German gov plans software company's liability for damages caused by vulns
golem.de
golem.de
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
It's targeted at commercial proprietary software with disclosed and unfixed vulnerabilities. In other words, if you're knowingly selling software that materially harms your users, you're on the hook.
As an example: You're buying "Foo Professional" from MegaCorp. It contains an insecure version of Log4j. You're paying MegaCorp $500,000 per year for license fees. MegaCorp refuses to patch the used version of Log4j. With this proposal, you now have a legal basis for arguing that you _deserve_ a fixed version of "Foo Professional" unless MegaCorp told you clearly by which date "Foo Professional" expired.
I think that's a sensible way to think about it.
And yes, part of both the GDPR and the CCC proposal is effectively weeding out those whose business model is solely to undercut legitimate competition by putting their customers at risk of losing control of their data or of wasting money on products that are effectively a danger to their data sometimes not even a year after they were bought (looking at you here, cheap-ass Android phones).
I suspect that this is intended to be a single rather than double negative, or did you mean to assert that GDPR was universally recognized as a complete failure at limiting bad behavior?
It will not be enforced by an overworked regularly body, but by customers suing software companies.
No reason for the government to investigate proactively (as long as the government was not affected).
In one podcast I heard t hem compare it to software in cars where if there is for example an encoding error so all bluetooth connections are reduced to a low bitrate they won't fix it until the next version of the car is released
If this kind of regulation is the only way to make security part of the development process and chosen tooling and not am afterthought, so be it.
If that means we can't buy insecure IoT lightbulbs with no tls, no authentication and no sha checking for under $10, I guess we'll just have to live with it.
This is exactly the proposal that comes up every time HN discusses things like routers and IOT, which are frequently abandoned without updates despite critical known security issues. Well, now you know when you buy it that "updates will be provided through 2024". If the vendor fails to provide support through that date, the customers will have a claim against the vendor (i.e. it's not a situation of government enforcement, it's between you the customer and the vendor).
And again, the problem is, this is a tragedy of the commons situation. Bad actors who don't provide security updates provide fodder for botnets to attack the rest of us. At some point it becomes necessary to address that, and the way you do that is a measure like this one, to transfer liability to corporations who are "dumping waste" to avoid the cost of proper "software handling".
(also, the easy answer is - open source your software and it won't be an issue! that hypothetical router that a company now has to provide with security updates? just release your router with official DD-WRT/OpenWrt/Tomato support and 95% of your workload goes away.)
The CCC is in favor, and they're not exactly computer-illiterate nobodies, or against innovation in software. Something really has to be done about software quality, or the Internet Of Shit is going to ruin the internet for good.
Engineers that design bridges and buildings are liable when these structures fail and cause damage or loss of life. Lessons-learned are critical to ensuring corrective actions are taken to ensure similar failures don't happen in the future.
Software development has almost none of that. The lessons of the past are relearned on an apparent two to four year cycle.
"Most of you," says Vyssotsky, "probably recall pictures of 'Galloping Gertie,' the Tacoma Narrows bridge which tore itself apart in a windstorm in 1940. Well, suspension bridges had been ripping themselves apart that way for 80 years or so before Galloping Gertie. It's an aerodynamic lift phenomenon, and to do a proper engineering calculation of the forces, which involve drastic nonlinearities, you have to use the mathematics and concepts of Kolmogorov to model the eddy spectrum. Nobody really knew how to do this correctly in detail until the 1950s or thereabouts. So, why hasn't the Brooklyn Bridge torn itself apart, like Galloping Gertie?
"It's because John Roebling had sense enough to know what he didn't know. His notes and letters on the design of the Brooklyn Bridge still exist, and they are a fascinating example of a good engineer recognizing the limits of his knowledge. He knew about aerodynamic lift on suspension bridges; he had watched it. And he knew he didn't know enough to model it. So he designed the stiffness of the truss on the Brooklyn Bridge roadway to be six times what a normal calculation based on known static and dynamic loads would have called for. And, he specified a network of diagonal stays running down to the roadway, to stiffen the entire bridge structure. Go look at those sometime; they're almost unique.
"When Roebling was asked whether his proposed bridge wouldn't collapse like so many others, he said, 'No, because I designed it six times as strong as it needs to be, to prevent that from happening.'
