Author Topic: EU "cyber" regulation, and secure firmware updates mandatory?  (Read 2002 times)

0 Members and 4 Guests are viewing this topic.

Online nctnico

  • Super Contributor
  • ***
  • Posts: 30155
  • Country: nl
    • NCT Developments
Re: EU "cyber" regulation, and secure firmware updates mandatory?
« Reply #25 on: Yesterday at 01:12:44 pm »
Then again, generally the quality of EU regulation is good - most of it exists for good reasons, most of it is well-designed.

And if your product is unsafe shit, you should make it good and safe even if there were no rules. Rules are needed to enforce actions on foul players who decline to act when they should.
I agree with this. For some reason big companies have the moral compass of a 4 year old kid. So regulation is necessary to prevent mishaps, death and destruction. For those in doubt I can highly recommend the documentary: 'The yes men fix the world'. It is available for free on Youtube.
There are small lies, big lies and then there is what is on the screen of your oscilloscope.
 

Online NorthGuy

  • Super Contributor
  • ***
  • Posts: 3518
  • Country: ca
Re: EU "cyber" regulation, and secure firmware updates mandatory?
« Reply #26 on: Yesterday at 01:35:44 pm »
Brussels will always make regulation.

You don't say. Like forcing idiotic "we use cookies" pop-ups. Or their most recent regulation where they introduced some kind of new postal tax which is impossible to comply with to the point that our post office doesn't accept shipments to EU any more.
 
The following users thanked this post: peter-h, rteodor

Offline tszaboo

  • Super Contributor
  • ***
  • Posts: 9787
  • Country: nl
  • Current job: ATEX product design
Re: EU "cyber" regulation, and secure firmware updates mandatory?
« Reply #27 on: Yesterday at 02:02:07 pm »
Brussels will always make regulation. That is their job. They cannot stop and will never stop.

There was a great video online (can't find it now) of a generously proportioned EU official called Seebohm saying (aviation context) "this is an area where there is no regulation, which is unacceptable, so we must create some".

It takes special talent to say that with a straight face.
You wouldn't need all that regulations, if the companies wouldn't act like psychopaths.
This is not a Brussels problem, this is a "profit above all else" problem.
And an incompetence problem, see battleborn batteries.
« Last Edit: Yesterday at 02:04:28 pm by tszaboo »
 
The following users thanked this post: nctnico, Siwastaja

Offline Perkele

  • Regular Contributor
  • *
  • Posts: 73
  • Country: ie
Re: EU "cyber" regulation, and secure firmware updates mandatory?
« Reply #28 on: Yesterday at 02:21:12 pm »
There are three separate EU cybersecurity-related directives coming into power this year and before the end of next year.
Depending on device design and declared usage, your product might or might not be in scope of all three, but it will be in scope of CRA.

The directives are:
RED: https://single-market-economy.ec.europa.eu/sectors/electrical-and-electronic-engineering-industries-eei/radio-equipment-directive-red_en (already in power)
CRA: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act (partially in power)
Updated EU Machinery Directive: https://eur-lex.europa.eu/eli/reg/2023/1230/oj/eng (in power from end of Jan. 2027.)
 
The following users thanked this post: rteodor

Offline peter-hTopic starter

  • Super Contributor
  • ***
  • Posts: 5992
  • Country: gb
  • Doing electronics since the 1960s...
Re: EU "cyber" regulation, and secure firmware updates mandatory?
« Reply #29 on: Yesterday at 08:51:50 pm »
Quote
You wouldn't need all that regulations, if the companies wouldn't act like psychopaths.
This is not a Brussels problem, this is a "profit above all else" problem.
And an incompetence problem, see battleborn batteries.

It's not that simple.

We get the vendors we deserve - by buying the cheapest crap we can find.

The result is that vendors are climbing over themselves to ship the latest product without much regard for bug fixing. The EU reg will not solve this, obviously. It's always been like that. It will cause some US firms to not sell to Europe (UK would be OK but they tend to be too dumb to know that) and others will do some workaround, or just sell old products to Europe (introduced before this reg). And stuff on Ebay etc is not enforced anyway so the final profit will be the Chinese selling on Aliexpress, Temu, Amazon, Ebay...

In most of Europe there is zero enforcement of any EU reg. The UK enforces none of ROHS etc etc. The trade mags are full of enforcement / bust stories, planted by EMC labs :) And the UK is a "rich" country. Places like Spain, Italy, struggle to just stay afloat. Germany is the big Brussels fanboy but selling into Germany is really hard (I've been exporting tech since 1978). France doesn't like Brussels much and does its own thing (and nobody there would dare run a "frexit" referendum ;) ). BE NL and a few others are also Brussels fanboys. Former Soviet bloc, nobody gives a damn.

It will go like ROHS. Smaller firms used the control and monitoring exemption which gave them ~15 years and by then nobody cares provided you tick all the boxes for the ~200 chemicals. The main hassle is large customers sending you the forms all day long. I especially like the Chinese customers demanding confirmation we don't use child labour ;)

There is no way to magically improve products, while remaining competitive etc etc. Claude will probably help :)

And as with ISO9000, if you made crap before, you make crap after. Nothing actually changed. It became a pure marketing tool. Its main effect was to exclude small firms from the approved supplier list of any sizeable company. This will do the same. It gave weirdoes without a life (ISO9000 quality managers) lots of power - almost as much as the LGBTQ+ compliance officer has today ;)
« Last Edit: Yesterday at 09:29:20 pm by peter-h »
Z80 Z180 Z280 Z8 S8 8031 8051 H8/300 H8/500 80x86 90S1200 32F417
 

Offline rteodor

  • Frequent Contributor
  • **
  • Posts: 487
  • Country: ro
Nothing actually changed. It became a pure marketing tool. Its main effect was to exclude small firms from the approved supplier list of any sizeable company. This will do the same.

[George] Stigler is best known for developing the Economic Theory of Regulation (1971), also known as regulatory capture, which says that interest groups and other political participants will use the regulatory and coercive powers of government to shape laws and regulations in a way that is beneficial to them.

It certainly feels this way even if there are things that are sane and should be done in some of them. The one 10^(N) euro question is: couldn't those things be done with already existing regulations or just by updating already existing regulations ? I keep dreaming that someone someday may be able to give a straight answer.

And is it only me that noticed a difference between UK and Germany + some of the surrounding countries: there are no or very few small shops?
Everything seems like captured by big businesses.
 

Online nctnico

  • Super Contributor
  • ***
  • Posts: 30155
  • Country: nl
    • NCT Developments
Quote
You wouldn't need all that regulations, if the companies wouldn't act like psychopaths.
This is not a Brussels problem, this is a "profit above all else" problem.
And an incompetence problem, see battleborn batteries.

It's not that simple.

We get the vendors we deserve - by buying the cheapest crap we can find.
That is not true at all. We need regulations for product safety. Otherwise: how do you know the apples you buy in a store a safe to eat? You don't have the equipment, time or knowledge to test each batch of apples and other food by yourself. And think about the non-stick frying pans. Everybody thought these where great products until it turned out the chemicals used (PFAS) are highly toxic and basically poisoned the entire planet. It would not surprise me if it turns out PFAS has made it to the moon. This all happened due to lack of regulations (and allowing self regulation). Dupont has been aware since the early 1950's that their product is toxic but went on making and selling it nevertheless while actively dodging regulations by altering chemical compounds slightly into unregulated chemicals.
« Last Edit: Today at 09:19:44 pm by nctnico »
There are small lies, big lies and then there is what is on the screen of your oscilloscope.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf