Simon Phipps
OSI Standards director · Meshed Insights CEO · Geek-Nerd · Cat servant. Personal account, see pinned post. Beware clones, see hub and check for validation ticks.
Fediverse citizen since the 1980s: UUCP, BBSs; IRC; identi.ca,; mastodon.cc · Old posts are auto-deleted.
The @EUCommission@ec.social-network.europa.eu has just published guidance documents clarifying how the Cyber Resilience Act #CRA affects (among other things) #OpenSource. This is the result of the extensive engagement of many open source community members.
I feel terribly guilty when I visit a new city, post photos of my travels, only to have a friend say "Hey! Why didn't you let me know you were in my neck of the woods?"
Similarly, if I bump into an old acquaintance at a conference, we both tend to say "If only I'd known you were here, we could have had dinner together last night!"
I do enjoy the serendipity of events like FOSDEM - randomly seeing a mate and expressing the joy of spontaneity. But I also like arranging to meet up in advance.
At the moment, my strategy is sending a blast on social media saying "I'm visiting [this city] next week, anyone fancy a beer and a natter?" I've met friends all over Europe, Australia, and New Zealand that way. It mostly works. But I can't help feeling it is inefficient and prone to missing connections.
I even wrote my own code to auto-post FourSquare checkins to my other social media sites.
Here are my ideal scenarios. Imagine something built in to Signal / WhatsApp / Whatever app you already use.
Plan In AdvanceI tell my app that I'm going to Barcelona from 14th - 19th February and am happy to meet any of my friends.
✨Background Magic✨
My friend Alice has also planned a trip to Barcelona around those dates. She gets a ping saying that one of her friends is going to be in the same city. Does she want to know more?
So far, so Dopplr.
My friend Bob lives just outside of Barcelona. He's set his "willing to travel" settings to be about 30 minutes, so also receives a ping.
I don't know that either of them have seen the notification until they decide they want to meet.
Spontaneous FunI step off the train in Manchester, England England. Perhaps the app notices I'm away from home, or maybe I press the "Anyone Around?" button.
On a map I can see friends who have shared their rough location. I decide to message Chuck to see if he's free for a chat.
Dave notices my location is now within his preferred travel distance. He gives me a ring.
A bit like how FourSquare used to be - but with less precision.
DownsidesThe above is very much the "happy path". It doesn't look at any of the knotty problems or grapple with the UI that would be needed to make this work. But we know the technology for sharing location is viable - so what are the social issues that make this so difficult?
Social Awkwardness"Oh, fuck, Edgar's location says he's in town. Can we pretend to be out of the country?"
Alternatively, "Huh, I know at least a dozen people who live in Skegness. Why aren't any of them responding to me?"
Social pressure and awkwardness are hard problems. No one wants to use the app that makes you feel like a friendless loser.
PrivacyDo you want your friends knowing your every movement? I'm sure some people do, but most probably don't. It's possible to sketch out some vague controls:
- Only send a notification if I push this button.
- Don't send alerts if I am within this radius of my home / work.
- Fuzz my location to the city / state / country level.
Is it a risk to let people know vaguely where you are? Is meeting up with (semi-) strangers from the Internet a smart life choice? Is having an app stalk you across the globe giving too much data to advertisers?
Does that creep from work abuse the system to keep popping up whenever you're out with friends?
TechnologyI said the technology exists for this, and that was sort of true. Every device has GPS & an Internet connection. Storing a log of friends and sending them a message is a solved problem.
But is it solved in a decentralised and privacy preserving way?
No one wants to give all this power to one company. Google will build it and kill it. Facebook will sell your secrets to dropshippers. A funky start-up will be acquhired by Apple & restricted to iOS devices.
My location is fuzzed to an acceptable degree of imprecision and then sent… where? To all my friends directly? To a central server? Can k-anonymity help?
Is this a separate app? Everyone seemed to leave FourSquare after they buggered around with it. Perhaps it is just a feature in existing apps?
What's Already There?Messaging apps like Signal, Telegram, and WhatsApp allow you to share your location with one or more friends.
To me, it feels a bit weird to manually send a dropped pin to some / all of my contact. It also doesn't let you share "tomorrow I will be in…"
Using "Stories" is the common way to share an update with all contacts - but none of them let you automatically share your location in a story.
FourSquare's Swarm app allows you to check in to a "neighbourhood". But there's no obvious way of saying "London" or "Manchester" - and I'm not sure how close to an area you need to be to get an alert that your friend is there.
What's Next?I don't want to build this. Trying to get everyone I know to adopt a new app isn't going to happen. With the fragmentation of messaging and the lack of interoperability, this is likely to remain an unsolved problem for some time.
So here's my strategy.
- Get back in to using FourSquare. Most of my friends seemed to stop using it back in 2017 when it was split into Swarm. But a few are still on there.
- Manually post a story on Mastodon, BlueSky, Facebook, WhatsApp, Signal, and Telegram saying "Visiting Hamburg next week. Anyone want a beer?"
- Hope that something better comes along.
The top appeals court of the European Union has once again found that standards referenced from safety law must be made "freely accessible under a system of access which is general, effective, without charge and non-discriminatory."
I assume CEN/CENELEC and the national standards bodies it works with are urgently seeking a new business model.
https://curia.europa.eu/site/upload/docs/application/pdf/2026-04/cp260060en.pdf
I felt old when I found the computer on which I learned assembler in the Computer History Museum. But I think being featured in archival footage about #OpenSource and #OpenJDK in the new #Java documentary might just beat that.
The Java Story | The Official Documentary
Want a job shaping the future of #OpenSource in EU tech? European tech standards body ETSI has a new paid position available for an open source expert.
The advert doesn't say it quite like that because they have members who dislike open source, but "SDG" is the term for what was originally "Open Source Group" and this person will be managing collaborative open source projects on open source tools in a unique, challenging but hugely influential setting.
@rdicosmo@mstdn.social & @zacchiro@mastodon.xyz just received an #EOSAwards26 for @swheritage@mstdn.social - congratulations to them, very proud to be part of their team!
Finally a real prosecution of a British water company.
The FSF comes out against OnlyOffice abuse of the AGPL
https://www.fsf.org/blogs/licensing/agpl-is-not-a-tool-for-taking-freedom-away
Thanks to the huge effort we all have put in to help the @EUCommission@ec.social-network.europa.eu understand the value of open source and the role it plays in cyber security they are taking care to include it in all their thinking around the #CRA. For example, this page explains why they created a new legal category of #stewards in the CRA: https://digital-strategy.ec.europa.eu/en/policies/cra-open-source
Strong new report from @openrightsgroup@social.openrightsgroup.org
> The UK is currently facing a crisis of digital dependency. The country is overly reliant on a small number of tech giants for its critical digital infrastructure, which poses significant economic, security, legal, and policy risks, including to democracy and public debate.
Has the #Amazon Blink team explicitly broken the ability of #OpenSource Home Assistant to log in to Blink?
https://github.com/home-assistant/core/issues/176836#issuecomment-5080466993
Here's a petition I broadly support, with caveats. It calls for a referendum on bringing the UK water industry into public ownership.
https://petition.parliament.uk/petitions/762640
Caveats:
* Not a fan of plebiscites. Parliament should Just Do It. But needs must.
* "Public ownership" needs nuance. Natural monopolies should be run by non-profits (TfL is an examplar; CICs are great) under public oversight. Infrastructure should be leased to them by the state, not owned.
"Obligations of non-commercial #OpenSource software developers under the #CRA are ZERO. Anybody telling you something else can please go away and read the law."- Carl-Daniel Hailfinger, from the German market regulator BSI, at #FOSDEM
Very sad this is not an April Fools post.
https://www.collaboraonline.com/blog/tdf-ejects-its-core-developers/
Are you going to @oggcamp@mastodon.social this year? April 25-26 in Manchester (the original one in the UK).
Having seen these thugs on the local streets (they also meet nearby to taunt refugees) I can't find any capacity for surprise at this finding. It would be fascinating to get demographic data on R-party supporters......
This is a really good explanation of how modern #OpenSource #software #development is in fact #distributed, not centralised (despite the best efforts of some to create control points).
https://www.collaboraonline.com/blog/distributed-by-design-how-modern-open-source-works/
Yes, i read your document.
No, there are no comments because I can only correct something that's almost right.
A significant change of objective has quietly happened to the #standards system in #Europe, with the transformation of standards from a tool to promote #interoperability to a mechanism to comply with the law.
Yet the toleration of #patents in standards remains, meaning complying with the law may require a relationship with the corporations controlling the market. Surely this is anti-competitive and reverses the very purpose of standards?
https://opensource.org/blog/standards-and-the-presumption-of-conformity
OSI has a new API! There has actually been an OSI license API for many years thanks to the efforts of some of the directors a decade ago. Since it was manually maintained, it kept getting out of date.
I am delighted that OSI now has a new API integrated into its WordPress instance that uses the same metadata as the license pages themselves so is always correct.
https://opensource.org/blog/introducing-the-new-api-for-osi-approved-licenses
The only people who think they can define #OpenSource to suit their own needs are people who want to deny some or all others #SoftwareFreedom
The major #OpenSource #CMS
communities #Joomla #Wordpress #Typo3 and #Drupal have got together to tell the @EU_Commission@social.network.europa.eu how much the #CRA worries them despite their support for its goals.
"in their current form, the proposed regulations run the risk of reducing software security, as well as undermining the EU’s core aims and values"
The #CRA is now published in the Official Journal so comes into force as European law in 20 days. Next task: the #standards.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847
With the #CRA finalised, the European Commission needs to accommodate the Fourth Sector (see https://blog.opensource.org/modern-eu-policies-need-the-voices-of-the-fourth-sector/) in future deliberations and hear the voices of the Commons. To get this started, a group of us who have engaged during 2023 got together to organise a unique set of workshops at FOSDEM 2024 on Sunday February 4 - see https://md.softwarefreedom.net/FOSDEM24). If you want your voice heard, come along to one of the workshops!
Near Oslo? I will be joining @isocnorway@mastodon.social for a discussion about the Cyber Resilience Act #CRA (and other #policy and #legislation) and its potential impact on #OpenSource on Saturday 22nd April.
https://isoc.no/event/will-the-coming-eu-regulations-kill-open-source/





