Responsible disclosure is a courtesy. Exploits are valuable. Information asymmetry is the name of the game. Apple is not entitled to free labor. If they don't like it they should hire researchers, as the FBI has.
Responsible disclosure is a courtesy. Exploits are valuable. Information asymmetry is the name of the game. Apple is not entitled to free labor. If they don't like it they should hire researchers, as the FBI has.
This seems a lot like saying, if someone pays you to do a structural analysis of a parking garage because they want to know if they can profit by shorting the company that owns it, and you discover that the garage is likely to collapse, you don't have any obligation to disclose the vulnerability.
There is a vital difference in that scenario: You paid the engineers who did the structural differences and thus have an expectation that they would disclose that information to you.
If someone comes around and pokes at your building without you having paid or told them to do so, I don't think there's any legal expectation whatsoever for them to tell you about any faults. (Ignoring the code of ethics professional Engineering societies have.)
It caused their professional society to condemn their acts and put in special ethics rules with regards to torture, etc.
Depending on how this exploit works, a simple denial of service when someone needs to call for emergency services may indeed represent an "imminent physical danger". People rely heavily on their phones, both for connectivity and to store important information. As this reliance increases in the future, the probability of a phone being part of a life threatening situation will approach one.
I didn't imply that it's inconceivable that the vulnerability eventually leads to danger. The point is that the safety issues at a garage directly lead to harm, while the safety issues with a phone don't. (Note that the garage doesn't require anyone to actively exploit it to harm people.) Also, there's no way for the garage collapsing to help people, while selling an exploit to the FBI can conceivably help people (not difficult to imagine scenarios).
Then why is the CFAA still a law?
> Also, there's no way for the garage collapsing to help people, while selling an exploit to the FBI can conceivably help people (not difficult to imagine scenarios).
What do you mean? I laid it out already. You can short the company that owns it. Quite profitable. And maybe you donate the money to cancer research. If the garage happens to collapse at night when it only damages millions of dollars worth of cars but no people then it's not difficult to imagine that could come out as a net positive (it's clearly a personal positive for the short seller), and of course we won't know the extent of the harm ahead of time in either case.
I'm not even convinced that this should create a legal obligation to disclose it, especially in the cases where the most likely harm is financial or property damage. Otherwise that would pretty much ban half the stuff Wall St does. But not disclosing a vulnerability still makes you a jackass, which kind of implies that at least the government should not be doing it with tax dollars.
Plenty of things are illegal without directly causing physical harm to people. This is irrelevant.
I think I've made it clear what the relevant ethical difference between garage and exploit. If you think one still informs our ethics regarding the other, fine; I disagree.
Software runs our telephone networks and the telephones themselves. Are you suggesting the inability to contact emergency services isn't vital?
Software runs our cars. Is the ability to remotely disable a car something that won't hurt people?
Note that there's a difference between something that will cause a failure versus something that could be exploited to cause a failure.
• mining equipment: not dangerous :: enriched vein of uranium discovered using mining equipment : dangerous
• chemistry equipment : not dangerous :: nerve gas, napalm, etc. : dangerous
It's a strange situation where the equipment has a set of very legitimate uses, but once you allow it into people's hands, they now have complete unmonitored autonomy in how they use it, and might very well use it to bring about something dangerous with no-one the wiser.
This is unlike most experience we have with dangerous tools. Cars, for example, can easily be used as weapons—but that danger only applies in public where others can observe you using the car, and your driver's license can be revoked. Similarly, a HAM operator could, on a whim, pollute the RF spectrum around them with noise—but that's also an action that by its very nature is observable, and so their broadcast device could be tracked down and shut down, and their operator certification revoked.
But nobody sees you when you decide to mine for uranium, or produce chemical weapons, or develop software exploits. These aren't the tool being used as a weapon, being used to attack; these are instead cases of a tool being used to create a weapon, to create the potential for future violence, violence that—until it ever comes to pass—has no observable effects out on the world that will hint that this person is acting with malicious intent.
It really seems like the law doesn't know what to do about that category of things, generally.
FWIW "enrich" in the context of uranium is the thing done by centrifuges. You don't get enriched uranium out of the ground.
And Napalm is basically styrofoam and gasoline. You don't need much in the way of chemistry equipment to make it.
> It really seems like the law doesn't know what to do about that category of things, generally.
The main problem with the concept is that it doesn't end. A person with malicious intent can cause quite a lot of destruction with only the stuff everybody already has. There is no point in restricting chemistry equipment when people already have gasoline (or olive oil or lard or alcohol or ...)
The only way to separate a person from the means to cause trouble is to eject them naked into the vacuum of space, and even then it's mostly because you can expect that to kill them.
You can use a hammer to construct something, or to bash someone's skull. That's human nature, and freedom. To not have that choice would mean we have lost a lot more than we'd have gained.
This moral ambivalence makes it (luckily) nearly impossible for any form of authority to make a definite statement or prevent usage. It ensures freedom.
And sometimes bashing someone's skull might be the "positive" action, and using a hammer to construct a building the "negative" result, as when the building is used predominantly to harm people. One could use hacking tools to get around totalitarian governments or locked-down operating systems, or even to get into a former lover's device but at the same time prevent that exploit to be used anywhere else because of the bug's exposure. Even the "criminal" might be the good guy in the long run – morality is highly complex.
IT security really ends up most often in ambivalent, shades of grey territory, and not in the clear black/white contrast preferred by many people and especially law- and policy-makers.
It's nearly impossible to enforce something like this because of anonymous markets and crypto currencies, but we should at least shame people that advocate for it or admit to doing it.
Also, LA gangs used EV cars for modern drive-by's. Should EV cars now have a "gun tax"?
Think of the people with home automation systems, where they can press a button on their phone to turn the lights on and off in their living room. You are saying that they have installed a weapon. That is crazy. It could damage their washing machine, but so could a 2-liter of soda.