Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really mean? Daniel explains it’s not too bad. There are plenty more requirements coming, but this one feels very approachable.
Episode Links
This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
Episode Transcript
Josh Bressers (00:00) Today, open source security welcomes back one of my favorite guests, Daniel Thompson, the CEO of Crab Nebula, an expert repertoire at ETSI a security theater actor in the guy behind Comply Land. Daniel, welcome back, my friend.
Daniel (00:15) It is great to be here. It’s a different season. I think the last time I was on your show we were talking about what Santa had to do to get ready
Josh Bressers (00:21) Yes.
Daniel (00:22) for the CRA.
Josh Bressers (00:23) Which is awesome. But so so we are obviously filming this slightly before, but I’m going to put this out right after kind of the first bits of CRA kick in. So September eleventh
Daniel (00:32) Sure.
Josh Bressers (00:33) is the date, you know, the date we’re all waiting for. So we’re post September eleventh, like what’s going on? What like what what
just happened, Daniel?
Daniel (00:40) okay, so
well the way I like to talk about this is if you just think back to the epoch. The epoch started January first at midnight? No, midnight one. Did it actually begin at zero and that zero moment was December thirty first, nineteen sixty nine? I go with the nineteen sixty nine one because that way I can tell everybody actually at the end of the day, the end of your day on September tenth, twenty twenty six.
The first obligations on manufacturers from the Cyber Resilience Act are going to be in application. So from the perspective of where we are now, this just happened. And what does it mean for manufacturers of products with digital elements? Well, if your product is on the market and you are undergoing an actively exploited vulnerability, you have an indicator
Josh Bressers (01:36) Yep, yep.
Daniel (01:37) of compromise.
you know that something’s going down inside of your product, then you have to go to the ENISA single reporting platform, sign up for you know, a login, and then fill out a thirty field web form.
Josh Bressers (01:56) Yes.
Daniel (01:57) I hope doesn’t crash. Maybe you use like a Word document beforehand or something. But
Josh Bressers (02:02) Yeah, yeah.
Daniel (02:03) you have to do this within 24 hours of becoming aware of the vulnerability being actively exploited. And the odds are in proving that we’re gonna see something like this just a day or two ago from the perspective of when this is aired, this, this, this podcast.
Josh Bressers (02:20) Yeah, yeah.
Daniel (02:21) And there’s a lot of a lot of questions that
That have become clarified through the July publication by the European Commission about their guidance to how to understand the Cyber Resilience Act and what does it mean for manufacturers? And and I think that, you know, a year ago we all thought we knew what was going on, but now it’s it’s really quite clear. It’s really clear. if your product is in service, then it you have the obligation.
Even if it’s been in service for 20 years, if you’re still selling it, then if it’s if it’s hacked, you gotta report it. Now, this is not the same as dependabot s smashing your
Josh Bressers (03:06) Right.
Daniel (03:06) inbox with 300 things you gotta update or maybe vulnerabilities. It’s not the same. yeah. I’ll get to that in a minute. But what what we’re what we’re talking about is you’ve been you’ve been exploited. Your product is under attack and you can prove it. You got the log lines or whatever.
And that’s what you have to report. You got 24 hours to report it, and then you’ve got 72 hours after this first instance. Within that time, you have to give an interim report. You have to give them more information. Hopefully you’ve already solved it. but if you haven’t solved it by then, until you solve it, you have time to file a a report, a final report that explains everything. Now
You’re supposed to inform your users. you could ask for an embargo. I mean, there are there are very real scenarios where you don’t wanna tell the whole world that you’re undergoing a cyber attack until you resolve the cyber attack. I mean, there’s there’s a lot of cases of of responsible disclosure where in in our industry you discover something and maybe it’s even being actively exploited by threat actors.
and until you solve the problem you don’t publish the fix because you don’t have one. You don’t tell people necessarily. And so there’s a a mechanism in this whole scenario where supposedly you’re s you’re able to say, Hey, don’t disclose this yet. You know, let’s the the let’s keep it quiet.
Josh Bressers (04:43) Sure.
So I’m I’m just gonna say as a security person, like I’ve been doing disclosure for a long time. And if your product is being actively exploited, the embargoes no longer apply. Because while you may not have a fix, you can give like indicators of compromise and other information, maybe workarounds to customers and users. So I get super jittery over the ability to do this, but I don’t want to dwell on it either, ‘cause like that’s not the point of this discussion.
But I and I
I I understand also why ENISA has probably allowed this because I know there are a lot of companies that would like lose their minds if they couldn’t do that. But from a a purely like ethical disclosure perspective, I am like I’m extremely opposed to this idea. That’s okay.
Daniel (05:29) It’s well basically it gets more complicated. Because ENISA, you have to understand, ENISA is like the cyber czar of Europe. But what’s Europe? Europe is a construct. It’s a I mean Europe is a construct based on sovereign nations that come together and empower the commission. They empower ENISA
Josh Bressers (05:51) Yeah, yeah.
