We have no way of knowing because he never attempted to do the right thing.
We have no way of knowing because he never attempted to do the right thing.
[1] http://www.forbes.com/sites/andygreenberg/2012/12/06/lock-fi...
I understand the various incentives for Onity, and I think a great incentive for them is, given six months to address the issue, knowing it'll be made public, to take at least some proactive steps such as notifying large customers or being ready upon public disclosure with a mitigation plan.
His whole blog entry is a lot of handwaving to cover up the fact that he never even gave them a chance to do something anything like the right thing.
That being said, I think this kind of thing should be covered by whistleblower protection laws (I don't know if it's ever been tested)... although it seems those are only enforced when it's convenient.
So while I think he may have reached the right conclusion, I don't think it was for the right reasons. If sufficient protections for disclosers are in place, this should be a relative non-issue (though it makes sense to adjust the disclosure window based on the ease and risk of the vulnerability in order to apply pressure for an expedited fix)
[1] Given there's no payout for the researcher other than having the vulnerability fixed, it is conceivably not too hard to defend against. That doesn't change the fact that they can be sued, which is expensive, time-consuming, and stressful.
Alternately, do so 'legal anonymously', perhaps by the EFF approaching the company and saying "we have in our possession information on a security vulnerability in your product. We want to give you information on it. In six months this information will be made public. We ask for and want no compensation or consideration at all."
That's it. There exist methods to do this safely; Daeken could have done it, and didn't.
I'm not paying a lawyer because you have broken software that I had nothing to do with making.
Why do you presuppose that its the right thing?
edit: In particular, I'd rather know that when I stay at a hotel with an Onity lock, I should take security precautions instead of remaining in ignorance. I would rather know that there's a general public pressure via the media to change from insecure locks to secure locks. I would rather that hotel managers know about this via the 6-o'clock news rather than in some mailing with a PR spin.
Consider the Therac-25 case and the problems the vendor exhibited in fixing it. That behavior is endemic, and I'd rather be a consumer in the know than trust to the chancy kindness of a corporation whose interest is not per se aligned with my personal interests.
"The right thing" is carefully considering and balancing a variety of qualitative factors and guesswork (and to not expect much thanks in return).
Our legal structure creates situations where the "right thing" sometimes has to be balanced against the potential for personal ruin, so it turns into the "rightest" thing given the circumstances.
Then there's the matter whether Onity seems like a trustworthy company, that would do the right thing. A company whose ONE job is to make electronic locks, but still has an obvious security hole in their system is either 1. really stupid or 2. knows about it and has done nothing. A security whole in a beast like Windows (which main purpose is not security btw) I could understand and sympathize with. A lock is not nearly as complex. Either way I wouldn't trust them to do the right thing.
"Dear Onity, I found a security problem in your product that will cost you millions of dollars to fix. Fix it now or I'll go tell the world about it."
I'd be afraid my car would blow up the next time I turn the key.
I had no way of asking her if it was Onity after the fact, but whoever it was is actively working on the problem. It takes a bit longer to push out something to millions of non-networked devices than it does to just fix something on the App Store.
I can only conclude he really does believe he did the right thing. I hope the people who's rooms were broken into see it that way too.