Cyber Resilience Act – Brian Fox, Sonatype
Representatives of member states of the European Union (EU) reached a common agreement yesterday regarding the proposed Cyber Resilience Act (CRA). While the intent of the CRA is to improve cybersecurity and cyber resilience, the seemingly purposeful omission of exemptions for open source would put undue onus on open source foundations and maintainers, posing a serious risk to not just EU innovation and security, but global collaboration and the open source community as a whole.
Transcript
This is Textron tv. Hi everyone. Welcome back here to techron tv.
I'm really happy to have my friend Brian Fox on with us. Brian hasn't been on in months, maybe even a year. I bet.
Uh, Brian, if you don't know, is the c t o in one of the co-founders over at Sonotype. Uh, we've been working with Sonotype here at, uh, Techron, been media ops before that for eight or nine years. Hey, Brian, it's great to have you back on.
How have you been? I've been good. Glad to be here.
Absolutely. Brian. We've, as I mentioned, we've worked with Sonotype and anyone who's working in DevOps, dev SecOps, probably heard of Sonar type, but in case anyone you know is not familiar, why don't you give 'em a little, why don't we start with that, a quick little sonar type kind of background.
Yeah. So Sonotype we founded back in 2007. We initially were, um, doing a lot of heavy lifting behind Apache Maven, um, building tools and, and services around, uh, the Maven ecosystem.
Uh, we are also still the company that runs the Maven Central repository, which is where the world gets all of its open source Java. So basically every organization worldwide, they're probably doing Java somewhere. Um, you're, you're using some of our services somewhere somehow.
Um, you know, for the last, uh, 10 plus years, we've been building tools to help organizations deal with what the world now calls sbo M'S software, supply chain security. That's been a big focus of ours for, for well over a decade at this point. Oh, yeah.
Excellent, excellent. Um, and, and you, you guys do, of course, a ton of stuff for the community as well all day. DevOps was, was of course, is a sonotype event and, and involved in Linux foundations and, and everything else.
I mean, it's own type, a pillar of the open source community in, in many, many ways, right? Um, and that's what we're talking about a little bit today, right? There's a new, there's a new act or new regulation being bandied about over in the EU called the Cyber Resilience Act or A C R A and, and this thing could have some profound implications for the open source world, the open source community.
Um, this is something near and dear to you. We, I actually saw your writing about it on, uh, on LinkedIn, I think it was, and ask you to come on and, and kind of educate the audience a little bit. Can you kind of lay, can you lay the foundation, Brian, give us the background and then we'll take it from there.
Yeah. So, you know, maybe if we take a, take a step back for a moment. I think, you know, given that long view we've had on supply chain security and these types of things, um, you know, we've, we've long been advocating that, um, the industry needs to do a better job, that they need to step up.
And, and in, in the early days of that, people weren't listening. They thought open source was fine. I've got a firewall on a security team, I don't have to pay attention to it.
You know, multiple struts issues over the years. The log for J SolarWinds, um, these types of things have really driven awareness within the, in the industry. Um, and also within regulators, you know, in, in the us the, the government has, um, I think taken a very mature approach and ex and, and said that, you know, they, they want to uplevel what's going on.
They're considering changing liability so that companies can't disclaim all liability and continue to, you know, have a race to the bottom in ti in terms of, um, security posture. Um, and, and this is good because in, in last year's state of the software supply chain report 2022, we did some research and we found that when a, a vulnerable component is being consumed from Maven Central, you know, when, when somebody is downloading that 96% of the time, there's already a fixed component available, right? So the problem as we see it is not that open source is doing a poor job, uh, fixing and responding to issues, it's that the consumers are doing a poor job of updating their own dependencies, right?
And, and you know, even log four J that team released, um, the fix over a holiday weekend within days, I would challenge any commercial organization to have turned around a patch in as fast a time. And yet, uh, over a year, you know, 18, 19 months later, 30% of the downloads of Maven Central are still of those known vulnerable log four J. That's not a problem that log four j the team can fix.
So that's the landscape that we sit in. The US government has said we need to do a better job. They've been talking about SBO M standards and think rethinking the national cyber strategy focused on, you know, trying to, to, to change the, the economics of that and, and focus a bit more on software liability.
