The products covered by the obligation to repair currently include:

  • washing machines and washer-dryers
  • dishwashers
  • refrigerators
  • electronic displays
  • welding equipment
  • servers and data storage products
  • mobile phones, cordless phones and tablets
  • tumble dryers
  • e-bikes and e-scooters batteries (from 18 February 2027)
  • local space heaters
  • GoatSynagogue@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    18 hours ago

    The root of trust can never be on the owner of the device for anything that requires actual security.

    • cmhe@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      15 hours ago

      I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.

      Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren’t.

      Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.

      • GoatSynagogue@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        13 hours ago

        If the only person that can verify the safety of your device is the owner, that device will and should be marked as insecure and not to be trusted in any instance where security matters.

        • Jajcus@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 hours ago

          Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.

        • cmhe@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          12 hours ago

          You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn’t do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn’t matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.