BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//open-source-conference-luxembourg-2026//ta
 lk//NWSN7P
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251007T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Achilles: Don't trust\, just Verify the Binary! - Daniel Thompson-
 Yvetot
DTSTART;TZID=Europe/Luxembourg:20261007T150000
DTEND;TZID=Europe/Luxembourg:20261007T153000
DTSTAMP:20260916T160759Z
UID:pretalx-open-source-conference-luxembourg-2026-NWSN7P@pretalx.com
DESCRIPTION:When the EU **Cyber Resilience Act** enters full application\,
  manufacturers become legally accountable for the security of every produc
 t with digital elements they place on the European market. That accountabi
 lity only functions if someone outside the manufacturer can actually check
  the claims being made. Regulators\, procurers\, and users all confront th
 e same practical difficulty when they try: verifying what a binary really 
 does\, what it is composed of\, without source access\, vendor cooperation
 \, or even the skills to know how to look under the hood.\n\nAchilles emer
 ged directly from that verification gap\, as a runtime auditor that observ
 es application behaviour while it happens\, rather than trusting documenta
 tion about it. It records network endpoints contacted\, filesystem and cre
 dential access\, update mechanisms\, and embedded third-party components\,
  then turns those observations into structured\, comparable evidence. Four
  distinct audiences shaped the design from the beginning: manufacturers va
 lidating their own conformity claims\, market surveillance authorities che
 cking products at scale with limited technical staff\, downstream integrat
 ors performing supply chain due diligence\, and even mere mortals concerne
 d with the safety of their work.\n\nDuring the talk I will walk through th
 e architecture\, examine what runtime evidence can and cannot prove\, and 
 explain the tamper-evident transparency log and changelog mining layer. Li
 ve audits of real desktop applications will demonstrate how findings map o
 nto CRA essential requirements.
LOCATION:Governance\, compliance and business
URL:https://pretalx.com/open-source-conference-luxembourg-2026/talk/NWSN7P
 /
END:VEVENT
END:VCALENDAR
