The products covered by the obligation to repair currently include:

  • washing machines and washer-dryers
  • dishwashers
  • refrigerators
  • electronic displays
  • welding equipment
  • servers and data storage products
  • mobile phones, cordless phones and tablets
  • tumble dryers
  • e-bikes and e-scooters batteries (from 18 February 2027)
  • local space heaters
  • arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    ·
    3 days ago

    Unfortunately there are some exemptions. Flexible / folding displays are not covered. Fitness trackers and watches are not covered.

    There is also a battery regulation coming in next year to require phone batteries to be replaceable with no tools but that has loop holes too - long life batteries aren’t covered, IP67 rated phones aren’t covered. So you can bet your boots those two reasons will be what makers use to bullshit their way out of it.

    • Jiral@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      3 days ago

      Having those rules is much better than not having them. Also, IP rating is not enough, batteries also need to have sufficient load cycles. So if it forces them to use only long life batteries that reduces the need for battery repkacements and is already something.

    • cmhe@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      3 days ago

      Also software… I would love to have regulations that make it clear that the root of trust on all devices need to start by the owner of the device, not by the vendor… That would allow the end users to repair the software on their devices… Replacing it with whatever else they want. Next would be to provide hardware documentation to the owners to program their own devices… I don’t expect that to happen, but I can dream.

      • GoatSynagogue@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        2 days ago

        The root of trust can never be on the owner of the device for anything that requires actual security.

        • cmhe@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          2 days ago

          I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.

          Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren’t.

          Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.

          It is not okay for companies or government to hold the data of individuals hostage… That is not security, that is a business strategy.

          • GoatSynagogue@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            2 days ago

            If the only person that can verify the safety of your device is the owner, that device will and should be marked as insecure and not to be trusted in any instance where security matters.

            • cmhe@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              arrow-down
              1
              ·
              2 days ago

              You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn’t do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn’t matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.

              • GoatSynagogue@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 day ago

                The reason is obvious, which is why I didn’t think I had to say it lol

                Imagine if you went to work at a bank in IT for example. They issue you a laptop. You go “oh no it’s ok I’ll use my own, I assure you it’s secure and safe”.

                You connect to their network and instantly their network is compromised, every device on the whole network gets a cryptolocker virus.

                You said it was secure though, so how did this happen?

                You can trust it all you want, but other systems absolutely do not have to, and anything that requires security assurances will not and should not trust it. The device owners word/assurance means nothing.

                • cmhe@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 day ago

                  Imagine if you went to work at a bank in IT for example. They issue you a laptop.

                  Who is the owner of that device? The Bank.

                  Who is the owner of that network? The Bank.

                  So they are the arbiter of trust in that area. They are free to exclude non-bank-owned devices.

                  I work in IT, and I’m fine with getting a company laptop for company work. I don’t trust that laptop. I isolate it when I work at home. But the company trusts it, and that is fine.

                  • GoatSynagogue@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    1 day ago

                    Yes, and you seem to have missed the point.

                    They won’t trust your device no matter how secure you say it is. That’s my point. Just because you say a device is secure doesn’t mean it’s secure, and it doesn’t mean it gets treated as if it’s secure.

            • Jajcus@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 days ago

              Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.

              • GoatSynagogue@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                1 day ago

                I’m talking about every service that you use your device for. They will not and should not trust some random phone owner that their device is secure and safe to let use their services. They will, however, trust Google saying that the device is secure and not tampered with - as they should.

                • Jajcus@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  1 day ago

                  Secure services should always have limited trust to user data and devices. Security built on ‘Google says the device is secure’ is broken. Yes, it is convenient fir service providers who do not care about their customer rights, but more for ‘intellectual property’ and liability.

                  Lots of apllications still work in web browsers without TPM-based, kernel level DRMs and many of them are still reasonably secure. They are built with the assumption user controls their device. This has always been possible and still is possible. Just inconvenient for corporations.

                  • GoatSynagogue@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    1 day ago

                    Websites and web applications don’t trust the user though, or at least they shouldn’t. They should all be doing server side verification and checking of anything the user inputs. This is why some banks will let you use their website on an old phone but not their app.

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      3 days ago

      Flexible / folding displays are not covered

      So that’s why after almost a decade, only now Apple is ready to launch their foldable

    • GoatSynagogue@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 days ago

      Those aren’t loopholes though, they’re part of the legislation. Phone makers don’t need to “bullshit” their way out of anything if they meet the criteria, which almost every mobile phone released these days does - making the regulation pretty pointless lol

    • HuePony@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 days ago

      Fitness trackers would be hard to make them easy repairable, when most of them is waterproof