The products covered by the obligation to repair currently include:

  • washing machines and washer-dryers
  • dishwashers
  • refrigerators
  • electronic displays
  • welding equipment
  • servers and data storage products
  • mobile phones, cordless phones and tablets
  • tumble dryers
  • e-bikes and e-scooters batteries (from 18 February 2027)
  • local space heaters
  • Jajcus@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.

    • GoatSynagogue@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      6 hours ago

      I’m talking about every service that you use your device for. They will not and should not trust some random phone owner that their device is secure and safe to let use their services. They will, however, trust Google saying that the device is secure and not tampered with - as they should.

      • Jajcus@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        7 hours ago

        Secure services should always have limited trust to user data and devices. Security built on ‘Google says the device is secure’ is broken. Yes, it is convenient fir service providers who do not care about their customer rights, but more for ‘intellectual property’ and liability.

        Lots of apllications still work in web browsers without TPM-based, kernel level DRMs and many of them are still reasonably secure. They are built with the assumption user controls their device. This has always been possible and still is possible. Just inconvenient for corporations.

        • GoatSynagogue@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 hours ago

          Websites and web applications don’t trust the user though, or at least they shouldn’t. They should all be doing server side verification and checking of anything the user inputs. This is why some banks will let you use their website on an old phone but not their app.