Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Daniel Ehrenberg

@littledan@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

This is now a Cyber Resilience Act stan account
(((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

943 Followers
582 Following
19 Posts
Joined November 23, 2022
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

At ETSI, we're developing a new European standard about web browser security to support the Cyber Resilience Act. Come read the draft at https://labs.etsi.org/rep/stan4cra/en-304-617/-/blob/main_publish/EN-304-617.md

Be the first to file an issue! No one from outside ETSI administration has done so yet, so this is a prize you can claim. https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues/new

In addition to development in GitLab, we have regular calls. The next one is tomorrow, Feb 3rd at 3 PM (CET). If you want to join this or a future call, please DM me and we can discuss how that works.

labs.etsi.org

EN-304-617.md · main_publish · STAN4CRA / EN 304 617 Browser · GitLab

10
4
8
1
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

I spoke at FOSDEM about the new European web browser security standard, under development in ETSI, as part of the Cyber Resilience Act. Video here: https://mirror.as35701.net/video.fosdem.org/2026/h1309/YMQ3J3-the_cyber_resilience_act_and_web_browsers.mp4

This standard is still in development, at https://labs.etsi.org/rep/stan4cra/en-304-617 , with weekly meetings freely accessible to open source developers, as well as ETSI members. Please get in touch with me if you want to be involved.

mirror.as35701.net
8
0
2
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

At the FOSDEM browser track, I will be giving a talk:

The Cyber Resilience Act and web browsers

The Cyber Resilience Act defines web browsers as an important product requiring special attention to cybersecurity requirements. What does this mean? How can you participate in defining in what it means for a web browser to be secure?

https://fosdem.org/2026/schedule/event/YMQ3J3-the_cyber_resilience_act_and_web_browsers/

I’m really honored by this invitation from @sylvestre@framapiaf.org for my first FOSDEM.

fosdem.org
5
2
5
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

The Cyber Resilience Act mandates that commercial software handle vulnerabilities well. What does that mean exactly? The CRA names sound principles in Annex I Part II, but applying them in practice is another thing. For this reason, there's an ongoing standardization effort translate these principles into more clear requirements to meet, to make it easier to demonstrate compliance.

The draft standard now entering a public review phase, so *we need your opinions, thoughts and analysis to improve it*. This article explains where things are, and how to get involved.

https://www.agoria.be/en/services/expertise/technical-regulations-standardisation/standardisation/public-enquiry-concerning-the-new-draft-standard-pren-40000-1-3-vulnerability-handling-in-support-of-the-cyber-resilience-act

agoria.be
4
0
6
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 6mo ago

For April Fools, I told the ETSI CYBER EUSR rapporteur group on web browsers that the European Commission was giving us until April 15th to submit our final draft. Got them good! Well, some requests for clarification but actually no laughs… (Real timeline: edit through May, then more review stages)

2
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 9mo ago
Replying to
This work is co-funded by the EC and EFTA [1] You can find the current draft in https://docbox.etsi.org/CYBER/CYBER/Open/ . Look for “browser” within that directory. [2] File issues in https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues/new?description_template=Vertical%20Standard%20Comment . Anyone can sign up for an account and post issues. Please apply the template carefully to give the committee all it needs to address on your comment. [3] The Zagreb event: https://cyberstand.eu/events/cra-standards-unlocked-eu-tour-zagreb Keep an eye out for further events at https://cyberstand.eu/events [4] https://fosdem.org/2026/schedule/track/cra-in-practice/ January 31st from 15:00-19:00 in room UA2.114 (Baudoux) [5] https://cyberstand.eu/10th-specific-service-procedure-sme-perspective . Note that the current SSP (more commonly known as CFP) focuses on the perspective of Small and Medium Enterprises. Future SSPs may have different focuses too. But please apply even if you’re not sure if you are qualified! My contact information: https://littledan.dev Thank you for everyone’s support while I focused on my health over the past 9 months.
docbox.etsi.org

Directory Listing /CYBER/CYBER/Open/

3
0
1
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago
Replying to
@letoams@defcon.social My standardization request is scoped to the CRA. That’s out of scope for me!
1
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago
Replying to
@Edent@mastodon.social good question, keep them coming! IMO web would make sense.
1
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

RESCHEDULED: Please join Daniel Thompson-Yvetot and me on Tuesday the 27th, at 1 PM Central European Time for an interactive deep dive into the draft standard for BROWSERS under the Cyber Resilience Act (CRA). https://www.stan4cra.eu/event-details/cra-standards-unlocked-deep-dive-session-on-browsers-2

CRA Standards Unlocked: Deep Dive Session on Browsers | Stan4cr
Stan4cr

CRA Standards Unlocked: Deep Dive Session on Browsers | Stan4cr

As work on the Vertical Standards for the EU’s Cyber Resilience Act (CRA) moves forward, ETSI warmly invites you to join an exclusive deep dive into the ongoing development of the European harmonized standard for Browsers.

1
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

RE: @littledan@hachyderm.io

Rescheduled for Tuesday, the 27th at 1 PM. Hope to see you there!

hachyderm.io

Daniel Ehrenberg: "EDIT: This event is postponed. I'll post here aga…" - Hachyderm.io

1
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

RE: @littledan@hachyderm.io

This event is postponed. I'll post here again when it is rescheduled.

hachyderm.io

Daniel Ehrenberg: "EDIT: This event is postponed. I'll post here aga…" - Hachyderm.io

1
0
1
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago

If you were dictator of Europe, what would you require all software developers to do properly?

1
4
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago
Replying to
(8) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
0
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago
Replying to
Find the current draft in https://docbox.etsi.org/CYBER/CYBER/Open/ File any issues in https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues
docbox.etsi.org

Directory Listing /CYBER/CYBER/Open/

0
2
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 8mo ago
Replying to
Our work on the CRA browser standard is funded by the European Commission and EFTA.
0
0
0
0
Open post
Daniel Ehrenberg @littledan@hachyderm.io
· 6mo ago

Ve a aquest esdeveniment gratis aquest dijous a CTTC a Castelldefels per a sentir-me xerrar del Cyber Resilience Act i els navegadors web.

Ven a este evento gratis este jueves en CTTC en Castefa para escucharme charlar del Cyber Resilience Act y los navegadores web.

Come to this free event this Thursday in CTTC in Castelldefels (Barcelona) to hear me talk about the Cyber Resilience Act and web browsers.

Registra't aqui: https://cyberstand.eu/events/cra-standards-unlocked-eu-tour-barcelona

(Background music: Jennifer by Els Catarres)

cyberstand.eu

CRA Standards Unlocked - EU Tour in Barcelona | Cyberstand

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:02:51 UTC