About this talk
This talk explores the evolution and impact of open source software in relation to societal changes and regulatory frameworks. The speaker emphasizes the importance of storytelling within the open source community to preserve history and context for future generations. Key moments in open source history are discussed, including significant incidents like Log4j and their implications on security and governance. The Cyber Resilience Act is introduced as a new legal framework that designates responsibilities for open source maintainers and promotes the idea of an 'open source steward.' The talk highlights the need for sustainable funding models for open source projects and addresses how generative AI tools are changing the landscape of software development and maintenance.
Full transcript
It's nice to see a couple of familiar faces out there and so many new faces. Today I'm here to tell a few stories. Those of you who have seen me come to give talks at conferences may have heard a few of these stories before. Most of you probably haven't. Really though, I want you to start telling stories. We, open source community maintainers, leaders, we've changed the world.
And that's reflected in so many things we touch every day. It's reflected in geopolitics. It's reflected in policies of world governments. But the generations that followed us even by just 5 or 10 years, they need to hear our history. They need to hear our stories so they understand the context they are living through now. And our cultural propagation depends on this and on all of you also
telling So so yeah, let me get started. I'm I'm going to skip the background, I guess. I don't know. Probably saw it in my bio. But I want you to think of a moment in your own life where you were not where something happened, but something monumental happened and the space you were in is embedded in your memory of that. For me, one of those moments was
riding a motorcycle in the mountains of Arizona, New Mexico, somewhere in there. Um On a vacation while I was working for the US government at CISA where I was leading open source strategy. That's the first vacation I took in the job and I had a great team. It was fine. And I I I stop in this little mining town and I'm surrounded by literal donkeys and and
old saloons and I have some ice cream and then the wrong phone rings. They never called my work phone even when I wasn't on vacation. So I answer it and I'm like, "Okay." XZ utils had just happened. And the government needed me to figure out what to do. So that moment is part of my story of XZ. Many of my friends have stories like that for log
for shell or heart bleed or other incidents that are part of our collective past. I want you to pay attention to those moments and remember them and tell them. Because in the past couple years a lot of things have happened that those of us who were working in open source 20 years ago or 10 years ago, if you were there early days of Linux or early days
of Kubernetes you might have thought, "What happens when we succeed? How do we continue protecting these things that we're building when we don't know who's going to use them in what situations?" Now we have Linux in the Mars rover and Linux in nuclear power plants. Our responsibilities have changed a little bit, just a little bit. So keep that framing in mind as I talk through some inflection
points that I've lived through. These are part of my stories, but also part of all of our stories because they've changed the shape of open source with each of these. And for the first phase 80s, early 90s, I wasn't really working in open source yet. I was just going to college in 90 95, 96. The Hackers movie was a fun movie. If you've never seen Hackers, go
watch it. It's a good part of our our cultural history as well. And yeah, the the state of the internet back then was really in flux. It was shaped by some folks here. But a lot of the institutions that we have today started in that window of time. They didn't exist before that. They were not here forever. When I when I'm teaching younger folks that I know,
a lot of them think that Debian's just sort of a fixture. It's always been here. It's This is what I want us to pass on. These things are built by us. They haven't always been there. They will be changed by us and the next generation. So for the next inflection point, who remembers this t-shirt is a weapon era? Right? This is when I was in college and
I was beginning to write code and publish code and I was kind of worried that I would accidentally step across some unknown line in the math I was working on and publish an algorithm that would get me a phone call from the NSA or something like that. I didn't know. I was I don't know, a kid in college playing with math. And the Bernstein case which I
think most folks have probably forgotten about or maybe have you never heard about, but it was a court case that ran for about 5 years in the US. Bernstein versus the US Department of Justice. The government claimed that it should prevent people from publishing code if the code might contain very important sensitive algorithms, eventually they the court back the government backed off under a lot of pressure
and multiple tries from the community. That court case directly gave birth to SSL. SSL 1.0 HTTPS SSH and everything we do online today that has open source libraries for encryption is possible because of that case. A lot of it directly was published by the people who were in that involved in that case. The pressure on the court and on the US government to back off came largely
from the beginning of e-commerce. And a bunch of companies that couldn't really do what they do now if we didn't easily usable cryptographic libraries in open source. Google, Facebook, Amazon and all the rest of the e-commerce and advertising and little bookstores online, all of that became possible because open source tools allowed it. The first company I worked at, for us to do this without those tools would
have cost more money than we had in seed funding. Buy hardware, license software pay for SSL certs. All of these things would have been prohibitively expensive in 1999 if not for the early open And so many companies started in that era. And this gave rise to some very profitable companies. So the early aughts up until 2008 was marked by the kind of slow growth until 2008 something
monumental happened. Who in the room remembers like what happened in that year besides the financial crisis? In open source, do you remember? I'm going to say three major things MySQL was bought for a billion dollars. I should say sorry, $1 billion. Um but this is the first time that an open source company, not the first time they were acquired or went public. Red Hat went public before
then. The first time it was such a large sum of money that everybody noticed. Silicon Valley noticed. Institutional investors suddenly wanted every startup to have an And Silicon Valley pivoted. Same year Android and Bitcoin were both published which have also changed the shape of open source and changed the shape of the world since then. Right? So the growth from the late 90s led to this. Our communities
led to That changed everything. Venture capital money began pouring Excuse me, began pouring in. The cloud began to grow. Companies began moving to the cloud because all of the investors were prioritizing operational cost rather than capital expenditure. Looked better on the balance sheet. You had to have open source in there. Open source is free. It doesn't cost anything so we can ignore it on the balance sheet
and so everything sort of moved into the cloud. Mostly Amazon and Google and then Azure and a couple others. And then the community tried to respond to that as well by building open source clouds. I jumped from working on MySQL stuff to working on OpenStack at the very beginning and then Kubernetes. everyone started doing open source as a social activity with the growth of social media. Again,
using open source tools under the hood for Twitter and Facebook. That's how those all got And then GitHub got acquired by Microsoft and we all can see now with generative AI exactly how well that's resulted in. But everything changed again in that era. And to keep costs low, businesses came to rely on these shared digital building blocks, these common tools of infrastructure. And so I want to
ask, is this what success looks like? We as a community have been working on free and open source software and advocating for it for 30-ish years. Is this what success looks like? Most of the world runs on open source. Some products are almost entirely open We have Harvard studies that measure the cost-benefit ratio is 2,000 times hot better like return on on investment. The world spends billions
building open source. The world gets trillions in benefit from open Is this success? Why then does it feel like every developer I know is either burned out or out of a job right now? Like if this is success for open source, what's wrong? And what isn't in our stories? Not just our stories to friends, but in the media in the press, in the government narrative, what is
missing from the story that explains why all of my open source friends are burning out. So, success leads to crisis, which leads to reaction. And it's not that CBEs and open source didn't exist before. Of course, they did. It's the developers I'm sorry, it's not that developers didn't feel pressure before because of course we did. I worked long nights in '99 to prevent to make sure that
our servers didn't crash from Y2K flipped over. Like we all felt pressure over years. But even in our little corner of folks who go to Burning Man and idealists and crust punk hackers, uh we didn't feel like our code affected the whole world until the last 6 years. I don't think anyone can ignore it now. And thanks to what I will point at as a shoddy engineering
practices and profit-motivated [clears throat] insecurity inside companies that take open source and put it in their product and don't do their diligence and don't pay attention and don't support upstream and don't actually participate, uh they just push the liability out into the commons rather than take responsibility for it. Thanks to that, 11 lines of JavaScript could take down half the world's websites. Log4j shell resulted in congressional
hearings that some of our colleagues were were summoned before Congress to try and explain a little open source bug. A couple developers began to turn their code into protestware during the last couple years ago in Russian invasion of Ukraine. And a slow-rolling social engineering attack very nearly implanted a skeleton key in every Linux system in the world. So, a policy reaction was inevitable. Right? Governments are going
to have to do something when all of the systems of society start to buckle and be vulnerable. But before I dive into talking about the Cyber Resilience Act, by the way, has anyone Raise your hand if you've never heard of the Cyber Resilience Act? Wonderful. Raise your hand if you feel like you know everything there is to know about Great. >> [laughter] >> So, before I dive
into that, I want to zoom way, way, way out. >> [snorts] >> Because throughout human history, information propagation asymmetry has led to rapid social change. The the inflection point from handwritten books to the printing press enabled the Protestant Reformation. The spread of ideas changed the shape of this continent because of information propagation asymmetry, those who had the tools to spread their ideas faster could change minds, could
change countries. Well, the same thing happened with radio and television broadcast. right? You could put a radio station next to a border and send your message to the people across that border. That wasn't used anywhere for for anything. >> The same thing happened with the internet and social media. Early days, folks on the Usenet groups and whatnot talked about this utopian ideal of digital democracy. Those tools
were pretty effective at changing and overthrowing some uh except the world doesn't really have an immune system right now to social media manipulation. It'll be kind of nice. And now with generative tools, we have yet another problem. The very epistemic grounds of our shared understanding through digital means are disrupted. Deepfakes, chatbots, all of these sorts of things also changing the asymmetry of power here and how we
talk with each other and of course affecting open source communities. So, [snorts] I'm going to talk about the Cyber Resilience Act. But not the whole thing. It's a long text. If you're not a lawyer and you don't enjoy reading legalese, um there's some good summaries online. >> I have a bad hobby. Developed this probably 15 years ago. When I couldn't sleep, I'd read court briefings uh and