"Roebling was a good engineer, and he built a good bridge, by employing a huge safety factor to compensate for his ignorance. Do we do that? I submit to you that in calculating performance of our real-time software systems we ought to derate them by a factor of two, or four, or six, to compensate for our ignorance. In making reliability/availability commitments, we ought to stay back from the objectives we think we can meet by a factor of ten, to compensate for our ignorance. In estimating size and cost and schedule, we should be conservative by a factor of two or four to compensate for our ignorance. We should design the way John Roebling did, and not the way his contemporaries did-- so far as I know, none of the suspension bridges built by Roebling's contemporaries in the United States still stands, and a quarter of all the bridges of any type built in the U.S. in the 1870s collapsed within ten years of construction.
"Are we engineers, like John Roebling? I wonder."
[0] https://www.seltzer.com/margo/teaching/CS508.19/background/p...
Yes.
More than that, anything that has a backdoor or a "default password" should be viewed as being at least criminally negligent or outright criminal.
I'm pretty sure that's not true, at least not in practice.
Not even once have I read about an engineer being liable for a failed bridge.
But I'm open to being educated.
Can you point to a single case, in US, of an engineer being liable for a failed bridge?
Who found them liable (federal government? state government?) and what happened after they were found liable (a fine? jailtime)?
The architects were acquitted in the end ( who knows why, it was as clear cut as possible), but the company lost its engineering licenses.
The german text:
Der CCC fordert dort eine "Haftung bei unkorrigierten oder gehäuften
IT-Sicherheitsproblemen inklusive einer Versicherungspflicht,
zwingender Angabe eines Verfallsdatums [...]Other profession had hundreds of years to mature, but software will not be allowed time to grow.
And this is how, I believe, AWS will become kind of required, as it will be the only way to get a certified-up-to-date version of a Linux, of a database, of a library, etc. And programmers will only be responsible for the glue code between those services.
Which is ok. (As long as you don't claim that it's something it's not.)
And it's also ok for a company to actually use your blueprint (ignore copyright for a moment).
The problem is if a company uses the hobbist blue print without verifying that it fulfills necessary requirements, like being safe in case of an earth quake.
https://www-oern-pt.translate.goog/v-0C0J0H/informatica?_x_t...
Not being a Mechanical Engineers doesn't prevent building the car and putting it on the road, provided the regulations are met.
And if something happens to someone else with that car, the one building it is also liabiable, provided it was caused by a construction error.
However not having an Engineering license doesn't forbid it to being built.
Many programmers are factory workers, plugging software libraries, that is why open spaces are organized like the mills from industrial age, or the offshoring sweet shops exist.
Dev doing a successful OOS project in his spare time is something that fortunately still happens. Dev doing a successful OOS project _and_ accepting liability for potential mistakes is something I really expect to see less of.
Plus don't forget the death by a thousand papercuts. If you have this regulation, and that liability, and who knows what else - this is a very time-tested pattern: it raises barriers to entry in an industry and favors large, incumbent companies. Paying a lawyer is a small price to be sure that you can't have competitors smaller than that.
And it's kind of cute how SAP now fits in Microsoft's pocket.
Sooner or later this will be an EU proposal anyway like the GDPR.
> The more they trip themselves up, the longer the US can easily keep its crown and the trillions of dollars that go with it.
A lot of the success of the US tech giants is built upon the cost of people suffering in a myriad of ways, from the cost of following up with data thefts to literal death from exploitative working conditions. European countries - while not perfect - tend to value their citizens a bit more than the US... and if the US continues on its current path, it may very well see the consequences of dissatisfied citizens. The election of the 45th President was only the beginning of what may happen.
I have mixed feelings about a law like this but I can't say I don't agree with something like this as a principle for paid software. Maybe liability will reduce the number of backdoors in software that we pay for. As for FOSS projects on github and such, there is no contractual obigation of any kind as long as you don't see lic's or stuff like that. That being said... I've heard some horror stories that defy common sense so wouldn't be surprised by anything.
This is not draconian to reasonable software firms and is analogous to structural/civil engineering.
a) not look for vulnerabilities
b) if they are found anyway, to not classify them as vulnerabilities (but regular bugs)
Then what? Relying on unpaid people to find and disclose vulnerabilities?
And what about all the people who think that they found a vulnerability but didn't? Consider that there are US senators and governors that think reading HTML code is hacking.
What bureaucracy will we have to build to decide what is and isn't a vulnerability?
This is Germany. Lots of software companies already do this type of work with SOC2 or FedRamp contracts.
A vuln is typically reported to NIST and assigned a CVE record. That 3rd party system allows for embargo, publish, dispute, etc. If a manufacturer denies that is is a vuln, the researcher can release their work and malicious actors could prove the manufacturer wrong. I work in cybersecurity, so this isn’t new to me. Maybe it is new to you… ?
These companies already have reasons not to look for vulns. IMHo they need more incentives (eg. Regulator/economic pressure) to look for them.
My guess is that this rule is being pushed in the aftermath of Log4j, which is a publicly identified CVE/vuln, but which is compiled/linked into other products. Any proprietary product which uses a known vuln in their software supply chain should have to either fix it (by releasing a patch) or make a public statement that the upstream vuln does not create a software vuln downstream or suffer liability. This already happens with companies/products that do this with large contracts.
The Missouri Governor is a political stooge, but his Department of Justice is prosecuting what the journalist did after he took the PII that was embedded in the page. We will have to wait to see if that was legal. I suspect he took a SSN that was in the page and used it to fill in a web form, which could be prosecuted as fraud. That would be an example where good faith efforts by security researchers should be exempted from prosecution, but has no relevance to this German proposal.
Your complaints seem to be extremely defensive/reticent. I think such posture is only useful if you also consider the value
The keyword here is "fahrlässig" (translates to negligent). Whoever is damaged must be able to prove that a bug caused through your program was negligent. I myself have tons of weekend project that have no stakes at all (most are libraries that are used by essentially no one and I make $0 from all of them combined) and even there I spend a little bit of time keeping dependencies up to that. With the few bug reports I get I at least look into them. It will be very hard to extort any money out of me under this law.
If you are running a startup and making money you will need to allocate resources to maintenance, stability and bug fixing.
Yes such which are dependent on their party software components they pay for.
Like companies using payment system plugins.
Or smaller laptop/computer/smartphone manufacturers.
Another much more chilling question is what happens to FOSS projects? Is Germany going to start going against every software developer that uploads an MIT licensed package on Github? What about the Log4j vulnerability who is on the hook for that?
I agree security needs to be taken more seriously and we need to step up our game, but I grow concerned when the government starts making broad laws like this.
If you go by the proposal, FOSS and Open Source is out of scope. In the case of Log4j, companies knowingly selling software that contains in insecure version of Log4j now need to own that defect.
Doesn’t help your local restaurant if they didn’t get the memo about the poisonous scallops, particularly if there existed a regular scallop-poison-level newsletter they could check.
Regarding the start-up argument, the amusing upshot ( for Germany ) of this is that they get software that has been already beta tested in US ( think Tesla autopilot ).
Judging by the CCC statement, this is more intended for cases of negligence in face of known security problems. It specifically says "unkorrigierten oder gehäuften IT-Sicherheitsproblemen" (uncorrected or accumulating/amassed it security problems).
Is it users? It can’t be. They aren’t engineers, and even the users who are don’t have access to our source code.
Is it the government? No.
Is it … nobody? That sounds like a terrible idea.
The only people left are us. The company or team who ships a product.
This is the same as everything else in civilisation. I’m responsible for food I sell. If I sell you poisoned food, you can sue me for the harm my food caused. If you hire me to build a house, I’m responsible for making the house safe. If the house falls down and injures you, you can sue me for damages. The general principle is that we are responsible to our neighbours insofar as our actions could foreseeably hurt one another. Lawyers call it Tort Law and frankly it makes sense.
Why should software be exempt?
As for opensource - if you pull in a random (free) MIT licenced piece of code on GitHub, one of the license conditions is that you take all responsibility for the software. The opensource dev isn’t responsible and (I am not a lawyer) almost certainly wouldn’t be held liable for bugs.
No amount of regulation will save users from installing a hundred of toolbars if they want to do that.
But it will hinder legitimate programmers from publishing useful software (especially free and open source software).
Would you except restaurant-goers to be liable if they get poisoned? Now compare that to picking your own mushrooms, or dumpster diving. Part of the deal when you start charging for something, has to be that the customer can expect the product to… work.
How are users supposed to vet all the software we run? How are you supposed to know that a compiled binary from Wacom snoops on your computer? That gmail - or, worse, some random startup has no security vulnerabilities?
