Video summary
The presentation by representatives from the Free Software Foundation Europe and the Federal Office for Information Security focused on the Cyber Resilience Act (CRA) and its implications for digital products within the EU. This legislation mandates that networked devices must maintain security standards throughout their entire lifecycle, including mandatory vulnerability reporting and updates until end-of-life support is complete. While the act generally applies to most CE-marked devices, it includes a specific exception for free open-source software (FOSS) developers, though commercial distributors of such software are still classified as manufacturers responsible for compliance. The discussion highlighted significant ambiguities regarding the transition from project maintainers to manufacturers, particularly concerning monetary thresholds and living expenses, which has led some projects to preemptively remove code out of fear of liability when facing demands for rapid fixes from manufacturers.
To address these uncertainties and undefined aspects in current guidance documents, such as Software Bill of Materials formats and resource requirements for security auditors known as "Stuarts," the speakers launched a questionnaire to gather feedback on real-world challenges. The overarching goal is to foster collaboration between manufacturers and open-source projects without overburdening developers or stifling innovation, ensuring high security standards against large-scale threats rather than targeting small entities. Regarding product lifespans, while a five-year liability period is the general rule, it is not absolute; manufacturers determine intended lifespans, and market surveillance plans to issue guidelines extending support for long-life products like trains. Furthermore, although manufacturers can choose their own risk assessment methods, courts ultimately judge compliance against the law itself, making adherence to harmonized standards crucial as proof of conformity.
The operationalization of the "Stuart" role requires manufacturers to decide whether to integrate projects directly or collaborate with maintainers, a process that must be negotiated per product to ensure safe CE marking. Since operating systems like Linux are not standalone products but become so when integrated into a system, the resulting system requires a CE mark, whereas software like LibreOffice currently lacks one, forcing companies using it to manage their own cybersecurity insurance risks. Ongoing discussions with insurers, such as Zurich, aim to assess these specific risks. Looking toward the future market structure, a state-run approach is discouraged in favor of self-regulation through private funding. Proposed models include a collective society or fund where beneficiaries of free software contribute financially, ensuring that projects without direct manufacturer ties can still participate and receive funding based on ecosystem value and risk factors.
Read the full video transcript
Welcome to Talk Z:
Cybersecurity in Society, presented by
Alex and Michael. Alex works for the
Free Software Foundation Europe and
Michael for the Federal Office for
Information Security. We are delighted
with the presentation.
Thank you very much. Yes
. Um, we met here about a year ago, almost exactly
a year ago,
and we exchanged ideas about the
Cyber Resilience Act and
then planned to submit a project as part of the dialogue for
cybersecurity
, where we would work on the Cyber
Resilience Act. We will
now briefly explain at the beginning
how we came to this and what this
dialogue is. Then we'll briefly go through
the Cyber Resilience Act so that we
all have roughly the same level of knowledge,
and then we'll look at what
we've been doing in the last year
and, uh, what we've been working on regarding the Cyber Resilience Act
, what's on our minds,
and then try to discuss that
with you in the last third of this event
. Exactly
. Thanks. So, the dialogue for
cybersecurity is a platform where
organized civil society,
state, business, cultures, girls and
science come together
and are basically
a platform organized by the BSI to
work collaboratively on social issues that
address cybersecurity and attempt
to consider the whole thing holistically.
For this purpose, a
so-called think tank is held once a year.
For this purpose, interested parties can collect and develop ideas, and
I believe the period is about to begin,
which can be submitted,
where topics can be presented that will
then be worked on for a year
in a larger group. These
would then be the so-called workstreams.
And I first participated in the
dialogue for security two years ago
because I hadn't
been at the BSI for very long, and Alex had been doing it for
several years before, and
we got talking last year at Froscon
. At some point
the question came up: we still have a barrel of
beer here, what do we do with it?
Um, the exchange became more and more intense,
and then we thought, let's
see if we
can bring up a topic, and one topic
that has been on both our minds for
several years now is the
Cyber Resilience Act. And when you're at
the Frost Conference, at the Frost Conference, you talk about things up there
here and there. That means
let's bring this together and
see what effects, or rather
, what effects
the Cyber Resilience Resource
Community has in its various forms, which
is always interesting. Exactly
. What is the Cyber Resilience
Act? And in principle, this is
legislation that
was passed last December,
is now in the transition phase for 3 years,
before
all the requirements contained in the
Cyber Residency Act have to be
implemented from December 11, 2027 onwards; there are
already reporting obligations for next year in September
that have been brought forward. This
means that
manufacturers
who actively exploit vulnerabilities,
or who become aware of them, or who gain
knowledge of them,
must report them to the reporting platform and
to the national certifying body responsible for the
manufacturer, in order to
track and monitor these vulnerabilities.
The Cyber Resilience Set is the EU's attempt
to obtain CE marking for cybersecurity. This means that what
already exists for safety, such as
mobile phones with their CE marking indicating that
you won't die immediately if you pick them up
, is now being expanded
to include cybersecurity.
This applies to products, or almost
all products, with digital elements.
The robot vacuum cleaner, operating systems,
mobile phones, routers – basically anything
that is networked to some extent
and communicates digitally with other
things.
There are certain exceptions, such as
medical technology, aerospace, and
automobiles,
because these are already significantly regulated,
at least to the same extent or more so, through other regulations
. And there is an
exception, for example, for free open source
software.