draft laws and um old patent filings from like the '80s. It's been fun, but I don't recommend it. So, I'm going to talk a little bit about a certain part of the Cyber Resilience Act that's very relevant to us in open It creates a new concept of an open source steward, a new class of legal entity. It doesn't exactly define who is a steward, but there's some
good indicators in there. This is a a function in law called a delegated act. It means it isn't written yet. So, the CRA is written, the CRA is law. There's a timeline, it'll go into effect. There's five components in it that are delegated, not done yet. The commission will write them and it will implement something to fill in that gap. So, this particular gap um is in
order to facilitate the obligations of manufacturers that integrate third-party components like Um those companies have to take responsibility for their entire product including all the open source they put in it. They are responsible cuz it's their product. But if an open source steward or a project or somebody else wants to facilitate that due diligence, they could do something called a voluntary security attestation. What What this is
isn't really known yet. It isn't defined yet. But I started working last year to to figure out what this could be. Started working with a bunch of open source communities together to come up with a theory of how this might work. the main reason for this is if you take the whole CRA and you tease it apart and you look at how is this envisioning a structure
for society after these this law and it's it's part of like five laws massively changing how Europe regulates digital safety, security, products, and market. When I look at how they all fit together, there's a missing piece. And it's this delegated act. Open source has a huge part to play in this entire regulatory framework. But open source is done by volunteers. It's carved out from liability, right? As
it should be. We're just volunteers and we're just building stuff. We don't know how it's used. We cannot be held responsible for what a company does with code that we publish. Nor should we. And that doesn't change. But if the maintainers want to help the company, there's got to be some way for that to become a sustainable ongoing effort. So, not alone in thinking that this might
be really good even though we don't know exactly how it works yet. But I want you to imagine again, not just your own stories, but imagine the best sustainable future where open source maintenance is paid for, is funded, people aren't burning And that the stewardship of our digital commons becomes just a part of the fabric of society like uh nature conservation and neighborhood uh cleanups and roads,
clean water, all things that can be cared for, that governments understand must be cared for for people to live fulfilling and healthy lives. So, imagine that. As I talk through a little bit because this didn't just start out of nowhere in the CRA as it was written what, a year and a half ago? The theories and the concepts behind this and the the motivation is a reaction
to things that happened It's a reaction to all the crises that have happened. Log4j shell, XZ utils, all of those. current geopolitical shift is also a result of the European Commission coming to FOSDEM and meeting European government leaders, some from national level, some from the commission learned about open source, began to come to our community events and say hello and get to know us. And then they
changed the drafts. If you saw early draft of the CRA, some were circulated, they were not so great. They didn't really align to how open source actually functions. I think it's really cool that the governments of Europe met and changed their mind and did something different that works with us. So, since then, a whole bunch of uh other communities have gotten together to work on this. I
kicked off the working group back in October. Um it's kind of a whirlwind right now. yeah, I don't know. I'm trying to wrap up a a theory in the next few months. So, we're going to have a workshop later to dive into this a little bit more. I hope you'll come to the workshop. >> Uh you can find us online or uh every 2 weeks we have
a meeting. There'll be a link on my last slide. The goal I think I spent way too long talking about all the cool ideas, but the goal here really is to uh support the cybersecurity, the whole CRA, this is the goal. Market efficiency. And open source has been the most efficient way for companies to develop products for a long time now. Uh it's very clear the goal
of this is avoid altering the liability apportionment, open source maintenance, open source development is completely exempted. The responsibility falls to manufacturers. The theory we have right now is that this should break down into two tiers of attestations of lightweight that works basically like just saying, yeah, we've had a secure development practice. I've been a maintainer for a long time. These sort of things it's a little checklist
of stuff we all already do. Is a project reasonably mature in its development process? Great, that's pretty much done. Um the German BSI also published a an open source security standard. I it's the same thing basically. On the heavyweight side um what's come out of the discussions we've had so far is for manufacturers to actually have their due diligence obligation reduced. We think the open source project
would need almost a full CRA um product assessment, which is a weird thing to do because it's not a product, it's not a a thing for sale. If it's a product you're selling, that's different. This is the open source I'm talking about. Um but that might be able to help manufacturers. Of course, that's not easy to do, not free, takes a bunch of time. So Uh oh,
no, this is the lightweight one. I think it clipped off the top. Um yeah, it's just documented cybersecurity policy, documented vulnerability handling process, generate maintain S-bombs, have an email address that people actually pay attention to for vulnerability reports, and be willing to cooperate with the uh market authority, if ENISA or BSI or something says, "Hey, we think there's a really serious vulnerability going on, can you help?"
