Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Daniel Ehrenberg

@littledan@hachyderm.io
mastodon 4.6.6
  • Open on hachyderm.io

This is now a Cyber Resilience Act stan account
(((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

0 Followers
0 Following
19 Posts
Joined November 23, 2022

Posts

Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Apr 01, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

For April Fools, I told the ETSI CYBER EUSR rapporteur group on web browsers that the European Commission was giving us until April 15th to submit our final draft. Got them good! Well, some requests for clarification but actually no laughs… (Real timeline: edit through May, then more review stages)

1
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Mar 23, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

Ve a aquest esdeveniment gratis aquest dijous a CTTC a Castelldefels per a sentir-me xerrar del Cyber Resilience Act i els navegadors web.

Ven a este evento gratis este jueves en CTTC en Castefa para escucharme charlar del Cyber Resilience Act y los navegadores web.

Come to this free event this Thursday in CTTC in Castelldefels (Barcelona) to hear me talk about the Cyber Resilience Act and web browsers.

Registra't aqui: https://cyberstand.eu/events/cra-standards-unlocked-eu-tour-barcelona

(Background music: Jennifer by Els Catarres)

0
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Feb 07, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

I spoke at FOSDEM about the new European web browser security standard, under development in ETSI, as part of the Cyber Resilience Act. Video here: https://mirror.as35701.net/video.fosdem.org/2026/h1309/YMQ3J3-the_cyber_resilience_act_and_web_browsers.mp4

This standard is still in development, at https://labs.etsi.org/rep/stan4cra/en-304-617 , with weekly meetings freely accessible to open source developers, as well as ETSI members. Please get in touch with me if you want to be involved.

7
0
2
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Feb 03, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @letoams@defcon.social
@letoams@defcon.social My standardization request is scoped to the CRA. That’s out of scope for me!
1
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Feb 02, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @Edent@mastodon.social
@Edent@mastodon.social good question, keep them coming! IMO web would make sense.
1
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Feb 02, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

At ETSI, we're developing a new European standard about web browser security to support the Cyber Resilience Act. Come read the draft at https://labs.etsi.org/rep/stan4cra/en-304-617/-/blob/main_publish/EN-304-617.md

Be the first to file an issue! No one from outside ETSI administration has done so yet, so this is a prize you can claim. https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues/new

In addition to development in GitLab, we have regular calls. The next one is tomorrow, Feb 3rd at 3 PM (CET). If you want to join this or a future call, please DM me and we can discuss how that works.

10
4
8
1
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 28, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @littledan@hachyderm.io
(8) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
0
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 28, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

The Cyber Resilience Act includes some very well-considered requirements for vulnerability handling. Worth a read.

[Software commercialized in Europe] shall:
(1) identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products;
(2) in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;
(3) apply effective and regular tests and reviews of the security of the product with digital elements;
(4) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;
(5) put in place and enforce a policy on coordinated vulnerability disclosure;
(6) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements;
(7) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner;

0
2
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 28, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

The Cyber Resilience Act mandates that commercial software handle vulnerabilities well. What does that mean exactly? The CRA names sound principles in Annex I Part II, but applying them in practice is another thing. For this reason, there's an ongoing standardization effort translate these principles into more clear requirements to meet, to make it easier to demonstrate compliance.

The draft standard now entering a public review phase, so *we need your opinions, thoughts and analysis to improve it*. This article explains where things are, and how to get involved.

https://www.agoria.be/en/services/expertise/technical-regulations-standardisation/standardisation/public-enquiry-concerning-the-new-draft-standard-pren-40000-1-3-vulnerability-handling-in-support-of-the-cyber-resilience-act

4
0
6
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 26, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

At the FOSDEM browser track, I will be giving a talk:

The Cyber Resilience Act and web browsers

The Cyber Resilience Act defines web browsers as an important product requiring special attention to cybersecurity requirements. What does this mean? How can you participate in defining in what it means for a web browser to be secure?

https://fosdem.org/2026/schedule/event/YMQ3J3-the_cyber_resilience_act_and_web_browsers/

I’m really honored by this invitation from @sylvestre@framapiaf.org for my first FOSDEM.

5
2
5
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 23, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

RESCHEDULED: Please join Daniel Thompson-Yvetot and me on Tuesday the 27th, at 1 PM Central European Time for an interactive deep dive into the draft standard for BROWSERS under the Cyber Resilience Act (CRA). https://www.stan4cra.eu/event-details/cra-standards-unlocked-deep-dive-session-on-browsers-2

1
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 22, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

RE: @littledan@hachyderm.io

Rescheduled for Tuesday, the 27th at 1 PM. Hope to see you there!