The goals of the CAA, or what the
Commission and the EU intend to achieve with it
, are, firstly, that products
placed on the European market meet
security requirements from the outset, or
are generally more secure in terms of
cybersecurity,
and secondly, that the devices remain secure
or are repeatedly returned to a secure
state for the
entire life cycle of the
product, including the
support period.
This means that a manufacturer never brings the product
to market and then
no one cares anymore. He is obligated to
provide updates
and address vulnerabilities
.
The second point is that it should be
made easier for those who use the products
to use,
buy, and then obtain safe products.
What does all this mean
for a manufacturer and for
a product?
The manufacturer starts developing a product
and must
conduct a risk analysis right at the beginning, where he looks at
how strongly he needs to implement certain requirements
. These are the
product-related basic
security requirements that are set out in
Annex 1 of the Cyber Resilience Act
. And that means it contains
requirements, e.g., it wants
secure authentication to be used
. It states that secure
communication is essential. This means that
data transferred from one device to another is
transferred securely. It says inside that
data is stored securely. However, it all
depends on the
risk. That means if I
have products that are in more critical environments
, then it might be interesting
that when you log in or access the site
, you don't just
enter a username and password, but use
multi-factor authentication. It might
be that with certain products
that exist only once in the world and
were sold on the market, you could
leave it somewhere in the room in the
darkroom where nobody else
goes because it's locked three times;
then a username and
password would suffice. So it always depends
on the risk.
As mentioned, vulnerabilities must be fixed during the support period
. There
must be technical documentation
. Manufacturers must demonstrate compliance with the requirements before they can
bring their products to market
. For most products, this is
simply a
self-explanatory statement. These are also things
that we already have under the CE
marking.
There are also important products in
categories 1 and 2. These include, for example,
operating systems, routers, and firewalls in their
various versions.
There, the approach to conformity is slightly
different.
The important products
can be tested once at a designated point to prove
that they
meet all safety requirements. And
for the important category 1, where, for example,
switches or routers are included.
If there are harmonized standards
that have been cited by the Commission,
then it is sufficient for a manufacturer
to say, "I will adhere to
this harmonized site and
declaration."
That's why location is relatively important
in all legislation.
Security flaws must
be rectified, and
the manufacturer must report any vulnerabilities for as
long as the
product exists.
Something
that comes up alongside the Cyber Resilient Act,
or is mentioned as a term,
is the New Legis Legis Framework.
And that is basically the idea of
the Commission and the EU: to harmonize the entire
legislation to some extent
.
Imagine it as a huge network of
regulations, all
interconnected in some way, and none of
them stands alone in the forest. In
general, it regulates how, for example,
market surveillance should proceed, and what
all the processes are. It regulates the
meaning of
harmonized standards and
norms, what
conformity assessment procedures look like,
all regulations are set out in the
New Legislative Framework
, which is quite important
because I often experience in
discussions
that many people always consider the CAA in relative
isolation. But it
belongs to this whole
construct of other laws that
also exist, which are somehow related to each other
. This also means that
things we already do for safety,
and things that
generally apply to safety, can
also be applied to the CA to some extent
.
That is, for example, um, interesting.
The CH itself is a
product regulation.
That is, what's interesting is what it
means that it's a product for
and when I have to comply with the things
that are in the CA. And then there's
the so-called Blueegide, which
is basically a tool that
tries to explain certain things about the NLF, the New Legislat Framework, to a certain extent. And it says,
for example, that... Making a
product available on the market means any
supply of a
product for distribution,
consumption or use on the
Union market in the course of a commercial
activity, whether for consideration or without limit.
And then
we quickly reach the point
where this exception for Free Open Source
comes into play.
These are not
products that are placed on the EU market in terms of regulation,
and therefore they are excluded. These are
not products
where someone simply sticks a CE label on
. There are manufacturers, including
open-source manufacturers,
who earn money with their open-source products and
have a commercial activity. In this case, it's considered a product
under the regulations, and they are
seen as manufacturers. They
must meet all the requirements of the CA (Certificate of Authorisation).
However, a
developer who simply develops
open-source software in their free time because they enjoy it, and there
can be several developers working together on the project
, doesn't automatically fall
under the CHA (Certificate of Authorisation) exemption. Regarding consumer
protection,
if it's sold on the European market
, it's considered a product and
therefore treated
as such. Exactly
.
Yes, we've already heard from Michael
about manufacturers and that this
is a product regulation. Uh, that all makes perfect
sense. However, we have
also heard that there are
perhaps different perspectives regarding free software,
and the
legislator has taken this into account to some extent
and has
introduced different roles in the legislative process. So,
obviously, we have the manufacturer, and
then he also introduced Stuart, which in
German is called administrator
. These are the people who, um, well, um,
projects, um, for example, Men or
similar, and then there's
the aforementioned exception:
Individual Developers, uh, a bit of code
somewhere on some Git or something
else. So, basically we have
three roles relevant to the
Cyber Resilience Act, but only two
roles. The manufacturer and Stuart.
So, Stuart is someone who
provides a project, which is
then taken by a manufacturer
and ends up in a product
. And so that these people who work on the project, who do it in their free time, who perhaps also do it for donations, in the common association or however you come together to create these projects, so that they are not confronted with the regulations of the Cyber Resilience Act in the form of having to assume these obligations. Um, as
someone just said, the manufacturer has to, um, always
assume all the obligations at some point. So, everything that
falls outside the scope of the Cyber Resilience Act, he has to take over for
the projects, and that means it's
not simply taken
and followed somewhere else, but rather,
in principle,
a relationship has to develop between the
manufacturer and the project team, and that's the
question we
discussed with a consultant last year
. What could this uh relationship
look like? So how can we
ensure that manufacturers and
Stuarts communicate in a way that
is good for safety, but
also good for the price within the ecosystem?
