João Costa @JD557@blog.joaocosta.eu Follow

Portuguese software engineer at Kevel.

My instance is running on a small server so please #nobot

Web

https://www.joaocosta.eu/

GitHub

https://github.com/JD557

Twitter

https://twitter.com/JD557

Itch.io

https://jd557.itch.io

  • Notes
  • Articles 6
  • Followers 47
  • Following 59
European Commission's avatar
European Commission
@EUCommission@ec.social-network.europa.eu

Europe champions digital freedom and its open source community.

We have introduced a tailored approach to boost open source development across EU countries and ensure it is safe from cyber threats.

We only apply security rules to software used in commercial activities.

We are also creating open source software stewards to support security with a light-touch regime and no administrative fines.

Find out more 👇
https://link.europa.eu/Jc7hBy

Cyber Resilience Act - Open source Shaping Europe’s digital future
The image features the phrase "Be open. Be bold. Be" written in white text centered against a deep blue background. Below the word "Be," there is a circle of twelve golden yellow stars, which is the iconic emblem of the European Union.
  • permalink
  • a day ago
Pascal Drabik's avatar
Pascal Drabik
@PascalDrabik@mastodon.social

in reply to this object

@EUCommission

"Better late than never", a we could say. But isn't too late?
Managers have been informed more than 25 years ago...

  • permalink
  • 4 hours ago
An Anarchist Pigeon's avatar
An Anarchist Pigeon
@ivy_pigeon95@mastodon.social

in reply to this object

@EUCommission FOSS has been too much of a success for the EU's comfort. "High quality software, being produced outside of capitalism and government regulations? Quick, regulate it before the plebs realise we're a parasitic superstructure!"

  • permalink
  • 21 hours ago
vlakicas's avatar
vlakicas
@vlakicas@mastodon.social

in reply to this object

@EUCommission About also "freedom" (FSFE dot org / @fsfe) https://en.wikipedia.org/wiki/Free_Software_Foundation_Europe

Free Software Foundation Europe - Wikipedia en.wikipedia.org
  • permalink
  • a day ago
Françoise Beltzung's avatar
Françoise Beltzung
@tchouri@mastodon.social

in reply to this object

@EUCommission
C'est bien. Mais que faites-vous à propos des outils de paiement? Nous attendons d'urgence un équivalent EU à Mastercard, Visa, Paypal, etc

  • permalink
  • a day ago
Fenix's avatar
Fenix
@fenixmaster@mastodon.social

in reply to this object

@EUCommission EU: They mean well, but they always make a mess of things.

  • permalink
  • a day ago
Mr.Mark "The Sharpie King"'s avatar
Mr.Mark "The Sharpie King"
@markmetz@sfba.social

in reply to this object

@EUCommission
Thank you for posting on the Fediverse!

  • permalink
  • a day ago
T Lisa B's avatar
T Lisa B
@TLisaB@zirk.us

in reply to this object

@EUCommission

"Europe champions digital freedom and its open source community"

Yeah, meanwhile, support the US Tech-Nazis, follow us on their platforms and add to their wealth. Heil Edolf Muskler.

yet another EU website linking to US fascist networks
  • permalink
  • a day ago
DNKrupinski 🧡🏴‍☠️'s avatar
DNKrupinski 🧡🏴‍☠️
@dnkrupinski@hannover.town

in reply to this object

@EUCommission „Be open. Be bold. Be a circle of stars?“ 🤔

  • permalink
  • a day ago
Daniël de Kok's avatar
Daniël de Kok
@danieldk@mastodon.social

in reply to this object

@EUCommission If you *really* care about open source, please end Google's use of remote attestation (through Play Integrity) to push open source competitors out of the market.

I can understand that banks and governments want remote attestation, but it should be open to all players, not Google, nor a company cartel.

  • permalink
  • a day ago
kriφm :unverified: ☮  ⏚🔻's avatar
kriφm :unverified: ☮ ⏚🔻
@kriom@framapiaf.org

in reply to this object

@EUCommission

And what about #ChatControl 1.0 ?
You’re not completely making fun of us, are you?

https://mastodon.social/@Tutanota/116277691327823258

Tuta (@Tutanota@mastodon.social) Mastodon
  • permalink
  • a day ago
The_Universality's avatar
The_Universality
@The_Universality@mastodon.novotnykrystof.com

in reply to this object

@EUCommission Awesome, I really like this.

