Support us by visiting our sponsors and win a €20 Amazon Voucher every month

Follow maltainfosec on TwitterTwitter or RSS 2.0 feed

May 11
The European Commission is proposing that software makers give guarantees about the security and efficiency of their code

Software companies could be held responsible for the security and efficacy of their products, if a new European Commission consumer protection proposal becomes law.

[BSA director of public policy Francisco Mingorance] said the performance of a piece of software depends on the environment it operates in, how the code is updated, whether it is possible to adapt and modify the software, and whether the code is attacked.
According to Mingorance, the proposed regulatory extension would cover all software, including beta products, and would cover both proprietary and open-source software.

Right now, under the current EU Sales and Guarantees Directive, physical products are expected to carry a guarantee of two years. Extending those terms to software would have the effect of limiting customer choice, as contract terms would have to be extended to a minimum of two years, Mingorance added.

Software companies have long argued against accepting responsibility for the security and efficiency of their code. Linux kernel developer Alan Cox in 2007 told a House of Lords Committee that neither proprietary nor open-source developers should be held accountable for their code.

Source

Posted by Donald Tabone

1859 hits
May 11
This year the Information Security Solutions Europe Conference (ISSE 2009) will be held on 6-8 October 2009 in The Hague, The Netherlands.

ISSE is Europe's only independent, interdisciplinary, security conference. It is designed to educate & inform on the latest developments in technology, solutions, market trends and best practice.

Now in its eleventh year and jointly organised by EEMA, ENISA, TeleTrusT and the municipality of the Hague; ISSE 2009 will attract over 400 representatives from across Europe, providing an informal and stimulating environment for attendees to learn, share experiences and explore solutions with their European counterparts, focusing on security and related issues like cost of ownership, risk management and interoperability.

To join them or for further information please visit the event website at http://www.isse.eu.com

ISSE 2009 is co-organised by ENISA

Posted by Donald Tabone

2611 hits
Please consider sending us a small donation to keep this site going. Click the PayPal logo below. Thank you!