And, um, yes, we've essentially asked ourselves this question, and we've
approached the whole thing, and perhaps
we'll first look at
what the obligations are for manufacturers,
and then we'll see that
many things simply cannot or should not be done by the ST duart,
and
then we'll consider how it
could be done. So, the manufacturer is
fundamentally responsible for the
product. Yes, well, it is
always the manufacturer who brings a product
to market and they are responsible for
everything that has to do with that product
. He needs to
address the weaknesses.
If he is
collaborating on a project, he must
report the vulnerabilities to that project and he must also
share the patch. This means, um,
that if you're
basically sitting on your project
, you don't actually have to do anything
except wait for
a manufacturer to come along. The
manufacturer then says to you, "I'm
using your project, it's in my
product, and uh, would you like to
become Stuart for me?" And then
this workflow would
begin, right? So, the project
would receive the patches, and they would
then basically be available to everyone else as well
. So, that means, um,
if you
have a project in a product and it
gets patched there, is the patch still
available for everyone else? Exactly
. But as I said, all
these things are the responsibility of the
manufacturer, but of course
the manufacturer can't do it alone.
So he has to communicate with this
project somehow. The patch has to
actually
get there somehow in the end. Yes, so there must be
someone in the
project who does that.
And um, if you look at how
manufacturers envision it, then
I think you can see that clearly with KL
. Um, they just received an
email. That means, well, we
're manufacturers, we use CL
by the way, um, we now have to
become compliant. Go ahead and do it. Yes, and that's
exactly what we don't want.
Yes, we don't want
manufacturers to approach projects and
say, "This is what will be incorporated into
our product, and because our
product is so great, you'll help us
now." Yes, but it has to
happen in some way, so
that the ST is keen on it,
so that he is keen
to work with the manufacturer
and so that
this exchange can take place, which
we have just shown. So, in order for the
manufacturer to be put in this position to
do this, he needs
Stuart, and therefore it makes perfect
sense that they are kind to each other
, yes, and not just kind in the sense
that they send each other back and forth in a friendly manner
, but that
resources are perhaps also made available
. Yes, so basically,
Stuart must or can, so to speak,
immediately help the manufacturer
to fulfill these obligations. If he
does that, then in my opinion at least he should be
supported
. And that's a question
we've been asking ourselves, so to speak, about um, uh,
questions. So, we've
published questionnaires, we'll get to that in a moment, to
see where this is
already working in the ecosystem
, where we
can take blueprints and then transfer them into
guidelines, because that is, um,
let me just
finish this thought briefly, the central point is that
not everything is happening in a vacuum.
We have the Cyber
Resilience Act, which contains many
articles and regulations, and so on
and so forth, but many questions remain
unanswered. Yes, and
for these unanswered questions there are
guides. There are these standards
we've already heard about, which
are particularly relevant for manufacturing. There are
things like ATT, there are implementing
Acts, delegated Acts, and so on and
so forth. Much of the Cyber
Resilience Act is still not fully
fleshed out. Among other things, this
relationship, how manufacturers and
Stuarts are currently working together.
Yes, manufacturer Stuart, as it has now been explained
by me, is the issue that
manufacturers now only use resources
very quickly, of course, there is a risk that
you yourself become the software manufacturer
, because we are suddenly commercial
and profitable, and
that means the manufacturer offers me,
so to speak, here you also get a
little money for getting a bank.
Now you are a manufacturer.
Okay, so the question was, or rather, the
comment was, what happens when
the manufacturer provides resources to the project, which
was previously not monetarily involved, especially
monetary resources,
and whether Stuart then also
becomes a manufacturer, because so to speak
the money game begins, and um, well, that
's not the case, because it's
not a product. Yes, well,
the project isn't a product in
itself, but rather,
nothing is actually being manufactured, right? It's just that there's
code lying around somewhere,
which will then be patched somehow,
but
nothing is actually being sold right now, right? Therefore,
no product will be sold.
So. Well, um, and therefore you wouldn't become a
manufacturer right now,
and maybe you'll even go back later
. So you're always just for, well,
that's also important to
know, so a Stuart, um, wo
n't itself be CE compliant or anything like that.
Yes, so it's always about one
specific product. So, for example, you could
now work with Stuart and a manufacturer
. The manufacturer has
two products. Regarding one product,
you say, "I think it's a great product,
I'll work with you." With the
other one you say, no, I don't feel like it
, I'm not a Stuart. So, and all of this
, what is still
unclear is, uh, fundamentally,
where the monetary threshold is. So, from what point does one become
a Stuart, so to speak, up to what point can one
earn money without being considered a
manufacturer? This
hasn't been spelled out yet, but there
is, um,
a discussion point, we can
perhaps say, which
suggests that the threshold is, um, what
your living expenses are. So,
if you're doing this as a private individual
, the threshold is
roughly what your
living expenses are, and the second
threshold is when you're bigger, to make
the thing run. Yes,
so what you need, uh, to keep the
project from dying, so that
it survives and
fulfills these, um, things. If you start making
billions from this
, then we might need to take another
look, but overall it's fine for now
, so
these are the thresholds that are currently being
discussed. So the project
continues. There may
also be an expert group convened by the Commission,
and there is also
a working group that
deals with obsourcing, and
these questions are currently being
examined there as well, because
you cannot have both roles, meaning no
one can be both for a
product at the same time. You can
have both roles, but you can never
be both the manufacturer and the starter for a product.
And it is not intended that
once the sword is paid for,
he automatically becomes the manufacturer,
and guidance is currently being
written by the Commission on this, and that is
one of the points related to the
Implementing Act. Something needs to be
published by the
Commission this year that clarifies
how the Commission views this and
describes these roles more precisely
. Um,
if I'm now, so to speak, a
project, then
maybe we could briefly ask some
questions to clarify things, but
perhaps the discussion should be left for the
end. Um, because otherwise I
think we could now, well, I see so
many hands, um, that I think otherwise there would be
questions of understanding. Yes,
unfortunately I arrived too late. Well,
a product, if I offer a server
or service that I
can start, is already a product, or a CLI
tool, or Liberoffice, or something like that. It can be
used independently by anyone who
downloads it from the internet. Is this already a product
?
So, we had that at the beginning. Provides a
definition; perhaps you should
also take a look at the slides. Exactly.
Now we're going to make whales. Um,
exactly. So, as I said, there is what
we stand at now, and what's also
important is that there are things like
Implementing Acts, Delegated Acts, which
can come, which don't have to come, but
Implementing Acts, which must come. For
example, the question that is often
discussed is: what should the SBOM
look like? This is an Implementing Act; it will be
passed, and you will
get these answers then. We ca
n't tell you yet; we have feelings about it
, but nothing more than that. Um,
Geidens is something that comes from the
Commission, but perhaps
also from the market surveillance authority, which
then spells out, for example, where
these limit values are? Um, how
much money can you earn? Uh, like
which, um, and that's certainly something
one
can expect, is that this guidance will also
use many examples.
Yes, so in order to clearly define
what is a project, what is a
manufacturer, and so on and so
forth, this guide will certainly
include examples. And
with these documents, the basic idea is
that someone who
has no clue reads and understands them
and knows, okay, all right, I am
now a manufacturer, I am now Duart,
and so on. It is, so to speak, the
process. Yes, well, all of this is still
in the works. So this is
exactly the implementation that is
taking place now. We've already heard that
we'll hear about these thresholds by the end of the year
. Um, uh, and this will
continue until 2027.
Um, to get closer to this, this, this mess, so to speak,
and above all, to
contribute to this guidance. I think that's particularly
important for us as an FSVE, because we don't really pay
that much attention to what the
manufacturers are doing.
I believe they can usually stand up for themselves. We're
looking at what's happening with the projects,
what's happening with individual developers, and
so on and so forth. Yes, and that's why
we asked ourselves the question:
how does the manufacturer communicate with
Stuart? But what other
questions are out there? So, what
problems are there? What niches are there?
What are the different types of hair removal zones? Where, where, where
are things that would make any of you
read the Cyber Resilience Act and think, "
Wow, what does that mean
for me?" That's why we sat down as part of
this dialogue
for maritime safety and developed a questionnaire
which can currently
be filled out until the end of the
month. We started in July
and now, what
comes next is primarily
the feedback we've
received in the last month. We want to
circulate this with you all a bit
and see what you think. And
overall, we would of course
also like to encourage you to fill out the questionnaire now
in the next, um, current month
, so that we can then, so to speak,
continue working with your results
. And our goal is
basically to get these results,
especially here, into this
guidance. Yes, so we want to
find out what your problems are
and address them in this guidance so that
you
ultimately have a document
you can look at and say, "My
example is mentioned," or "I find myself reflected
here in some way
and know how I should
act within the framework of the CA in the future
." Yes,
and that's why we created questionnaires
for manufacturers, projects, and
potential open source Stuarts
. Yes, and where you
roughly find yourself, you fill out a questionnaire like this
. If you're
unsure, you might want to consider
potential open source options. The questions
are more or less similar. You do
n't have to fill out the entire questionnaire
. So, if you're unsure about
something, if you don't know what to do at any point
, just leave it blank.
And what is particularly important to us is that it utilizes
the free spaces. Also, write in there what, so
to speak, if there
are any questions that were missing or
if you want to tell us anything else
, use the question fields to
explain to us what
the problem is for you, so that
we
can ultimately include it in this guidance and
thus solve this lack of clarity
and
help you understand who you are and
what you have to do. Exactly
. And um, another point
we have at the very bottom: we are
also in contact with certain or
several foundations that are
already actively dealing with the Cyber Resilience Act
.
We talk to representatives of the
European Commission to
pass these things on to them and simply
name examples and where there are questions, because these are also initial
things that we are doing and also when we
hold talks.
With open source, there are things
we've all never thought of, and there are
projects that collaborate in that way
.
You learn something new every day.
And when the law was being developed and
written, the
commission did indeed talk to an incredibly large number of people
.
But in the end, as mentioned above, it's
just that small point again, and
certain things have been added for that purpose, and
now we have to see where everyone knows
what the text looks like, how to
promote it externally so that it
works for everyone else, and
that they know what they have to do
if they have to do anything. So, as I
said, a project in itself must comply with the
Cyber Resilience Act; if no
tangible product in a monetary sense
comes out of it, they don't have to do anything.
If they don't want to become a start, they wo
n't be a start. If they
never want to talk to a manufacturer, then
they don't have to.
