IT
  
Attualmente si sta visualizzando la versione Italy del sito.
Volete passare al vostro sito locale?
12 TEMPO DI LETTURA MIN

Newsdesk

THIS ISSUE: EU threat to open source Plasma features face chop Gnome opens window plans Debian embraces RISC-V

SECURITY

EU passes Cyber Resilience Act

EU states have agreed to draft legislation, despite opposition from the Linux Foundation and others. Is this the end of open source in Europe?

The Cyber Resilience Act was proposed in September 2022 and mostly seems to target interconnected equipment such as IoT devices. In theory, it ensures minimum standards for connected devices as well as requiring mandatory security updates. As well meaning as the legislation is, the impact on open source development could be devastating. In April, more than a dozen open source industry bodies, including the Linux Foundation Europe, wrote an open letter to EU legislators asking them to reconsider the current wording (https://newsroom.eclipse.org/ news/announcements/open-letter-europeancommission-cyber-resilience-act).

In theory, the Act exempts “free and open source software developed or supplied outside the course of a commercial activity”.

In practice, many open source projects would be considered commercial if any contributors were paid for their work. This would encompass most major versions of Linux, as well as popular open source apps such as LibreOffice.

Some aspects of the Act would also be almost impossible to guarantee. In January, GitHub pointed out that Annex I, for instance, would require software to be delivered “without any known exploitable vulnerabilities”. The company points out that vulnerabilities exist on a “continuum of risk” and new ones are being discovered all the time.

The open letter points this out, as well as making a tongue-in-cheek reference to the fact that most open source projects don’t have the “benefit of an established relationship with the co-legislators”.

Joe Brockmeier, head of community at open source development company Percona, points out more chilling effects of the legislation for the community: “The CRA wants to force projects to report vulnerabilities within ‘hours’ of reporting to an EU institution, which flies in the face of industry practices and will have severe unintended consequences. Open source projects are frequently combined in ways that are unpredictable and may cause vulnerabilities that were unforeseeable to the original authors.”

Brockmeier cites the zero-day vulnerability Log4Shell as a good example of this. He also points out that onerous requirements like these could force open source software development out of Europe entirely.

Sbloccate questo articolo e molto altro con
Si può godere di:
Godetevi questa edizione per intero
Accesso immediato a oltre 600 titoli
Migliaia di numeri arretrati
Nessun contratto o impegno
Prova per €1.09
ABBONATI ORA
30 giorni di accesso, poi solo €11,99 / mese. Disdetta in qualsiasi momento. Solo per i nuovi abbonati.


Per saperne di più
Pocketmags Plus
Pocketmags Plus

Questo articolo è...


View Issues
Linux Format
September 2023
VISUALIZZA IN NEGOZIO

Altri articoli in questo numero


MEET THE TEAM
MEET THE TEAM
This issue, we’re getting AIs to badly develop ap plications for us. Hurrah! So, what are you going to do with all the spare time your personal AI is going to free up?
Not so smart
A rtificial intelligence is like any other tool
REGULARS AT A GLANCE
JUST BUGGIN’
Jon Masters is a kernel hacker who’s been
Kernel Watch
Jon Masters keeps up with all the latest happenings in the Linux kernel, so you don’t have to.
ONGOING DEVELOPMENT…
John Ogness posted Wire Up Nbcon Consoles, which
Answers
Got a burning question about open source or the kernel? Whatever your level, email it to answers@linuxformat.com
Mailserver
WRITE TO US Do you have a
Hot Picks
Immich
ATTACK OF THE A.I. Pi BOTS
Fun artificial intelligence projects you can build and run at home on the cheapest of hobbyist hardware!
REVIEWS
BarraCuda 8TB HDD
Cheap and cheerful – that’s not how Shane Downing parties.
GeForce RTX 4060
A good graphics card with the wrong name, ponders Chris Szewczyk.
Murena Fairphone 4
Fairest of them all, Jonni Bidwell is excited by an ethical phone with a privacy-respecting operating system.
Peppermint OS
After years of sampling Linux Mint, Nate Drake opts for something spicier in the hybrid Peppermint OS, which integrates cloud-based apps.
Fatdog64 Linux 814
Nate Drake decides to look in on Fatdog, a Puppy-based OS that’s grown into a very credible canine in its own right.
ROUNDUP
Media-creation distros
Michael Reed examines five distributions, aimed at creative types, that come packed with applications, utilities and plugins.
Customisations & extra features
How much does each distro add?
Base distro and package repros
We need a strong foundation with access to the latest software.
Using the user interface
Creative flow is paramount.
System efficiency
It’s a shame if the distro starts gobbling up resources before you’ve even started.
Audio, music and plugins
Showcasing what Linux can do in this realm and saving installation effort.
Video and graphics apps
Ready-to-go drawing and painting applications are always welcome.
Documentation and support
Information on how to get things running and overcome difficulties.
The verdict
Media-creation distributions
A.I. CODING
Matt Holder spends some time discovering how AI, ML and LLM can be used to help us with our programming – and, yes, he explains what the acronyms mean as well…
Pi USER
Pi Foundation open sources its Code Editor
Accelerating feature development and generally doing the right thing all round, hurrah!
RP2040 ETH Mini Dev
Les Pounder loves all his Pi collection, but sometimes there’s some he simply can’t love as much…
Sonic Mini 8K S
Always on the lookout for upgrades, Denise Bertacchi doubly likes it when there’s a bargain, too.
Build a flashy dice roller with NeoPixels
Les Pounder is learning to multitask but we think he misunderstood the instructions.
Smart management for smart kiosks
Tam Hanna takes a look at how Ubuntu Frame harnesses Wayland’s strengths to make smart display management more comfortable.
TUTORIALS
Best kept secrets
A man who keeps his cards close to his chest, we struggled to persuade Shashank Sharma to reveal how he protects his passwords.
Upgrade your Steam Deck SSD
Neil Mohr asked hardcore PC gamers Tony Polanco and Katie Wickens to upgrade a Linux device – what could possibly go wrong?
Access services with Nginx reverse proxy
Nick Peers discovers how to open your network services to the internet with this user-friendly implementation of Nginx.
Add Raspberry Pi GPIO to your PC
PCs don’t offer a GPIO header like the Raspberry Pi, but Mike Bedford reveals that a low-cost add-on is all you need to join in the fun.
Render real-world 3D maps in Blender
Credit: www.blender.org
ADMINISTERIA
A ROCKY ROAD AHEAD?
Stuart Burns is a Linux administrator for a
Docker is dead, long live Docker
Docker has been the king of containers but could Podman put an end to Docker’s reign?
LXD gobbled up by Canonical
LXD ownership is transferred to Canonical in the hope of making great strides.
Who installed that?
Yum is more than just a way to install applications – it can do all sorts of interesting stuff.
HostPapa
Ruby P Jane tries this paternal web host provider that offers a range of services for both personal and business use.
Cloudways
A competent host offering scalable cloud-based solutions that has Ruby P Jane loving what she sees.
IN DEPTH
AWS vs Azure
What’s the difference? Not all cloud providers are the same. Steve Cassidy compares the two biggest platforms
CODING ACADEMY
Text adventure combat mechanics
Often found making love and not war, this month Nate Drake takes our interactive text adventure down a dark, violent path.
Code your own Breakout retro game
Matt Holder discovers that writing a ’70s-style classic game isn’t as simple as he first thought.
Creating Flutter apps
David Bolton shows how to set up a Flutter development environment on Linux and then how to build a simple calculator in Flutter.
Chat
X
Supporto Pocketmags