Obviously, responsible maintainers will say yes and try to deal with the bug in their spare time. This covers a big chunk of the actual CRA obligations. The heavyweight stuff still TBD. So, I'd love feedback on that. Uh for anyone else who's been involved in CRA standardization process this is where it gets a bit really unknown yet cuz a lot of that just isn't public yet. Waiting for
the standards bodies to publish it. Again, manufacturers ultimately bear that responsibility. These would only be indicators. >> Not a warranty. It's not a declaration of some type, it does not affect the license. Um it is not a commitment to anything, it's just basically the badgering that a lot of projects already do. I think that is sufficient. But this is all still theoretical. So, I have one more
question for you all to think about. Where were you when you first realized that um these generative uh artificial augmented intelligence tools actually do things that will change your work? I've refused to use any of the cloud-based AI tools. So, I built my own cluster at home. Bots and big GPUs. I did this back in 2018. It's been a pretty good gaming system since then, too. >>
Um I did it uh just a few months ago. Uh I bought a couple Framework desktops. You can reconfigure them. There's 100 gigs of RAM dedicated to the GPU. You can run a 120 billion parameter model locally with those. Uh which does some interesting things. I actually that moment myself just in the past few weeks of like, my interface to these tools is different now. I don't
need to write code. I can, I have for most of my life. I can describe the code. And then I can review it and I can fix if I think of coding as a tool my interface to that tool has just changed. I don't like that. when we moved from hand sewing to the loom, people who sewed by hand suddenly didn't have as much of a job.
When we moved from scribes copying books by hand to the printing press, scribes I still have my fountain pen and I still journal as often as I can. People still have the need of those skills, just our interface has changed. I don't know if this is going to be good or bad. But something has shifted and we're living through that right now. I don't know that the
world needs a a class of labor industry that sits at keyboards all day in little cubicles like they do in some parts of the world just typing away. But it does need people who understand how software works, how hardware works, the principles of programming, that's not going away. It needs people who can steward our digital commons and who take care of And who understand why these things
need to be written a certain way and maintained a certain way. And working together in community will still be important. open source is still the best way to steward our digital commons. I deeply believe that. But Linus's law needs to be re-understood because if you apply a good LLM tool today to code anywhere, you can find bugs in it. Our paradigms are shifting. Uh Mikos's law however,
is still true as far as I can tell. Communities still have time and no money. And companies have money and they don't want to spend the time waiting for people to write code. This you know, it's a problem. Probably why a lot of my friends are uh feeling burned out and out of work. Um the CRA now holds up a threat over companies' heads and says, "If
you do not take good care of your product, if you do not build safety and security into the product well, there's a 3% of global revenue potential fine dangling over them and their insurance companies. So, my hope is companies are going to take more care about stewarding their products. And because they have an obligation to contribute back to open source now. If they find a vulnerability in
open source, they have to tell the upstream. If they fix the vulnerability in their product, they have to contribute the patch upstream. That's a law now. So, that's not enough to motivate companies to be better, well, I would hope the commission or the European governments would uh maybe raise the fine or do something because the goal of the CRA is to make this balance stay safe between
communities and companies that take our code. To rebalance it. So, I want to wrap up with one more reason. I've got 1 minute left. Why I don't think open source is going away anytime soon. Even with open claw and all the recent discussions about LLM washing GPL code into non-GPL code computers cannot be held accountable for these decisions. And when companies actually have a liability on their
bottom line, someone needs to be accountable. Stewardship of a digital commons that gives the world building blocks for our modern day life. That's still going to be important even if our tools have changed. Thank you. >> [applause] >> Thank you, Eva. Um any questions for Eva? Please raise your hands and then I'll try to get you as soon as possible. Thank you very much, Eva. Uh I
understood more about the CRA in the half hour than in the last 3 months probably. Um [snorts] I'm wondering regarding the everything gen AI related, do you think the the way we audit um vulnerabilities and the whole security services are going to change and our methodology is going to change in the next years? I think it has [snorts] to and I think for some it already has.
