The IT security culture, hackers vs. industry consortia
laforge.gnumonks.org
laforge.gnumonks.org
1. The impetus in the academic research community is to disseminate, not hide. Likewise, most research is not considered a one-off but a progression. I highly encourage looking at writings by CS research leaders like Simon Peyton Jones and David Patterson on their approach to having shaped large areas of computer science for the last 30+ years. Reasons include improving your own understanding, improving how you present it to others, and getting others engaged.
2. There is a personal bean counting aspect that some researchers are stuck with that limits where they do the first conference publication. They care due to particulars of the promotion process, e.g., tenure, which is in turn subject to publishing rules for academic conference & journal papers around minimal publish units. None of that applies here.
HOWEVER, the author is clever here! As the point is to disseminate & improve, by taking an unusual position and writing about that, they've achieved the goal.
And final caveat: the non-academic security researchers are among the few that (a) has individuals making up and following personal ethics and ignoring internal review board (IRB) etc. regulations that scientists are required to follow and (b) are fearful/surprised of getting their results buried, most of the time (but not always) IMO as a result of that.
Sounds like a Responsible Disclosure kind of thing to me. However, they didn't just ask for the research, they requested additional work in the form of a presentation. That's labor for which there should be compensation. Further, a contract with this potential client that explicitly prevents the client from blocking other presentations and publications; perhaps even barring this client from speaking publicly about the research and what you've found any time before your public presentation. They need to cover the legal expenses for the researcher as well.
So you give them a price to get this advance presentation. Maybe you offer an olive branch (and maybe you label it "responsible disclosure") that they might also have access to the research itself before publication.
Or maybe you tell them to stick it and go public on your own schedule and throw this industry group under the bus. But that seems like destroying the canyon wall before any bridges could even be built (let alone burning bridges that may have already existed...)
I think it's totally reasonable to demand compensation for private presentations (else, why not just have the company attend the CCC talk?).
I think if you've got Stallman-esque purity, it's reasonable to refuse on principle: you don't want to do anything to help un-free software.
But I don't see any such coherent reasoning here.
In this particular case, though, I do detect a principle from the author even though you don't. The gist of the article seems to me to be that the GSMA is seen as a "bad guy" with corporate self interest first over public good and their interest in the talk is to get info (unsaid but presumably to give grounds for an injunction) rather than to get patching...?
I'm not seeing the conference participants as the "bad guy" if they wanted the hacker to teach them about the problems. I'm not going to say the hacker was the "bad guy" either so much as taking a selfish strategy that only reinforces the problems they research and present on.
If he had approached them cold it may have been a different matter, but that's not what happened here.
You can't "threaten" someone by refusing to give a presentation to them.
The takeaway, for me, was that the industry group seemed to have a very entitled attitude. I wonder how the author would have reacted if approached for a paid speaking engagement.
I don't do security research, but I can understand the motivation of putting my own interests (be they reputation, or getting paid) ahead of public interest. If I don't put myself first how is my work sustainable?
Maybe. At many such conferences, the attendants or their company actually pay to go there for the benefits of the conference. I'm not sure if the speakers at telecom conferences get paid outside the salary their companies' already pay them. If not, it's unsurprising that the guest speaker wasn't offered money given the conference organizers might see attendance itself as payment given the perceived benefits to networking, reputation, or career progress.
I find there are quite a few folks in security who tend to be glory-seeking drama queens.. More than you might find in mainstream IT/Development. There are still plenty of good ones though, who silently discover and squash with little fanfare. Not sure what that is.. I guess it runs a similar vein to all of those disgruntled angsty network engineers as well.
I'm curious if other industries have similar role associations with character traits (e.g.: product safety, FDA, OSHA inspectors all being disgruntled negative nellies)?
This is where the researcher needs legal advice and a contract with the client. Sure, do the private presentation, but make sure you have a contract that says the interaction with corporate staff in no way prevents the researcher from presenting the findings publicly.
That said, it might be a nice way to test the waters with them to understand their actual agenda. IF you said, "Sure I'll come and give you a talk but you need to all sign and say you will take no action to prevent my talk from happening in the future in public." And if they refuse to sign such a stipulation then you have your answer on their motives.
Note that if that is in fact what they were trying to do, and you "gave away" that you knew what they were trying to do, it might just force them into action anyway even without a lot of evidence that the talk would harm them.
Note that their promise not to push for an injunction holds little meaning, since if a transcript or recording was passed on to some corporation not so pledged, that corporation could still press for the injunction. The way to be discreet is to be discreet.
Note: These hackers don't represent hackers in general. Many if not most bug hunters are more than happy to tell the suppliers what they found. I'm only focusing my comment on those with opinion similar to author.
The only concern I'd have is they try to prevent the CCC talk with legal action after the presentation scares them shitless. I don't know what the odds of that are for telecoms or CCC talks. I know companies occasionally try to block a damaging talk in the States. I'd ask for a contract from participants saying they wouldn't block the talk or sue me over discussing any flaws I found in my work. If they refuse, I'd offer to deliver them a presentation in video through email or posted to that conference's web site after CCC. Alternatively, show up at next years conference at their expense to deliver an even better talk.
Via email, im assuming.
>>Who am I?
One of the authors of osmocombb and OpenBSC, two tools that have enabled foundational research into vulnerabilities in mobile networks.
>>Am I spending sleepless nights and non-existing spare time into security research of cellular modems to give a free presentation to corporate guys at a closed industry meeting?
I doubt anyone has that expectation. Harald has created a penalty for asking if there are disclosures that need to be addressed.
>>The same kind of industries that create the problems in the first place,
Has open source eliminated security vulnerabilities in software?
>>and who don't get their act together in building secure devices that respect people's privacy?
Is the situation getting worse, staying the same or getting better over time? I can confidently argue better.
>>Certainly not. I spend sleepless nights of hacking because I want to share the results with my friends. To share it with people who have the same passion, whom I respect and trust. To help my fellow hackers to understand technology one step more.
That reasoning is what it is I guess. I don't agree with the clique approach, but I respect him for being so blatant about it.
Good for the GSMA. Change at scale is hard. It takes time. Some of these coference presentations help motivate change(stagefright comes to mind)... Lead time helps the workerbees get executive alignment to invest in fixes. It is better for everyone that they at least tried to get some information for marshalling a response. Not all presentations are as serious as their title or abstract suggest. I guess we learned where Harald's priorities lie.
Not giving a presentation ahead of time could be viewed as reducing the chance of suppression.
He's been around long enough to know this issue as well. I think it is fair to infer the risk of legal entanglement did not influence his decision by the fact that he didn't bring it up.
The way I read his blog post, his main point seems to be about behavior that reflects being a part of a scene or culture that embodies certain passion and values.
Some quick tips:
* get everything in writing;
* make sure there's not a clause, agreement, etc that prevents you from presenting it elsewhere;
* make sure to clearly say what they're allowed/not allowed to do with the presentation - record? share slides internally? publicly share everything?
* clearly document that you continue to own everything 100% - (slides, code, etc);
* get compensation - I'd suggest travel, two hotel nights, per diem for meals, and at least one daily fee on top (travel+presenting is possibly 1.5-2 days);
* make sure you understand what any non-disclosures cover and for how long.