Re: [hrpc] FCC's new Internet regulatory gambit and human rights

Vittorio Bertola <vittorio.bertola@open-xchange.com> Thu, 28 March 2024 14:54 UTC

Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: hrpc@ietfa.amsl.com
Delivered-To: hrpc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CEDDC14CE42 for <hrpc@ietfa.amsl.com>; Thu, 28 Mar 2024 07:54:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=open-xchange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rNXsJPMIP47Y for <hrpc@ietfa.amsl.com>; Thu, 28 Mar 2024 07:54:43 -0700 (PDT)
Received: from mx4.open-xchange.com (mx4.open-xchange.com [87.191.57.184]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7EE37C14F690 for <hrpc@irtf.org>; Thu, 28 Mar 2024 07:54:43 -0700 (PDT)
Received: from imap.open-xchange.com (imap.open-xchange.com [10.20.28.82]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx4.open-xchange.com (Postfix) with ESMTPSA id 58AA26A12C; Thu, 28 Mar 2024 15:54:41 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com; s=201705; t=1711637681; bh=KOQGasxHWq9PNJCzqbWAmgdjVMGWCzoFKJZLOpTdBNA=; h=Date:From:To:Cc:In-Reply-To:References:Subject:From; b=eSW4UQOmTiAdQwEcE3ZpkwCGbMs/Q60hXWMA+IX770wrV/DHj1O25U1Hw2fyb12y/ rRwPjozQt2/iEA0dEABFyoOj9lpsQEnDxE0iY1JKifDy62t5NojBzAuqM86irDLiCP loP59PTwlli3dXcc/SuoWfZQVQi7/HQ7FgkNSpntoyaxhOThgP6L2Uc/IWzWIzN+gt fBZ43q79jAtVSIfSzVaAaUHBh+qHNlIqmLyhnxVBjR0gqarWG/A2ePeUAi8R8i6IC3 8753APQyZE0k5vGvXrcBvmWrBj47VkwGQUESjL5UUaBn4OvbrtmbssXWPKLGw/eti1 J+jjSJlZDDAXA==
Received: from appsuite-gw2.open-xchange.com ([10.20.28.82]) by imap.open-xchange.com with ESMTPSA id XH7jE7GEBWa6ERwA3c6Kzw (envelope-from <vittorio.bertola@open-xchange.com>); Thu, 28 Mar 2024 15:54:41 +0100
Date: Thu, 28 Mar 2024 15:54:41 +0100
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: rutkowski.tony@gmail.com
Cc: hrpc@irtf.org
Message-ID: <1633729151.141406.1711637681285@appsuite-gw2.open-xchange.com>
In-Reply-To: <9346223d-d0b7-487b-a566-c6464aa31a07@gmail.com>
References: <659E347E-B474-4CD7-A41E-394BC5B99285@mnot.net> <110ee2ad-fbd4-4917-9464-4fd3e0511d6e@andersdotter.cc> <D216AB41-DE37-4747-A5B1-33B70C121F78@mnot.net> <4ed43236-6061-4d57-aa26-fc9e8b13d499@andersdotter.cc> <CABcZeBMZy0jVDpJpG_vo6DY0KvVN22+GKCyNOPf+0O3NJCU9Sg@mail.gmail.com> <333c35f8-ec94-4cd9-a201-e4e223baf664@andersdotter.cc> <CAGVFjM+=nk+WDy1oPHfr0dK5z7ppEdXbebHSwa06tJRiZLEGhg@mail.gmail.com> <38f5d8a0-86c9-4e26-a75d-0c37615597dc@andersdotter.cc> <9346223d-d0b7-487b-a566-c6464aa31a07@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.6-Rev59
X-Originating-Client: open-xchange-appsuite
Autocrypt: addr=vittorio.bertola@open-xchange.com; prefer-encrypt=mutual; keydata= mQENBFhFR+UBCACfoywFKBRfzasiiR9/6dwY36eLePXcdScumDMR8qoXvRS55QYDjp5bs+yMq41qWV9 xp/cqryY9jnvHbeF3TsE5yEazpD1dleRbkpElUBpPwXqkrSP8uXO9KkS9KoX6gdml6M4L+F82WpqYC1 uTzOE6HPmhmQ4cGSgoia2jolxAhRpzoYN99/BwpvoZeTSLP5K6yPlMPYkMev/uZlAkMMhelli9IN6yA yxcC0AeHSnOAcNKUr13yXyMlTyi1cdMJ4sk88zIbefxwg3PAtYjkz3wgvP96cNVwAgSt4+j/ZuVaENP pgVuM512m051j9SlspWDHtzrci5pBKKFsibnTelrABEBAAG0NUJlcnRvbGEsIFZpdHRvcmlvIDx2aXR 0b3Jpby5iZXJ0b2xhQG9wZW4teGNoYW5nZS5jb20+iQFABBMBAgAqBAsJCAcGFQoJCAsCBRYCAwEAAp 4BAhsDBYkSzAMABQMAAAAABYJYRUflAAoJEIU2cHmzj8qNaG0H/ROY+suCP86hoN+9RIV66Ej8b3sb8 UgwFJOJMupZfeb9yTIJwE4VQT5lTt146CcJJ5jvxD6FZn1Htw9y4/45pPAF7xLE066jg3OqRvzeWRZ3 IDUfJJIiM5YGk1xWxDqppSwhnKcMOuI72iioWxX0nGQrWxpnWJsjt08IEEwuYucDkul1PHsrLJbTd58 fiMKLVwag+IE1SPHOwkPF6arZQZIfB5ThtOZV+36Jn8Hok9XfeXWBVyPkiWCQYVX39QsIbr0JNR9kQy 4g2ZFexOcTe8Jo12jPRL7V8OqStdDes3cje9lWFLnX05nrfLuE0l0JKWEg8akN+McFXc+oV68h7nu5A Q0EWEVH5QEIAIDKanNBe1uRfk8AjLirflZO291VNkOAeUu+dIhecGnZeQW6htlDinlYOnXhtsY1mK9W PUu+xshDq7lXn2G0LxldYwyJYZaJtDgIKqVqwxfA34Lj27oqPuXwcvGhdCgt0SW/YcalRdAi0/AzUCu 5GSaj2kaGUSnBYYUP4szGJXjaK2psP5toQSCtx2pfSXQ6MaqPK9Zzy+D5xc6VWQRp/iRImodAcPf8fg JJvRyJ8Jla3lKWyvBBzJDg6MOf6Fts78bJSt23X0uPp93g7GgbYkuRMnFI4RGoTVkxjD/HBEJ0CNg22 hoHJondhmKnZVrHEluFuSnW0wBEIYomcPSPB+cAEQEAAYkBMQQYAQIAGwUCWEVH5QIbDAQLCQgHBhUK CQgLAgUJEswDAAAKCRCFNnB5s4/KjdO8B/wNpvWtOpLdotR/Xh4fu08Fd63nnNfbIGIETWsVi0Sbr8i E5duuGaaWIcMmUvgKe/BM0Fpj9X01Zjm90uoPrlVVuQWrf+vFlbalUYVZr51gl5UyUFHk+iAZCAA0WB rsmACKvuV1P7GuiX3UV9b59T9taYJxN3dNFuftrEuvsqHimFtlekUjUwoCekTJdncFusBhwz2OrKhHr WWrEsXkfh0+pURWYAlKlTxvXuI7gAfHEQM+6OnrWvXYtlhd0M1sBPnCjbyG63Qws7Rek9bEWKtH6dA6 dmT2FQT+g1S9Mdf0WkPTQNX0x24dm8IoHuD3KYwX7Svx43Xa17aZnXqUjtj1
Archived-At: <https://mailarchive.ietf.org/arch/msg/hrpc/rtdGS8QSDy_dvH4KXtFrVK9HYEo>
Subject: Re: [hrpc] FCC's new Internet regulatory gambit and human rights
X-BeenThere: hrpc@irtf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: hrpc discussion list <hrpc.irtf.org>
List-Unsubscribe: <https://mailman.irtf.org/mailman/options/hrpc>, <mailto:hrpc-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/hrpc/>
List-Post: <mailto:hrpc@irtf.org>
List-Help: <mailto:hrpc-request@irtf.org?subject=help>
List-Subscribe: <https://mailman.irtf.org/mailman/listinfo/hrpc>, <mailto:hrpc-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Mar 2024 14:54:48 -0000