The ability for a generative [snorts] uh it might be an LLM, might be a different type of model to look at bytecode and opcode and find vulnerabilities without even having source code, that exists now. Um or for it to look at the source code of things and infer things that would take people far, far longer. That's also already changed. So, if if companies are not paying attention
to that don't wait 2 years, it's already Uh hi, Eva. Thank you for your talk. Uh I would accept I don't know as an answer to this question, but uh I'm curious. You talk about these two large tiers of software that uh you have in mind of the sort of command line or library class and then the product class. I'm wondering if there's a relationship between communities
and companies and European governments and a sort of third category which is software with no obvious commercial applications or software which is at a stage prior to its breakthrough into the market. So, great question. Um the CRA addresses this in the legal text. We don't need to look at at any theory of attestations. It's very clear. Open source software the development of open source, the publishing of
your ideas, that is unregulated. The use in commercial products is regulated. That's where the regulatory power lands. And there's a middle ground which is if you are stewarding, if you're developing software that you know has commercial use, it is clearly for commercial intent, then there's a very lightweight they call it a lightweight tailor-made regulatory regime for that. But if it's not intended for commercial use, if it's
just your hobby projects, you're a college student publishing out of scope entirely. Not necessarily in terms of regulatory constraints, but in terms of sustainability. In terms of sustainability, I guess then I don't quite follow if you're just publishing code and you have a community of folks who want to tinker with it. I'll I'll pick on on one of my own favorite tools. It's the Mix DJ software.
I don't want to give my money to Pioneer, so I use open source and I can write some C code and fix it. But it it clearly has no commercial intent behind it. It's outside of scope of this area So, first here's another person hoping that the CRA will actually help sustainability of open source software. But I wanted to ask the question for like these project like
tiers. Was your idea that companies having an interest in that software could like fund the project itself so they have a CRA assessment like part in their official body? Did I get this right? You got that right. I didn't want to talk too much about funding because so much of that is unknown and still in development by the working group. But the the idea is these voluntary
security attestations under Article 25 of the CRA don't need to be free. They could be free. They could be published on the open internet. They could be licensed or sold or made available in other terms because they're not part of the software Um I know of some open source foundations who are interested in doing this as a member benefit. If you're a member of the foundation, then
you get these attestations. Right? Um [snorts] there are other approaches that could be out there as well. The the theory we have so far is that the lightweight ones require so little that there is some value there, but not that much. The heavyweight one that's more product like, I'm thinking of like an entire operating system or an office suite that has a lot of dependencies because downstream
is not going to change it very much. They're not going to change the use case, the threat assessment, the risk model, all of that. If that were developed upstream, then the downstream simple market efficiency. Right? If 10 companies pay 10%, they all save 90% of the cost of doing it themselves. Uh and it it makes more sense to use the the heavyweight as the lever Oops. There
we go. Um as the lever to get companies to engage than for every CLI tool, uh but it's still still helpful That's the theory right now, but if you have other ideas, please please bring them to the group. All right. Thank you, Eva. >> [music]
More from this event
See all 47 talks →
Seyi Kuforiji – Bridging the Gap: Encouraging African Talent to Open Source #FOSSBack
23:57
Educating the next generation of open source contributors #FOSSBack
36:35
Jan Dittrich – Best practices and (very) small projects #FOSSBack
24:03
Johannes Näder – Let’s tackle Openwashing! #FOSSBack
24:58