EU puts smart device manufacturers on the hook for cyber security
- Reference: 1663306436
- News link: https://www.theregister.co.uk/2022/09/16/eu_cyber_resilience_act/
- Source link:
"Computers, phones, household appliances, virtual assistance devices, cars, toys … each and every one of these hundreds of million connected products is a potential entry point for a cyber attack," explained Thierry Breton, European commissioner for internal market. "And yet, today most of the hardware and software products are not subject to any cyber security obligations.”
The Commission's concerns go beyond the hacking of the product itself and to the impact one incident might have on the entire supply chain. The org cited potential fallouts as "severe disruption of economic and social activities across the internal market, undermining security or even becoming life-threatening."
[1]
Yes, the Commission mentioned death by cybers.
[2]
[3]
The [4]draft legislation , which has been in the works since September 2021, "introduces mandatory cyber security requirements for products with digital elements, throughout their whole lifecycle."
[5]China's single aisle passenger jet – the C919 – likely to be certified next week
[6]Climate change prevention plans 'way off track', says UN
[7]Amazon allegedly punishes sellers who dare offer lower prices on other marketplaces
[8]Microsoft Outlook sends users back to 1930 with (very) mini-Millennium-Bug glitch
[9]Microsoft rolls out stealthy updates for 365 Apps
The Act provides infosec requirements that must be met before products can reach Europe's markets, some covering their design, development and production.
Once the products go on sale, the Act will oblige manufacturers to disclose incidents within 24 hours of becoming aware of them, and address vulnerabilities through security support and software updates. Manufacturers are required to resolve cyber security problems for a period of either five years, or the product's expected lifetime.
"The new rules will rebalance responsibility towards manufacturers,” said the Commission.
[10]
Once the law passes, manufacturers will have a grace period of two years to adapt to the new requirements. For vulnerability and incident reporting, the grace period is just one year.
The proposed regulation does provide some exceptions for products such as medical devices, airplanes, and cars, as they are already subject to other regulations.
Failure to comply could result in fines of up to $15 million (€15 million) or 2.5 percent of the offender's total worldwide annual turnover for the preceding financial year.
[11]
Lest anyone assume the legislation will only affect Europe, the Commission was not shy to express that it has potential to establish global standards, calling it "likely to become an international point of reference."
The Commission won't mind if that happens, having already led the world with the General Data Protection Regulation (GDPR) and action against tech giants over their business practices and use of data. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YyRJOs39oenbQ5QKIjsThQAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyRJOs39oenbQ5QKIjsThQAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyRJOs39oenbQ5QKIjsThQAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://ec.europa.eu/commission/presscorner/detail/en/ip_22_5374
[5] https://www.theregister.com/2022/09/14/chinas_c919_passenger_jet_certification/
[6] https://www.theregister.com/2022/09/14/climate_change_prevention_plans_way/
[7] https://www.theregister.com/2022/09/15/amazon_california_competition/
[8] https://www.theregister.com/2022/09/15/microsoft_outlook_date_glitch/
[9] https://www.theregister.com/2022/09/15/microsoft_365_automatic_update/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyRJOs39oenbQ5QKIjsThQAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyRJOs39oenbQ5QKIjsThQAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Does that include TeleScreens?
Should've bought a dumb screen. The channel 4 website runs in a browser as do lots of "Fake my location" plug-ins.
This is why we have to have laws to enforce security, because otherwise people just buy any old shit.
Re: Does that include TeleScreens?
But at least you might reasonably expect it to work for a TV genuinely located in the UK?
Re: Does that include TeleScreens?
Sale of Goods act should apply, demand a replacement as not of sale quality and not fit for purpose.
Connected != Smart
And it works also for Humans.
== Bring us Dabbsy back! ==
I can understand...
..the desire to protect citizens, but who is going to want to launch a new tech product in Europe when the slightest mistake could result in a painful legal battle and fine?
Startups will go to America where "move fast and break things" works. Products will be launched where early fixes and revisions are tolerated, and maybe taken to Europe a few years later. Maybe.
Re: I can understand...
Mistakes are allowed. You just need to fix them and provide updates in a reasonable time period. No company that does this will have to worry. Those selling junk that is insecure and unmaintained will not be in business for long.
Plenty of people will continue to launch and release products in Europe as it is a massive market that has money to spend. Equally of all the cheap and disposable junk stops being sold and nobody wants to ship new products to Europe then European businesses will launch their own products to fill the gaps. You do realise that plenty of products are designed and manufactured in Europe?
Re: I can understand...
"Are designed and manufactured in Europe", or "Were designed and manufactured in Europe"?
I jest, but when you're a startup, there is not much of a line between cheap and disposable junk, and the next great innovation. You launch a product hoping you can get through the next three months whilst you figure out what needs to change, not committing to supporting that exact first revision for five years.
Clearly from your response you believe companies can magically afford to commit to a five year product support cycle when developing something new. I don't think that's true, and I suspect it's just going to cause more companies to close down early to avoid being dragged into legal battles. Or not launch in Europe in the first place.
This is not about the good intentions or otherwise of product developers, this is about the financial and legal realities of developing new products, which in the current economic environment means making pragmatic decisions about what and where you launch.
Startups need to sell alpha versions
Startups depending on making money from a first version of their product that is likely defective will already have a hard time if they sell to consumers here.
They are liable for defects for 3 years and can choose to either repair or replace with a working version at their cost and if unable to do either in a reasonable time they have to refund the full price.
Re: I can understand...
Many companies, in the smart devices startup arena, avoid this problem by recalling all the previous sales and substituting the old faulty version with an updated version.
Re: I can understand...
Those selling junk that is insecure and unmaintained will not be in business for long.
Little in recent history suggests that is true. They'll just rebrand, hiding behind shell corporations, and continue to sell their tat directly via Alibaba and eBay.
Re: I can understand...
It is rather better to have a limited quantity of quality, than a mess of total crap, as we have at the moment.
Re: I can understand...
The problem is, you're trusting unseen bureaucrats to set the criteria for "quality products".
As I say, I can understand people wanting someone in power to make everything safe and reliable. But it's ridiculous to believe they have the power to do so, and there won't be unforeseen consequences in an industry that relies on innovation and experimentation.
Re: I can understand...
It is aimed as a barrier of entry to stop the dumping into EU of shitty smart devices by cheap Chinese manufacturers, be it by direct export or repackaging the electronics with non value added importers in EU.
Re: I can understand...
who is going to want to launch a new tech product in Europe when the slightest mistake could result in a painful legal battle and fine?
I hope we can tag Windows too as code attached to a device and fine the screaming cr*p out of Microsoft for providing code that other companies would not even dare release as alpha level dev test, but I know for a fact that especially in the country I live there is absolutely no chance of that.
Re: I can understand...
..the desire to protect citizens, but who is going to want to launch a new tech product in Europe when the slightest mistake could result in a painful legal battle and fine? Reducing the amount of IoTrash out there, reducing the ability to just release the next buggy, insecure, unsupported, thoughtlessly designed and implemented and just overall shitty piece of IoTrash is a feature, not a bug.
"Expected product lifetime ... or five years"
The fact sheet gives an obligation of the expected lifetime or five years. Who decides that lifetime?
Also, it's "whichever is the shorter". It certainly seems ridiculous for a car manufacturer to have no requirement for what is in practice more than half the lifetime of a car.
While a car is probably the most extreme example, similar can probably be said for many products.
Re: "Expected product lifetime ... or five years"
Cars are excluded as they are regulated separately.
This is a starting point. It will most likely be expanded over time. It is a good thing that suppliers will be expected to ensure products are secure for a reasonable time period.
Re: "Expected product lifetime ... or five years"
We can expect products whose cyber security warranty will be void when connected to the Internet. Like some smartphones advertised waterproof whose warranty will not cover water damage. So everybody don’t worry, cheap crap will continue to flow into EU.
Offline
Should also be a rule that all devices should be either allowed to work offline so when they close the servers, all kit doesn't become useless. And would allow those who know to setup their own local or cloud based servers that they can point the device to.
Re: Offline
Not sure that's technically or practically possible.
If my Magic Doohickey synchronises with my Phone using some discoverable server in a vendor specific cloud, there is no easy answer when the discoverable server stops existing.
"Sorry, we have failed as a company - here are the instructions for installing Couchbase, twenty microservices, an SMS relay and a proprietary speech to text tool we depend on. Also, here is the source code that we spent a million euros developing."
It's a start, but of course it won't change smart meters
Which are supposed (in the UK) to have a 15 yr life, as opposed to the 40 years of "dumb" meters (before they are re-certified and can be reused)
OTOH the head of IT for a certain US energy company (in Congressional testimony) said they are computers, with a lifespan of about 7yrs before they need replacing.
But these are UK smart meters, which will be a special order.
Yeah. Right.
Still good start for the rest. And I do like the "Offline mode required" so if (when) the company goes TITSUP the product has some usability.
Enforcement?
Quote #1: "The Act provides infosec requirements that must be met before products can reach Europe's markets, some covering their design, development and production."
Quote #2: "....having already led the world with the General Data Protection Regulation (GDPR)...."
Quote #2 first........The Royal Free Trust allowed Google/DeepMind to slurp 1.6 million personal medical records...not one single citizen was asked for their consent as required by GDPR. No penalties (yet) for the Royal Free or Google. So much for enforcement of GDPR.
Quote #1.....Now we get this suggestion that someone (unnamed) will be certifying the business processes inside device manufacturing companies. Really?? ......there are thousands of such manufacturers, many (most) of them in China. Not possible!!
Both laws have almost no possibility of enforcement. Both are simply government marketing of the sort -- "Someone is doing something". Like GDPR this latest suggestion is a joke.
Does that include TeleScreens?
The All4 app on my 'smart' TV stopped working because the All4 server's GeoLocation code doesn't believe my IP address is in the UK any more, and no-one is taking responsibility to fix it.