> Il 28/03/2024 15:05 CET Tony Rutkowski <rutkowski.tony@gmail.com> ha scritto:
> 
>  
> https://circleid.com/posts/20240327-the-fcc-cyber-trust-label-gambit-part-ii
> 
> HPRC and the IETF might wish to weigh in on this gambit - incredulously 
> promulgated under a regulatory section called "Internet Freedom."  It 
> rather makes a mockery of the phrase.
> 
> Note the FCC delegation of surveillance authority to private "CLAs" 
> based on vague references to a CFR 155 ISO/IEC standard. That's 
> remarkable non-transparency.  There are enough human rights abridgements 
> here to write a book.

I don't know what is inside this regulation, but by trying to extract the facts from the prose of the article you link, it looks like a self-certification scheme of adherence to a set of security best practices, similar to the regime just introduced in Europe by the CRA but with a more limited scope (the European regulation also applies to pure software and not just to connected devices).

We - meaning, the open source industry including anything from SMEs to the Linux Foundation - just came out of a 1-year interaction with the European Commission on the CRA. We managed to make it substantially better than the first draft, yet the regulators were firm on the fact that Internet software and devices are now a vital industry, and much like you can't distribute (not even for free) a car or a hairdryer to European customers without appropriate security certifications (the CE mark), you shouldn't be allowed to distribute insecure software.

We tried to play the card of "software as literature / as a form of free expression" but we were sort of laughed at. This is now a multi-billion euro industry and a bug in key software libraries (even volunteer-based, open source ones) can bring the entire society to a halt. The risk of underfunded, volunteer-based software projects used at large scale is just not socially bearable any more, they think; someone must take liability for their security, which needs to be based on some kind of standard practices (the EU ones will now be developed by CEN-CENELEC). On the other hand, we succeeded in making this a self-certification requirement for almost any type of software.

It looks like most countries around the world will follow suit under the same approach.

-- 
Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
vittorio.bertola@open-xchange.com 
Office @ Via Treviso 12, 10144 Torino, Italy