Tobie Langel

@tobie
803 Followers
816 Following
91 Posts

That was the #CRA panel w/ @bagder @tobie @senficon

The audience questions were pretty good, I hope our answers were useful to someone.

There’s a recording here https://m.youtube.com/watch?v=DLxZdU8kzxM

Otherwise, head over to the https://orcwg.org FAQ to contribute/ask or wait for the @EUCommission to publish their guidance, which I’ll surely post about once it is published.

The Cyber Resilience Act and Open Source: What Maintainers Really Need to Know

YouTube
On May 27th at 18h CEST, I’ll participate on a (streamed) panel on the #CyberResilienceAct for maintainers of Free and Open Source Software, with @ag_dubs, @bagder and moderators @tobie and @senficon.
Info at https://maintainermonth.github.com/schedule/2025-05-27-CRA
The Cyber Resilience Act and Open Source: What Maintainers Really Need to Know

Check out this Maintainer Month event

🚨 The #CyberResilienceAct is here and it's a game-changer for all digital products entering the EU market. Join us on April 18 for an OnRamp session feat. @tobie from @EclipseFdn.
Essential insights for #OSPOs, SMEs, and tech leaders. #CRA #cybersecurity

For all details ▶️ https://mastodon.opencloud.lu/@OSPOAlliance/114273458414631147

OSPO Alliance (@[email protected])

Attached: 1 image 📣 Next #OSPO OnRamp on April 18! 🔐 Topic: The #CyberResilienceAct is here. Now what? 🎙️ @[email protected], Tech Lead ORC WG @[email protected] & Principal at UnlockOpen 📅 10:30–12:00 CEST 🌐 No reg, just join: https://bbb.opencloud.lu/rooms/flo-iof-4xr-orc/join ℹ️ https://ospo-alliance.org/onramp and https://forum.ospo-alliance.org/t/onramp-session-on-april-18th-about-the-cyber-resilience-act/155 #CyberSecurity #OpenSource #CyberResilienceAct

OpenCloud Luxembourg Mastodon instance

Together with other representatives from #FOSS communities, like the Apache Software Foundation, @EclipseFdn (@tobie) @openssf (@fukami) and others, our goal is to help the Commission create meaningful guidance for FOSS contributors and maintainers. We particularly want to be involved in how the implementation of the regulation affects open source technologies and critical digital infrastructure. 2/2

@LarsFrancke

If you're not a #FOSDEM (like me!) and have questions or concerns about the EU Cyber Resilience Act (CRA), then this repository is the place to be:

https://github.com/orcwg/cra-hub

Review the current FAQ, and ask questions if your question is not already asked in the issue tracker. Thanks @tobie for creating this helpful space.

GitHub - orcwg/cra-hub: Everything you ever wanted to know about the CRA and its implementation

Everything you ever wanted to know about the CRA and its implementation - orcwg/cra-hub

GitHub
Looking forward, at the conundrum of the next years’ CRA implementation process, open technology strategy advisor @tobie spoke about the problem on the horizon: “There is a fundamental mismatch between how open source is created and implemented, and the way today’s European standardization organizations are built up.” #EUPolicy 🧵 10/10

🎙 Join us for the first #OSPO OnRamp session of the year. @tobie from UnlockOpen will kick off 2024 with some difficult but necessary introspection on #OSPO alignment with organisational mission, goals, and strategy.

📅 Jan 19th
⏰ 10:30 - 12:00 CET
📷 https://ospo-alliance.org/onramp/

#Open to all/safe environment/no registration

cc @gvlx @publiccode @OpenForumEurope @EclipseFdn @mmilinkov @gblondelle @paolo @silona @yakaceme @yakaceme @fdesbiens @waynebeaton @ainali @webmink @bzg @Ammienoot @paulbuck

OSPO OnRamp

Home of the OSPO Alliance.

🚀 Exploring the 'Commons' in the digital economy. I discuss the French government's endorsement of a proprietary messaging platform, highlighting a deep misunderstanding of key digital dynamics.

As an expert in instant messaging, I offer insights into why this matters.

Join the conversation on this crucial topic.
#InstantMessaging #OpenSource #XMPP

https://www.process-one.net/blog/instant-messaging-protocols-are-commons-lets-take-them-seriously/

Instant Messaging: Protocols are “Commons”, Let’s Take Them Seriously / ProcessOne

TLDR; Thirty years after the advent of the first instant messaging services, we still haven't reached the stage where instant messaging platforms can freely communicate with each other, as is the case with email. In 1999, the Jabber/XMPP protocol was created and standardized for this purpose by the Internet Engineering Task Force (IETF). Since then,

ProcessOne
In this talk at #fossback 2022, @tobie dug into what W3C’s priority of constituencies is, and discussed how we could apply the priority of constituencies to #opensource and what that reveals about the complexity of the open source ecosystem. https://m.youtube.com/watch?v=6YTcILOAEZY&feature=youtu.be
#FOSSBack: Tobie Langel – Does open source need its own Priority of Constituencies?

YouTube

#SecureWebForward ~1.5 billion websites deployed on the web today. Of these, ~1 billion run #jQuery! Of these, ~500 millions run an "outdated and unpatched version" of jQuery. @tobie has been looking at securing jQuery, focusing on #security holes that jQuery opens in the web #browser sandbox that don't exist without it.
▶️ https://www.w3.org/2023/03/secure-the-web-forward/agenda.html#session-3 (with slides and transcript)

🎬 https://youtu.be/efOljAYQz2I

Live sessions

Bringing together experts to drive developer awareness and adoption of Web security standards and practices