Lets now repel the mess Digital Omnibus enables with the simplification of GDPR and think of more meaningful way.

(Or if we want to simplify regulations, lets first start with the regulatory mess regarding agriculture)

  • permalink
  • a day ago
cybard :geordi_yes:'s avatar
cybard :geordi_yes:
@hagbard@corteximplant.com

in reply to this object

@EUCommission Frontex muss FOSS nutzen dann wäre alles gut und schön und toll auch

  • permalink
  • a day ago
Thibaultmol 🌈's avatar
Thibaultmol 🌈
@thibaultmol@en.osm.town

in reply to this object

@EUCommission Curious if anyone reading this knows, but is the problem of the original version of this program where it made any volunteer project into an unsustainable red tape hell business project now resolved?

  • permalink
  • a day ago
The_Universality's avatar
The_Universality
@The_Universality@mastodon.novotnykrystof.com

in reply to this object

@thibaultmol @EUCommission
"This is why only free and open-source software that is made available on the market, and therefore supplied for distribution or use in the course of a commercial activity, falls in scope of the Cyber Resilience Act."

Second paragraph of the link.europa.eu/Jc7hBy .

In short, if any FOSS app isn't offer commercialy, sold, etc. it shouldn't be fined.

  • permalink
  • a day ago
João Costa's avatar
João Costa
@JD557@blog.joaocosta.eu

in reply to this object

@The_Universality@mastodon.novotnykrystof.com @thibaultmol@en.osm.town @EUCommission@ec.social-network.europa.eu

But isn't that contradicted by the next paragraph?

Furthermore, recognising the importance for cybersecurity of many products with digital elements qualifying as free and open-source software that are published, but not made available on the market within the meaning of the CRA, the novel legal category of open-source software stewards is introduced. These are legal persons who provide support on a sustained basis for the development of such products which are intended for commercial activities, and who play a main role in ensuring their viability, and are subject to a light-touch and tailor-made regulatory regime.

So if you have a big non-commercial project (I assume something like curl), you might still fall under the CRA, it's just that you won't be fined.

  • permalink
  • interact from your instance
  • a day ago
  • 1 like
  • 1 reply
Likes
@iamhannamartin@mastodon.social @thibaultmol@en.osm.town
The_Universality's avatar
The_Universality
@The_Universality@mastodon.novotnykrystof.com

in reply to this object

@JD557 @thibaultmol @EUCommission Yes, you are correct.
I just badly phrased my reply, let me fix that.

  • permalink
  • a day ago
João Costa's avatar
João Costa
@JD557@blog.joaocosta.eu

in reply to this object

@thibaultmol@en.osm.town @EUCommission@ec.social-network.europa.eu also curious about this... From the announcement, I see:

[...] free and open-source software that are published, but not made available on the market [...], the novel legal category of open-source software stewards is introduced. These are legal persons who provide support on a sustained basis for the development of such products [...], and are subject to a light-touch and tailor-made regulatory regime.

So, I believe that if a volunteer project is big enough, the maintainers become "open-source stewards"

Open-source software stewards are subject to the obligations laid down in Article 24, notably [list of obligations]

And it appears that there are some obligations for volunteers... BUT:

In accordance with Article 64(10), open-source software stewards are not subject to administrative fines for infringements of the CRA.

So... Volunteers have obligations, but there are no consequences?

Not sure what to take of this, but I hope the EU doesn't punish volunteers just because their projects became too successful.

  • permalink
  • a day ago
  • 8 likes
  • 1 share
  • 1 reply
maybenot's avatar
maybenot
@maybenot@mstdn.social

in reply to this object

@JD557 @thibaultmol @EUCommission

this
"[...] provide support on a sustained basis for the development [...]"

almost makes it sound like these stewards would be dedicated people who'd interface between the regulatory regime (and it's security requirements) and the maintainers, like some sort of dedicated "office for supporting important projects", but that seems too good to be true

  • permalink
  • a day ago
Powered by microblog.pub 2.0.0+dev (source code) and the ActivityPub protocol. Admin.