4 ms·
Schneier on Security: Software Problems with a Breath Alcohol Detector
- old-gregg 17y agoThis should be applied to SaaS as well: something needs to be done about GPL parasites hiding "in the cloud". If you're building on top of GPL, users of your cloud software should be able to download your code, examine it and modify/deploy on their own servers.
- delano 17y agosomething needs to be done about GPL parasites hiding "in the cloud". Companies and individuals that disregard the specifics of the licenses they are bound by are demonstrating a general lack of care and attention. We already have a solution to this problem (which is ironic given the license in question): the free market. As consumers become aware of the alternatives, they'll move towards companies and products that are more open.
- old-gregg 17y agoIt's not just about consumers, it's about programmers and their incentives as well. Torvalds' famous tit-for-tat doesn't work with SaaS - they get all the "tit" and keep "tat" to themselves.
- Dobbs 17y agoTake a look at the agplv3. Its to fight exactly what you are saying. It 'closes' the hole in the cloud.
- KirinDave 17y agoWait, this article had nothing to do with the GPL. The GPL is almost entirely unrelated to the notion of code audits and transparency. Lots of code licenses and business models allow for (or even promote) that approach. Why did you bring the GPL into this?
- old-gregg 17y agoYou are right, I got carried away a bit here. The article reminded me of reddit storing my password in plain text, which wouldn't go unnoticed if their code was open. [yes, I know they eventually released their code, which was very kind of them]
- deleted 17y ago[deleted]
- deleted 17y ago[deleted]
- jws 17y agoThe analysis sounds suspect to me. 2. Readings are Not Averaged Correctly: When the software takes a series of readings, it first averages the first two readings. Then, it averages the third reading with the average just computed. Then the fourth reading is averaged with the new average, and so on. There is no comment or note detailing a reason for this calculation, which would cause the first reading to have more weight than successive readings. The code is computing an exponentially weighted mean. Read that last sentence of the quote again, the analysis has it backwards. The last sample carries more weight, not the first. Now, type "uptime" at your unix prompt. Those last three values are computed the same way and have been for decades. (There are three different weighting factors used in them instead of the 1:1 implied in the text here.) The exponentially weighted mean is useful when you care more about the most recent values and when processor resources are highly constrained. It may be what was intended, or maybe not. Generally you would use a weighting factor to make the earlier factors not fade into oblivion as fast as these do, but I'm not going to take the word of someone who can't correctly describe the algorithm in his report. And the bit about turning off the illegal opcode interrupt... the premise is that some sort of failure would alter the program memory in such a way that one of the opcodes became illegal, yet the program would continue to function but produce erroneous results. I'd have to say the probability of this is vanishingly small, in fact, given valid opcode density for microprocessors, much smaller than an instruction being mutated to a legal opcode that somehow allowed the program to still run but produce erroneous results. I guess I should complete with my doubts about 3. Just because the A/D reads 12 bits doesn't mean you have 12 bits of data. If the 8 low bits are noise there is no information loss in dividing by 256. You have to understand the machine to know if this is a problem.
- HeyLaughingBoy 17y agoAnd the bit about turning off the illegal opcode interrupt I agree with your other analysis, but I have to disagree here. One of the basic tenets of embedded systems design is that ALL interrupts should be handled, even if the handler is just to say "Hey I processed an interrupt that should never fire." Given that a system in the wild can be subjected to conditions never encountered in an office or a lab (e.g., a police radio transmitting 2 inches away while this thing is measuring someone's Blood Alcohol Content) you simply can't predict how the processor will behave. That's why you make sure that things like the Watchdog and Illegal Instruction interrupts and resets are properly handled. That this device took these shortcuts would immediately cause me to suspect the rest of the design. If I were the auditor (I would love to get into this kind of work, BTW), I'd start digging deeper right away.
- HeyLaughingBoy 17y agoComputer Operating Properly interrupt: anyone else think this sounds like a National Semiconductor processor device? ISTR they had an interrupt labelled COP. When was the last decade National made a processor, anyway?
- joe_bleau 17y agoMotorola called their watchdog module a COP in the 8 bit lines. National still makes MPUs (http://www.national.com/appinfo/mcu/ http://www.national.com/appinfo/mcu/) and IP (http://www.national.com/analog/compactrisc/architecture http://www.national.com/analog/compactrisc/architecture) I've never seen a natsemi micro in the wild, however.
- blahblahblah 17y agoIf the readings are, in fact, averaged in the way described by the article, the device is useless and should not be allowed as evidence since such a scheme permits a single outlier reading to produce an erroneous result.
- mlLK 17y agoThis is an excellent lesson in the security problems inherent in trusting proprietary software This sentence made my day, given who is using it and how often it's being used.