But what we want, or what interests us, is what happens if someone wants to do this? How can we—and this is again part of the guidance—what kind of guidance can we provide if someone wants to take on this role, if someone prepares their project in such a way that it already fulfills many things that a manufacturer would then have to fulfill? Because conversations with manufacturers that we have sometimes go like this: they use an incredibly large number of projects.
They simply can't
look after all of them. They don't have the resources either
.
They are completely
responsible for it. That means
they have to do something.
Now you can go to someone who will take care of it
. One can try to
remove the open source projects from one's product and replace them with
components purchased from elsewhere,
products that have been bought on the market,
because these
products have to meet the CA requirements, then
I can simply
move everything a little further along, but that also costs
money. So, in other words, why do
n't we create some kind of
collaboration
where resources and funds are paid to those
who are already
working on their project all day anyway? If I'm going ahead with the project
, there's someone there who might be able to do all that,
and then that's okay too.
But it is quite possible that
someone will then take care of the abandoned project and do
certain things
correctly again. We do have
weaknesses, and that happens sometimes
. Why don't we support
those who are originally working on it, if that's what
they want?
As I said, a project in itself does
n't need that. If they don't feel like it,
they simply don't feel like it, period.
And we need to make sure that
things like what happened to Körl don't
help anyone. If
100 manufacturers come and say, "You have
two weeks, please fill
out the Excel spreadsheet."
At some point, someone quickly gets fed up with the project
and says, "I'm quitting
, I'm not continuing at all." This is also the case,
and it helps if
manufacturers have guidelines on how to get
in touch. And there's already a
lot of it, and you just need to
process it all, bring it
together in such a way that you
have something uniform that several people
can work with.
Uh, I have a question regarding
STRS. Can there be multiple versions of an open-source
project?
No.
So, the question was, can there be
more "you" for an open source project?
No.
The answer was no.
Not planned.
This has opened up an unbelievable mystery.
Perhaps, as I said,
we should move this back to
the discussion section and try to make some
progress on the content first. Exactly
. So, uh, as I
already said, we have this
questionnaire, this survey has been running for
a month now, and it's important for us to give
you a
little preview of some initial results,
to see what we've gotten so far.
It is definitely, um, I think it's
evident that we can
see tendencies, that certain things keep
recurring and, um, um, certain
problems are repeatedly identified by
different
participants
. The goal now, and this
is not our position, yes, it's not
irrelevant whether it's right
or wrong, but it's about
presenting this first
and then having a
little discussion afterwards and seeing
what you think about it and whether
you
have any corresponding opinions. Exactly
. So the points we
recorded are simply
random individual answers to the
questions we have, where we now
think, firstly, you can see to some extent
what really interests us.
So, let's start with the first question.
A few Developbar members are working together on
the project without any single
entity or developer behind it
.
Those who work on the project
are paid by companies,
and then, as stated here, a company
offers services related to this
project. What does this mean in the context
of the CA? Those who
work on the project are then
automatically considered manufacturers. And at
first glance, one might say no, then
one might say again, but if you as a
manufacturer work on it, won't they fall
down after all? I have an
opinion on that, but
these are the things
we would like to consider in guidance
, because there will be guidance
from the Commission.
It may be that the biggest
questions have already been answered here, but it may
also be that additional things will come up in the project examples,
and what we have considered or
where we want to go, so that we can
look at how to simply go through these
examples step by step with the Commission's guidance
and other documents
.
In this case, it's
simply a handful of people working
together.
So, no manufacturer. They're being
paid now. What does that mean? No
manufacturer or producer. Then
you have to find something, and hopefully you can do that using the
Commission's guidelines, so that you can
simply work your way through these example projects to some extent
and explain why they are considered
manufacturers, or why they are
not considered manufacturers, or why
they are considered starters. That's one of the
songs. And what you generally
see now is with the
second one. The
second and third actually belong
together. Someone is working on the project
and then a manufacturer comes along with a
deadline of z weeks. I've
found a vulnerability; you need to
fix it for me now.
If I had a project, I
probably wouldn't want that.
And you can see that there are
already certain fears in the Open
Source Commuter community regarding the projects that
these projects
deal with, and that such a question or such an answer came up several times. And in the end, it also helps
if there is guidance that
explains whether they
even need to do that.
Perhaps a note on that. So I did a random
sample and it was a bullseye:
Kobit has
taken the project off the network.
Recourse.
Yes, definitely
. Yes
. Yes, we can see that. So, the
point was that projects are already
ceasing to make their materials available, so to speak, out of
preemptive fear of a
cybersecurity crisis. And
another question: did
you also send the questionnaire to the
manufacturers, i.e., associations?
Yes, yes, yes,
yes.
You continue. Exactly
. Then there are people asking questions of the
manufacturer. There we
asked questions such as, what dangers do you see
if you are responsible for all Opensur-free
components in the product?
And what do you do with projects where you do
n't know if they already
meet the requirements of the Cyberilience Act,
especially if you can't then step in to do
that, or whatever other
issues there are in general? And then,
already in the first
point,
that manufacturers
are also considering what they can do.
And these are also things that we
see that way. Projects are being requested.
Either you can take on the
support yourself, or you can
support the project
and then simply provide the things
the manufacturer needs for the project so that they
can integrate it and
meet all the requirements, so that they then
take it over for the project and
play along with the feedback. Here too, one has to see
if that can work, and
scaling is another matter entirely, but there are
already considerations
and discussions on that,
and sometimes it feels as if the
discussions are being conducted in parallel without being brought together
.
