Re: [Dorset] Euro CRA act

2023-12-31 Thread Ralph Corderoy
Hi Hugh,

> A quick skim read: doesn’t apply to open source stuff, and
> manufacturers can self certify…

I haven't read Tim's links, I just plumped straight for
https://en.wikipedia.org/wiki/Cyber_Resilience_Act as an overview.

That suggests the exception isn't for by licence, e.g. open source, but
instead by how commercial it is.  And that's a difficult, subjective
line to draw.

The Civil Service may argue for ‘alignment’.

-- 
Cheers, Ralph.

-- 
  Next meeting: Online, Jitsi, Tuesday, 2024-01-02 20:00
  Check to whom you are replying
  Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
  New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk


Re: [Dorset] Euro CRA act

2023-12-30 Thread Hugh Frater
A quick skim read: doesn’t apply to open source stuff, and manufacturers
can self certify…

So a paper exercise in essence, no different to self certification against
the low voltage directive (for example)…

Sent from my iPhone


On Sat, 30 Dec 2023 at 21:59, Tim  wrote:

> I came across a statement released by Debian about the new impending
> Euro CRA act. Debian as you can imagine has taken a strong dislike to
> anything that it see as breaking the user and release of free software.
>
> While I have read a few documents (many of them going straight over my
> head), I am not sure where  the UK sits of supporting EU IT legislation,
> but I don't think this act is in anyway going to help the situation
> which they foresee it helping, just making it a lot worse.
>
> Anybody else seen\heard anything about this
>
> Tim H
>
> Debian Statement
>
> https://bits.debian.org/2023/12/debian-statement-cyber-resillience-act.md.html
>
> CRA - Impact Assessment
>
> https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-impact-assessment
>
> EU Cyber Resilience act
>
> https://www.europarl.europa.eu/RegData/etudes/BRIE/2022/739259/EPRS_BRI(2022)739259_EN.pdf
> --
>   Next meeting: Online, Jitsi, Tuesday, 2024-01-02 20:00
>   Check to whom you are replying
>   Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
>   New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk
>
-- 
  Next meeting: Online, Jitsi, Tuesday, 2024-01-02 20:00
  Check to whom you are replying
  Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
  New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk


[Dorset] Euro CRA act

2023-12-30 Thread Tim
I came across a statement released by Debian about the new impending 
Euro CRA act. Debian as you can imagine has taken a strong dislike to 
anything that it see as breaking the user and release of free software.


While I have read a few documents (many of them going straight over my 
head), I am not sure where  the UK sits of supporting EU IT legislation, 
but I don't think this act is in anyway going to help the situation 
which they foresee it helping, just making it a lot worse.


Anybody else seen\heard anything about this

Tim H

Debian Statement
https://bits.debian.org/2023/12/debian-statement-cyber-resillience-act.md.html

CRA - Impact Assessment
https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act-impact-assessment

EU Cyber Resilience act
https://www.europarl.europa.eu/RegData/etudes/BRIE/2022/739259/EPRS_BRI(2022)739259_EN.pdf
--
 Next meeting: Online, Jitsi, Tuesday, 2024-01-02 20:00
 Check to whom you are replying
 Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
 New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk