2 ms·
Intent matters, but that's only one half of a problem. Improperly implied permission is an equal issue. There are bad software updates that are not malicious,
by nonrandomstring 2y ago
Intent matters, but that's only one half of a problem. Improperly
implied permission is an equal issue.
There are bad software updates that are not malicious, just inept, or
an unfortunate accident that cause havoc. I think the Crowdstrike
event was such a mishap.
And there are plenty of software updates that are plain malicious but
hiding behind the "legitimacy" of an update. I'm thinking here about
Amazon deleting the 1984 book, or printer 'updates' that lock-out
third-party ink etc. These are really violations of computer misuse
acts and ought to be prosecuted - because they are indeed vandalism
indistinguishable from a attack.
Maybe they're worse than a cyberattack, because they are harms that
abuse a privilege.
Because companies have not been prosecuted but allowed to get away
with this sort of crap for decades were in a sticky situation now.
There's a whole spectrum of intent between sincere security updates
that go wrong and spiteful for-profit sabotage. People need educating
that if you allow anyone remote access to your computing property,
no matter what their credentials and bona-fides, they are in a
position to massively abuse that trust. Just because someone sold you
some hardware or software doesn't mean they continue to have your best
interests at heart or any rights to interfere with your property.
All software and hardware should by law come with the ability to lock
out the original vendor, supplier and to reliably stop egress and your
device from "phoning home with telemetry".
The customer is buying a product not a relationship.