Scientist banned from revealing codes used to start luxury cars
theguardian.com
theguardian.com
http://www.cypherspace.org/adam/shirt/uk-shirt.html
Or turn some portion of it into a flag?
http://en.wikipedia.org/wiki/File:Free-speech-flag.svg
Maybe he can get Bob Dylan to write a song with the codes and perform it live to a group of hackers. The possibilities are endless when knowledge is arbitrarily outlawed due to an inconvenience for the privileged. Then again, this is the UK where the first amendment doesn't apply.
I suppose the lesson here is: honor and honesty gets you in hot water when you deal with people who have lots of money. Better to make the devices in your garage and sell them to criminals. I'm sure this paper isn't the thing holding criminals back from making them anyway... anyone who's looked at their key-fobs knows they aren't exactly high security RSA encrypted signals. ( http://hackaday.com/2010/07/13/key-fob-programming/ )
The problem is, as long as it was a physical object it was all fine, sort of atleast. You could put anti tamper mechanism (like safes with relockers) that would destroy the core technology/secret if someone tries to pry it apart. But with computer code and mathematics, it's guaranteed that the attacker/pryer is able to make millions of duplicates at zero extra cost. So if approach #564 doesn't work, all he has to do is cp ../downloads/file ../project/reverseengineer/ and boom he has another copy to work with.
The only thing holding an intruder out of a system is the solidity of the mathematical concept that system is based on. And now that the intruder knows that there's a break, and that he potentially will gain a lot by discovering it, he can continue unhindered.
Obviously I'm preaching to the choir, but if you've encountered such people you should give this analogy. In the real world, the guy needs to buy your widget each time he fails to reverse-engineer the anti-intrusion mechanism, but if he were able to make a 100% replica copy of the widget and work on that copy he could try everything. So if he fails once, he'll just make another copy and try a new approach at opening your widget. He knows it's broken, and there's no real extra "cost" associated with duplicating the widget to try again, there's literally no stopping him until he gives up.
Another thing that crossed my mind was this. The manufacturers would want to keep this knowledge (i.e. that the exploit exists) secret, but ~~if~~ when he discovers the backdoor, do you want to be considered responsible for your car being stolen instead of the manufacturer for the manufacturer's mistake? Would you not prefer that the manufacturer calls you and recalls your car to the garage and replace it with a better part? It's a shame because Bentleys, Porsches, and Audis are NOT cheap. You're paying for the name, and at times like this, when the name comes under fire they should do something and stand by their customers instead of against them.
So we transform "Researchers are able to unlock Ford car given they have few hours to bruteforce and a laptop an a secluded place" to "Research that is so dangerous, the court outlawed it"
(also discussed on HN a month back: https://news.ycombinator.com/item?id=5826486)
The professional criminals are affiliated with syndicates and mafias have money and resources. They can hire the talent able to figure out decoding these trivial radio signals.
I don't expect even older radio access systems to be that simple to abuse. For example this application note from Atmel[0] describes such a system. It uses an AES-based MAC and a rolling window counter to prevent message spoofing and replay. I wouldn't bet this implementation is actually secure, but it's not so trivial to attack.
Please note I'm not saying that criminals haven't abused vulnerabilities in these systems, just that it's not a simple matter of 'decoding these trivial radio signals'.
[0] http://www.atmel.com/images/atmel-2600-avr411-secure-rolling...
Lots of eyeballs on this and the fact that the exploit stays "monopolized" is poised to drive its price on the market up.
The way I interpret this, the manufacturer has thrown a backdoor into the system, allowing access to anyone who knows the backdoor key - and the researchers have managed to extract the backdoor key.
I think dangerous information in general should be censored, though that is a very dangerous road to go down. But if it was possible to do so without corruption or having good things censored too, then I think it should be done.
Even though this scientist first discovered the vulnerability, it doesn't mean that someone else won't do so in the near future.
It's nothing new and has been around for a while. I've worked for 3 years at one, very exciting job!
Yeah right, like the theorized "sophisticated gang" can't break into and steal the paper/research. Or, more easily kidnap/extort/blackmail/bribe scientists to give them the info.
Criminalizing information means only the criminals will have access to it.
Here's what Blackstone's commentaries had to say about it in the mid-18th century:
The liberty of the press is indeed essential to the nature of a free state; but this consists in laying no previous restraints upon publications, and not in freedom from censure for criminal matter when published. Every free man has an undoubted right to lay what sentiments he pleases before the public; to forbid this, is to destroy the freedom of the press; but if he publishes what is improper, mischievous or illegal, he must take the consequences of his own temerity.
It's true that the U.S. version of the doctrine has developed in a much stronger form, however.
Then again if they start enforcing it like piracy with ridiculous fines and jail time they best researchers would be criminals.
£50,000?! Good Lord, that's a lot of money! All one needs is a microscope and a razor.