One question,
for example, was whether
it would help if there was proof
that projects meet this requirement.
And there's another point, um,
that the manufacturers can't do it themselves
because they would need the resources
to do it for all the products
that
are inside their product.
And the point is, the proof would have to come from
the open source manufacturers themselves
. So,
if we now – and we see that
several have written this –
if these are the fears of
manufacturers,
then we are back at the point where
we cannot initiate things in such a way
that the manufacturer
pays, receives the certificate
that the product is okay, and
ends the matter with them.
The third are the Stuarts, and then
we're back to Guidance. There are
also many who
have answered the questions; they know relatively precisely
whether they want to be Stuart or not.
So, we assume
that some Foundation employees also
contributed to the responses, and in
many places it is relatively clear that
the role of the Jewers is being taken over there.
Where support is needed is the question of who
should
pay for it if someone wants to become a Stewart
and does become a Stewart, and
what does it really mean? What
requirements must a Stuart fulfill in accordance with the
CHA in order to avoid
further problems
with
market surveillance and nothing else? It must be
said that a pilot in itself has
significantly fewer requirements
to meet than a manufacturer,
and no penalties can or will be
imposed on pilots. What?
He must report weaknesses. The
vulnerability reporting process for actively
exploited vulnerabilities
is therefore taken from the manufacturer's articles
or requirements
. He must have a cyber security
policy and he must
cooperate with market surveillance. It
must always be in mind if he doesn't
do it. There are
no penalties,
but um, he has to cooperate with the
market surveillance authority so
that
things can be fixed.
I think what also came up often, uh, is uh,
tools, is definitely something that
people really
want to see. Um, so they want to see text,
they want tools to help them,
resources, money, whatever. Yes,
and also to
elaborate on this understanding of roles and to see if it might be
useful to
allow dual roles in one or more places.
So these are the points that we
have repeatedly seen in the
questionnaires, but also
generally in many discussions that
we are having, especially
with projects, to
understand the market realities to some extent and to see how this
can then be incorporated into guidance. Exactly
. So, I think to reiterate what
underlines the whole thing, well, um,
from the questionnaires
we would say that approximately 50%
of people know their role and can
assess it fairly well. That's
nice, of course, but also bad. So
fifty-fifty years, right? It's somewhere in the middle,
whether that's good or bad. Um,
we definitely see that, uh,
especially projects, individual
developers, so everything that
isn't a manufacturer,
feel a certain pressure to do
something, and it's a
bit vague for them what
exactly that should be. Um, and how do you
get there, and above all, where do
the resources
come from to do it? Um,
we also hear things like, which
I thought was a very apt
sentence, "Like to do Software Engineering,
not management, right?" So, people do
n't usually start their projects because they want to deal with big
management issues
, uh, but rather they just want to tinker with their
project, right? And that, of course, is something that needs to be
preserved. So
we don't want to ensure
that everyone who
starts a project is then busy with some
strange paperwork
, but rather that people
can just get on with their work. Um,
the problem is, as we just
said, we're looking a
bit at blueprints, so where is
this already happening? Where are projects
somehow connected to manufacturers?
Where is there already resource exchange where
we support this? Um, and
we can definitely see across the board that
this is not cost-effective in any way
. So it's
not like the projects are
getting so much money that they have to worry
about whether
they're manufacturers, but rather they're
thinking, can we keep the project alive
with the money we're
getting here? So the support currently in place
is often lower than
the actual costs. This is the
current reality we
are facing. Um, what we've also
heard repeatedly is a
feared loss of quality in
projects. This is primarily a practice recommended
by manufacturers. So, they're
kind of afraid that if they
collaborate on these projects,
they might be able to do things like quality assurance and stuff.
So, they have, um, problems there,
and also a few other things that keep
coming up, like what about
the overall research environment
? Fear of costs. Yes, well, everyone seems to have that on their wallet
. Um, the
S-bomb question is something that keeps people
thinking about, right? So there's another
implementing act for that as well. It's
still being defined, uh, there's simply
nothing yet. And then, um, yes, things like
supply chain attacks, licensing problems, those kinds of
issues are also on people's minds.
So it's not like, uh, that it has
n't appeared, so to speak.
Therefore, as I said, there are
a few other things as well. So, if you
filled out the questionnaire and do
n't see yourself reflected here, we
still looked at everything, but these
are the relevant points
for us, uh, that we
have identified so far. And that's why we're appealing to you again:
if you feel that
your
position isn't reflected here, please let
us know in the questionnaire. This helps
us to
address this as a problem to the Commission, for example,
and
to get it included in these guidelines, in order to
address the problem and, ideally,
to solve it. And now, I
think I can say this for both of us
, the feeling is definitely
that we are being heard and that there is a
real attempt being made
to clear up such problems. Yes, so
nobody wants to
ruin anything by over-regulating, nobody wants
to ruin projects, nobody wants to
ruin SMEs or micro-
enterprises, that's not the goal at all
. Perhaps one could take another look at it, similar to what was done with
the data protection reform. It's not about somehow
taking the small baker around the corner out of the market, but
it's about going against Google and Facebook,
that sort of thing. And
this Sabe security legislation should be
viewed in a similar way. It's about taking a
closer look at the junk that comes onto our market, especially
where a lot of junk is mass-produced,
and not just some
small project cobbled together by two
manufacturers, right? So,
perhaps at the end, there will also be
a market supervisory authority. Yes,
I'll just have to take a look at it. These are also
people who have resources available to them
. Uh, that means they'll
naturally be looking at where they can get a
lot of money, where they can
create, um, so to speak, big examples that might then
appear in the media, so that
other manufacturers see, oh, oh, oh,
the market surveillance system
really does monitor things, maybe I should do
a bit more cyburity myself.
