[-] Damage@feddit.it 2 points 16 hours ago

Paywall, here are the contents

Cyber Resilience Act: EU Commission provides more clarity for open source

Source: heise online
Author: vbr


Before the first reporting obligations of the Cyber Resilience Act (CRA) take effect, the EU Commission is providing manufacturers, developers, and companies with a guide. The guide, published on Monday, explains in about 80 pages how the cybersecurity regulation is to be interpreted. This ranges from defining affected products and essential software updates to rules for open source. The CRA itself has been in force since December 2024 and stipulates uniform minimum requirements for the cybersecurity of digital products across the EU throughout their entire lifecycle.

According to the Commission, the handbook answers key questions from the industry. It is intended to help those affected to implement the requirements legally. The guide explains, for example, which products fall under the CRA, how crucial program revisions are to be classified, and by what standards support periods are to be determined.

In addition, it provides information on how risk analyses and reporting obligations can be practically fulfilled. The EU Commission places particular emphasis on startups and small and medium-sized enterprises. Numerous practical examples and application scenarios are intended to clarify ambiguities and avoid unnecessary administrative effort.

Open source should not be slowed down

The Commission devotes considerable space to free and open-source software. During the negotiations on the CRA, developers and open-source foundations warned that voluntary projects could be discouraged by new liability and documentation requirements.

The Commission is trying to allay these fears. Freely available open-source software generally does not fall under the CRA as long as it is not brought to market as part of a commercial activity. It now explains when such an activity exists. Anyone who sells open-source software, offers paid enterprise versions, or monetizes other services through a program is considered a manufacturer in the sense of the CRA.

The situation is similar if users are required to provide personal data for purposes other than security or interoperability, or if donations are effectively a prerequisite for accessing the software or essential updates. Conversely, voluntary contributions, public funding, or sponsorship funds alone do not constitute commercial activity. Paid consulting, training, or support services also do not automatically mean that an open-source project falls under the CRA – as long as the software itself remains freely available.

What exactly are open-source stewards?

Further clarification will likely be important for many developers. The Commission explicitly distinguishes between project managers and suppliers. Those who merely fix bugs or submit new features generally bear no responsibility under the CRA. The situation is different for individuals or organizations that publish a project and exercise control over releases, roadmaps, and steering. Merely having write access to the source code repository is not sufficient for this.

The role of "stewards" also becomes clearer. This can include foundations or other organizations that provide permanent organizational or technical support for open-source projects without marketing them themselves. Their obligations depend on the intensity of their involvement: Those who only handle community work have significantly fewer obligations than organizations that operate infrastructure or actively participate in development and security management. Depending on the type of support, reporting obligations for security incidents or exploited vulnerabilities may also apply to stewards.

Furthermore, the Commission explains when a change to a product is considered "essential". Updates that exclusively fix vulnerabilities or maintain or improve the existing security level generally do not trigger a new conformity assessment procedure. The situation may be different if new features alter a product's risk profile or create additional attack surfaces. The guide also provides clarity on repairs: If only identical replacement parts are supplied, this is not considered a re-release of the product.

The clock is ticking

The guide also specifies requirements, for example for risk analyses and future reporting obligations. Although the guide is not legally binding, it is likely to be decisive for manufacturers and national market surveillance authorities on how the regulation will be interpreted in practice. The German government has designated the Federal Office for Information Security (BSI) for this purpose.

EU Commission Vice-President Henna Virkkunen described the handbook as part of Brussels' relief agenda. It is intended to help companies implement their new obligations on time and legally. A secure Europe and a business-friendly Europe go hand in hand. In the Commission's view, the CRA is gaining importance due to the advances in powerful AI models with cyber capabilities. The first reporting obligations will take effect on September 11, 2026. Manufacturers must fully comply with the regulation from December 11, 2027.


This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.

[-] Damage@feddit.it 1 points 1 day ago

You don't understand, they've got children! Which matter, unlike the children their governments likes to massacre all over the world.

[-] Damage@feddit.it 4 points 1 day ago

267€? What are those, 4GB sticks?

[-] Damage@feddit.it 3 points 1 day ago

My goal was to explain why the status quo is the way it is and most of it does come down to whatever makes the games the prettiest. I can’t fault people for that.

You can and you should. Just blindly going through life chasing your own enjoyment at the expense of everything else is egoistical and detrimental to civil society. Egoism is what is destroying the world.

Everything in life shouldn’t require research and an ethics check.

Unfortunately it does, and while I agree we can't fix everything at once, some things are easier than others.

These kinds of issues are why we have elected officials and governing bodies and it’s their failures you should be upset at.

Yeah, and that's another thing where people should pay more attention, but they don't because they care more about their immediate satisfaction, with hobbies and enjoyment, rather than long-term outlooks.

[-] Damage@feddit.it 1 points 1 day ago

Russia is just codename for "world powers", which include the US and China.

EU officials can't just outright say we can't trust our main ally anymore.

[-] Damage@feddit.it 4 points 1 day ago* (last edited 1 day ago)

Yeah, you're confirming that ~~gamers~~ people care more about numbers and shiny things than principles. Who cares if you're destroying your hobby, when you can have slightly better lighting in a game?
Gamers made nVidia's fortune and nVidia is one of the main reasons for the crypto and ai messes. It's not the only factor but it's one.

[-] Damage@feddit.it 6 points 1 day ago

The US is the only country to have used nukes in war

[-] Damage@feddit.it 9 points 1 day ago

I used to work with a guy who was addressed exclusively by his nickname. Sometimes I wonder if his work contract sported his name or nickname.

Funnily he was one of our union reps in the company, one day we had a big assembly with a couple of union officials, at the end the officials thank each of our three reps: "ok, so thanks to [name], [surname], [name], [surname], and.... [guy's nickname], sorry I don't know your actual name."

[-] Damage@feddit.it 11 points 1 day ago

I've been AMD-only since forever, since before AMD cards even existed, my computer ran an ATi card when AMD bought them and when they went from being team green to team red. I swore off nVidia after they killed 3dfx, that's decades ago.

I never had problems running games except when they were infected by nVidia's fuckery, and I never had to put much effort in avoiding them.

Gamers just care more about big numbers and shiny things more than they care for the well-being of their hobby, and are directly responsible for part of the AI-shitshow we're in nowadays.

[-] Damage@feddit.it 22 points 1 day ago

WHEN ARE YOU FUCKERS GONNA START SETTING YOUR FOOT DOWN?

CALL A FUCKING GENERAL STRIKE.

Americans make movies depicting themselves as badasses ready to fight for freedom, while in reality they can't even do the most basic thing to defend their democracy.
Not to mention how their shit spills out all over the world.

[-] Damage@feddit.it 40 points 2 days ago

He now has a fancier PC, courtesy of LTT.
screenshot of Linus Torvalds and Linus Sebastian

[-] Damage@feddit.it 10 points 2 days ago

Long standing tradition

21
submitted 2 years ago by Damage@feddit.it to c/formula1@lemmy.world
146
submitted 2 years ago by Damage@feddit.it to c/3dprinting@lemmy.world

I think 1kg spools are too much, I want to experiment with ALL THE COLORS... But few manufacturers offer 250g, and they are sometimes twice the cost by weight.

77
Old and new (kbin.run)
submitted 2 years ago by Damage@feddit.it to c/3dprinting@lemmy.world
406
submitted 2 years ago by Damage@feddit.it to c/games@lemmy.world

Today, on February 28, nearly five years after Control’s initial launch, Remedy Entertainment, the team behind the Alan Wake, Quantum Break, and Control series, released an announcement regarding a deal between them and 505 Games, detailing a full transition to Remedy acquiring full rights to the franchise. While Remedy Entertainment previously developed the game with 505 Games having publishing, distribution, and marketing rights over Control, this latest transaction converts this authority to Remedy, giving them full rights over Control, Control 2, and their upcoming multiplayer game currently under the code Condor.

view more: next ›

Damage

0 post score
0 comment score
joined 3 years ago