/blog/is-this-the-end-of-open-source-software

Is this the end of Open Source Software?

EU is trying to end OSS with a new law.

Evil Corp. (ehm, EU headquarters)

Evil Corp. (ehm, EU headquarters)

The good

The Cyber Resilience Act (CRA) is an EU law proposal submitted last year, in September, its aim is to improve the level of cyber security in EU-based software by creating a framework for legal responsibility and financial liability, in case of security issues discovered on Open Source Software.

We talk about it right now because there has been movement in the OSS environment, from multiple sources (like this open letter but also here), all agreeing that this proposal is dangerous to OSS in EU.

Don’t get me wrong. I have read a summary of it. I know it has a positive underlying idea behind it.
Data breaches and security threats are becoming more dangerous for users. I understand that we should do something to address the issue, but this law has some oversize challenges for OSS maintainers, companies, and foundations that will potentially destroy them.

The bad

First, why are we not making a distinction between an open source indipendent author and big corp-backed software?
We can’t impose the same legal and financial responsibility on a single, often upaid, individual and giant companies with millions in revenue.
It doesn’t make any sense.
This proposal could be the end of innovation and collaboration in the software industry as a whole: what a disaster.

The ugly

There are also a few weird and unclear definitions such as “incomplete sofware product” and “commerical activities” that must be clarified at some point. Laws shouldn’t be debatable at least in their fundamental definitions.

“In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software.”

This could be a step back (or more than one) in European OSS, damaging the whole ecosystem and the position of EU companies in comparison with US or Asian ones.
It is crucial that the European Parliament revises the CRA before its approval not to undermine the future of innovation in software development and IT.

Is there some kind of petition we, OSS users and authors, can sign?
Let me know in the comments.
It is time we make our voices be heard, once again!

Follow me here, hit that green button!
Feel free to comment, share and tag me to discuss.
You can follow my other social media (here).

See you next time!


Originally published on blog.mb-consulting.dev.