He now has a fancier PC, courtesy of LTT.

- 0 Posts
- 879 Comments
Might be nice if you’re used to it
Damage@feddit.itto
linuxmemes@lemmy.world•taught my machines to talk and this is how they repay me
1·3 days agoI have a raidz5 array of 8tb drives, one died, replaced it with no issues
Is it about copyright?
Damage@feddit.itto
Technology@lemmy.world•Viral De-Flock America campaign urging people to destroy AI cameras on Halloween night gains momentumEnglish
173·16 days agoAmericans rediscover the origins Carnival and Saturnalia.
It jumps up quickly to a bigger size and then keeps increasing more slowly if you keep shaking it.
Damage@feddit.itto
Europe@feddit.org•EU pushes back as US revives trade pressure on blocEnglish
8·20 days agoIt’s also better to decouple as much as possible before their trillions invested into AI go poof, I don’t want a repeat of 2008.
I’ve installed it on both my desktop and laptop, and I’m rather satisfied
Damage@feddit.itto
Europe@feddit.org•So, Europeans, share that one earworm song in your local language that is currently stuck in your mindEnglish
5·21 days ago13 buone ragioni by Zucchero
Damage@feddit.itto
Ask Lemmy@lemmy.world•What is the creepiest/spookiest/most unsettling thing you have experienced in your life?
17·21 days agoSo when I was a teenager I used to have a desktop computer in my bedroom, with desk, chair and all, the bed was against the far wall from the door, with the desk in between. One night I woke to a dark figure bending down over me while I slept, and my instinct was to punch it! And I kinda hurt myself by hitting the metal frame of my computer chair which I had somehow rolled next to the bed without noticing, with a black hoodie draped over it.
Damage@feddit.itto
Technology@lemmy.world•Firefox is now the last major browser that still supports uBlock OriginEnglish
161·21 days agoDon’t feed the troll, down vote and move on
Yeah that was my thought too, but it turns out it was a misconception. It’s perfectly customisable, I can install whatever I want in multiple ways without messing up my system. Right now I’m running IDEs with multiple compilers, LLMs, diffusion models, 3D printing slicers, 3D modeling, etc…
I stayed on it for many years, but Bazzite stole my heart
What comes default on fedora KDE spin
Damage@feddit.itto
Programmer Humor@programming.dev•Everyone's asking, 'Who's Json?', but nobody's asking, 'How's Json?'
131·24 days agoEw JavaScript
Damage@feddit.itto
linuxmemes@lemmy.world•In a universe of enshitification, Linux is one of the few things that consistently gets better.
20·24 days agoThe thing with Linux is that it’s 100% freedom. It lets you do whatever you want with it, there’s plenty of tools that facilitate customization and management.
By contrast, when I use windows at work I often find it won’t allow me to do what I want.
“What do you mean that’s not possible?”
Paywall, here are the contents
Cyber Resilience Act: EU Commission provides more clarity for open source
Source: heise online
Author: vbr
Before the first reporting obligations of the Cyber Resilience Act (CRA) take effect, the EU Commission is providing manufacturers, developers, and companies with a guide. The guide, published on Monday, explains in about 80 pages how the cybersecurity regulation is to be interpreted. This ranges from defining affected products and essential software updates to rules for open source. The CRA itself has been in force since December 2024 and stipulates uniform minimum requirements for the cybersecurity of digital products across the EU throughout their entire lifecycle.
According to the Commission, the handbook answers key questions from the industry. It is intended to help those affected to implement the requirements legally. The guide explains, for example, which products fall under the CRA, how crucial program revisions are to be classified, and by what standards support periods are to be determined.
In addition, it provides information on how risk analyses and reporting obligations can be practically fulfilled. The EU Commission places particular emphasis on startups and small and medium-sized enterprises. Numerous practical examples and application scenarios are intended to clarify ambiguities and avoid unnecessary administrative effort.
Open source should not be slowed down
The Commission devotes considerable space to free and open-source software. During the negotiations on the CRA, developers and open-source foundations warned that voluntary projects could be discouraged by new liability and documentation requirements.
The Commission is trying to allay these fears. Freely available open-source software generally does not fall under the CRA as long as it is not brought to market as part of a commercial activity. It now explains when such an activity exists. Anyone who sells open-source software, offers paid enterprise versions, or monetizes other services through a program is considered a manufacturer in the sense of the CRA.
The situation is similar if users are required to provide personal data for purposes other than security or interoperability, or if donations are effectively a prerequisite for accessing the software or essential updates. Conversely, voluntary contributions, public funding, or sponsorship funds alone do not constitute commercial activity. Paid consulting, training, or support services also do not automatically mean that an open-source project falls under the CRA – as long as the software itself remains freely available.
What exactly are open-source stewards?
Further clarification will likely be important for many developers. The Commission explicitly distinguishes between project managers and suppliers. Those who merely fix bugs or submit new features generally bear no responsibility under the CRA. The situation is different for individuals or organizations that publish a project and exercise control over releases, roadmaps, and steering. Merely having write access to the source code repository is not sufficient for this.
The role of “stewards” also becomes clearer. This can include foundations or other organizations that provide permanent organizational or technical support for open-source projects without marketing them themselves. Their obligations depend on the intensity of their involvement: Those who only handle community work have significantly fewer obligations than organizations that operate infrastructure or actively participate in development and security management. Depending on the type of support, reporting obligations for security incidents or exploited vulnerabilities may also apply to stewards.
Furthermore, the Commission explains when a change to a product is considered “essential”. Updates that exclusively fix vulnerabilities or maintain or improve the existing security level generally do not trigger a new conformity assessment procedure. The situation may be different if new features alter a product’s risk profile or create additional attack surfaces. The guide also provides clarity on repairs: If only identical replacement parts are supplied, this is not considered a re-release of the product.
The clock is ticking
The guide also specifies requirements, for example for risk analyses and future reporting obligations. Although the guide is not legally binding, it is likely to be decisive for manufacturers and national market surveillance authorities on how the regulation will be interpreted in practice. The German government has designated the Federal Office for Information Security (BSI) for this purpose.
EU Commission Vice-President Henna Virkkunen described the handbook as part of Brussels’ relief agenda. It is intended to help companies implement their new obligations on time and legally. A secure Europe and a business-friendly Europe go hand in hand. In the Commission’s view, the CRA is gaining importance due to the advances in powerful AI models with cyber capabilities. The first reporting obligations will take effect on September 11, 2026. Manufacturers must fully comply with the regulation from December 11, 2027.
This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.