4 ms·
>> It seems simplest for the Govt to avoid trying to mandate detailed security standards for continuously changing tech >Govs can do a lot of broad legislation
by therealjumbo 9y ago
>> It seems simplest for the Govt to avoid trying to mandate detailed security standards for continuously changing tech
>Govs can do a lot of broad legislation rules that is non-specific.
>The software industry requires a legislative bitch slap like the auto industry received. These rules would wreak havoc on the industry but if you ask me for the better.
>- Are you running unpatched software exposed to the internet for which CVE patches exist? Pay a fine every day until you do so.
Just to play devil's advocate, I'll try to pick the harder cases, not the easy ones.
Define unpatched.
Does this include free to use websites?
What about non-profits?
What if a CVE does not exist? (yes you said for which patches exist, why is this an exception, how well is this exception going to hold up in the legislative session, and if it's not explicity made as a distinction, how is it going to hold up in court?)
What about software I host for free and let you download, But the hosting software itself does not have CVEs?
What about software I let you automatically download and automatically update, and is exposed to the internet from your machine, by default or by configuration, but is not installed by default? What if I'm the manufacturer of the device?
What if I'm the manufacturer the device in the previous example I give access to install the software through my portal, but I don't own the software, nor have the ability (because I don't have the source) or the legal rights to patch it without the owner consent (ala iOS)? In this case I do have the legal right to remove it, how does that interplay with this?
What if in the above scenario, the software manufacturer is outside your jurisdiction? How is that decision going to affect the software industry in your jurisdiction?
>- Ban IoT devices that do not have automatic signed software updates over encrypted channels (which would probably ban all current IoT devices).
How does that affect the right to repair if that was passed as a law?
>- Ban all IoT devices without crypto capabilities. Must have a hardware RNG and a set of standard crypto algorithms.
Who defines the standards, both for the hw RNG and the algos? The US gov't has been shown to be more or less subversive to good crypto. If you select another org, a nation state with said resources can just neuter that org by infiltration.
How are you going to verify that the standards are actually being followed? Refer to the most recent question, Snowden, Reflections on Trusting Trust, and ultimately even if the end user had the source how does he verify that's what is actually being executed? Most end users won't go through this effort, but if nobody can, then your essentially not verifying anything.
How do you verify compatibility for this standard? Generally standards that succeed, do so by defining a common sense test suite. Where does that fit in?
>- Does an IoT maker have a CVE and has not patched all their devices in X amount of time? Daily fine.
Does the fine increase per day? Why or why not? If yes, how much and why that much?
How much is the fine, is it based on revenue, profit, units shipped etc?
How do you pick the amount of time? I bring this up mainly in reference to
a) The Project Zero disclosures that seemingly didn't give Microsoft enough time, and yet if you don't set a deadline...
b) What about products like Android that have security patches that aren't deployed to end users due to the product org, manufacturer apathy, and carrier blockades? Is there a fine, there was a patch... Who gets the fine?
How do you levy it on firms in other jurisdictions that don't let you levy fines like China?
What if the devices are meant to be offline for a certain period of time? How much is acceptable before a device needs to call home? Specifically, what about industries where the devices will eventually sync, but may not for an indefinite period of time (military, mining, heavy construction, anything done in the middle of nowhere)?
What if not all devices are accounted for? More generally, how are you counting devices?
Referring to the previous question, how do you count devices that were discarded by the owner, but not reported to the manufacturer?
>- Are you a vendor who has not patched a CVE for your software after X amount of time? Pay a fine every day until you do so.
Define vendor. Software or Hardware? Does FOSS count?
Otherwise same as previous.
These questions are meant to get you thinking, not to be argumentative.
edit: formatting
- bitmapbrother 9y agoWhat about the 100's of millions of Windows computers that spread most of the viruses, malware and ransomware? Is there a fine for Microsoft's negligence? What about the millions of zombie Windows computers launching DDOS attacks daily? Is there going to be a fine for that too?
- rapsey 9y ago> Define unpatched. Software that has a vulnerability, for which the vendor has made a fix available. > Does this include free to use websites? Obviously. A compromised server is a compromised server that is a vector for other attacks. > What about non-profits? Legal status of the organization is entirely irrelevant. > What if a CVE does not exist? You cant legislate all software must not have security issues. CVE pathway is industry standard and the best practice we have come across. It's not full-proof but it's good enough. > (yes you said for which patches exist, why is this an exception, Because the makers will also be liable to provide patches. > how well is this exception going to hold up in the legislative session, and if it's not explicity made as a distinction, how is it going to hold up in court?) Have a public DB of CVE's, plenty of which exist. I fail to see what the problem is. > What about software I let you automatically download and automatically update, and is exposed to the internet from your machine, by default or by configuration, but is not installed by default? Software you put on the internet is your responsibility. The manufacturer must provide a pathway to update, you must make use of it. > What if I'm the manufacturer of the device? Provide patches for all CVEs that can be used on your devices. Otherwise fines. > Who defines the standards, both for the hw RNG and the algos? Plenty of very good crypto algos exist. Pick a group and give manufacturers the option to implement a subset. > The US gov't has been shown to be more or less subversive to good crypto. If you select another org, a nation state with said resources can just neuter that org by infiltration. There are branches of government. It's not one single thing. > How do you verify compatibility for this standard? Generally standards that succeed, do so by defining a common sense test suite. Where does that fit in? New agencies have to be made. Just like there are is a FDA and whoever certifies cars so they can be used on roads. > Does the fine increase per day? Why or why not? If yes, how much and why that much? > How much is the fine, is it based on revenue, profit, units shipped etc? Details that are really not an issue. > How do you pick the amount of time? I bring this up mainly in reference to Not enough time is complete bullcrap. Give them a month and the fines start. Google made a fucking disaster with Android. Anyone attempting to do anything similar today should get fined in the billion range. > How do you levy it on firms in other jurisdictions that don't let you levy fines like China? If they are selling products in a market, they can legislate standards. If you use something for free, you are liable yourself. > What if the devices are meant to be offline for a certain period of time? How much is acceptable before a device needs to call home? Specifically, what about industries where the devices will eventually sync, but may not for an indefinite period of time (military, mining, heavy construction, anything done in the middle of nowhere)? Then those devices aren't really a security issue and a danger to the rest of the Internet. > Referring to the previous question, how do you count devices that were discarded by the owner, but not reported to the manufacturer? Whoever is connecting the device to the internet is liable. Devices must have the capability to call home (manufacturers servers) and update if necessary.