Watch how long it takes them to fix it then, and watch how reactive they become to responsible disclosure next time.
Also, short their stock before you go on TV. A little something for your troubles.
Watch how long it takes them to fix it then, and watch how reactive they become to responsible disclosure next time.
Also, short their stock before you go on TV. A little something for your troubles.
First, you have no idea what the manufacturer needs to do to fix the problem, alert customers, do recalls and recertifications, and the like.
Second, you put yourself directly in the line of fire unnecessarily and for all the wrong reasons. You could find yourself on the end of all kinds of legal trouble, and on top of that you would be morally culpable for any harm.
Do it the right way: get a lawyer. The lawyer will know how to contact the vendors, the regulatory agencies, media if necessary, and customers if necessary.
Because this is the world we should want to live in? Where you must pay a member of the protection racket to mediate publishing knowledge of someone else's extreme wrongdoing?
That is terrible advice. Its road ends with TORified disclosures of weaponized automated exploits, because as pure info sec has shown, that's the only way the message ever gets across when you give people the insulation to not listen.
Publicly demonstrating these exploits to an amicable media is the best idea I've heard yet, as they have straightforward real-world effects that can be easily illustrated. If certain manufacturers choose to send goons after you rather than fix their buggy products, then the community-accepted custom for them can change to psuedonymous press releases accompanied by a video with a (mock) live human subject.
Might be useful to distinguish between the ideal and the actual: in an ideal world, you of course shouldn't need a lawyer and the manufacturers should smilingly thank anyone who discovers an exploit and tells them. In this less-than-perfect world I'd suggest getting a lawyer and then going to the media.
Specifically, the above comment references having a lawyer handle (and moderate) what should be open technical communication with the manufacturer and regulatory agencies, the implication being that simply disclosing facts put you at grave risk from an endlessly complex legal system.
In this case, lawyers are more like mercenaries. Yes, you can pay them for protection, as you can a racketeer. The differences are that they don't come to you demanding money, and if you don't pay they won't turn around and hurt you, nor will anybody they're directly working with.
Some other lawyers may cause you grief; however, they will be working on behalf of some other party, not the lawyers you didn't hire.
You could argue that the legal system as a whole is a racket, but that's a different sense of the word.
2) I'm pretty sure that communication isn't the problem, the problem is that he want's to pressure them into fixing their mess, and that is exactly the point where things get messy from a legal perspective. I can hardly imagine a legal system in which a situation like this would be unproblematic.
This phrase and the article contain the same fallacy ( ("disclosing 0days when they can kill people"). I may be accused of semantic quibbling here, but I think it is important to state the issues clearly and accurately.
Information cannot kill anyone, nor exert any effects at all, ever. It is not causal. Actions using the information may be enabled by knowledge of the information, but they are human choices and not automatic.
This is not merely a matter of careless expression that does not affect the argument. In fact the fallacy is not only, or not exactly supposing that knowledge is causal, but rather in eliding the whole articulation of what happens between the revealing or acquisition of knowledge and the action that may or may not use it in some way.
The situation has a common element with the gun control issue: if someone has a gun, violence is easier, and this may be considered bad, but it does not excuse conflating the shooter's action with someone else's conduct of merely allowing that person to have a gun. It does not shift any responsibility from a competent adult actor to someone who merely allows a gun to be available.
Note also that the gun-possessor, or the person newly armed with knowledge, need not act on it at all, and those who confuse things by missing these distinctions manage to avoid the fallacy in those cases.
You mean like guns, toxins, and martial arts?
If you would find a recipe for a toxin that is deadly, untraceable and can be mixed together from common household items by a talented 14 year old, it's probably a bad fucking idea to post that to 4chan. The same goes for hypothetical weapon blue prints or martial arts techniques that would allow to kill with a microscopic risk.
Does this count as a straw man argument? Wouldn't the actual scenario would be more like disseminating the information that a deadly toxin that is deadly, untraceable, and can be mixed together from common ingredients exists, not the recipe itself.
It's important that people be aware of the risks they face, and seeking to silence that conversation is not helpful. If anything, it will create an environment where any perpetators might go unpunished because it's just implausible they did what they did.
If the company you're criticising doesn't like critics, doesn't care about bad PR, and has to feed their lawyers, you won't have a good time any way you do it.
Some rare occasions you might be better off with a strong public opinion supporting you and people coming out of the bush to help your case, than trying to do it the sneaky way and still get caught in a hell of legal troubles that not much people really heard of, and you get cast as the little guy trying too pull money from the big corp because of the narrative sold to the media by your opponent.
Major pro bono matters, or smaller cases with great
human interest, are far more likely to receive extensive
coverage. Holland & Knight, for example, received highly
favorable and extensive coverage of its work in the
Rosewood case, including a glowing front page, above the
fold, article in the Wall Street Journal and People.
Hogan & Hartson, similarly, received a great deal of
play in the media concerning its representation of
African-American plaintiffs alleging that Denny’s
restaurants had discriminated against them. In both
instances, the firms undertook these time-consuming,
controversial cases because it was the right thing to
do. However, their creative, successful lawyering
became a front-page story.Guns don't kill people...
Use the MedWatch form to report adverse events that you observe or suspect for human medical products, including serious drug side effects, product use errors, product quality problems, and therapeutic failures for:... Medical devices (including in vitro diagnostic products)
Hu?
I can see an argument that is is ineffective (maybe it just drops into the FDA bureaucracy), but I'm not sure how you can argue it is actually a barrier?
The FDA does actually have some pretty significant regulatory authority over medical devices. IANAL, but it appears this may be one of the limited cases where the FDA may actually be able to force a recall[1] as opposed to just requesting it. I suspect (and hope) the "recall" would actually be limited to a software update in this case. Even if they can't force it, a FDA-requested recall is a pretty significant thing.
[1] http://www.fda.gov/downloads/AboutFDA/Transparency/PublicDis...
That strikes me as really optimistic. Another scenario:
Medical equipment manufacturing lobby (I'm assuming there is such a thing) pushes to have such disclosures treated as acts of terrorism. Manufacturer issues a patch that fixes your very specific vulnerability in some trivial, meaningless way. Your career is ruined. Pacemakers truly secured: 0.
Yes, there is a lobby.
Let's say one of them panics out of fear, has a heart attack, and dies. The family reports this to the media. Now the news media is hunting you down. The authorities want to have a word with you, and you're the target of several lawsuits. Not to mention, you just killed someone with your flippant remarks. Technically speaking, the device manufacturer hasn't hurt anyone at this point. But you've contributed to the death of a person. Is that really what you're after?
Contacting a lawyer to understand the protocol for disclosure and the ramifications won't cost you anything for the initial consultation. Contact the EFF or ACLU and ask for advice. Ask them who you should contact next.
I agree that this could happen, but the obvious argument is that technically the device manufacturer did just kill their customers by 1) selling them a defective product; and 2) failing to take the opportunity to fix it when notified.
The whole idea is to handle this knowledge in the way that leads to the least hardship/pain/death. It's quite possible that a "stunt" like this is the best way, especially considering that there will likely be other less virtuous people making this discovery on their own soon.
I'm assuming no pacemaker owners were harmed in the finding of this vulnerability.
We should probably check first to see if BIOTRONIC is one of their advertisers first, might be an issue.
BIOTRONIC releasing the patch they should have released anyway, just to stop your evil scheme of murdering the elderly, turns into a PR win for them.
In short - media showing the potential results (and dramatizing them) puts heat on the company to fix it.
[1] http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/21...
http://www.secure-medicine.org/public/publications/icd-study...
http://en.wikipedia.org/wiki/Medical_Implant_Communication_S...