If you are a #FreeSoftware manufacturer, project, or a potential steward under the Cyber Resilience Act #CRA , please contribute by filling out those surveys (best already by end of July):
Potential Free Software stewards (EN)
https://dialog-cybersicherheit.limesurvey.net/146965?lang=en
Free Software projects (EN)
https://dialog-cybersicherheit.limesurvey.net/241948?lang=en
Manufacturer (EN)
https://dialog-cybersicherheit.limesurvey.net/582853?lang=en
Currently hearing from @davidawheeler of the @openssf about the recently-published "Cyber Resilience Act (CRA) Brief Guide for Open Source Software (OSS) Developers" https://best.openssf.org/CRA-Brief-Guide-for-OSS-Developers On the OpenSSF's "CRA Tech Bi-Weekly" call. I'm so glad my contribution ("Don't Panic!") made it in.
Anyone can join these calls, by the way if you want to learn more about the CRA and how it might apply to your work. Visit https://github.com/ossf/wg-globalcyberpolicy#meeting-times to find out more about how to get involved.
Want to influence the rules for vulnerability handling for every internet-connected product sold in the EU? Of course you do!
You are invited to the vulnerability handling deep dive session for the Cyber Resilience Act. July 22, online, free registration:
https://www.stan4cra.eu/event-details/deep-dive-session-vulnerability-handling
More info: https://www.stan4cra.eu/resources
Lower House of Parliament, Madrid, 09 October 2024. The President of the Government of Spain has vindicated the executive"s "humanitarian and responsible" migration policy, announcing measures to improve migrant integration and to promote their contribution to the demographic challenge.
Some professional news:
1. I’m now a Special Rapporteur for the Cyber Resilience Act.
2. My company is hiring EU subcontractors with network and security expertise!
Bow Shock Systems won a contract with ETSI to lead development of "vertical" cybersecurity standards for specific products. I'm leading the one for operating systems.
We're looking for people with technical expertise and leadership ability to lead three other verticals.
1/n
👋 Hey infosec.exchange! We’re the CHERI Alliance — excited to join the community!
🔐 We’re all about CHERI (Capability Hardware Enhanced RISC Instructions) — a powerful hardware-based approach to making memory safety and software security actually enforceable, by design.
💡 CHERI helps stop things like buffer overflows and use-after-free bugs before they cause trouble — with hardware-enforced protections built right into the architecture.
We’re here to:
- Share news about the CHERI community in general
- Talk about what our members are building with CHERI
- Connect with folks who care about deep, meaningful security improvements
Check us out 👉 cherialliance.org
Give us a follow if this sounds like your kind of thing!
#CHERI #MemorySafety #SecureByDesign #InfoSec #CyberSecurity #HardwareSecurity