That's the thinking behind this
law and what will realistically
result in the end. Yes, it's
not going to be the case that the BSI (Federal Office for Information Security) is going to hire 2000 people
who then spend all day wearing
market surveillance jackets
in the media market. That's never certain;
maybe
someone else will do it,
right? But no, these aren't
realistic scenarios where
the entire
media market is somehow cleared out and every
product is scrutinized from one day to the
next. Yes,
exactly. So, to reiterate the question
, what happens next? For
us, the next step is definitely to continue
evaluating this questionnaire. Uh, we will
take these results, try to bring them into play
, try to talk to the Commission
, try to
get in touch with other market regulators. Uh, here's another
request: please fill out
this questionnaire. Find it at
dialog-cyicherheit.de/aktuelles,
because it's current, it
's definitely current. Uh, and like I
said, tell us about your project, tell
us about it, tell me about it,
tell me about it, send us an
email, I don't know, write about it
on social media. So, we just
showed you this K project,
right? Things like that help. If you're doing something like that
, if you're a project and
a
manufacturer approaches you in a really strange way, publish
it. Then we can go to the commission and
say, look, this is
reality. This cannot continue.
These people will never become Stuarts
. And so to speak, there is
a great interest on the part of the people who
made the law that as
many people as possible become Duarts, otherwise the
whole concept doesn't really work.
Um, and that is of course a
positive situation for us, in which we
can ensure that this Duarts,
that the projects ultimately
benefit from it. Yes, so that is
our goal here, what we are
pursuing. And um, finally,
as I said, if you
have any direct contacts, use them. So,
if you happen to meet people from the BSI (Federal Office for Information Security),
tell them.
Um, if you happen to
meet commission officials or anything like that,
talk about it, try to make it
tangible and understandable somehow, and
like I said, show us
your niches, okay? Um, that helps us
to understand them and, if
necessary, illustrate them with examples
.
In that sense, I think we can
all have a nice beer today
and then meet up again next
year. Until then, we'll definitely
answer a few more questions,
discuss things with you a bit, and we
probably won't be quite so early today and tomorrow, but we'll still be
there. Um, uh, talk to us,
talk to us,
and otherwise all the best.
[Applause]
Exactly. And I think, uh, you'll help us with the
moderation. Yes. Uh,
exactly. So there are people walking around with
microphones. Please wait until it's available
for the stream. um, so that the
questions are clear for the people who are
joining online, so that they
understand what it's all about.
So, uh, we now have just under 10 minutes
for the Q&A session and uh, can we
get started right away? So, the important thing is
that the questions are also included in the stream,
and if, for example, the microphone
is difficult to reach, then please
repeat the questions again.
Now
I would say I'll first go a bit
by topic, or that the
people who raise their hands have a suitable connection to the question,
and otherwise
I would go by seating position.
Good.
Um, who has questions? So, from here on out,
we already said earlier
that we are
allowed to...
We have a question about what you
had on the slides at the beginning, regarding
the deadlines, so there is this
wording in the CA with 5 years or so
to speak the lifetime, the
intended lifetime of the product.
Um, the manufacturer determines that; the
intended lifespan is determined by a roll of the dice
. Um, can he always do 5 years
or how does that work?
So,
if I buy an airplane, how long
is the 5-year liability period? The
idea is that the 5 years are a general
rule for now, unless there are compelling
reasons why it is shorter. So,
yes, there are products that simply don't last
as long as insulin,
but there are certain products
that aren't even around for 5 years. There are
already products where the life cycle
and support period are longer because
other regulations stipulate
different timeframes. The plan is for
market surveillance to look over the years at what
the expected
support period should be, and then issue
guidelines on
when these periods should be extended.
So, 5 years is now the final term.
This may change over the years for
certain product categories.
So a train will certainly be looked at for longer than
5 years.
Yes,
but we have another question for you,
which might be quite good:
as a manufacturer, can I choose my own
risk assessment methodology and the standard or whatever I
use for it? People from
Herrneller have already told me, "I want to
take this, I want to take this." Complete
overgrowth.
What does everyone know about this? Basically
, you can do whatever you want if you
believe you are following the law.
I would rather make sure
that I
follow Geiden's standards, because then I can always
say that it came from the Commission and the BSI and
they wrote down how it's done,
and if you stick to it, you're
not on the safe side either,
a court can still
say, yes, the standard is nice, what you
wrote down there, but it's
not in accordance with the law. So, in the
end, the court looks at the law, and
if you can prove that you
abide by the law and the court
believes you.
So, this is partly why
standardization is currently so important,
because if there is a harmonized
reference site, then
manufacturers producing products in important
Class 1 can declare themselves compliant with this
standard
. And when he
was quoted, the Commission said that, from
our point of view, what is written there is sufficient to
demonstrate conformity if it is followed
.
And the more uniform or
harmonized the standards are, the better,
then the
manufacturers or many manufacturers will
follow them, in the Commission's view; they don't have to.
Harmonised standard
cites harmonised standard.
Yes, it's my turn.
