Burkhard Stubert
Latest posts
Understanding the CVSS Metrics for Exploitability
Instead of fixing hundreds of CVEs, manufacturers can provide enough security measures to make the exploitation unlikely. The decrease of the CVSS metrics is a useful indicator how effective the security measures are. This post is about understanding the CVSS metrics.
Running Example for CRA: Heat Pumps in Private Homes
From now on, I'll use heat pumps in private homes as the running example for my CRA articles.
Real and Imagined Consequences of Substantial Modifications
WRONG: substantial modification => new placing on the market. Logical somersaults needed to avoid infinite support periods and full conformity assessment for all legacy products. --- RIGHT: substantial modification => update conformity assessment. No trickery needed.
No, Light-Touch or Full CRA Compliance for FOSS Components
Do suppliers of FOSS components like Qt LGPL, Weston/Wayland, Linux BSPs, containers and OTA update solutions have to perform no, light-touch or full CRA compliance? The answer affects how much due diligence machine and device manufacturers must exercise for these components in their CRA compliance.
Fundamental Definitions of the Cyber Resilience Act
The definitions for making available on the market, placing on the market, intended purpose and substantial modification are crucial for understanding the CRA. The CRA, Blue Guide and Commission guidance interpret them differently. I am trying to sort out this mess.
Using Wardley Maps to Get Big Architecture Decisions Right
Big architecture decisions have big business impact. Wardley maps help us identify money pits in product development. They show us the way how to save money by commoditising hardware and software that is not part of our core business.
Qt Sql under LGPL Despite MariaDB under GPL
The Yocto recipe gives GPL as the license of MariaDB. The Qt Sql library implements its MySQL driver with MariaDB. Hence, it would be under GPL - and so would be all applications linking Qt Sql. Businesses would have to open-source their code. A disaster! So, what's wrong?
Legal Disclaimers as CRA Mitigations
A device violates essential CRA requirements. Although simple state-of-the-art security measures are available, the manufacturer mitigates the violations with legal disclaimers. This goes against the intention of the CRA: improving cybersecurity in real life and not just on paper.