[1] http://tweakers.net/nieuws/101472/lenovo-overtreedt-wet-met-... (lang:nl)
Lenovo didn't just sell something with broken security. It purposely broke the security, and profited from it.
Did they inform their customers in advertisements, in the stores, or in any way that sold devices was being used by Lenovo after sale? Were there a meeting of minds where customers agreed to have their traffic MiTM and have advertisement of Lenovo choice on their device in return for fair compensation? That could have made it legal, but as it stand, no aspects of consumer protection laws, advertisement laws, contract laws, computer crime laws, or data protection laws seemed to have be followed.
They secretly snuck into peoples private property, used a backdoor, and earned profits doing so. They didn't tell anyone for obvious reasons. Had it been a one-man company doing this, then that person would be facing jail time.
In the Lenovo case, probably not. But in the case of an employer-provided system and network intended for business purposes which performs SSL interception for security and data leak prevention? I think it can clearly be considered reasonable for the company to do that, and the user's expectation of privacy is significantly different. I do feel it's important that Acceptable Use Policies, Employee handbooks, etc. disclose the activity though.
a) selling capability to advertise to you, without your real consent, and
b) when the do it, the implementation is so horribly broken that it exposes end users to be exploited by just about anyone.
I see little malice, I see a lot of incompetence and outright, unforgivable stupidity. This opens door to the malice of others.
Choice quote: The settlement requires HTC America to develop and release software patches to fix vulnerabilities found in millions of HTC devices. In addition, the settlement requires HTC America to establish a comprehensive security program designed to address security risks during the development of HTC devices and to undergo independent security assessments every other year for the next 20 years.
[0] http://twitter.com/JustinBrookman/status/568466666771910657
Here's a screenshot of what their MitM proxy provides back to the browser for a compromised connection to Bank of America:
https://defaultstore.com/four.png
Note that my MitM proxy cert is one gen'd with OpenSSL and is not the Superfish private! While it's cool that the private can be extracted, given the failure of the Superfish software to properly validate the public in the SSL/TLS handshake, the Superfish private isn't something a bad guy needs to get in the middle of encrypted traffic.
Maybe the cost of a security audit required as a consequence of this issue might qualify - I don't know. But there would have to be actual costs involved.
Ok, googled it, wait for it... "As I understand it".
Whew!
Incidentally, I didn't understand this one, but I don't blame OP (oops, I mean 'original poster') for misunderstanding the linguistic norms of HN (hacker news).
Similarly, compare "(c) 2015 philh" to "this post is copyrighted by philh, as of 2015".
So, basically what you're saying is that I can secretly take nude photos of you (when you're not in a public place), and "enjoy" them (in whichever manner) but not share them with the public, and you can't sue me unless you can demonstrate my actions actually costed you money?
However, depending on your jurisdiction that may be a crime. In that case, I or the state might be able to prosecute you under criminal law. I don't generally understand that to be within the meaning of "sue" though. And, again in general, criminal conviction leads mainly to punishment rather than reparations to the victims.
Oh, and exceptionally, if I'm your "model" then without me signing an appropriate release I own copyright on your photos, so I may be able to sue you for losses (probably to the value of you buying an equivalent market-rate DVD or something).
You sure about that? AFAIK the copyright is with the creator, i.e. the photographer. Model release is required on for privacy purposes, not for copyright.
1.http://www.theguardian.com/technology/2014/aug/22/monkey-bus...
I'm no lawyer, but as I understand it, you sue people under civil law for some kind of compensation - for financial loss, loss of reputation, psychological consequences, etc. Your voyeur example would hopefully fall under criminal law, which deals with the things society considers morally wrong. But a criminal trial would be prosecuted by the government, not by you suing.
Those damages may be minor -- you don't have to have killed anyone -- but they have to exist.
If, in your example, GM only installed the worn out brakes on that one car, and the worn-out brakes never caused any damages, then no, GM cannot be sued for it.
Note that "I had to pay a mechanic to replace the brakes" is damages.
I am not a lawyer, this is not legal advice, I may be wrong, etc.
But in this case, there is good precedence for claim of damages. People has used time it have taken a engineer to investigate, clean, and fix a computer system after a computer intrusion. Even a few hours work will result in several thousands, much more than the laptop itself is worth.
The offence of unauthorised access requires proof of two mens rea elements, (see section 4 CMA):
(1) there must be knowledge that the intended access was unauthorised; and
(2) there must have been an intention to obtain information about a program or data held in a computer - section 1(2) CMA.
[0] http://www.cps.gov.uk/legal/a_to_c/computer_misuse_act_1990/[1] http://en.wikipedia.org/wiki/Donoghue_v_Stevenson "it was reasonably foreseeable that failure to ensure the product's safety would lead to harm of consumers."