1751
submitted 2 days ago* (last edited 2 days ago) by inari@piefed.zip to c/technology@lemmy.world

The products covered by the obligation to repair currently include:

  • washing machines and washer-dryers
  • dishwashers
  • refrigerators
  • electronic displays
  • welding equipment
  • servers and data storage products
  • mobile phones, cordless phones and tablets
  • tumble dryers 
  • e-bikes and e-scooters batteries (from 18 February 2027)
  • local space heaters
you are viewing a single comment's thread
view the rest of the comments
[-] GoatSynagogue@lemmy.world -1 points 1 day ago

The root of trust can never be on the owner of the device for anything that requires actual security.

[-] cmhe@lemmy.world 4 points 1 day ago* (last edited 1 day ago)

I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.

Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren't.

Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.

It is not okay for companies or government to hold the data of individuals hostage... That is not security, that is a business strategy.

[-] GoatSynagogue@lemmy.world -1 points 1 day ago

If the only person that can verify the safety of your device is the owner, that device will and should be marked as insecure and not to be trusted in any instance where security matters.

[-] Jajcus@sh.itjust.works 1 points 19 hours ago

Are you talking about owner safety, or some bussiness security. Yes the device is 'insecure' if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.

[-] cmhe@lemmy.world 2 points 23 hours ago

You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn't do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn't matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.

[-] GoatSynagogue@lemmy.world 1 points 5 hours ago* (last edited 5 hours ago)

The reason is obvious, which is why I didn’t think I had to say it lol

Imagine if you went to work at a bank in IT for example. They issue you a laptop. You go “oh no it’s ok I’ll use my own, I assure you it’s secure and safe”.

You connect to their network and instantly their network is compromised, every device on the whole network gets a cryptolocker virus.

You said it was secure though, so how did this happen?

You can trust it all you want, but other systems absolutely do not have to, and anything that requires security assurances will not and should not trust it. The device owners word/assurance means nothing.

[-] cmhe@lemmy.world 1 points 3 hours ago* (last edited 2 hours ago)

Imagine if you went to work at a bank in IT for example. They issue you a laptop.

Who is the owner of that device? The Bank.

Who is the owner of that network? The Bank.

So they are the arbiter of trust in that area. They are free to exclude non-bank-owned devices.

I work in IT, and I'm fine with getting a company laptop for company work. I don't trust that laptop. I isolate it when I work at home. But the company trusts it, and that is fine.

this post was submitted on 01 Aug 2026
1751 points (99.8% liked)

Technology

86849 readers
3378 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS