6 ms·
Could you explain a little more why you didn't go for responsible disclosure to Onity? In the article you suggest that you don't think they could fix it. Maybe
by screwt 14y ago
Could you explain a little more why you didn't go for responsible disclosure to Onity?
In the article you suggest that you don't think they could fix it. Maybe true but shouldn't you (a) give them the oppurtunity to try (just cos you can't spot the fix doesn't mean it's impossible), and (b) give them the chance to say "yep, it's broken - give us 3 months to ship out new locks to all our customers" (yes, highly unlikely I know!).
Given that you sat on this for a year before publishing, there was ample oppurtunity to inform Onity before you publish.
- daeken 14y agoGiven the simplicity of the vulnerabilities (as mentioned in the article, you have full and unauthenticated memory access) and the length of time -- over a decade -- that these locks have been on the market, there is absolutely no doubt that they knew about this. Given that, I felt that they would delay, delay, delay, and delay some more before finally going silent, at which point I would be forced to do this anyway. Simply put, I have zero confidence in their ability to mitigate this properly, and I believe that the only proper course of action is to make this public and let the hotels make themselves secure by whatever means possible. I know that's a bit of a strange answer, but this is a strange situation; it's taken me a while to figure out the correct course of action, and I feel that this really is the best way for the safety of the public. Edit: Toned down some of the wording; unnecessary.
- akamaka 14y agoThat's a completly bogus excuse. The question wasn't why you're releasing it publicly, but why you haven't made any attempt to contact the company beforehand, which you seem to have had a year to do. Edit: The only reasons I can think of are laziness or just plain not giving a shit about responsible disclosure.
- Kadin 14y agoIn order so that they could do ... what, exactly? It doesn't sound like there's any mitigation that they could perform. At the very least, the guts of every lock has to be replaced. Given that, the rational, profit-maximizing thing for them to do is to stonewall, misdirect, bring out the lawyers, shoot the messenger, and generally continue to sell as many flawed locks as possible. We've all seen vendors do that in the past when faced with intractable, deep-seated defects in a product, so it wouldn't be unexpected or unreasonable to assume. All the notification would be is a courtesy, allowing them time to start designing and marketing a new product, instead of having the market get handed to their competitors when hotels suddenly have to start replacing their locks with less-flawed ones. And I'm not sure a company that produced a flawed products deserves that.
- huhtenberg 14y ago> what, exactly? They could plug the access holes, with custom pentalobe screws. That's an under a dollar per lock fix.
- tptacek 14y agoSo, that's more than a million dollars more than NYSE:UTX's gross profits for the last quarter, and ~1/4 of their gross revenue over the same quarter. No, I don't think they were going to do that.
- huhtenberg 14y agoC'mon. It's well under a dollar. And that's a 10 second idea, I'm sure there are other options. (edit) That's not even considering that this cost can be carried by the hotels. I'm sure they can cough up $500 to secure their facilities. -- Please don't tell me that you, of all people on HN, think that there's no need for a private disclosure on this guy's part?
- tptacek 14y agoIt's way more than a dollar. How many locks could one technician replace/fix in an hour, and what's their hourly rate? "Me of all people"? Am I a spokesperson for "Responsible disclosure" now? I would have notified the vendor ASAP, and I might not have put the vendor name into the talk at all. But that's me, and I am super conservative about this stuff. Lots of very reputable security people would do exactly what Cody did.
- huhtenberg 14y agoNot in bulk. Hotel technicians install and service locks, I'm sure they'll manage to screw a bolt into a hole. They are salaried. "You" as a "sensible security guy". Or at least that was my impression of you based on what you post here.
- peterwwillis 14y ago
- nowarninglabel 14y agoThere is the possibility of being dragged through a lawsuit, and/or the company one works through being dragged through a lawsuit. I don't know if that is applicable here, but I have been involved in a responsible disclosure where I gave the information to a colleague, who then disclosed to the company, and the company then sent a letter threatening a lawsuit, whereas my colleague nearly got fired (the fact that he didn't was the one time I can remember the union stepping up to do something useful by defending him). Whether or not such lawsuits would hold merit, they'd be expensive for all involved, and lots of listed companies are more than happy to put the lawyers on you for invalid reasons.
- danweber 14y agoPeople do use the legal system for suppression of free speech, to chill censors. There are also lawyers who will take issues like that pro bono. Google up the Popehat Symbol for some examples.
- huhtenberg 14y agoNot cool, dude. Not cool at all. The company might be lazy and ignorant, but it doesn't mean they won't move when faced with a lingering public disclosure. You must give them a chance. What you are planning to do is egoistic, it serves your own interests, and it does that at the expense of people staying in the hotels. How is this even remotely ethical?
- wccrawford 14y agoI agree that it's probably futile, but the white-hat thing to do is give them notice. If they say they will not fix it, or ignore you, then you release the info. If they say they're working on it, you give them a reasonable timeframe for that, and then release it. That way, you've done everything 'properly', and nobody can say otherwise. With the path you're on, everyone is going to blame you instead of them, even though they're at fault. Please consider doing this the proper way, even though we both know it's most likely futile.
- sneak 14y ago> but the white-hat thing to do is give them notice That's why you _shouldn't_ do it that way. > Please consider doing this the proper way "whitehat" != "proper".
- david_shaw 14y agoWhile, yeah, I'm in the security industry, I agree that the "whitehat way" isn't always the "proper" way. That said, there is an easy way to compromise on this one, and is the way I generally go about disclosure: 1.) Email security contact with vulnerability, announce that you will be releasing information in 30 days. 2.) 30 days later, release the information. If a month isn't enough time to apply a fix (I do 60 days if it's a particularly complex issue), then the organization pretty much doesn't care. I don't support responsible disclosure because it's "whitehat approved," nor do I do it because I particularly care about the vendors themselves. I'm a proponent of giving the vendor a chance because of all the sysadmins that would suddenly have an 0day on their hands and be forced into the difficult position of either: (1) shutting down the effected service (2) hoping they just don't get targeted, which is unlikely (3) trying to release a patch themselves. That is a shitty position to put people, in my opinion. Daeken, I've chatted with you in #startups once or twice (as 'dshaw'), and I think you're a genuinely cool guy. This research is awesome, but I still think you should give vendors a chance. Assuming that they already know about the vulnerability might actually be giving them too much credit... they did create the issue, after all.
- unimpressive 14y agoSince everyone else replying is telling you what a lazy horrible person you are, I'll go ahead and let you know that I agree. Theres nothing they can really do at this point. And because of that the companies only real option is to just stonewall you for as long as possible. EDIT: And if it weren't for the long history of large companies suing security researchers for blackmail/etc when they try responsible disclosure I'd have probably sided with everyone above.
- caf 14y agoAgreed. The companies that have tried to shut people up with strategic lawsuits in the past have salted the earth.
- st3fan 14y agoYou are acting on assumptions. If you actually talk to them first you will find out what will really happen. They might actually have a way to deal with this. Maybe the only thing they need is some time.