But what they did very clearly is they said, you know, we understand that open source is the root of most innovation going on, and these regulations should not apply to the producers of open source. We don't want to kill that ecosystem, but that commercial entities that are choosing open source and putting 'em into products, and then, you know, those products fail for one reason or another, they're the ones who should be responsible for those decisions. I wholeheartedly endorse that approach.
What's been going on inside of the European Union, however, with there's two acts. There's a Cyber Resiliency Act, the c r a, and there's also one called the Product Liability Directive, the P l D. Um, both of these took a similar arc, and I started writing about this in November, but the problem is their exclusion for open source had a bunch of caveats on it.
It says, um, you know, open source would be excluded from this act unless it's done in the context of a commercial activity. And that was very vague, and we, we recognized that that was a challenge back way back in November. Well, the, the version that came out of committee just this week has added additional clarifications that actually don't, don't make it better.
Um, they have defined that, uh, commercial open source, um, should follow the, all of the requirements within the C R A, which includes fines and mandatory reporting, and, you know, a lot of things that will be difficult for people in their spare time, uh, that are working on projects, um, to, to comply with. But what's worse is they've defined commercial open source as open source where the main contributors work for a commercial entity, like full stop. So basically what they've said, if you've turned it around, unless you're unemployed or you work for an academic, the open source contributions you make could actually make that project suddenly, uh, a commercial project in the eyes of the regulation and suddenly be liable for fines up to 15 million euros.
Right? Further, they've gone to say that, um, contributions from commercial entities, if they're of a recurring nature, would also make those projects no longer excluded. So what they've, what they've inadvertently done is basically disincented people from working on open source, they've disincented commercial entities from paying developers to contribute back to the projects they use.
Like this is the thing everybody's been trying to drive towards. And this regulation will cause companies to say, wait, we, we can't do that anymore because it might make liability for it, and, and it'll make the projects potentially not willing to accept those donations because that project becomes not pure anymore. Um, and so it's, it's a bit of a frustrating situation, um, that, that this regulation is, you know, on its face trying to make things more secure will probably end up making things within Europe for sure less secure, because projects may, um, you know, rather than deciding to give up on their, their, their hobby or their their side project, they may choose to say, you know what?
We're changing our license. This code can't be used in Europe. You know, field abuse restrictions might be something that comes into play.
Um, you know, and, and so what that means is that European companies dependent upon open source, might find their entire open source stack effectively abandoned because they're no longer allowed to use it. And, and that can't be good for anybody. No.
And, and, and quite frankly, Brian, I think that's an artificial thing. I think the world is so interconnected today. I mean, one could say, all right, if I'm a European company, I'll host this code in a US data center.
So it's not necessarily part of it nonsense. That doesn't work. You're still a European, you're under their jurisdiction.
By the same token, if you're an American company and running your code in America, but you have European customers or partners or what have you who are interacting with it, you are gonna wind up getting caught in that web as well. I'm, I'm glad you brought that up. And I think that that's a model that the regulators have in mind, that if you think about the G D P R, you know, the same thing, the cookie warnings that we all have, companies not inside of the European jurisdiction because they wanted to do business there, were basically forced to comply.
So every website has to deal with that, that when you have a company who is trying to survive and make a profit, you can, you can get them to comply in those ways. But Brian, the open source developer working on something in my part-time, I have zero incentive to do something that is potentially gonna make me liable for a $15 million AB abs. I agree, man, You have no leverage over people who are contributing their stuff for Well, no, you do have leverage.
You could drive them away from doing that. That's right. That's the only thing.
Or that's leverage. I said, that's, or I can say, you know what? I'm gonna keep doing it, but I'm gonna, I'm gonna change my license so that anybody that is bringing my code into Europe, whether it's direct or inside a product, no longer has a license to use my stuff, that might be an option.
Because I can say, you know what? I'm gonna put my stuff out there for the rest of the world. And these are the, the, the, the terrible that's, that's, that's messy.
That the open source, it, it is messy. There is no good answer. That's not going to be a, that's gonna be impossible to enforce here.
