5 ms·
I say this often, and it's quite an unpopular idea, and I'm not sure why. Security researchers, white-hat hackers, and even grey-hat hackers should have strong
by Buttons840 1y ago
I say this often, and it's quite an unpopular idea, and I'm not sure why.
Security researchers, white-hat hackers, and even grey-hat hackers should have strong legal protections so long as they report any security vulnerabilities that they find.
The bad guys are allowed to constantly scan and probe for security vulnerabilities, and there is no system to stop them, but if some good guys try to do the same they are charged with serious felony crimes.
Experience has show we cannot build secure systems. It may be an embarrassing fact, but many, if not all, of our largest companies and organizations are probably completely incapable of building secure systems. I think we try to avoid this fact by not allowing red-team security researches to be on the lookout.
It's funny how everything has worked out for the benefit of companies and powerful organizations. They say "no, you can't test the security of our systems, we are responsible for our own security, you cannot test our security without our permission, and also, if we ever leak data, we aren't responsible".
So, in the end, these powerful organizations are both responsible for their own system security, and yet they also are not responsible, depending on whichever is more convenient at the time. Again, it's funny how it works out that way.
Are companies responsible for their own security, or is this all a big team effort that we're all involved in? Pick a lane. It does feel like we're all involved when half the nation's personal data is leaked every other week.
And this is literally a matter of national security. Is the nation's power grid secure? Maybe? I don't know, do independent organizations verify this? Can I verify this myself by trying to hack the power grid (in a responsible white-hat way)? No, of course not; I would be committing a felony to even try. Enabling powerful organizations to hide their security flaws in their systems, that's the default, they just have to do nothing and then nobody is allowed to research the security of their systems, nobody is allowed to blow the whistle.
We are literally sacrificing national security for the convenience of companies and so they can avoid embarrassment.
- AbstractH24 1y agoAt what point do we need to treat this data like one’s health data? The risks associated with medical malpractice certainly slows the pace of innovation in healthcare, but maybe that’s ok.
- thatguy0900 1y agoI mean, the problem is people will break things. How do you responsibly hack your local electric grid? What if you accidentally mess with something you don't understand, and knock a neighborhood out? How do we prove you just responsibly hacked into a system full of private information then didn't actually look at a bunch of it?
- sunrunner 1y ago> How do we prove you just responsibly hacked into a system full of private information then didn't actually look at a bunch of it? Pinky promise?
- sublinear 1y agoIf we're strictly talking about software there should be some way to test in a staging environment. Production software that cannot be run this way should be made illegal.
- Buttons840 1y agoIf a security researcher knocks out the power grid of a town, we should consider ourselves lucky that the vulnerability was found before an opposing nation used it to knock out the power of many towns.
- kube-system 1y agoThe ideal scenario is that a responsible security engineer finds the problem, and doesn’t cause a power outage. Power outages aren’t necessarily just an inconvenience, they can cause serious economic damage, and kill people. I think there’s a better solution somewhere in between doing nothing, and letting bumbling idiots recklessly fool with things they shouldn’t be messing with.
- Buttons840 1y agoSure, we should avoid people purposely doing harmful things, but they should be given the benefit of the doubt unless it can be proven they were intentionally doing harm beyond just testing the security. One thing that is not a good option is the status-quo we're discussing here, in which a "bumbling idiot" can take down a city power grid. If that's how things are, the we shouldn't cower and hope we remain safe from every idiot out there, we need to shake things up and find the problems now. Hopefully without actually taking out any power grid.
- msgodel 1y agoThe internet is really a lot like the ocean, things left unmaintained on it are swallowed by waves and sea life. We need something like the salvage law.
- valianteffort 1y ago> Experience has show we cannot build secure systems It's an unpopular idea because its bullshit. Building secure systems is trivial and at the skill level of a junior engineer. Most of these "hacks" are not elaborate attacks utilizing esoteric knowledge to discover new vectors. They are the same exploit chains targeting bad programming practices, out of date libraries, etc. Lousy code monkeys or medicore programmers are the ones introducing vulnerabilities. We all know who they are. We all have to deal with them thanks to some brilliant middle manager figuring out how to cut costs for the org.
- KaiserPro 1y ago> Building secure systems is trivial I'd suggest you try and build a secure system for > 150k employees before you make sweeping statements like that.
- tdrz 1y agoSometimes it is the management that doesn't understand anything. In their perspective, security doesn't improve the bottom line. I worked for an SME that dealt with some sensitive customer data. I mentioned to the CEO that we should invest some time in improving our security. I got back that "what's the big deal, if anyone wants to look they can just look..."
