About this talk
This talk focuses on the Cyber Resilience Act (CRA) and its implications for market surveillance authorities across Europe. The speaker, Daniel, shares insights from his work at Crowd Nebula, where he is authoring harmonized European standards for the CRA. He emphasizes that the CRA aims to establish conformity assessments for products and ensure compliance across all EU nations by 2027. However, there are challenges regarding the readiness of market surveillance authorities, the enforcement of regulations, and the availability of qualified conformity assessment bodies (CABs). Daniel also introduces a tool he developed, called Achilles, which assists untrained personnel in identifying vulnerabilities in software products. He concludes by stressing the importance of market surveillance for the success of the CRA, highlighting that without adequate staffing and processes, product assessments may fall short of expectations.
Full transcript
[music] >> Great. Um, hey everybody. Um, going to ask for a show of hands. How many people out here work for a government? That's exactly the problem. Um, so today I'm going to talk a little bit about the uh, the Cyber Resilience Act and how it impacts our uh, public officials around Europe. Uh, again, uh, I'm Daniel. I created the Tory framework. Working at Crowd Nebula. Uh,
currently authoring two uh, harmonized European standards for the CRA. And I've been doing this for a very long time. Uh, that QR code's my LinkedIn, but we all know each other already anyway. So, just going to get started. Um, market surveillance authorities in Europe have a very important task and that is to assess the viability of products on the market and their conformity with the expectations of
the regulation. So, we just had a talk uh, about these uh, software bill of materials, the S-bombs. So, you're all so much familiar with the Cyber Resilience Act. Has anybody read it here? I know you have. >> [laughter] >> Yeah, thank you. Um, so, what what we know is in 2024, it uh, entered force uh, in September this year. It will be in partial application. Uh, that's
the whole reporting uh, issue that we just heard about. And then in December of 2027, it will be in full application. And at that point, all have to uh, conform. I mean, there's nuances here, but basically, what does conformity mean? Well, it sort of means different things the further north you go in Europe. So, we've heard that in Finland, for example, even open source is getting uh,
more attention than it deserves. Uh in fact, you might be fined for doing open source improperly. Uh in Sweden, it's similar. The Germans BSI is crazy. They're They're They're going to be the ones really moving the the needle forward. And the further south you go in Europe, the more relaxed people are about compliance. It's maybe a Mediterranean thing, I don't know, but at any rate, the Cyber
Resilience Act is a piece of harmonizing legislation that expects every European country every sovereign nation, all 27 of them, have to have a market surveillance authority. Now, the most important date for having a market surveillance authority is obviously going to be in June. Because in June this year, June 11th, the market surveillance authorities will be the entities notifying conformity assessment bodies. what the notification process means is,
you have a conformity assessment body that does assessments uh that proves the compliance of a product um according to these various modules you might have heard of A, B, C, and H. And so, when a CAB is notified, it's gone through an entire process. And normally speaking, a CAB can't be Well, a CAB is notified for a piece of legislation and a product type. The problem is
we don't have harmonized standards yet. We won't get them until December, but by December, all of the CABs are supposed to be notified, which kind of puts us in this this weird position of we don't have the government entities ready yet across Europe. The CABs are kind of following along the best they can with the harmonized standards. And then, you know, the the reality of this is
yesterday, there was a meeting from the commission talking about uh you want to be a cab? Okay, let's go. There's about 100 entities interested in becoming cabs. the median number that they all agreed to is 15 assessments. I'm not a good mathematician, but that doesn't seem like it's going to fulfill the expectation of 10% of the entire product market needing conformity assessment in Europe. It seems like
it's a little shy. the the fantasy of the Cyber Resilience Act and the reality of how things are make some conclusions almost apparent. We're not ready. And the governments are behind. Like let's just imagine it's it's April. And in June, oh gosh, it's almost May. That's reality again. In June, you have to have the entity set up that is ready to notify your conformity assessment bodies in
your country. Okay, let's assume you get that done, but then in September you're already going to have to start assessing products for their conformity. Uh, based on this whole um uh, problem area of needing to report actively exploited vulnerabilities. So, we're behind. The people that are going to be hired need to be hired. Need to be trained. Time is really running out. So, Article 35 is very
specific about what uh, a market surveillance authority is um, and that that's where it starts to get complicated, right? Because if you have a product that's supposed to be uh, surveilled by one entity in a country, what if that product is also composed of um, AI or telecommunications? So, the the the the challenge is that now you have multiple authorities within a country that are going to
