mattis, to random
@mattis@eupolicy.social avatar

The European Parliament has adopted the ! Great news.

517 votes in favour, 12 against and 78 abstentions.

Now waiting for Council to formally approve the Act, which will most likely not take long.

https://www.europarl.europa.eu/news/en/press-room/20240308IPR18991/cyber-resilience-act-meps-adopt-plans-to-boost-security-of-digital-products

nemobis, to Bulgaria
@nemobis@mamot.fr avatar

:

«a harmonised standard, adopted on the basis of a directive [...] forms part of EU law»

«the rule of law, which requires free access to EU law for all natural or legal persons of the European Union»

«there is an overriding public interest [...] justifying the disclosure of the requested harmonised standards»

«As is apparent [...] the Commission should have acknowledged [...] the existence of an overriding public interest»

https://curia.europa.eu/juris/document/document.jsf?docid=283443&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1&cid=6375509

nemobis, (edited )
@nemobis@mamot.fr avatar
josemurilo, to Bulgaria
@josemurilo@mato.social avatar

"This blog concludes a 17-month journey to understand the 's attempt to regulate software with the . I engaged in this policy process in an effort to minimise damage to the practice of free and software development.
" policy engagement: a retrospective" features my struggle to understand how Brussels works, roughly on a chronological timeline."

https://blog.nlnetlabs.nl/what-i-learned-in-brussels-the-cyber-resilience-act/

textvr, to foss German
@textvr@berlin.social avatar

Is your open-source project in scope for the CRA? #fosdem2024 #foss #cyberresilienceact
#fairphone3photoqualityismeh

textvr, to foss German
@textvr@berlin.social avatar

#cyberresilienceact Regulation does not cover non-commercial projects. Regarding conformity assessment: For #foss self-assessment possible unless critical products (only hardware), open-source software is excluded. #fosdem2024

textvr, to random German
@textvr@berlin.social avatar

#cyberresilienceact is nearly finished. Much more open-source elements in the final version. Closed several holes of the law. CE mark will also cover security mechanisms in near future. #fosdem #fosdem2024

maarten, to foss
@maarten@techpolicy.social avatar

Come experiment with us at : we’re bringing policy makers and developers together in an EU policy devroom to discuss impending legislation with relevance to . There are four two-hour blocks you can attend, on Sunday Feb 4th.

First in the morning: discuss and implementation with their authors and join a workshop. Some lightning talks will get us started.

And there’s more! Schedule available at:
https://fosdem.org/2024/schedule/track/eu-policy/

rettichschnidi, to linux
@rettichschnidi@swiss.social avatar

Toller Artikel bei : ": Kernel-Entwickler drücken freie Grafiktreiber durch

Selbst Schwergewichte der Grafikchip-Branche sind eingeknickt und bieten mittlerweile quelloffene -Treiber an. Anwendern verschafft das Freiraum."

https://www.heise.de/news/Linux-Kernel-Entwickler-druecken-freie-Grafiktreiber-durch-9582895.html

fj, to random
@fj@mastodon.social avatar

Debian: "To retain parity with proprietary software the open development process needs to be entirely exempt from requirements”
https://bits.debian.org/2023/12/debian-statement-cyber-resillience-act.md.html

maarten,
@maarten@techpolicy.social avatar

@fj I love Debian to bits. But its statement on the #CyberResilienceAct is based on old text. I suppose that's inherent in commenting on a draft that is evolving behind closed doors. But now the actual text is public, a number of worries in the Debian statement are no longer an accurate reflection of reality.

debbryant, to Bulgaria
@debbryant@fosstodon.org avatar

TODAY! Friday Dec 8 is final day for submissions to the @fosdem Policy devroom. In a refreshing format designed to directly engage policy makers and @FOSS developers, CFP seeks ideas and engagement, not talking heads, to envision improved public consultation. Also seeking volunteer rapporteurs. Please share. https://fosdem.org/2024/schedule/track/eu-policy/

RegisHaubourg, to random French
@RegisHaubourg@mastodon.social avatar

I'm breathing again 😅 .

softens its position regarding Free Software !

This doesn't mean we won't have a major step in security requirements coming from users and devs, raising their expectations.
In project, we already see a lot more messages to forward vulnerabilities.

I am still unsure if open source with open core model will be concerned though.

See the Open Forum Europe statement :

https://openforumeurope.org/eu-cyber-resilience-act-takes-a-leap-forward/

jmaris, (edited ) to Bulgaria
@jmaris@eupolicy.social avatar

The has been making a lot of bad decisions recently ( , and others...) in particular when it comes to the open source community.