Daniel (05:52) to have opinions and hire terrible contractors. Did I say that out loud?
Josh Bressers (05:58) Like you right. No, I’m sorry.
Daniel (05:59) Well,
I mean, let me ask you a question. What security reasons might there be for the single reporting platform only being addressable by a web form instead of via an API?
Josh Bressers (06:18) Well, I mean, I assume that at this point they’ve done it because they just didn’t have time to to properly f you know flesh this all out. Because I know like the fact that they have this web form ready is shocking to me because I think what, like six months ago they had nothing. So that like from a government perspective, six months is like 15 minutes for the rest of us. So like
Daniel (06:35) Right.
Josh Bressers (06:36) I’m shocked that they just didn’t end up saying, like, here’s an email address, please don’t spam us or something. So a a web form seems like progress. And and the other thing to remember.
Is anytime you’re dealing with regulators and this kind of stuff, they’re always very slow to start and then they, you know, evolve all of this as we go. Cause like a good example is you’re talking about exploited vulnerabilities. What is the defin like have they defined that? I suspect they have a definition that’s going to change drastically over the next year.
Daniel (07:04) KEV a known exploited vulnerability is not part of the actual nomenclature within the Cyber Resilience Act. We might actually see an implementing act come up where this gets declared. We might actually even get a a a disclosure about or a a a an i an implementing act that tells us that hey, actually there is no minimum in an S bomb. Everything belongs in your S bomb, you know, like
Like you know, we just we just we just learned from the the collab between Germany and the US and ENISA coming up with this US standard of basically the minimum means there’s no minimum. But
Josh Bressers (07:49) Yeah, yeah.
Daniel (07:51) we’re still in September fourteenth and what happens there’s like i i i if you read the the law, there’s like this point where it’s like what happens if you can’t reach
the single reporting platform ‘cause it went down.
Josh Bressers (08:08) Right, right. Which it very might it might go down on day two because, you know, a bunch of people hit it.
Daniel (08:13) It might.
It I mean, come on. Like, there’s there’s so many like low orbit ion cannons out there with the mini Shai-Hulud or whatever. Like, come on. Like you have to imagine that that this is going to be a big target. But
Josh Bressers (08:30) Yeah, yeah yeah.
Daniel (08:32) you’re supposed to then inform your national market surveillance authority. How do you do that? In Germany,
Josh Bressers (08:39) Ha ha ha ha.
Daniel (08:40) you might be able to fax it.
you might actually be able to fax your
Josh Bressers (08:44) Excellent.
Daniel (08:45) findings to the BSI, or if it is the BSI, I’m not sure that’s been fully disclosed yet, or decided. So the the thing is, the single reporting platform, it it means single reporting because all of the European Cyber Acts are supposed to then report to this thing. So if it’s a if it’s a Dora violation or
you know, something about NIS2 everything is supposed to ultimately end up there. And the thing is, ENISA and the single reporting platform, they don’t actually do anything. It’s the market surveillance authority that has the actual power. So
Josh Bressers (09:29) Right, right.
Daniel (09:30) let’s just pretend for a moment that the platform goes down and you figure out how to send it to your market surveillance authority. How do you determine which market surveillance authority?
Is responsible for your product, the company. There’s actually a list in the CRA that tells you where your company is founded, where your authorized representative is founded, where you have the most users, or where the most impact is. But you know, as we as we recently saw, the the Hamburg court took jurisdiction over an Irish product.
very recently and so i like like i’m telling you these are sovereign nations here this isn’t like yeah we
Josh Bressers (10:18) Yeah, yeah.
Daniel (10:19) like we work for the european commission it’s the other way around and and and that’s why i think if you’re not based in europe and you’re placing a product on the market you might want to consider hiring an authorized representative really quickly
Because then you get to choose your venue. if you
Josh Bressers (10:42) ‘Cause then your
authorized representative can be one of the places you use and if you have an authorized representative in a
Daniel (10:45) Right. But it would be the place.
Josh Bressers (10:48) I gotcha, I gotcha.
Daniel (10:49) It would be the place. Right? So if you don’t choose it, it might be ANSI in France, it or whoever is the French. It might be Italy. It might be Germany. It might be Finland. Who knows? And if you get a legal letter from the BSI, guess what language it’ll be in?
Josh Bressers (11:10) right, it’ll become in the whatever the local language is for that that jurisdiction. Yeah, yeah.
Daniel (11:12) German. It’ll be in German or French
or Italian. And those become legal documents that have to then be legally translated and you know like it’s it’s it’s one of those things where the the the law doesn’t require you to have an authorized representative. You have to have an importer, an authorized representative, or a fulfillment provider, if you’re not based in Europe. You have to have one of those three.
but right now at the place we are at with this first part of the obligations entering application, where we’re at right now, the things are still kind of fuzzy. you don’t have a CE marking on your product, but you do have to report these things about your product. And it’s anything in service. So
I mean at at work right now, what we’re doing is we’re spinning up a Vex system to make sure
Josh Bressers (12:16) Thanks.