be conflicting potentially. So, who's responsible? >> [sighs and gasps] >> That takes time to figure out who's responsible. There's not even any real shared infrastructure between them. uh you know, like like I've been saying, the first obligations start in September. So, that's uh May, June, July, August. So, like four or five months away. I don't work for the regulator. I'm not a government employee, but I do
work in open source, and I feel that like we can provide a system, a way for the governments to get their act together. So, I mean, if just numbers again, like I said, I'm not a huge mathematician, but if there's thousands and thousands and hundreds of thousands of products on the market, I mean, just think about every app on the App Store. Like the Apple Store, the
Google Play Store, all all of these stores have millions of products that all have to be compliant. How do you as a market surveillance authority even keep up? you're understaffed, you're underpaid, you probably want to go work for a private cybersecurity firm. all of this stuff is also specialist knowledge. I don't know like how how much uh exposure you have to the local uh market surveillance authorities
in your country, but you can't just start a conversation about S-bombs with anybody in the office. And so, we're faced with um a a very important part of the Cyber Resilience Act, which isn't small businesses. It's not the products themselves. It's how we can support the the the governments in their their duty, their task of protecting us from bad products. Right? Like if we take the the
the maximalist approach of understanding what the commission was actually trying to do with these laws, it's trying to protect people, right? So, that collaborated in the expert group uh for the Cyber Resilience Act created a number of product verticals that are what we call important and critical. And in order for you as a manufacturer to get your product on the market when it's important or critical, you
have to use conformity assessment body. There's not going to be enough in Europe. We don't know how that's going to work outside of Europe. It might be possible for you to use a a local conformity assessment body in your country to get your product that's outside of Europe certified to work in But, we don't know exactly how any of this is going to shake out. And basically,
what this means is products are going to be stalling. There's not enough CABs, and the the the general expertise that we need in order to assess these products is is very small. Like I said, not everybody, even in this room, understands the scope of a software bill of materials. Right? We we we were we were just talking about that, and I think that, problem gets worse. in
Annex 1 part 1.2 parentheses A, products with digital elements are not allowed to be placed on the single if they have known vulnerabilities. You may not place them there. If you know that there's a vulnerability in your product, you cannot put it on the market until that product's vulnerability is fixed. Um I There's a whole bunch of evidence here about, you know, it's the duty of the
manufacturer to do this. For example, today I installed Teams, and Teams downloaded, and the first thing it did was it checked for an update. Good practice, right? Making sure that you're all you're up to date. The S-bomb can sort of help you, but it can also be a problem. Um because, like I said, getting the uh software bill of materials to someone's desk who can read it
is a challenge. I think uh in in Malta, where I work, there's a half dozen people at the Malta Digital Innovation Authority who's probably going to be the one responsible who are able to read the S-bomb, but even then, the S-bomb itself, unless you enrich it, doesn't tell you that much. Right? Yeah, okay, there's all these uh third-party components, but which one is the vulnerable one? You
have to coordinate your your knowledge somehow. I built a toy. I'm going to give you a demo today. It's called Achilles. And this is uh and I'd love your feedback on it because the idea is this is for an untrained professional working in a market who has the task of looking at the market and discovering if there are things that shouldn't be on the market. Things that
shouldn't be placed on the market because they have inherent Um so, the idea is, like I said, you don't need a specialist uh It uses the EUVDB, uh which is the the database that ENISA has been putting Um there's other ones available as well, like uh the GHSA from GitHub. Um it produces evidence that you can use and then hand off to others. And it's a it's
a non-commercial license, so it's uh totally available to the government to use. Like I said, we have GHSA. It's It's It's optional. I didn't turn it on by default because you have to use a stupid personal access token. But we do have the NVD, we do have the OSV, and the EUVD as these various sources to a non-technical specialist doesn't matter as long as the person who
does know says, "Yeah, okay, this looks right. This is This is what we want it to do." So, change over to other screen. Great. This is This is Achilles. Um scanning. I don't know if you can really even It's very small, isn't it? I'm sorry about that. Um but basically, what we have are a number of apps that are installed on my device in the applications folder.
And let's see, which one was I Okay, let's look at Discord. All right, I'll give you a good a good example. So, so Chromium Google Chrome is It looks pretty safe because it's a very late version. Like it's from I think yesterday or the day before. So, there's no known vulnerabilities. We're safe. We were We've have a product that's been delivered to us in a safe state.
However, if we go look at uh at Discord, um we are way behind. We are behind on Node.js, we're behind on Electron, and on Chromium. So, like I just updated Discord. Discord is delivered to me in a known vulnerable state. So, I'm just scrolling scrolling scrolling scrolling forever for vulnerabilities that are fixed everywhere, right? Like it it can't do this for every type of software out there.
Uh and again, like I said, this is just kind of a toy to explore the idea of showing uh you know, what we can um what we can accomplish. And there's enough information here that this would get flagged. So, Discord would now be flagged by whichever market surveillance authority feels they want to take it on, and until they update their electron and their chromium and their node.js,
they can't be on the European market. I I'm I'm just explaining how this has to work. I don't know if it's going to be this tool that I've built here, but they're deploying a vulnerable product to the market. And I mean, it's electron, so we kind of know that already. We're just ignoring it. Um Is there a good electron signal? Signal's been on electron since version two.
There's no advisories from CVEs. Sandbox isn't safe. Oh, there are a few. So, there's there's a an HTTP transport vulnerability in node.js, the version of node.js that Signal is using. Sorry, Mac. I'm I'm not I'm not here to try to to pick on electron. Because if you look at Safari, there's also a number of vulnerabilities that have not been treated in the latest version of Safari, even
though I just updated this Mac over the weekend. So, I'm about as up-to-date as I can be, and it's already there's already CVEs that have not been addressed in this version of Safari, which then trickles down into all of the web views that use Safari uh probably probably on iOS and on Mac. So, I don't I don't need to be an expert in cybersecurity to know that
we have vulnerabilities here. And now, what would probably happen is we would export these vulnerabilities, and we would contact the manufacturer and say, "Hey, here are a list of vulnerabilities. Please Please prove to us that your code is not vulnerable to any of these potential vulnerabilities." You have 48 hours. Or something draconian. Uh it could even be a week. But like the the the thing that I'm
trying to tell my friends who are building software is the the the fine isn't the problem. Yeah, you might get fined 3% or 10% or whatever of your global business. But not being able to be on the market if just imagine if no one in Europe could use Discord right now. The Israelis would be sad. And and and and that's the power that the market surveillance authority
really has. yes, they can line you up for a fine, but just saying no, you cannot ship to Europe. Suddenly the app stores, Apple, Google, all those app stores have to remove or at least block until they get permission to show it again. The the this is kind of the I mean anyway, I'm just trying to help my friends in market surveillance because they don't know how
to how to communicate this stuff. that was the demo. It's on GitHub. Uh it uh you know, source available like I said. And and you know, the here, I'll go back there for you. like the the the the challenge of the low-level officer working in market surveillance today is that they're being put in a position that they were not trained for to understand things that they don't
comprehend, and then they have to make actionable decisions on it that can literally impact and undermine entire businesses. So, sorry. Um Inside of the Cyber Resilience Act, there is a clause that explicitly permits market surveillance authorities go shopping. They're allowed to pull any kind of product from any kind of manufacturer at any point um the the cloak of being a a consumer. They don't have to go
to Discord and be like, "Hey, we're Europe. We want to download your app." They just download it as if they were a natural consumer. the the devices, like I said, right now this is just Mac, it's just a toy, but if if they do evolve this product, um they will then be able to just run this automated vulnerability triage. I didn't There's no AI involved in here
because we're relying on public sources of known then, if there's enough evidence that oh, this this looks like there could be problems, then they ask for more evidence. They say, "Hey, show us how this vulnerability assessment is wrong." And you have to respond as a manufacturer. And um they can also say, "Hey, Apple, what's up with Safari?" once they've compared with the S-bomb that the versions are
actually the ones that they think are being used, then they would trigger a a specialist review. So, basically, the idea is this can all happen by low-level officers who then hand off to someone who's um more uh able to assess the information. And sometimes, the specialist review might even be a conformity assessment body. Remember that problem at the beginning that we don't have enough qualified personnel to
review the actual problems? This this this does like uh trickle out to a very uh intense watershed situation. And then, enforcement. Right? Like, the worst thing you can do is not pick up the phone. Right? If they can't reach you, they will shut your product down. And And I think that especially in in light of the the horrors of the product liability directive, um there might also
be cross cross-border support. So, this What that means is that uh investigations in multiple jurisdictions that might not just be about software, might be about hardware, too. And like I said, the further north you go, the colder and harder the steel, obviously. Um what do we have to do? Like I I don't know if the MSAs are going to be watching this remotely or considering it. The
The member states have to choose somebody, some entity, or create an entity to do it. It's so important the industry is saying we need standards, but I'm telling we we need we need market surveillance. Otherwise, the whole Cyber Resilience Act doesn't work. Um then the the the feedback rounds with European Cybersecurity Competence Centre, the ECCC, the NCCs, they should be giving their feedback about what kind of
information is useful to collect at the at the low level that they can then see as as enriching. The national accreditation bodies have to have to move faster. Like I don't The The The risk is that we don't have conformity assessment bodies to the quantity we need them, and then what do we do? Excuse me. We have to everything just go through? It's like It's like we
Why Why are we even doing the exercise in the first place, right? everything in this area is going faster. Normally, writing standards is a 3-year process. That's been condensed down to 1 Uh creating a CAB is something that's about 12 to 18 months. Now, that's being shortened down to 6 months, even in the context of not having the standards to build upon. And then, like the the
the the scariest part for me is everyone who's building components. Because the component manufacturers are the ones who are upstream. They're selling their product downstream, and downstream needs to do diligence done on those components in order to have a fully certified product. The the the the timing is is is tricky, and there should be some unity around a common tooling. And and that's something for my friends
at the commission to DG Grow because um this this approach just isn't isn't going to be sustainable. >> [cough] >> So, I kind of uh went fast because I thought maybe there might be some questions uh to that the audience has. I'm happy to uh answer any that you might have. Thanks. >> [applause] >> Hi. Um thanks for the presentation. I I arrived in the middle of
it, so maybe I've missed it, but did you receive any feedback from anyone regarding this project, or did you present it to any potential MSAs or DG Grow or people like that? >> This Today was the very first presentation of it. Okay. Um and I've been in discussion with Malta uh about their decision to finally choose the MDIA. that's I think the next step, right? Yeah, I
would have been interested to know if you had any feedback or any precision on how they are planning to do because I don't know how organized member states are on this, and they're probably not at all. Uh so, I don't know which platform could be the right interlocutor for you, uh or if you are if you know to I mean, I'm going to to Stockholm tomorrow, and
I plan on uh talking to the ECCC. Uh I think that that's a a good coordination point, probably better than ENISA at the at this point in time. for reasons. All right. Well, thank you for the for the answer. All right. Great. Thanks for the talk. Thank you. >> [music]