Here's my bigger issue, and, and I don't mean to blame the eu, they're no better or worse than many other political bodies, including our own. When you have non-technical people who see a problem and say, oh, we, we, you know, I'm not a Ronald Reagan fan, let me say that upfront, but we, you know, but the old adage of, I'm here from the gov I'm from the government and I'm here to help, right? Scares the heck outta me when it comes to them trying to figure out how to regulate technology and stuff like this.
We, we, we, you know, quite frankly, it's a miracle, uh, that our software supply chain and SBU stuff is not, uh, I don't want to use a bad word, that it's o it's, it's not, it's not terrible, let's put it that way. Right? And, and it's, I think it's because the, the powers that be in politics have let the technical folks come in and say, Hey, this is how you gotta do this, or this is kind of the, the model we should use here, I would hope at the eu.
And, and in this particular case for the c r a, that we have a similar thing that people like you, people like the Linux Foundation, people who, you know, live and breathe open source, can come in and weigh in on this. Because I don't think the average politician understands the nuances of this. They, they, they don't.
And many of us have been working with anybody that would listen that that is part of that for more than six months. Um, and what, you know, there's, there's a lot of theories of out there, um, about what actually is going on. I'm not gonna, I'm not gonna spread those necessarily, but what we've come to learn recently is that it's not an accident that they've tried to, um, put some of the burden on certain types of open source that that is in fact, actually intentional.
You know, initially we thought this was an unintentional misunderstanding, and they were ensnaring more than they thought. No, it turns out very clearly that that was in fact, intentional. What I think they don't understand, though, is the knock on effects of that, that, like I explained, that, you know, you can't force a hobbyist to keep doing their hobby if you tell them they're gonna be liable for a $15 million fine.
Yeah. And, and having them give up on what represents, you know, in many cases, 90% of the stack of, of these businesses ends up making the situation worse, not better. That's crazy.
You know, the, the, the, the shame of it is, or the irony is that in fact, in general, the folks in Europe and EMEA were much bigger supporters of open source than we used to be here in the us right? We saw that in Maven and, uh, nexus Repository, and a lot of the stuff we did that the European, uh, users were the first to adopt this. Um, you know, they, they, Europe tends to understand better, you know, shared infrastructure, common infrastructure, design patterns, um, than than us in the West.
And so for that reason, Maven, I think, fit into that. And, and yes, for sure, open source was a much bigger user inside of Europe, which is the tragedy that if they end up inadvertently killing that industry within Europe, um, it has a disproportional effect on the rest of the industry. There's no, I agree, man, Brian, people sit watching this wherever they're watching it, whether they're sitting, standing, driving, whatever.
What, what can we do? What can we do to kind of make this right? So I think, you know, where, where the legislation is, it's out of committee.
Um, you know, it, it, it will go to some form of additional, uh, votes, uh, sometime probably in September. Um, so, uh, the best chance we believe we have at this point is for people who are in the European Union to contact their, their politicians for businesses that are in Europe to raise their voice. I think the challenge is not enough of the industry understands this, you know, potential tsunami coming their way, and we're basically at the last chance to do something.
Um, those of us that are outside of the eu, all we can do is try to raise awareness to those that are inside the eu because they are the ones that are being represented by this regulation. They're the ones that need to make their voice heard to their representatives. That's the only way to make this adjustment.
So, to my friends, and, and whether you're my friends or not, if you're watching this, you're in an EU country, We need you to go out there, contact your representatives, let them know that inadvertently or on purpose, they are putting a gun to the head of so many different, uh, first of all, developers who develop or who contribute code to open source to the open source community at large, who, who kind of maintains all of these projects and to the thousands and millions of organizations around the world, not just in the eu, who open source is the backbone of their, of their software usage. And every company's a software company today. So please, if, if you care, care about this issue, go out and do that.
Brian, thank you for coming on and making us aware of this. We'll, we'll, we'll keep doing everything we can here, and I know, you know, to get the word out, but you keep doing what you do, man. We, we need people like you on, on the, on the battle front, right.
And that look out keeping it going on, it's great seeing you. Come back on. Keep us posted.
Okay. All right. Thanks for having me.
Alrightyy. Brian Fox, c t o co-founder of Sonotype here talking about the Cyber Resilience Act, c r a out of vu. If you can do something to influence this, folks, please do.
It's important. We'll be back here on Text Trunk TV in a minute.