Daniel (12:17) that everything that we track is not tracked in a comment in an issue. It’s filed in a VEX because you know if you if you don’t know the the the vulnerability exchange is a system that allows you to define the way in which you’re treating a potential vulnerability, or actually
Josh Bressers (12:37) Right, right.
Daniel (12:37) a real one.
And this way you have proof and providence that you did your job. And and so, I mean, I’ll just I’ll just give you a a fun story from the sidelines of the standardization process. While we were working on the browser standard, there was a conspicuous few months this springtime where Mozilla didn’t come to the meetings.
No shade cast. They supported the the the standardization process, the the the authoring process amazingly well. Their their contributions were exquisite with regard to TLS. I’m not complaining. But why were they absent? Well, you know, the the the Vuln Apocalypse or the CVEmageddon or whatever you wanna
Josh Bressers (13:29) Yeah, yeah.
Daniel (13:30) call it, because of the rate at which every unsafe programming language has
it’s memory problems and now they’re all just kind of like bubbling up like silicon that you’re de-gassing. And
Josh Bressers (13:44) Yeah, yeah.
Daniel (13:45) and you know now and I think for the next six, twelve months, our industry is going to be paying the price of the shortcuts we took by not being militant about memory safety. And I’m not making a pitch for the best programming language Rust. I’m not doing that because
Josh Bressers (14:04) Well we can pitch
it. We love rust here. It’s fine. Everyone everyone use rust.
Daniel (14:06) I mean there’s there’s look there’s a lot
there’s a lot of other languages that are memory safe. Even Java can get you there. And Elixir and
Josh Bressers (14:12) Yeah, yeah.
Daniel (14:13) Erlang And I I’m not saying that Rust is necessarily the best. It’s one of the best. I love it.
Josh Bressers (14:18) I’ll say it, it’s the best.
Daniel (14:20) Okay. I mean I’m not gonna argue with you on that. It’s the best. Okay. but the the the point is that it hasn’t been around for twenty, thirty years.
Josh Bressers (14:33) Yeah, yeah, yeah, right.
Daniel (14:34) And and you know
There’s this old adage for you youngsters who don’t know how to write software but can vibe like crazy. The old adage is, if it’s not broken, don’t fix it. And and that’s what
Josh Bressers (14:46) Yeah, yeah.
Daniel (14:47) we built an entire industry upon. And the the the challenges that the Cyber Resilience Act, which by the way, was crafted pre-LLM dominance,
Josh Bressers (14:59) Yes, yes.
Daniel (15:01) is now starting to to to quiver a little bit.
I’ll give you another example from the standards. We we had a lot of discussions about security theater. I you know, I’m I’m a security theater actor, and
Josh Bressers (15:17) Yes.
Daniel (15:18) one of the things I always argue for is you zeroise your memory. You clear it when you’re done with it, you fragment important phrases across their spirit parts so there’s someone
Josh Bressers (15:27) Yeah, yeah.
Daniel (15:28) snapshots that they can’t instantly put it together. These are things, and I was told by very smart people in many rooms, Daniel.
That’s security theater. We can’t defend against a man in the box. And yet OpenClaw is like waving things in. And didn’t we just see a couple weeks ago, or actually like you know, mid-August, terabytes of of of data that is not data, that’s actually like private keys and passwords for every big industry player out there? just got leaked.
Josh Bressers (16:02) Yeah, well, I mean,
those were stolen from a backdoored library, essentially. But yeah.
Daniel (16:07) Yeah. so that’s right. It was supply chain again.
Josh Bressers (16:10) Yeah, I mean it it’s always supply chain. But i I I have an example for you though about that. So I used to work at Elastic, right? They do Elasticsearch, which is like an awesome search engine. I still use it every day.
Daniel (16:19) Yeah. yes, I know it.
Josh Bressers (16:22) And we had a vulnerability at one point where we had these buffers that we would use. And in Java, obviously there’s garbage collections, things like that, and we would
We would create these buffers for use. And they they basically were instantiated once and then just reused over and over and over again for performance reasons because the Java garbage collection is slow and it runs at weird
Daniel (16:41) So what have you?
Josh Bressers (16:42) times. So like we can’t trust it necessarily. And Elasticsearch is super performant. So that’s a concern they have. And there was a bug in one of the libraries using one of these buffers that wasn’t it, it basically was one of the typical like end of line care. I don’t know what they call it in Java.
Right, where like in in C you put like the zero, zero byte, the null byte at the end of a like your string, and then the string libraries know like this is the end. And whatever was happening in Java, the end of line wasn’t being set correctly. I forget if it was like an integer and the object or whatever. And so it would return the whole buffer. And it the buffer almost always contained the password for people logged in, like almost every time we ran it. I’m like, well, this sucks.
Daniel (17:23) Yeah.
Josh Bressers (17:24) And but I mean this is an example where like, yes, zeroing out is absolutely the right thing to do, but you’re now you’re you get pushback though from the people that like, No, we need the performance. We can’t afford to zero things
Daniel (17:33) What is the performance?
Josh Bressers (17:34) out and I’m like, I’m not gonna fight this fight, but we should be zeroing this out. So
Daniel (17:39) I mean nowadays we have faster computers, right? Thank you.
Josh Bressers (17:43) Yeah.
Well, except now we can’t buy RAM, so it’s fine, everything
Daniel (17:46) Now we can’t buy r I you know
I I wanted to buy a an NVMe of four gig and I’m like, how much money do you want for that? no.
Josh Bressers (17:54) man, it’s crazy, I know, right?
Daniel (17:56) It’s Yeah, well
Josh Bressers (18:01) Anyway.
Daniel (18:02) Anyway.
Josh Bressers (18:04) Okay, so I I wanna I wanna I’m putting we’re gonna put us back on track. So so September 11th, we have to do vulnerability reporting of exploited vulnerabilities. What defines an exploited vulnerability is almost certainly going to be a term that evolves over time, right? So so like what what else do we need to worry about like right now? Is that the big one? Is just just reporting vulnerabilities, or are there some other requirements we need to care about?
Daniel (18:29) I mean there’s like a major incident that you could report. this might be if the the the server got hacked. You know, it didn’t impact the
Josh Bressers (18:41) Okay.
Daniel (18:42) product itself, but the database that you’re running. That would be a major incident. That’s something you could also
Josh Bressers (18:46) Gotcha.
Daniel (18:47) report. And, you know, anybody can file reports, right? so there I I I’m looking forward to to how that pans out. but
There was there was a workshop that we had gosh, when was this? About two months ago, we brought together the some of the authors of the standards from ETSI and some from CENCENELEC And we had the the brass from both and ENISA as well as the commission. And we had a pres or the ENISA and the Commission gave us a presentation about what they were looking toward.
for this kind of you know where do you where do you draw the line and there was actually in discussion briefly it it got kind of sidelined but there there in discussion was the likelihood that something is going to be exploited in the next thirty days. You know that that amazing yes, the EPSS score.
Josh Bressers (19:54) the EPSS score. Yeah, yeah.
Daniel (19:57) Which was brought into discussion as something potentially useful. And we all said, No, that is not an indicator of compromise. That is a potentiality
Josh Bressers (20:04) Yeah, yeah.
Daniel (20:05) that has not arisen yet. And if you do that, then don’t wanna be Google. You know, you don’t wanna be fighting the front lines of a browser and you don’t wanna be in in any operating system, you know, like
Josh Bressers (20:21) Yeah, yeah.
Daniel (20:22) i i it it it has to be real. And and and I think that you know, to their credit.
To ENISA’s credit, to the commission’s credit, they’re able to take this kind of feedback and integrate it into their thinking as well as you know the whole process. And I I have to say it’s been really refreshing that we that that that the the powers that be are are are staying accessible to us and asking questions. And of course, you know, there’s there’s legal terms of art that we have to follow when we’re writing these standards, and because
They will then
provide manufacturers with the presumption of conformity. So we have to be very clear. And you know, at the very end of the the final drafting process, which just just just announced on the 13th of August, that all of the the 17 standards from ETSI have now been submitted for public enquiry. what we’ve what we’ve learned is that
Vulnerability handling is complicated and not every product can even treat it the same way. And so a one size fits all method doesn’t work, and yet there are similarities and there are lines that once crossed are very clearly the the situation that the the that the commission is after when and that is when something has been exploited.
Right? You got that
Josh Bressers (21:58) Yeah, right, right.
Daniel (21:58) log line, you have the indicator of compromise, and you know it. Now, one other thing we did learn from the guidance is if that problem is in your dependency, but you yourself have not been compromised, you shouldn’t report it. So you should not. So here’s the
Josh Bressers (22:18) Wait, you shouldn’t? interesting.
Daniel (22:22) situation. Here’s the situation. Imagine you are a fictitious.
JavaScript library called Right Pad And probably
Josh Bressers (22:34) That probably exists just for what it’s worth.
Daniel (22:36) just for the yeah, yeah. and and what it does is it overwrites the entire string and crashes the computer or something. I don’t know. It doesn’t matter. And and and it’s being downloaded tens of millions of times per week. You know, those fancy NPM metrics that tell you how popular per
Josh Bressers (22:52) Probably per day for left pad.
Daniel (22:55) Yes, per per per day, and you know, it’s not the number of machines that are using it, it’s the number of runs, but whatever.
Josh Bressers (23:02) Yeah, yeah.
Daniel (23:03) what they don’t want is they don’t want fifty thousand reports that are very similar but different enough that you have to address each of them. Right? So they want I mean, you could report that this particular
Vulnerability exists, but it’s not actually your report. It would be the the thing that is owned by that steward or that manufacturer. So
Josh Bressers (23:34) I see.
Daniel (23:34) that’s an important nuance, I think, that I I I hope helps people you know breathe a little easier. That said, if that vulnerability leads
Josh Bressers (23:42) Okay.
Daniel (23:44) to exposure in your product, then you are responsible for reporting it.
Josh Bressers (23:47) Okay. Okay.
There we go. That’s what I was wondering. Yes. Okay.
Daniel (23:49) Yes.
Josh Bressers (23:50) So so you’re saying hypothetical scenario, I have a dependency. And this actually this happens all the time. I mean, I deal with this on a regular basis with the the products Anchore has, where we have a dependency where some user of that dependency is is getting popped because of it, but the way we use it doesn’t put us at risk. And so in that instance, I don’t have to do anything, but if I’m the company being popped because of this, then I have to report. Yes.
Daniel (24:16) Absolutely. Exactly. Yeah.
Josh Bressers (24:17) Okay, that makes sense. That makes perfect sense. Yeah. I mean that’s very reasonable.
Daniel (24:20) Because you are not being exploited. It is an exploitable
Josh Bressers (24:23) Right. Yeah. Yeah.
Daniel (24:24) vulnerability and your vex clearly states this code path is not part of the happy, sad or
Josh Bressers (24:28) Yep. Yep.
Daniel (24:29) existing path ‘cause we tree shook it or whatever.
Josh Bressers (24:32) Which is literally what I do. I write vex statements that are like, We don’t use the code in question, so we’re fine here. Which is it it is funny though. I mean, something I’m sure everyone listening and I’m sure even you are aware of is like quite often if I have like a critical or a high finding, even if it’s technically I can vex it away, I fix it anyway, ‘cause it’s like it’s just less work
Daniel (24:50) Fix it anyway.
Josh Bressers (24:50) than dealing with this crap.
Daniel (24:52) Yeah, and I mean I th I I think also what what we’re seeing with the agentic gadget attacks is that even something that might be minor that you might
Josh Bressers (25:07) Yeah, yeah.
Daniel (25:08) not want to worry about can be the stupidest vector that no human would ever do because you gotta jump through thirty-seven hoops
Josh Bressers (25:15) Yes.
Daniel (25:16) at the same time.
But if you have a billion fingers and a dozen minds and you know, then it becomes possible and I totally agree with you, you know, if if it’s fixed with just an update to a latest version and I can prove it, then I will add that to my vex and say, Yeah, I updated.
Josh Bressers (25:32) Yep, yep, for sure.
For sure. Yes.
Daniel (25:36) Now, there’s another situation though, and that is I I think this is part of the the the story that the people who do vex authoring maybe don’t recognize yet, but there are situations where you later on become vulnerable.
Josh Bressers (25:52) Yes. Yes.
Daniel (25:54) Right. And so just because you fixed it once doesn’t mean that it’s not gonna come back to bite you in the future. That’s why you update or you patch if you can, right?
Josh Bressers (26:02) Right. Yeah, yeah. Right. Right.
Daniel (26:03) And and and and I guess the the advice is keep your vexes around and don’t be afraid to reopen them. Right? And ‘cause
Josh Bressers (26:11) you have to reopen them. I mean, that’s the
so the right way to do it is like every time you vex something away that’s like code present but not used, for example, you need to revisit that because even though the code’s present but not used today, there’s nothing stopping a developer from turning
Daniel (26:26) Yeah.
Josh Bressers (26:26) that into like used code tomorrow. And I mean, this is this has always been one of the concerns with the whole, I don’t need to fix that ever because it doesn’t affect me, right? I view it as the a a way to prioritize the work, right? Because we have
like an infinite number of vulnerabilities and we only have a certain amount of time to s to fix them. I’m going to fix the things I’m actually affected by before I’m going to fix the things that are, you know, code present but not used. But I also recognized as the clock ticks, the code present but not used bubbles up to the top because it eventually becomes we really, really need to get a handle on this and get rid of it.
Yeah,
yeah. Okay. Okay. So here’s we’re we’re we’re winding our clock down here, Daniel. But I I feel like everything you’ve described feels very approachable. Where I have to report exploited vulnerabilities to ETSI, hopefully to ETSI. Okay, sorry. that’s not ETSI? Who is that then? Or ENISA not ETSI, right? Yes, yes, okay.
Daniel (27:18) no to to the to the single reporting platform, ENISA. No. the si ENISA, yeah, yeah, ENISA.
Josh Bressers (27:27) Which is which is that feels very approachable and reasonable. so
I I guess I I feel like that’s something the bar is very low, right? But but the things coming next, the bar’s a bit higher. So like what what should we be working
Daniel (27:44) Yeah.
Josh Bressers (27:44) on now to get ready for cause the CRA has a couple steps and the the things are going to start phasing in. So like what’s what are some of the next things we need to think about?
Daniel (27:49) Right.
what what you’re gonna wanna do in the context of preparing for this is put together procedures and rehearsals, that’s what we call them. you can call them exercises, you can call them tabletops. But
Josh Bressers (28:03) Yeah, yeah.
Daniel (28:04) the general idea is you have a procedure that you file, maybe we have like a a means for your executive board to file them in your corporate documents or part of your QMS or your ISMS where you describe how your
Secure software development lifecycle works in the context of treating potential vulnerabilities and handling actively exploited vulnerabilities. Who do you call? What’s the procedure? When do you involve the police? Do you involve the police? Is it actually touching customer data? Do you have to tell your customers? If so, what’s the procedure for that? Who does that, when, how, and who is the responsible party for keeping it all together? So the advice is prepare for the secure software development lifecycle because that’s not going away.
Josh Bressers (28:47) Yeah, yeah.
Daniel (28:47) It it starts
it started three days ago. This is for the rest of time, for the rest of the lifetime, the active lifetime of your product, starting December eleventh, twenty twenty seven, assuming that is when the law enters full application, you’re going to have to retain your declaration of conformity. And I think that that’s the notion of resilience, right? We are not checkboxing our ISMS. We are keeping the checkbox checked.
When we have a vulnerability, we patch that vulnerability, we ship an update of that vulnerabilities fix to all of our customers, and we retain that for ten years. That’s the law.
Josh Bressers (29:28) Yeah, yeah.
Daniel (29:29) And it’s freely available. Wait. Yes, actually, true. This was this will and maybe my only criticism of the CRA, you have to, as a manufacturer, give security updates away for free. This is going to
Josh Bressers (29:43) Yes.
Daniel (29:43) change the market. It is a market shaping instrument.
I’m not sure I agree with it. I understand the premise, but I don’t know if the commission has overstepped its bounds. We will see if there is litigation that appears in 2028. But the way things stand right now, you have to supply your customers with free security updates for the lifetime of the product.
Josh Bressers (30:09) I mean, I’m comfortable with that. Like I I know there are for
Daniel (30:12) It’s for the better good.
Josh Bressers (30:14) for the the vast majority of software I would say does this. The the the sticking point comes from oftentimes like IoT type vendors, maybe some equipment manufacturers where they want you to have, you know, some sort of maintenance contract with them. I know a lot of like router manufacturers do this where you can’t get security updates unless you have a maintenance contract. Now, one of the keys though is like obviously we have to define customer in that context because like
If
I sell you a router and then you give the router to your neighbor, is your neighbor my customer? I d is that defined? I don’t know.
Yeah.
Daniel (30:50) Did
I give it to them?
Josh Bressers (30:52) What i I maybe yeah.
Daniel (30:54) Then then ownership
is transferred, you know, the the the okay. I’m gonna I’m gonna cop out here, and that’s because property
Josh Bressers (31:02) Yeah, that’s fine.
Daniel (31:03) ownership laws differ from European sovereign country to sovereign country.
Josh Bressers (31:07) That’s true. Right.
Daniel (31:09) And and that’s why the Product Liability Directive is not an act, it’s a directive that every country gets to enact the way that they see fit that aligns with their notion of
Josh Bressers (31:20) Yeah,
yeah.
Daniel (31:21) you know, civil law or property law or statutory damages or liability. And and I can tell you, because I’m tracking this, only a couple countries have even finished the transposition of the product liability directive. And so,
Josh Bressers (31:36) Yeah, yeah.
Daniel (31:38) I mean, that’s a whole another topic that we can talk about in February next year. But
Josh Bressers (31:43) Yeah, yeah.
Daniel (31:44) the the the the larger issues that I think people manufacturers should wrap their heads around is
Decide right now. Are you at the the end of downstream? Are you the the the dunnest of the supply chain? If so, you have time. Honestly, and I’ve done this for a lot of customers already. It’s a couple week to a couple month process. It depends on the number of products you have and their complexity and the supply chain’s
Josh Bressers (32:12) Yeah, yeah.
Daniel (32:13) complexity, the amount of due diligence that you have to do, the amount of open source that you’re doing.
So like there’s there’s there’s there’s variance here, but it’s not really gonna take you more than a two months.
That said, if you’re in the supply chain, if you are supplying components, whether those are hardware components or they’re software components, if you are a supplier in the supply chain and you’re not at the end of the downstream, your customers are going to be asking you
Josh Bressers (32:43) Yep, yep.
Daniel (32:43) for your CE marking, your declaration of conformity, and I promise you, your SBOM. If you don’t give them your SBOM, they’re gonna be like, well then how do I know?
And and I mean the
Josh Bressers (32:56) Yep, yep.
Daniel (32:57) law doesn’t force you to give anybody except the market surveillance authority your SBOM But every manufacturer that I’ve spoken to is like, yeah, we kind of have to give it to them because they expect it. And and so
Josh Bressers (33:09) Yeah. Yeah.
Daniel (33:11) for those of you that are in that position, the supply chain is extra complicated because the the the CRA was actually designed with final products in mind, but then
Software is made of pieces. And all of these pieces
Josh Bressers (33:28) Yep, yep.
Daniel (33:29) put together make you jointly and severally liable in the product chain for that final product of downstream. So you have to have your CE marking. Otherwise, people cannot buy your components.
Josh Bressers (33:42) Yep,
yep. You gotta love it, man.
Daniel (33:43) That’s that’s gonna become
the the new reality. And this is happening in Japan, this is happening in Singapore. I imagine that India is gonna be very close to to something like this soon. So
Josh Bressers (33:55) Yeah, yeah.
Daniel (33:56) that’s something to prepare for. Don’t take the cop out, it’s just Europe, because it’s spreading. The Brussels effect is very
Josh Bressers (34:01) No, no, everywhere.
Daniel (34:03) real.
Josh Bressers (34:03) Yep, yep. It for sure. For sure. It it’s coming. I mean, even in the US and some of the the regulated industries, we’re seeing this, you know, coming about. Like the auto industry has a bunch of wild rules about stuff like this right now. And and I think the FDA just put some guidance together for for medical devices. But it it it’ll be everywhere at some point, right? And let’s face it,
Daniel (34:22) Yeah, it will.
Josh Bressers (34:23) if you make stuff, you’re gonna end up in one of these supply chains sooner or later, right? Like it’s just the way it is.
Daniel (34:30) Now I think the other thing to think about, and this is just a hot tip because I I have it at top of mind. If you supply dual licensed components, for example, a GPL three and a proprietary license, just as an example.
Josh Bressers (34:43) Yeah. Yeah.
Daniel (34:45) If you supply your customers the GPL three, well, your consumers, because you’re not selling it to them, you just give it to them, if you
Ask them to give you their name, email address, and business name, etc. Any kind of PII, personal identifiable information, or business information. You are engaging in an exchange that is the equivalent of a market activity. In that context, you cannot be a steward for that GPL3 library that you’re giving
away in exchange for someone’s login information. It has to be
Like true to the OSI definition of free for everybody, anybody for any reason. and then you can be a steward for that that product. Yeah.
Josh Bressers (35:32) Sure, sure. And that makes sense. I mean, yeah.
Daniel (35:35) Yeah.
Josh Bressers (35:36) I accept that. All right, man. This has been like a fire hose of information. So let me see if I can recap this correctly just to make sure I’ve got my head wrapped around it all. So on September eleventh, which was in the past at the time this is released, but in our current future, on September eleventh, the single reporting platform will theoretically be live.
Which that’ll be inter I I know September eleventh is a Friday. I wonder if they did it on purpose to give them the weekend to fix whatever they break, but that’s probably another story. But
Daniel (36:05) No,
no, no. You have to file on a Saturday or a Sunday. You have twenty four hours.
Josh Bressers (36:08) Right, no, no, I I right, I get that for sure. Like so theoretically there’s going to be reports, but the for now, we need to report to the single reporting platform if we have an actively exploited vulnerability against our thing. And this is for manufacturers. Do the Stewards have to do this as well?
Daniel (36:27) Stewards are encouraged to do so. There are no fines for
Josh Bressers (36:30) Okay.
Daniel (36:31) not doing this. you might get sternly looked at, but
Josh Bressers (36:35) Okay,
but but if you’re an open source project, you do not have to report. Can you report if you’re an open source project though? You can. Okay.
Daniel (36:40) You can report. You can report.
Josh Bressers (36:43) Okay. And that’s basically those are the requirements for right now. It’s just reporting actively exploited vulnerabilities against your stuff.
Daniel (36:51) If it is on the market and in service. If if if
Josh Bressers (36:54) Okay.
Daniel (36:55) you had like a version two or let’s say version one of Angular, it’s no longer on the market, it’s not being supported anymore, and
Josh Bressers (37:01) Right, right.
Daniel (37:02) something happens to it, it’s it no, you don’t have to report it. But if you’re if you’re providing patches actively to s, you know, defend your thing, then yes, you have to report it.
Josh Bressers (37:13) Right, right. Okay. And that makes perfect sense. And then that is what we have to do until when is it, December of twenty seven when the next rules start to kick in?
Daniel (37:24) There is no until. That is what we have to do forever.
Josh Bressers (37:27) I’m sorry, not until. I mean until the next rule, the next things we have to do, I should say. Right. Yes, we’ll be reporting vulnerabilities forever. Absolutely. Like this is there is no the we’re Mr. Bones Wild Ride, right?
Daniel (37:31) the right, the the the the next the next rule set. Yeah. Yeah. This is the this is the new real
this is the new normal.
Josh Bressers (37:44) Yeah,
yeah.
Daniel (37:45) so right, the the next obligations are expected to arrive on december eleventh, twenty twenty seven. However, there have been situations in the past
Where the commission said, you know what, we’re gonna give you a little bit more time. Look at the AI Act. That got pushed out again. Parts of it did.
Josh Bressers (38:04) Yeah, yeah.
Daniel (38:05) Not all of it, but parts of it. So there’s also totally f totally possible that all default products have to comply by December eleventh, twenty twenty-seven. Anything important or critical has until summer and twenty-eight. I don’t know, but the the commission has the power to change it. Right now, we’re, I believe, on track from the perspective of the standards at least.
to make it possible for conformity assessment bodies and manufacturers alike to help the products attain the presumption of conformity and declare their conformity with the Cyber Resilience Act and any other laws that might be approved.
Josh Bressers (38:43) Yeah, yeah. And and look, no sane person is going to make the bet that they’re gonna push it out. So I just won’t worry about it. Right. Like we basically this is our runway. Even if it gets pushed out by six months, you’re not gonna regret having this work done, right? Because y it even even if you don’t necessarily need it for CRA, there are a million other compliance standards that basically need the exact same documentation. So there’s like you you probably have a lot of it already if you’re in any sort of regulated
Daniel (39:11) Probably do.
Josh Bressers (39:12) industry.
Daniel (39:13) Yep. And I mean, up until then, you can always give me a call. I will call you back. I will I will help you out. And even if you are an open source project, I can’t tell you which funds we’ve received, but we will be able to financially support the s the the open source community in its obligations
Josh Bressers (39:37) Nice.
Daniel (39:37) as stewards and help them
approach the the maturity that stewarded projects should have and again for everybody else in God we trust.
Josh Bressers (39:56) I love it. All right, man. This was this was super fun, Daniel. I want to thank you so much for giving us the time again. I I will say that I feel like you did a marvelous job of kind of explaining what’s actually happening on September eleventh, because I know I’ve I’ve read many things and I’ve I’ve talked to many people and there’s definitely a lot of confusion about like what actually has to happen. And I I feel like it’s not that bad. Like this is this feels like a nice way to just kind of slide into traffic here, you know. So I I think that’s great.
Daniel (40:24) You know, I’d like to just shout out to our friends at security table. We’ve been saying this for years, right? Patch your stuff. And now Europe’s like, Patch your stuff. It’s it’s
Josh Bressers (40:36) Only if it’s exploited.
Daniel (40:40) no, I mean okay. Extra credit time for the people who stick around to the end of the podcast.
Josh Bressers (40:47) Excellent.
Daniel (40:49) when you place your product on the European single market, your product with digital elements, you are expected to present it in a state with no exploitable vulnerabilities. Now
Josh Bressers (41:01) Right, right. Yeah, that’s fair.
Daniel (41:04) That means that you gotta patch everything or you have a vex for everything. And I do not want to be an Electron project at that point.
Josh Bressers (41:12) man, that’s gonna be crazy. Yeah. Yeah. Yeah. I mean that’s an instance where just upgrade the thing a lot. But I don’t know. It that’s gonna have
Daniel (41:18) But you’re always behind.
Josh Bressers (41:19) but that’s gonna have some wild I mean, this is a topic for another day ‘cause we’re basically out of time now, but like i it I do you use Steam? Have you ever used Steam, the gaming platform thing? So I don’t know
Daniel (41:29) Have you stood. I have you stood, yeah.
Josh Bressers (41:31) if you run Steam, the thing updates itself like multiple times a day. Right?
Daniel (41:35) Yeah.
Josh Bressers (41:35) And I don’t know no one knows like exactly what’s going on, but whatever. Valve is a weird company. But like that’s
That’s one of the things that worries me is are we gonna end up in a situation where like every piece of software we have is updating itself, you know, like constantly because of the the CRA and that that is gonna get weird and annoying, I think, sometimes. So
Daniel (41:54) Welcome to the world of module federation.
Josh Bressers (41:56) Yeah, I I know, man. Like it’s, I don’t know. I don’t know. It’s gonna be weird, but we’ll figure it out. Like I I
Daniel (42:01) We’ll figure it
Josh Bressers (42:02) this is the thing. Historically, our answer to these questions has been it’s too hard, don’t talk about it. And so I think saying it’s hard, let’s talk about it is probably the the right way to do it. So I’m excited. I’m terrified, but also
Daniel (42:15) It’s hard.
Josh Bressers (42:16) excited.
Daniel (42:17) It’s hard. Let’s talk about it.
Josh Bressers (42:18) For sure. All right man. Thank you, Daniel. Until next time, my friend.
Daniel (42:22) All right, see you around.