Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’
Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’
If you're a well lawyered security researcher this is probably fine.
If you're some IT related person that does something else as your primary job this may or may not be fine if the FBI shows up and starts asking lots of questions about all kinds of things.
This is exactly what I tell my coworkers who are getting into security. Keep your mouth shut about anything you find unless you have a reporting channel that leads to a "well lawyered" security company.
I've found vulnerabilities that I would have loved to disclose, but being a lowly IT generalist, I'm not going to stick my neck out. I can't imagine my employer would like the press.
I use one-off email addresses at my personal domain and historically warned companies that I was seeing spam to one-off addresses as possible indications of a data breach. By and large I was ignored, but occasionally I received a word of thanks. Even more occasionally I received notes of thanks that, in fact, I had uncovered a data breach.
Once, however, I received a nasty response insinuating that I'd breached their systems. The person I contacted didn't, apparently, understand what I was saying. They were confused that their company name was to the left of the "@" in my email address.
That was enough for me. I decided I was done reporting those events. Too much risk.
For the uninformed, how does spam to an address on your domain indicate a breach of someone else's system?
Years pass.
I start receiving email solicitations for erectile dysfunction remedies and, oddly, woodworking plans (what is it with the spam for shed plans?) to that address.
Either my address was sold or a data breach occurred.
(It could have been my own data breached, but it seems unlikely, if that did happen, that the result would be me receiving spam only to that one specific address.)
If I am a person interested in how these systems work, and maybe making some money off my work in the area, this sort of threat, both its severity (potentially years of costly litigation and or/jail) and how frequently it happens (seems we read of such incidents many times per year, which is only the tip of the iceberg) would make someone seriously question the straight white-hat path. Why not find the exploits and sell them on the dark web? One might even justify it with "they wouldn't listen anyway and it's their fault for releasing a system with such stupid vulns." and/or "they'll fix it only when they see real-world consequences and if they don't it doesn't matter". One's moral compass need not be very compromised to lean on such excuses.
There REALLY needs to be a Safe Harbor law with basic requirements that the work is documented, first revealed to the company security dept (perhaps citing the Safe Harbor law?), no action taken by the researcher to allow it to be disclosed or released publicly for 90 days, and perhaps a few other reasonable safeguards.
and how often it happens
Certainly. What I’m saying is that it should be cheap or free to neutralize their threat. There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.
Who's going to check it to make sure that "your responsible disclosure letter" actually is a responsible disclosure letter and not just nonsense?