1
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 21, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

RE: @littledan@hachyderm.io

This event is postponed. I'll post here again when it is rescheduled.

1
0
1
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 19, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @littledan@hachyderm.io
Our work on the CRA browser standard is funded by the European Commission and EFTA.
0
0
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 19, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @littledan@hachyderm.io
Find the current draft in https://docbox.etsi.org/CYBER/CYBER/Open/ File any issues in https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues
0
2
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 19, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

EDIT: This event is postponed. I'll post here again when it is rescheduled.

Please join Denjell (of Tauri fame) and me for a deep dive into the draft standard for BROWSERS under the Cyber Resilience Act (CRA). https://www.stan4cra.eu/event-details/cra-standards-unlocked-deep-dive-session-on-browsers

3
2
1
2
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 15, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

If you were dictator of Europe, what would you require all software developers to do properly?

1
4
0
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 09, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io
Replying to @littledan@hachyderm.io
This work is co-funded by the EC and EFTA [1] You can find the current draft in https://docbox.etsi.org/CYBER/CYBER/Open/ . Look for “browser” within that directory. [2] File issues in https://labs.etsi.org/rep/stan4cra/en-304-617/-/issues/new?description_template=Vertical%20Standard%20Comment . Anyone can sign up for an account and post issues. Please apply the template carefully to give the committee all it needs to address on your comment. [3] The Zagreb event: https://cyberstand.eu/events/cra-standards-unlocked-eu-tour-zagreb Keep an eye out for further events at https://cyberstand.eu/events [4] https://fosdem.org/2026/schedule/track/cra-in-practice/ January 31st from 15:00-19:00 in room UA2.114 (Baudoux) [5] https://cyberstand.eu/10th-specific-service-procedure-sme-perspective . Note that the current SSP (more commonly known as CFP) focuses on the perspective of Small and Medium Enterprises. Future SSPs may have different focuses too. But please apply even if you’re not sure if you are qualified! My contact information: https://littledan.dev Thank you for everyone’s support while I focused on my health over the past 9 months.
3
0
1
0
Open post
littledan
Daniel Ehrenberg @littledan@hachyderm.io · Jan 09, 2026
Daniel Ehrenberg
@littledan@hachyderm.io

This is now a Cyber Resilience Act stan account (((🏳️‍🌈🪗🎹🏊🟥🟨🟪)))

hachyderm.io

I’m getting involved in security standards for web browsers as part of my new role at CrabNebula! It’s important to ensure that the web’s security model is not compromised, as browser engines evolve, new browser derivatives become more popular, and brand new web engines emerge. The European Union’s new law, the Cyber Resilience Act (CRA), provides the basis for a new push here.

The CRA requires all commercial software made available in Europe to meet essential cybersecurity requirements, and correctly calls out web browsers as a high-risk type of product with additional security requirements. ETSI (a European Standards Organization, like Ecma or W3C but specifically authorized to write standards referenced by EU law) is developing a standard for one way to demonstrate that a browser meets these requirements.

This browser security standard is in active development, published on ETSI’s website [1]. We’re very interested in feedback. The easiest way to provide feedback is in a GitLab issue [2].

Writing this kind of standard isn’t about mandating new practices from an ivory tower, but rather collecting best practices deployed today and encouraging their spread and consistent usage more broadly. For that, we urgently need browser engineers and web security experts to be involved so that we can accurately document these security best practices.

If you’re interested in getting involved, there are a number of free-to-join, publicly streamed conferences coming up which discuss CRA and the “vertical” standards for particular high-risk products including web browsers:

- In Zagreb on January 20th, there will be a “CRA Standards Unlocked” event, one of several events over the coming months around Europe [3].
- In FOSDEM on January 31st in Brussels, in the “CRA in practice” dev room [4] will be open Saturday from 15:00-19:00 in room UA2.114 (Baudoux)

Another path to involvement is to become a paid (!) contributor to these standards via a CYBERSTAND.eu grant [5].

If you want to get involved, or have ideas for how to spread the word and get others involved, I’d love to be in touch. Please DM me here, or see other contact methods at littledan.dev

(Links/footnotes in next post)

17
2
8
0

Remote instance

hachyderm.io
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:42:36 UTC