Responsible Disclosure Can Be Anything But
daeken.com
daeken.com
We have no way of knowing because he never attempted to do the right thing.
Then there's the matter whether Onity seems like a trustworthy company, that would do the right thing. A company whose ONE job is to make electronic locks, but still has an obvious security hole in their system is either 1. really stupid or 2. knows about it and has done nothing. A security whole in a beast like Windows (which main purpose is not security btw) I could understand and sympathize with. A lock is not nearly as complex. Either way I wouldn't trust them to do the right thing.
[1] http://www.forbes.com/sites/andygreenberg/2012/12/06/lock-fi...
I understand the various incentives for Onity, and I think a great incentive for them is, given six months to address the issue, knowing it'll be made public, to take at least some proactive steps such as notifying large customers or being ready upon public disclosure with a mitigation plan.
His whole blog entry is a lot of handwaving to cover up the fact that he never even gave them a chance to do something anything like the right thing.
That being said, I think this kind of thing should be covered by whistleblower protection laws (I don't know if it's ever been tested)... although it seems those are only enforced when it's convenient.
So while I think he may have reached the right conclusion, I don't think it was for the right reasons. If sufficient protections for disclosers are in place, this should be a relative non-issue (though it makes sense to adjust the disclosure window based on the ease and risk of the vulnerability in order to apply pressure for an expedited fix)
[1] Given there's no payout for the researcher other than having the vulnerability fixed, it is conceivably not too hard to defend against. That doesn't change the fact that they can be sued, which is expensive, time-consuming, and stressful.
Alternately, do so 'legal anonymously', perhaps by the EFF approaching the company and saying "we have in our possession information on a security vulnerability in your product. We want to give you information on it. In six months this information will be made public. We ask for and want no compensation or consideration at all."
That's it. There exist methods to do this safely; Daeken could have done it, and didn't.
I'm not paying a lawyer because you have broken software that I had nothing to do with making.
"The right thing" is carefully considering and balancing a variety of qualitative factors and guesswork (and to not expect much thanks in return).
I can only conclude he really does believe he did the right thing. I hope the people who's rooms were broken into see it that way too.
Why do you presuppose that its the right thing?
edit: In particular, I'd rather know that when I stay at a hotel with an Onity lock, I should take security precautions instead of remaining in ignorance. I would rather know that there's a general public pressure via the media to change from insecure locks to secure locks. I would rather that hotel managers know about this via the 6-o'clock news rather than in some mailing with a PR spin.
Consider the Therac-25 case and the problems the vendor exhibited in fixing it. That behavior is endemic, and I'd rather be a consumer in the know than trust to the chancy kindness of a corporation whose interest is not per se aligned with my personal interests.
I had no way of asking her if it was Onity after the fact, but whoever it was is actively working on the problem. It takes a bit longer to push out something to millions of non-networked devices than it does to just fix something on the App Store.
Our legal structure creates situations where the "right thing" sometimes has to be balanced against the potential for personal ruin, so it turns into the "rightest" thing given the circumstances.
"Dear Onity, I found a security problem in your product that will cost you millions of dollars to fix. Fix it now or I'll go tell the world about it."
I'd be afraid my car would blow up the next time I turn the key.
Also, slides for his talk at Blackhat: http://demoseen.com/bhtalk2.pdf
Even if crooks only very occasionally trip the specialized replacements, they would alert hotels to active exploitation, allowing either immediate apprehension or timely review of security footage. Shifting the risk/reward for criminals could buy time for a more complete but gradual fix.
Fixing just a few per hotel (perhaps 1 per floor), with a tripwire device that reports attempts at exploitation, might be possible at 1/100th the cost. (Most locks aren't even touched.)
Still, anyone exploiting the vulnerability at scale would soon trigger a tripwire. At the very least that lets the hotel know exploitation has begun, and it might help apprehend the burglars almost instantly.
I doubt crooks who think they have a master key will stop at just a few rooms. And once the use of the tripwires to catch a crook is reported, alongside the stories of the vulnerability itself, the expected return to this hack drops way, way down. Even criminals respond to relative risk/reward.
EDIT: Yep, you're right. I don't know how I missed that given that I skimmed the article twice. Sorry.
That's the very first thing on the list. Quote: "The standard 'Responsible Disclosure' approach would be to notify Onity and give them X months to deal with the issue before taking it public."