I’m getting involved in security standards for web browsers as part of my new role at CrabNebula! It’s important to ensure that the web’s security model is not compromised, as browser engines evolve, new browser derivatives become more popular, and brand new web engines emerge. The European Union’s new law, the Cyber Resilience Act (CRA), provides the basis for a new push here.
The CRA requires all commercial software made available in Europe to meet essential cybersecurity requirements, and correctly calls out web browsers as a high-risk type of product with additional security requirements. ETSI (a European Standards Organization, like Ecma or W3C but specifically authorized to write standards referenced by EU law) is developing a standard for one way to demonstrate that a browser meets these requirements.
This browser security standard is in active development, published on ETSI’s website [1]. We’re very interested in feedback. The easiest way to provide feedback is in a GitLab issue [2].
Writing this kind of standard isn’t about mandating new practices from an ivory tower, but rather collecting best practices deployed today and encouraging their spread and consistent usage more broadly. For that, we urgently need browser engineers and web security experts to be involved so that we can accurately document these security best practices.
If you’re interested in getting involved, there are a number of free-to-join, publicly streamed conferences coming up which discuss CRA and the “vertical” standards for particular high-risk products including web browsers:
- In Zagreb on January 20th, there will be a “CRA Standards Unlocked” event, one of several events over the coming months around Europe [3].
- In FOSDEM on January 31st in Brussels, in the “CRA in practice” dev room [4] will be open Saturday from 15:00-19:00 in room UA2.114 (Baudoux)
Another path to involvement is to become a paid (!) contributor to these standards via a CYBERSTAND.eu grant [5].
If you want to get involved, or have ideas for how to spread the word and get others involved, I’d love to be in touch. Please DM me here, or see other contact methods at littledan.dev
(Links/footnotes in next post)