Users don’t have time to read the source code for every product. Even if they did, we don’t have the source code for most software on our devices. And even if we could get that, we don’t have access to any of the code running on someone’s web server.
Saying users are responsible is the same as saying nobody is responsible.
The only way a user can take responsibility is to refuse to use products and services from startups & young companies who don’t have a reputation yet. And if people feel the need to start doing that, it’s bad for everyone.
Obviously the companies are responsible for the stuff they make.
If companies make crappy software or groceries stock rotten vegetables the invisible hand of the market will take care of it and put them out of business.
This law, while well meaning, has obvious side effects that might make things worse than they are today.
Most importantly it creates an incentive for companies to create a culture of not looking for vulnerabilities. If they have a vulnerability they don't know about, they are fine. If they do know about it, they are potentially liable.
Then there's the issue of who decides what is a vulnerability. And if you think that's obvious just read "The Old New Things" blog for many examples of "vulnerability" reports that boil down to "If I can run program with admin privilege's, I can do bad stuff". Or look at US senators and governors who think that looking at HTML is hacking.
Finally, not of that is free. Government doesn't make money, it takes it from you. So when we create new regulation that require more government employees, you're paying for it, indirectly.
The FDA has 18,000 employees. The USDA has around 100,000.
The problem with IOT, routers, etc with unpatched vulnerabilities are much more akin to dumping toxic waste or spewing smog than a grocery equipment supplier making poor-quality goods. A grocer would naturally choose equipment that didn't fail and cost them inventory, but unpatched devices affect all of us, even the ones who didn't choose to purchase that equipment. And far from the invisible hand of the free market shutting them out, it actually tends to encourage this behavior (absent regulation) because it's cheaper to dump the waste in the river (not patch your known-vulnerable commercial software) than to pay to have it handled properly, and the market generally favors cheap above all else. It's a classic tragedy of the commons situation, and that's where regulations are important.
> Then there's the issue of who decides what is a vulnerability. And if you think that's obvious just read "The Old New Things" blog for many examples of "vulnerability" reports that boil down to "If I can run program with admin privilege's, I can do bad stuff". Or look at US senators and governors who think that looking at HTML is hacking.
Uh, MITRE already does that. The CVE list is a thing that exists, it works well and isn't filled with a bunch of nonsense. Some blog being bad doesn't mean there's no way to systematically track vulnerabilities and their severity.
This is nonsense throwing up your hands "who can, truly, know anything!?". We can, and we already do.
> Finally, not of that is free. Government doesn't make money, it takes it from you. So when we create new regulation that require more government employees
The beautiful thing is, this isn't about the government enforcing these regulations - this is about creating a civil claim by the customers of the business. The business will provide a support window for critical security vulnerabilities, and if they fail to meet it, they're liable just like any other support contract. It's a free market solution, in fact!
I'm not sure about that. The startup culture is different but not necessary worse.
The main pain point would be that you must get taxes right
and maybe that the system favors more substainable startups then moonshots which mainly hope to be bought for absurd prices by monopolistic companies.
> FOSS
Isn't sold (normally) so shouldn't be affected (in the common case).
Instead the company using it is responsible. Like using open source without vetting or potentially fixing it, is like using a building blueprint you found on the internet without vetting or fixing it.
This should favor companies using open source more responsible and payed support contacts.
That's is if any law resulting from this is properly done.
[1] https://learn.adacore.com/courses/intro-to-spark/chapters/01...
"At the urging of the aviation industry, that believed the airplane could not reach its full commercial potential without federal action to improve and maintain safety standards,[citation needed] President Calvin Coolidge appointed a board to investigate the issue. The board's report favored federal safety regulation.[10] To that end, the Air Commerce Act became law on May 20, 1926.[11]"
[0] https://en.wikipedia.org/wiki/United_States_government_role_...
229 If a builder builds a house for someone, and does not construct it properly, and the house which he built falls in and kills its owner, then that builder shall be put to death.
- Code of Hammurabi, ~ 1700 BC [0]
Free market without any regulation whatsoever can absolutely work to the detriment of society.
https://www.ncsl.org/research/financial-services-and-commerc...
The HHS regulates public health at the federal level. It has around 80,000 employees.
https://www.hhs.gov/regulations/index.html
https://en.wikipedia.org/wiki/United_States_Department_of_He...