Do you have a question? Yes
. Yes, I have a simple question. So
now you basically have four roles
in your game. This is the user,
this is the manufacturer. I would prefer to
call them the integrator; then it's
the project, they're the ones who
write the software. And now the fourth
new role is added, that is
Stuart. How can the role of the tax officer
be operationalized? That is the
question. Yes, because it seems
relatively new to me.
So, to reiterate, it's not a
free software law, right? It
's a product regulation, and then at
some point it was discovered that
products also contain free software, and so
this law
specifically addresses the issue of what happens to
free software. There are
also manufacturers who never have anything
to do with a project and yet still
make free software. Yes, so
maybe that's a
basic understanding, so to speak. And then, at the
end of the day, if I
'm a manufacturer and I access projects that
end up in my product, the
first question I have to ask myself as a manufacturer is:
should it stay that way?
So, basically, do
I need this, do I have to do this, do I want this? And
then I can ask myself, for example, if
I follow this, then I have
nothing to do with the project, I take care of it myself
, um, I do
n't have to integrate or
rationalize or anything else.
And at the moment I, as the
manufacturer, decide to collaborate on the project,
I have to
find a way with the project so that in the end I,
as the manufacturer, can say that I can
safely put a CE marking on it, and
for that I have to put Stuart in a
position to help me so
that I can do that.
And that's how you operationalize it. So,
for each product, a
manufacturer will come along and say, "For
this product I need a Celebel;
I'm using the one from your project. How do
we get there?" And then
this one product gets a CE label
for this one specific
process. And how that
looks in each case, that's something to be negotiated,
I would say.
OK. We have about 5
minutes left, right?
I see three or four messages right now.
I don't really know. Um, I can't really commit to anything right now
. You can then
ask questions in the hallway,
for information, and I don't know how
they respond so cheerfully.
The other one was also short.
Yes, a good example is that
system integrators
often use Linux in their systems.
Um, that would have to have a CE mark
, that Linux. Uh, where is a CE-
certified Linux distribution supposed to come from?
Linux itself is not a product,
but as you said, operating systems are
within the scope of Cass.
Yes, but it's not a
product in itself. So it only becomes a
product when you
do something with it, anything at all.
Okay, then we'll use the
word processor LibreOffice. If I want to
use this in my company
because I want to save on licensing costs
. However, it doesn't yet have a CE
mark, and my Cyburity insurance company
requires me to only use C-marked
products.
Then you need to consider what to do with your
cybersecurity insurance.
So I would say
the probability of
Lebro Office simply having a C
license plate slapped on it is relatively
low, and if you want to use the software
, nobody is stopping you from
using it.
Just because they want to use them with
Census symbols does
n't mean the software has to
put a Census symbol on them. If
someone requests this and makes it available in a
commercial context
, then that person can
become a manufacturer and then they can say, "This is a
modified Libraoffice with trademarks."
Dramatic.
I don't
think
this product is really safe.
Uh
yeah, just one comment on
this matter. So, there are already a
few talks underway with insurance companies
. So I
personally had talks with the
reinsurance company in Zurich, and
the people from the Open Chain process are
discussing things with the people in London.
So I believe the problem will eventually
resolve itself outside of
this area. So, yes, it's a
well-known problem, that can be
insured. So the insurance people
want to know what the risks are, and
they can't assess that yet.
So that's due to us, for example,
not you. So,
to roughly demonstrate these risks. If we
behave properly, the
costs will be low; if not, they will be
high. Also,
bring the traffic category sign. Yes
.
Yes, you have to multiply that by
two messages. We hardly have any
time left. I don't really know.
Okay,
I'd like to make a brief comment. So,
work is underway and currently in progress
. That means if you
're a manufacturer and you say, "I distribute my
browser" or "I distribute my
operating system" and you're worried that there's
nonsense in there," then find out more. They're working on this, they're
looking for employees with
expertise who really know
what's going on, and you should make sure
you can exert influence, because now's your
chance to help shape these standards
. So, anyone who is worried
that a business model will go under, in
two years the train will have left the station.
And it's really not terribly
difficult, uh, if you
want to get involved, to be able to get involved
. So, the doors are
definitely open.
This relationship between Stuart and
the companies that bring products to market
could, to make
a very, very unpopular
parallel, be handled through a kind of
collecting society. In other words,
companies buy a kind of
insurance for a specific open
source project, which can then
rise or fall with the product's value to the company
and with the
risk factor of the respective project,
and the company then receives money, or the
project receives money to
bring this product, or rather the sub-product, to market and
make it usable for the companies.
So, my personal opinion on this
is, I don't think we should build some kind of
state-run structure there
. I think
the market can
regulate this to some extent on its own. I also think it's important
that private
money is involved in this game. Um,
and then I could definitely
imagine something like this: there's a fund into which people
pay, and then there's
something like a Nutrcore on the other
side, and then you can see whether a
company is financing into the ecosystem or
not. And these funds are primarily
channeled into projects that don't have a particularly good
relationship with the manufacturer,
but still
want to participate in the process.
But, uh, so to speak, this, as I said, this:
how does money get to whom, when, and where?
Um, that's a problem that
I think many people see, uh, how it's
solved. There are few concrete
proposals. As I said, I personally find it
important that
this is primarily about private money
, meaning that those who benefit from free
software should
support those who make it available
. So, this principle
should generally be adhered to
. That's how the law came about
. Of course, there are also
state actors who benefit from free
software, and they must
also contribute, but overall
I see the
market participants as being
responsible for providing the resources
.
Okay, that's the end of it.
Many thanks again to Alex and
Michael. Yes, thanks.