I wrote a second blog post regarding the impact of Europe's Cyber Resilience Act. This one focuses on the unintended consequences of legislating product liability on the open source community, breaking the social contract that FLOSS is freely provided but without warranty or liability.
https://eclipse-foundation.blog/2023/02/23/cyber-resilience-act-good-intentions-and-unintended-consequences/
Mike Milinkovich
Executive Director of the Eclipse Foundation.
AFAIK, FileZilla is the first open source project to prevent downloads in protest of Europe's Cyber Resilience Act. It won't be the last. See https://filezilla-project.org/cra.php
For more context you can read https://eclipse-foundation.blog/2023/02/23/cyber-resilience-act-good-intentions-and-unintended-consequences/
Continuing my series studying the impact of upcoming European legislation on open source, I've published an analysis of the European Product Liability Directive. Yet another example of "I really hope I'm wrong".
https://eclipse-foundation.blog/2023/03/10/product-liability-directive-more-bad-news-for-open-source/
We hosted a members call yesterday to raise awareness of our concerns with Europe's Cyber Resilience Act. The video can be watched at the link below. Always interested in feedback! https://www.youtube.com/watch?v=7MeCkgHlvas
If you’ve been following the impact of the Cyber Resilience Act will have on the software industry and the open source ecosystem you’ll find this conversation interesting https://twit.tv/shows/floss-weekly/episodes/728
Very happy to announce the results of our annual Board elections. We had a great slate of candidates this year. Congrats to all of the winners, and sincere thanks to all who ran for office.
https://newsroom.eclipse.org/news/announcements/2023-eclipse-board-directors-election-results
@Rog@mastodon.radio @martinvermeer@fediscience.org @fsfe@mastodon.social I can imagine lots of ways that an amended CRA could be a true force for good. I just hope that we can convince the Parliament and Council that it needs to be changed.
@deshipu@fosstodon.org you are wrong again. The open source carve out is a recital, which is not legally enforceable. But don’t take my word for it, go read the OSI’s response:
https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/13410-Cyber-resilience-act-new-cybersecurity-rules-for-digital-products-and-ancillary-services/F3376611_en
@deshipu@fosstodon.org you are simply wrong. A license cannot over-ride a law. That’s why many open source licenses include “to the extent permissible by law” in their limitation of liability clause.
P.S. yes I’ve read the CRA.
@Rog@mastodon.radio I don’t think you could modify an open source license to prevent distribution to a region or jurisdiction. But I could imagine a notice file, sort of like an export regulation notice. Maybe. Would require study.