Don’t get too excited about this. The document clearly says it’s voluntary. Also, the “testing” is done by certified labs. Maybe if the testing was fully transparent, by security researchers aka hackers I would be happy about this. But the moment they open that up, there will be countless issues found.
This document also mentions how they allow patches after the certification. So a vendor could in theory have a clean version, wait for certification then push a back door out in a patch.
In short, I don’t see this as a win. More like a talking point to pretend things are being done, and most people won’t question since they don’t understand IT/cybersecurity.
Don’t get too excited about this. The document clearly says it’s voluntary. Also, the “testing” is done by certified labs. Maybe if the testing was fully transparent, by security researchers aka hackers I would be happy about this. But the moment they open that up, there will be countless issues found.
This document also mentions how they allow patches after the certification. So a vendor could in theory have a clean version, wait for certification then push a back door out in a patch.
In short, I don’t see this as a win. More like a talking point to pretend things are being done, and most people won’t question since they don’t understand IT/cybersecurity.