I've been working in the institutions for two years and am considering launching a wiki to explain how to better influence EU decision making, would this interest anyone?

EDIT: I somehow managed to make the poll 5 minutes, sorry!

informapirata, to fediverso Italian
@informapirata@mastodon.uno avatar

Il fediverso avanza nonostante il Cyber Resilience Act (e si parla anche di feddit.it)

Una montagna di innovazioni tecnologiche distribuite, contro i monopoli, dovrebbero essere valorizzate dai Governi.

Invece con il , si sposta la responsabilità quasi presunta sullo sviluppatore e non sul distributore.

Di @iusondemand su

@fediverso

https://www.spreaker.com/user/iusondemand/il-fediverso-avanza-nonostante-il-cra

mattis, to random
@mattis@eupolicy.social avatar
euractiv_tech, to Software
@euractiv_tech@eupolicy.social avatar
jodygarnett, to random
@jodygarnett@fosstodon.org avatar
luis_de_sousa, to opensource
@luis_de_sousa@mastodon.social avatar

According to @euractiv_global a final text will be ready already next week. There are good news and bad news. Legislators seem to recognise the nature of as a novel industrial process. However, projects under the umbrella of supporting organisations (e.g. foundations) are still required to comply with parts of the . To see if the dangerous upstream certification requirement remains.

https://www.euractiv.com/section/cybersecurity/news/eu-policymakers-advance-on-open-source-software-support-period-in-new-cybersecurity-law/

maarten, to Bulgaria
@maarten@techpolicy.social avatar

Arrived on my doorstep today! I blame the for my curiosity in more things and @StevePeers for sharing he worked on this update on Mastodon.

maarten,
@maarten@techpolicy.social avatar

@StevePeers And while we are on the subject of EU law, if anyone knows an expert on the #NewLegislativeFramework familiar with the jurisprudence on what constitutes “making available on the market in the course of a commercial activity”, me and several others #opensource people would like to better understand the (legal?) underpinnings of the writing in the Blue Guide on the matter. You would help us make sense of the #CyberResilienceAct. Sharing encouraged.

luis_de_sousa, to Bulgaria
@luis_de_sousa@mastodon.social avatar

1/6 A short thread on the current status of the . This is a digest of information conveyed through social media, the Linux Foundation and The Free Software Foundation Europe.

tommorris, to random
@tommorris@mastodon.social avatar

Oh no, I tried to read the EU #CyberResilienceAct.

Scoping such legislation to hardware/software that can connect to a network is a reasonable drafting goal.

But a "logical connection"—a "virtual representation of a data connection implemented through a software interface"? Wild stuff.

Given pipes and 'everything is a file' in Unix-land, the drafting might be vague enough to cover any software that does any I/O at all.

e.g. in curl SOME_URL | less - does less have a "logical connection"?

mattis, to opensource
@mattis@eupolicy.social avatar

More appeals for a better position for open-source software in the Cyber Resilience Act, this time from the Dutch "Vrijschrift" (member of EDRi). They call for including the exemption (with changes from Council) in the provisions of the Act, instead of the Recitals.

This does indeed occur in other EU legislation, for instance in the Digital Content & Services Directive, where open-source software is exempted in Article 3(5)(f).

https://www.vrijschrift.org/serendipity/index.php?/archives/261-Brief-Vrijschrift-EU-Cyber-Resilience-Act-zal-concurrentievermogen-schaden.html

mattis, to infosec
@mattis@eupolicy.social avatar

https://www.euractiv.com/section/cybersecurity/news/cyber-resilience-act-disclosure-requirement-concerns-raised-by-experts

"Cybersecurity experts have urged EU policymakers to reconsider a crucial part of the Cyber Resilience Act (CRA), the vulnerability disclosure requirements, in an open letter published on Tuesday (3 October)."

Heard quite some similar concerns at the ONE Conference...

IvanSanchez, to random
@IvanSanchez@mastodon.social avatar

Tomorrow (16:30 GMT, 17:30 CEST) I'll be taking part in a panel about the . See https://www.lpi.org/articles/lpi-europe-cra/ and join us!!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • rosin
  • Youngstown
  • ngwrru68w68
  • khanakhh
  • slotface
  • InstantRegret
  • mdbf
  • GTA5RPClips
  • kavyap
  • thenastyranch
  • DreamBathrooms
  • magazineikmin
  • anitta
  • tacticalgear
  • tester
  • Durango
  • cubers
  • ethstaker
  • cisconetworking
  • modclub
  • osvaldo12
  • Leos
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines