| ▲ | BadBadJellyBean a day ago |
| I'm not familiar with the Act. Can you explain how it would kill theses startups? |
|
| ▲ | lnsru a day ago | parent | next [-] |
| So basically you need 3 persons writing compliance documentation and taking care of cybersecurity. Basically another 200000€ personal cost year in low cost area. 250000€ or more in bigger cities. You have a microprocessor in your product and it’s done deal. No big deal for corporations though. Buddy’s workplace hired new compliance department for this topic with 30 persons. That’s competition european way. |
| |
| ▲ | BadBadJellyBean a day ago | parent | next [-] | | I'd rather have that than insecure hardware. It seems like it forces security to be a first class priority instead of an afterthought. | | |
| ▲ | lnsru a day ago | parent | next [-] | | The thing is not that the product will be somehow secure. It will have properly filled compliance papers. That’s the same story with functional safety. For example car electronic components break all the time, but they have well done paperwork. | | |
| ▲ | flohofwoe a day ago | parent | next [-] | | > It will have properly filled compliance papers Sounds like a perfect job for AI tbh ;) | |
| ▲ | BadBadJellyBean a day ago | parent | prev [-] | | > The thing is not that the product will be somehow secure. I don't believe that is true. Cars do break but they have to meet safety standards. That doesn't make them perfect but it's much better than not having them. You can't make perfect safety standards in an ever changing world but you can define minimum standards. I understand that documentation is a pain in the butt, but it's necessary to have some oversight. It's part of the enforcement. Everyone has to do it so we know the documentation should exist. That means we can fine companies that don't do it. If you mad the documentation and lied on it and it comes out you will probably fined even more. It's a deterrent and a way to enforce the rules. |
| |
| ▲ | WarmWash a day ago | parent | prev | next [-] | | What you are also saying in the same sentence is "I would rather only buy from megacorporations than small players" | |
| ▲ | logicchains a day ago | parent | prev [-] | | It forces Europeans wanting to build hardware startups to go overseas, so there's even fewer new European hardware companies and Europe becomes even more dependent on the US and China. | | |
| ▲ | BadBadJellyBean a day ago | parent [-] | | Just like everyone left when the GDPR went into place? Having safety standards in place (and yes that also means documenting them) can even be a selling point. To have demonstrably secure hardware according to a standard can be highly desirable. I think losing the companies that don't have security as a main priority isn't too bad. I assume that the EU will create import restrictions if there is a meaningful shift to avoid EU rules. |
|
| |
| ▲ | inigyou a day ago | parent | prev [-] | | You know that when a regulation mandates a role like this, it isn't the person's entire job, right? When GDPR says you need a data protection officer, it doesn't mean you need to hire someone to be your data protection officer. In a very small startup, it could mean the CEO is also the data protection officer. | | |
| ▲ | Muromec 20 hours ago | parent [-] | | You don't need a whole full timer for that either. When we had to deal with the usual iso stuff it was one guy hired through the agency working on Thursdays |
|
|
|
| ▲ | GJim a day ago | parent | prev [-] |
| It kills those hardware startups that attempt to make money by selling us insecure crap? See also, the GDPR killing startups that attempt to invade our privacy and exploit personal data without permission. |
| |
| ▲ | logicchains a day ago | parent [-] | | And then there are no European hardware startups and your own options for hardware are Chinese and American, both with backdoors. | | |
| ▲ | edb_123 a day ago | parent | next [-] | | From what I gather, the cyber resilience act applies to all products placed on the EU market, regardless of whether the manufacturer is based inside or outside of the EU. So European hardware vendors will be competing on the same terms as American and Chinese ones when it comes to the CRA. | |
| ▲ | GJim a day ago | parent | prev [-] | | Interesting that US Americans think letting their companies do whatever they want everywhere (as they currently do) is the better "strategy". | | |
| ▲ | dathinab a day ago | parent [-] | | it sometimes feels (some part of) US citizens are so used to companies systematically abusing them that they think it's normal and some other part seem to have "I have suffered so you must suffer too" mentality and in generally there seem to be an increasing lack of basic human empathy ... which is very worrisome | | |
| ▲ | GJim a day ago | parent [-] | | A significant percentage of HN readership are those working in US Adtech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing privacy laws (for software and hardware). |
|
|
|
|