4 ms·
Ok so I do appreciate the EFF's zeal in preemptively quashing a bug-hunter-hunt, but here's a scenario that throws their thesis into question: Bank of 'MURICA
by rotrux 8y ago
Ok so I do appreciate the EFF's zeal in preemptively quashing a bug-hunter-hunt, but here's a scenario that throws their thesis into question:
Bank of 'MURICA (Bo'M) gets a phone call from some random guy (Jack) who identifies a bug in the interface between PoS systems at gas stations across the US, and whatever Bo'M internal software-mega-structure manages checking acct balances for Bo'M customers. Now, Jack is a good Samaritan; he would never use this information to steal from millions of Bo'M customers...but like...he totally could. Jack's sister Jill overhears her brother's conversation with Bo'M's security team, & decides everyone needs to know immediately about Bo'M's negligence.
Lets pretend it's going to take a ~month to fix the interface.
Is it cool for Jill to get on Reddit and post the code necessary to exploit the bug before Bo'M has a chance to protect their customers?
Is this a victimless act? Was she just being responsible? Should she have waited to be responsible?
- deleted 8y ago[deleted]
- Chardok 8y agoOkay, but what about potential customers of BoA that have no idea that the bank they want to entrust their money to has a huge known exploit that increases their chances of identity theft? Does the customer not have a right to know what they are signing up for?
- tptacek 8y agoI have bad news for you. I don't know what bank you use, but I know this: your bank has huge exploits that increase your chance for identity theft.
- Chardok 8y agoI'm sure it does. Even if I already was a BoA customer in this theoretical scenario, I would also prefer to be in the know to avoid that specific POS/gas station company until the issue was resolved, instead of wondering why my identity was stolen and dealing with the fallout with my bank unknowingly to blame.
- tptacek 8y agoYou'd be in the know about one random thing, but there will be dozens of others, many of them also known to different subsets of people. I'm not making an argument about the public policy of disclosure. My view is: if you come about the information lawfully, publish whenever you're ready.
- rotrux 8y agoI mean, that's a decent point, but for the sake of my argument: let's pretend we're talking about a nuclear missile silo instead of a bank. The point is just that collateral damage can happen when people run their mouths about important/sensitive info. Sometimes, not always or even often: just sometimes, that's not cool & should maybe be prevented if possible. Should American citizens all be given access to the launch-codes because we pay taxes? This is a gray issue. I love the EFF but this article misses important nuance.
- 08-15 8y ago> Is it cool for Jill to get on Reddit and post the code necessary to exploit the bug before Bo'M has a chance to protect their customers? It's a trick question. Jill cannot post the exploit before Bo'M has a chance to protect their customers, because Bo'M already had a chance to do so. They just chose to leave their customers exposed by hiring cheap programmers who didn't know their computer science (aka math). Think that's sophistry? Well, look at the alternative: In a world where security researchers wait before they publish exploits, it's economically beneficial to cheaply write insecure software, wait for the White Hats to reports the flaws (hopefully before the Black Hats notice), then patch them. I'd argue this strategy amounts to outsourcing security engineering to government funded researchers. Do you want to live in such a world? Besides, why would Bo'M need to protect their customers?! The customers did nothing wrong, Bo'M did. Therefore, Bo'M is liable for damages. So... let me rephrase your question: > Is it cool for Jill to get on Reddit and post the code necessary to exploit the bug before Bo'M has a chance to cover their exposed backside? I think it totally is.
- rotrux 8y agoI wouldn't call this sophistry, but I do disagree with your logic here: > Jill cannot post the exploit before Bo'M has a chance to protect their customers, because Bo'M already had a chance to do so. Software has bugs...I can stick a file server in a pdf by poking at the file-headers. This doesn't necessarily mean we should stop using pdfs, nor that poor hiring practices at Adobe are to blame. My argument was merely that the language used in the article seems too categorical for a topic as complex as this one. I understand that big corporations often rush to market instead of doing due-diligence, but in certain realistic situations, this article would be advocating anarchy. I personally like electricity & running water, and so I disagree with the black & white take presented.