Debian developers have published a statement regarding the Cyber Resilience Act bill.

The results of the general voting (GR, general resolution) conducted by Debian project developers, involved in package maintenance and infrastructure support, have been published. The statement expressing the project's position regarding the proposed Cyber Resilience Act (CRA) legislation in the European Union has been approved. The bill introduces additional requirements for software producers aimed at enhancing security, disclosing incident information, and promptly addressing vulnerabilities throughout the product lifecycle.

In case of non-compliance, fines may be imposed, reaching up to 15 million euros or 2.5% of the company's annual turnover. Following the bill's adoption, producers will be required to provide means for delivering vulnerability fixes, conduct assessments of security-related risks before bringing a product to market, perform security testing (mandatory external audits for critical systems), address vulnerabilities throughout the entire lifecycle, and report security incident information within 24 hours of detecting an issue.

Despite the prevailing trends suggesting that the bill will primarily affect commercial software producers, the community is concerned about its negative impact on the open-source development ecosystem. They view the bill as a factor hindering the advancement of open projects and obstructing the development of open-source software as an international movement. Companies developing products based on international open projects or using open libraries will be held accountable for security issues and inadequate remediation of vulnerabilities in the code, even if that code is written by enthusiasts from other countries. It is anticipated that these additional business risks will lessen the appeal of creating software based on open source.

At the same time, the legal consequences may also affect independent projects that include code from commercial product manufacturers. For instance, there is uncertainty regarding liability in cases where open source code developed by a commercial company can be transferred to third-party non-profit projects and used in Linux distributions.

The bill introduces legal liability for non-compliance with safety requirements, which conflicts with Debian's social commitments to distribute software for any purpose without restrictions. Debian does not track the involvement of code in commercial projects, the employment of developers, or the funding sources for developments included in the distribution. Therefore, imposing the requirements outlined in the bill increases legal risks when using the distribution.

There is a danger that upstream projects may stop providing their code due to concerns about falling under the CRA and the associated penalties. The CRA may also complicate the processes of transferring open source code to the community—developers may have to assess potential legal consequences before releasing code. Furthermore, the bill reduces the attractiveness of the open development process, as the work is done in public and transparently for all, and the code can be used during development, allowing CRA requirements to be applied while working on the product, whereas proprietary software is developed behind closed doors and is subject to the law only after final release.

Debian developers are calling for a complete removal of the open development process from the scope of the CRA and for the law to only apply to final products. It is also proposed that CRA requirements should not apply to products from individual entrepreneurs and small businesses, as they cannot meet all the requirements set by the CRA and would be forced to shut down their business.

The statement also mentions the questionable nature of the requirement to report security issues to the European Union Agency for Cybersecurity (ENISA) within 24 hours of discovering a problem or receiving information about a vulnerability. Accumulating data on all unpatched vulnerabilities in one place could lead to significant problems for all users in the event of information leaks, transmission of data to intelligence agencies, or ENISA compromise.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster