3 ms·
Erm I've been talking about this for 4 years now. So I'm not sure how it can "come out of nowhere" unless you're paying 0 attention to really important regulati
by radicalbyte 1mo ago
Erm I've been talking about this for 4 years now. So I'm not sure how it can "come out of nowhere" unless you're paying 0 attention to really important regulation in your field.
There will be a post in 9 months from software companies crying about the PLD and CRA because their leaders were asleep at the wheel for the last half decade.
- ihateolives 1mo ago"in your field"? All small businesses and solo enterpreneurs that I know who are hit by this are not "in this field". Their field is making jewelry or knitted toys or something similar. Now many are just not planning to ship EU wide just because it's too high risk for them.
- teiferer 1mo ago> All small businesses and solo enterpreneurs that I know who are hit by this are not "in this field". Their field is making jewelry or knitted toys or something similar. Are they shipping within EU? Then they literally are in the field of shipping within the EU.
- xboxnolifes 1mo agoThats a stretch of the term "field". Are they also in the field of making money and the field of working within European law?
- warkdarrior 1mo agoYes, of course. They need to be aware of regulations in all aspects of their business (manufacturing electronics, shipping, consumer warranty, and taxation seem applicable).
- imtringued 1mo agoYou're somehow under the mistaken idea that the primary issue for businesses is that they don't want to be aware of regulations in all aspects of their businesses. The actual issue that you're sweeping under the rug is that these regulations create a minimum floor on the size of a business. For example, a CRA self assessment including CE will require around $20k in liquid capital that you need out of pocket even if all you want to do is sell a single piece of jewelry with some electronics embedded into it. Not to mention the indirect costs such as guaranteeing 5 years of security updates. There is also the issue that PLD for cloud services effectively means that you cannot easily update your software anymore while it is under investigation by a claimant because that could constitute destruction of evidence. This leads to a catch 22 with the CRA, where you are legally obligated to patch a security vulnerability within 72 hours. The conflict here is that for physical products, the owner receives a unique reproduction of the design plans, whereas with cloud software, the customer is using shared infrastructure that can affect other customers if it is under investigation. So the entire cluster running the software turns into the equivalent of a smartphone. If you want to sell an updated product, you need to sell a new smartphone aka run a new cluster.
- MrDresden 1mo agoNo one can reasonable think that someone who makes a few hundred artisan sales a year and ships them within the bloc should be monitoring what rules and regulations are coming down the pipe.
- kvemkon 1mo ago> CRA Well, how small business can report anything during 24 hours through weekends, long weekends, 1-week Christmas, 3-4-weeks summer vacations?
- ghosty141 1mo agoThose will obviously be exempt?
- kvemkon 1mo agoIf the law wouldn't say 24 hours counting only working hours (3 working days for small business or even weeks during vacations), then it wouldn't be an exempt.
- ghosty141 1mo agoNo you misunderstood it: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions https://www.enisa.europa.eu/topics/product-security/single-r... > Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident. If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.
- kvemkon 1mo agoThis is an interesting point of view. I've been thinking that only the moment counts, when the manufacturer has been made aware, regardless when the manufacturer has in fact actively become aware. Thanks!
- ghosty141 1mo agoI have a lot of contact with the CRA at work and I actually think its a very good piece of regulation. There are barely any parts where I think they are straight up bad. I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.