Python head hisses at looming Euro cybersecurity rules
- Reference: 1681284309
- News link: https://www.theregister.co.uk/2023/04/12/python_management_eu/
- Source link:
"If the proposed law is enforced as currently written, the authors of open-source components might bear legal and financial responsibility for the way their components are applied in someone else's commercial product," the PSF said in a [1]statement shared on Tuesday by executive director Deb Nicholson.
"The existing language makes no differentiation between independent authors who have never been paid for the supply of software and corporate tech behemoths selling products in exchange for payments from end-users."
The existing language makes no differentiation between independent authors who have never been paid for the supply of software and corporate tech behemoths selling products
European lawmakers last year introduced two pieces of legislation to address software security and liability. And since then, the technical community has been [2]voicing opposition to the broadly drafted rules.
The [3]Cyber Resilience Act aims to promote the security of digital products by requiring product makers to review product security, implement vulnerability mitigation procedures, and disclose security information to customers. The public comment period closed in November and the public consultation period for the law [4]concludes on May 25.
[5]
The maximum fines under the law can reach €15 million or up to 2.5 percent of [6]annual turnover , whichever is greater. The CRA has yet to be adopted by the European Parliament and Council.
[7]
[8]
The [9]Product Liability Act updates Europe product liability rules by including, among other things, digital product changes arising from software updates. It allows consumers to seek damages if they are harmed by products made unsafe through software revisions.
The PSF and other organizations including the [10]Eclipse Foundation and [11]NLnet Labs , to [12]name a few , are urging EU lawmakers to clarify the broad language in the proposed legislation so open source organizations and developers aren't held accountable for flaws in commercial products that incorporate their code.
[13]
"Under the current language, the PSF could potentially be financially liable for any product that includes Python code, while never having received any monetary gain from any of these products," the PSF said, adding such risk would make it impossible for the foundation to continue to provide Python and PyPI (the Python Package Index) in Europe.
The non-profit org, which oversees and champions the Python programming language globally, argues that holding open source developers liable for code contributions would discourage contributors to open source projects. It cites two particular passages as excessively broad.
The first is [14]Article 16 , which says "A natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of the product with digital elements shall be considered a manufacturer for the purposes of this Regulation."
[15]
That definition could be interpreted to mean that anyone who made a substantive change to an open source project would be liable for the consequences of that change.
[16]Open source software has its perks, but supply chain risks can't be ignored
[17]Three quarters of UK tech pros are ready to leave their jobs
[18]Nearly one in two industry pros scaled back open source use over security fears
[19]Python charmer? Data science whizz? Linux engineer? Get a load of these exciting career opportunities waiting for you
The second is a passage that exempts "free and open-source software developed or supplied outside the course of a commercial activity" but defines "commercial activity" as "providing a software platform through which the manufacturer monetizes other services" — a definition that could apply to organizations like PSF that offer any sort of paid products or services, like t-shirts, event tickets, or coding classes.
The PSF argues the EU lawmakers should provide clear exemptions for public software repositories that serve the public good and for organizations and developers hosting packages on public repositories.
"We need it to be crystal clear who is on the hook for both the assurances and the accountability that software consumers deserve," the PSF concludes.
The PSF is asking anyone who shares its concerns to convey that sentiment to an appropriate [20]EU Member of Parliament by April 26, while amendments focused on protecting open source software are being considered.
Bradley Kuhn, policy fellow at the Software Freedom Conservancy, told The Register that the free and open source (FOSS) community should think carefully about the scope of the exemptions being sought.
"I'm worried that many in FOSS are falling into a trap that for-profit companies have been trying to lay for us on this issue," he said. "While it seems on the surface that a blanket exception for FOSS would be a good thing for FOSS, in fact, this an attempt for companies to get the FOSS community to help them skirt their ordinary product liability. For profit companies that deploy FOSS should have the same obligations for security and certainty for their users as proprietary software companies do." ®
Get our [21]Tech Resources
[1] https://pyfound.blogspot.com/2023/04/the-eus-proposed-cra-law-may-have.html
[2] https://devclass.com/2023/01/24/eus-proposed-ce-mark-for-software-could-have-dire-impact-on-open-source/
[3] https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act
[4] https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13410-Cyber-resilience-act-new-cybersecurity-rules-for-digital-products-and-ancillary-services_en
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZDaBRGbJ8eeA9N9dxyI7cQAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://www.investopedia.com/terms/o/overall-turnover.asp
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZDaBRGbJ8eeA9N9dxyI7cQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZDaBRGbJ8eeA9N9dxyI7cQAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://ec.europa.eu/commission/presscorner/detail/en/ip_22_5807
[10] https://eclipse-foundation.blog/2023/02/23/cyber-resilience-act-good-intentions-and-unintended-consequences/
[11] https://blog.nlnetlabs.nl/open-source-software-vs-the-cyber-resilience-act/
[12] https://blog.opensource.org/the-ultimate-list-of-reactions-to-the-cyber-resilience-act/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZDaBRGbJ8eeA9N9dxyI7cQAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0454
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZDaBRGbJ8eeA9N9dxyI7cQAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2023/02/22/open_software_supply_chain_risks/
[17] https://www.theregister.com/2023/04/11/three_quarters_of_uk_tech/
[18] https://www.theregister.com/2022/09/14/snakes_on_a_plan_anaconda/
[19] https://www.theregister.com/2020/10/02/linux_engineers_job_ads/
[20] https://www.europarl.europa.eu/meps/en/home
[21] https://whitepapers.theregister.com/
And yet we have a whole article about a proposed law that will result in exactly that if it passes into law unchanged.......
You do not need permission from a lawyer to RTFA!
No the article is about some people fearing that it will do that... the key seems to be
"free and open-source software developed or supplied outside the course of a commercial activity"
and whether some open source developers who sell small bits of merchandise will qualify as 'commercially active'.....
Something needs to be done to protect consumers
But this isn't it, and open-source authors should not be covered.
However, any company that uses open-source within a commercial product should be responsible for ensuring that it is appropriate for the job - which means ensuring* that it does not introduce security or safety vulnerabilities into any product that they place on the market.
* "ensuring" does not mean that it will be defect free, as it is generally impossible to show that is the case. What is required (from a legal perspective) is evidence to show that the chance of a failure is as low as is reasonably practicable (which depends on the the cost/value of the product and costs/risks associated with failure) - which basically comes down to ensuring that development complies with a standard and that artefacts are produced to demonstrate how compliance with that standard has been achieved.
I'm sure there will be a lot of "but that slows us down" and "that stifles innovation", but it doesn't have to. Sure, it will have an impact up front, but it does not have a negative impact on timescales if appropriate processes are used.
Re: Something needs to be done to protect consumers
I would agree that if you write and publish some source code, then someone who chooses to use your source (rather than write their own) and include it in a product sold to 'the public' owns the liability for the product.
If they choose to give away the resulting product, then they should have no liability for errors in the product. It was free, they gained no revenue from it. Folk who use that product use it at their own risk.
So llvm, for example, used as is, should not impose liability on the authors (even if they sell tee-shirts and mugs) even if it generates stupendously evil code
The Linux authors are also exempt from liability, even if there's no inter-process protection or the file systems does horrible things to disk drives.
Fred's OK Software Company, however, who sell a data base or a financial package or whatever should be liable for damage arising from the use of their product. Since the product uses Linux to perform some tasks, Fred is liable even for errors in Linux that cause his software to misfunction. He's also liable for such misfunction caused by errors in llvm. And its libraries.
Similarly, Ford is liable for misfunction caused by (I make this up) the steel alloy they use to construct vehicles being out of spec. In general the vendor of the product, should be liable for any and all misfunctions that are attributed to the thing you're selling. True, perhaps the supplier who sold you the imperfect steel needs to make good that problem; but that should be an issue between Ford and the supplier.
When you build a software product on top of or through the use of free (in the "it costs no dollars" sense) then you can't go sue the providers. They're not in business; they **published** the source; you're the one who chose to use it.
Re: Something needs to be done to protect consumers
There's a difference between not being defect free and being out-and-out malware. There seem to have been plenty of reports here about software repositories such as Pypi being subverted to introduce malware into the supply chain. Should these be treated as a "product", even if not commercial, whose providers "should be responsible for ensuring that it is appropriate for the job"?
It's easy to say that those who use the repositories should each be responsible for vetting everything they use, tracking every new version and re-vetting all changes. Easier said than done - the overall cost would be huge when given that every user would be duplicating the work. The likely outcome would be that companies would simply stop using them or else there would be a second tier of commercial repositories who would vet new additions before adding them.
Ahh you gotta love the EU
They seem absolutely determined to legislate every business possible into total obscurity.
Erm
"adding such risk would make it impossible for the foundation to continue to provide Python and PyPI (the Python Package Index) in Europe."
Not all of Europe is in the EU. Hopefully this idea stays within the EU borders
Open Sores Idiots.
You are not responsible for somebody else taking your freely-available code and selling it. You are not responsible for somebody else not reading your freely-available code before selling it to their unwitting customers. You do not need permission from a lawyer to do mathematics. Let Ubuntu or IBM take the rap. That's what they're for.
You do not owe the people who use your code anything. You don't owe them updates, you don't owe them support, you don't even owe them the middle finger although they probably deserve ir.
You do not need permission from a lawyer to do mathematics.