The products covered by the obligation to repair currently include:

  • washing machines and washer-dryers
  • dishwashers
  • refrigerators
  • electronic displays
  • welding equipment
  • servers and data storage products
  • mobile phones, cordless phones and tablets
  • tumble dryers
  • e-bikes and e-scooters batteries (from 18 February 2027)
  • local space heaters
  • cmhe@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    2 天前

    Also software… I would love to have regulations that make it clear that the root of trust on all devices need to start by the owner of the device, not by the vendor… That would allow the end users to repair the software on their devices… Replacing it with whatever else they want. Next would be to provide hardware documentation to the owners to program their own devices… I don’t expect that to happen, but I can dream.

    • GoatSynagogue@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      1 天前

      The root of trust can never be on the owner of the device for anything that requires actual security.

      • cmhe@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        1 天前

        I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.

        Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren’t.

        Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.

        It is not okay for companies or government to hold the data of individuals hostage… That is not security, that is a business strategy.

        • GoatSynagogue@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          1 天前

          If the only person that can verify the safety of your device is the owner, that device will and should be marked as insecure and not to be trusted in any instance where security matters.

          • Jajcus@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            22 小时前

            Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.

            • GoatSynagogue@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              1 小时前

              I’m talking about every service that you use your device for. They will not and should not trust some random phone owner that their device is secure and safe to let use their services. They will, however, trust Google saying that the device is secure and not tampered with - as they should.

              • Jajcus@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                1 小时前

                Secure services should always have limited trust to user data and devices. Security built on ‘Google says the device is secure’ is broken. Yes, it is convenient fir service providers who do not care about their customer rights, but more for ‘intellectual property’ and liability.

                Lots of apllications still work in web browsers without TPM-based, kernel level DRMs and many of them are still reasonably secure. They are built with the assumption user controls their device. This has always been possible and still is possible. Just inconvenient for corporations.

                • GoatSynagogue@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 小时前

                  Websites and web applications don’t trust the user though, or at least they shouldn’t. They should all be doing server side verification and checking of anything the user inputs. This is why some banks will let you use their website on an old phone but not their app.

          • cmhe@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            1 天前

            You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn’t do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn’t matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.

            • GoatSynagogue@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              7 小时前

              The reason is obvious, which is why I didn’t think I had to say it lol

              Imagine if you went to work at a bank in IT for example. They issue you a laptop. You go “oh no it’s ok I’ll use my own, I assure you it’s secure and safe”.

              You connect to their network and instantly their network is compromised, every device on the whole network gets a cryptolocker virus.

              You said it was secure though, so how did this happen?

              You can trust it all you want, but other systems absolutely do not have to, and anything that requires security assurances will not and should not trust it. The device owners word/assurance means nothing.

              • cmhe@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                5 小时前

                Imagine if you went to work at a bank in IT for example. They issue you a laptop.

                Who is the owner of that device? The Bank.

                Who is the owner of that network? The Bank.

                So they are the arbiter of trust in that area. They are free to exclude non-bank-owned devices.

                I work in IT, and I’m fine with getting a company laptop for company work. I don’t trust that laptop. I isolate it when I work at home. But the company trusts it, and that is fine.

                • GoatSynagogue@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 小时前

                  Yes, and you seem to have missed the point.

                  They won’t trust your device no matter how secure you say it is. That’s my point. Just because you say a device is secure doesn’t mean it’s secure, and it doesn’t mean it gets treated as if it’s secure.

                  • cmhe@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    3 分钟前

                    You seem to be missing my point. You are arguing against a point I did not make.

                    I’m not the owner of that laptop, I would just be a user. So with my argument I wouldn’t have a right install my own keys on it. I don’t need to trust that device. It isn’t mine. It is the one of my employer in that case the bank.

                    So I never said that the bank should trust my personal laptop with their data.

                    However, if I am a customer of that bank, and they give me access to my account data from my private laptop or smartphone. Then they have no right to enforce someone else to put their root of trust on my device. I need to be able to trust my device to protect my data, so the root of trust needs to come from me. If I don’t want to manage my device or if I don’t trust myself to do so, I should be able to transfer my trust temporarily to some other third party, and pay them to do it for me.