- darzu 1y agoTake a broader view of what "building secure systems" means. It's not just about the code being written by ICs but about the business incentives, tech choices of leadership, the individual ways execs are rewarded, legacy realities, interactions with other companies, and a million other things. Our institutions are a complex result of all of these forces. Taken as a whole, and looking at the empirical evidence of companies and agencies frequently leaking data, the conclusion "we cannot build secure systems" is well founded.
- wonderwonder 1y agoThis is accurate. Especially in shops that implement firm shipping dates for Product Increments. You have X weeks to build Y features consisting of Z tickets. At the end of those X weeks you better have all your tickets done. So more often than not, the tickets are done and the features are implemented. Shops like this build incredible ticket closing machines. They are implemented to pass user acceptance testing not to hold back hackers or bad actors. When leadership incentivizes delivering features and a developers job or raise depends on delivering those features, you get what you incentivize.
- pojzon 1y agoDid you see Google or facebook or Miceosoft customer databases breached ? The issue is there is too little repercusions for companies making software in shitty ways. Each data breach should hurt the company approximately to the size of it. Equifax breach should have collapsed the company. Fines should be in tens of billions of dollars. Then under such banhammer software would be built correctly, security would becared about, internal audits would be made (real ones) and people would care. Currently as things stand. There is ZERO reason to care about security.
- GlacierFox 1y agoDidn't Sharepoint get hacked the other day? :S
- jaynate 1y agoYes, but those were on-prem deployments of Sharepoint, not Microsoft's infratructure.
- Spooky23 1y agoMany of those deployments were there because Microsoft can’t deliver the required assurance level!
- sugarpimpdorsey 1y agoIs the non-defective software only available in the SaaS version?
- samplatt 1y agoIt was for ALL on-prem deployments. This wasn't due to the user being insecure, this was Microsoft's fault. If anything it's yet another point AGAINST them - if they can't guarantee secure software without the caveat of running on a closed hardware black box then it's not secure software.
- slivanes 1y agoI’m all for companies to not ignore their responsibility for data management, but I’m concerned that type of punishment could be used as a weapon against competitors. I can imagine that certain classes of useful companies would just not be able to exist. Tricky balance to make companies actually care without crippling insurance.
- bongodongobob 1y agoNo. You cannot come to my home or business while I'm away and try to break in to protect me unless I ask, full stop. Same goes for my servers and network. It's my responsibility, not anyone else's. We have laws in place already for burgers and hackers. Just because they continue to do it doesn't give anyone else the right to do it for the children or whatever reasoning you come up with.
- krior 1y agoBut you would like to be notifiedby your neighbours if you have left your window open while away, right? Or are you going to sue them for attempted break-in? The issue is not that its illegal to put on a white hat, break into the user database and steal 125 million accounts as proof of security issue. The problem is people getting sued for saying "Hey, I stumbled upon the fact that you can log into any account by appending the account-number to the url of your website.". There certainly is a line seperating ethical hacking (if you can even call it hacking in some cases) and prodding and probing at random targets in the name of mischief and chaos.
- wahern 1y agoAnalogy with the physical world falls apart here. Few people would want to enshrine an exemption from trespassing someone walking house-to-house jiggling door handles and pushing on windows to see what's unlocked. If anything you may want to make it an explicit crime to do it systematically, as opposed to "targeting" a neighbor's house. In fact, I think this constitutes prowling, which is a crime in many places. But for white-hat hacking you want prowling. And it's very difficult to create technical definitions that productively distinguish "good" prowlers from "bad" prowlers. So why even try to draw a distinction between types of prowlers? Maybe prowling information systems online shouldn't be a crime at all, given the nature of information systems.
- cmiles74 1y agoIt seems like passing legislation that imposes harsher penalties for data breaches is the way to go.
- 1y ago
- pengaru 1y ago> I say this often, and it's quite an unpopular idea, and I'm not sure why. > > Security researchers, white-hat hackers, and even grey-hat hackers should have > strong legal protections so long as they report any security vulnerabilities > that they find. > > The bad guys are allowed to constantly scan and probe for security > vulnerabilities, and there is no system to stop them, but if some good guys > try to do the same they are charged with serious felony crimes. So let me get this straight, you want to give unsuccessful bad actors an escape hatch by claiming white-hat intentions when they get caught probing systems?
- doubled112 1y agoWhat about a white hat hacker license? Not sure what the criteria would be, but could it be done? Then there would be some sort of evidence the guy was a "good guy". Like when a cop shoots your dog and suffers no consequences.
- red-iron-pine 1y agothere are things like OSCP and CISSP which require a background check and sponsor. there is a reason they are popular for security roles. that's not the same as a white-hat license but it shows that you registered, that you made it clear where you're at, and that you've had some minimum ethical and professional training.
- Buttons840 1y agoIf we did give bad actors an escape hatch, what harm would it do in a world already filled with untouchable bad actors?
- worthless-trash 1y agoThis is a horrifically bad take, I know you probably see it this way because you can't imagine how easy some of these mistakes are, however I can assure you that there are MANY TIMES that I've accidentally found issues with systems. I do work in security, the average person would write this off as "oh just shitty software" and do nothing about it, however when one know what the error means and you know how the software works, errors are easy to turn into exploitable systems. I once had a bank account that fucked up data validation because i had '; in the transfer description of 120 characters. Immediately abusable sql injection. After my first time reporting this OBVIOUS flaw to a bank along with how it can be abused in both database modification and xss injection, I had to visit the local law enforcement with lawyers because they believe that 'hacking' had taken place. I now report every vuln behind fake emails, on fake systems in non extradition countries accessed via proxy on vpn. Even then I have the legal system attempting to find my real name and location and threaten me with legal action. Bad actors come from non extradition countries which wouldnt even TALK to you about the problem, You'd just have to accept you get hacked and that is the end of the situation. Its people like yourself who can't see past the end of their nose to realise where the real threats are. You don't have "it straight".
- atmosx 1y agoIf companies faced real consequences, like substantial fines from a regulatory body with the authority to assess damage and impose long-term penalties, their stock would take a hit. That alone would compel them to take security seriously. Unfortunately, most still don’t. More often than not, they walk away with a slap on the wrist. If, that.
- Ylpertnodi 1y ago> I say this often, and it's quite an unpopular idea, and I'm not sure why. > Etc...etc...etc.... Me, neither, if that helps.
- sugarpimpdorsey 1y agoDo you think we should have strong legal protections for people who go around your neighborhood trying unlocked car doors and opening front doors (with a backpack full of burglary tools) and when confronted claim they're uh doing it for your security?
- xboxnolifes 1y agoThe great thing about analogies is that they're just analogies. We can have different laws for different things. Cybersecurity vs physical security.
- sugarpimpdorsey 1y agoHey your front door was unlocked where is my bug bounty? Some people still live in places where you can leave your doors unlocked and not worry. Leave it to the tech industry to bring Internet of Shit locks to your doorstep. Would you be upset if in the course of their unsolicited work, these white/grey hats found your wife's nudes in the digital equivalent of kicking over a rock? Full legal protection of course. Ignore if they kept a copy for themselves for later use, they promised to delete them <wink>.
- deleted 1y ago[deleted]
- speff 1y agoIf everyone in the world is able to check if my door is locked and enter if not, yes I will give a bounty to someone who politely tells me that it's unlocked. Cybersecurity vulns are in a different class of exploitability from physical vulns.
- user_7832 1y ago> Hey your front door was unlocked where is my bug bounty? If you own a property where a million people live, that might not be a bad idea at all.
- 1y ago
- saurik 1y ago> ...these powerful organizations are both responsible for _____, and yet they also are not responsible, depending on whichever is more convenient at the time... This pattern comes up constantly, and it is extremely demoralizing.
- kube-system 1y agoNot all security research is the same. There’s a lot of room for nuance in this discussion. I think there’s a lot of things that many people would agree should be protected. For instance, people who report vulnerabilities they just happen to stumble upon. But on the other end of the spectrum, there are a lot of pen testing activities that are pretty likely to be disruptive. And some of them would be disruptive, even on otherwise secure systems, if we gave the entire world carte blanche to perform these activities. There are certainly some realms of security where technology can solve anything, like cryptographic algorithms. But at the interface of technology and society, security still highly relies on the rule of law and living in a high trust society.
- gettingoverit 1y agoProbably this wouldn't be a problem if Web was somewhat anonymous, so that merely stumbling upon a security issue, or using website in a regular way would not constitute a crime for the lack of the person to put that crime onto. Also if things stored in those databases weren't plain strings, but tokens (in asymmetric cryptography sense) so that only the service owns it, and in case of a leak user can use it to get a payout from the service, this problem would be solved. But no business is interested in provably making their users secure, it would be a self-sabotage. It's always just a security theater.
- jama211 1y agoIt’s an interesting point, but doesn’t that open up an easy defense so black hat hackers can hack anything they want in advance and as long as they say they were just “looking for an opening” they’d be legally safe under this scenario? They could plausibly claim they just never found a vulnerability to report, but they could note down anything they notice and then attack who or when they feel like it - or pretend they’re white hat their while career but secretly sell the methods to someone who will. Under the current system, they’re discouraged from doing that.