding models for FOSS it's not even funny"
Cybersecurity is not funny.
It is time to get it out of the hands of clowns.
But first...
We need to get actual cybersecurity testing straightened out first...I've messed around with quite a few "pentesters" in my time and it is vanishingly rare to find a pentester that actually knows their shit and doesn't just parrot from an automatically generated report.
One of my favourite past times is putting devices on the network for pentesters to find that are impossible...such as PCs running Windows 2000 by Sonos. The sheer number of times I've had people tell me that "you should really upgrade those Sonos PCs, Windows 2000 is massively out of date" is insane. I've even been known to place fake SNMP endpoints on the network with barking mad information on them to see if pentesters actually read the information...like the fake HP printer that advertises that it has 1,024 trays and 4TB of RAM with supported resolutions up to 20,000 dpi and a firmware date in the distant future that is managed by "Chief O'Brien".
For those interested in how you do this, you just need to add a bunch of fixed Mac addresses to the ARP cache in a switch or just use an ARP spoofing tool to broadcast to the network periodically (the vendor string for Sonos is 54-2A-1B) and to mess with fingerprinting you just need a device like a Raspberry Pi or something that can run Linux and use "macchanger"...to ensure they fingerprint as Windows 2000 or your operating system of choice, just spawn a bunch of netcat open ports that would normally see on a Windows 2000 desktop and have them respond with fake headers/banners and adjust your network parameters such as TTL to match your operating system of choice...most fingerprinting tools use TTL and other network parameters to fingerprint a device and lazy pentesters won't properly read the results...
If you decide to have fun with pentesters, the best part is where they warn you about your "print server" that has Telnet enabled with no password called "Terok Nor" managed by "Chief O'Brien" which is located next to "Quark's Bar".
Typically if these things are dropped into the meeting in a nonchalant manner, I'm not sure whether I should be more upset that they can't see the joke or that the pentester has never seen DS9.
I'm ignoring the FOSS/prop problem, in fact I'll stay clear of the whole load of snake-filled pits involved with this kind of legislation. But the overall impact will be one of increased profits for the corporates, and almost 100% likely a PITA for consumers.
The Corp$ WIll Benefit
...cost some €29 billion, but with €180-290 billion saved...
When advertising for tobacco was outlawed in the UK sales of baccy did not fall. Marketing spend did though. So the corps benefited, hugely. No single tobacco company would have benefited from going-it alone and dropping marketing spend, they would probably have lost market share. Forcing all $Corps to comply will mean they can all shift their pricing without breaking market positioning. For a larger profit margin, ofc.
Short term outlook: increased revenue for the corporates; for the consumer, every app has "We use cookies" plastered all over it.
This could get messy to implement.... For example, if I understand it correctly, in the context of open source smart homes, at first glance, Home Assistant wouldn't have to comply, because it's free and open source, but Home Assistant's cloud based remote access (Nabu Casa) would have to comply, because you have to pay for it.
However, the ability to communicate with Home Assistant Cloud is built in as standard, just not used unless you buy a subscription, so that might mean that Home Assistant has to comply after all...