Lawyers threaten researcher over key-cloning bug in high-security lock
arstechnica.com
arstechnica.com
When a security researcher gets threatened, there's a tendency to lambast the lawyers. I think that's unfortunate.
It is, very often, the client that demands an aggressive response. A lawyer should counsel against, since nastygrams to researchers tend to summon negative attention. Not being a jerk is also a plus.
That said, if a client insists--and they often do--the lawyers have little choice. Professional ethics generally require following the client's direction, and there isn't sufficient time to withdraw as counsel.
So, for the most part: Don't blame the lawyers, blame the DMCA. It's the law that's broken.
Edit0: In fact, the principles were more specific to international law vs national law and orders. However, the idea behind is still sane even if you don't violate international law.
Edit1: It's about recognizing personal responsibility.
Edit2: Those who disagree, why?
I believe this is what the GP poster is mentioning when he says that there often isn't "sufficient time to withdraw."
This is a very risky proposition as it happens all the time that the Supreme Court will deny certiori over some petty issue.
If you wonder why I use my real name here and elsewhere online, it's because I regard it as my duty to - someday - defend myself before the Supreme Court.
Please don't take this the wrong way: Research this topic further!
They probably feel that the Nuremberg trials are a hyperbolic example here, and worry that line of argument brushes a little too close to Godwin's Law.
Upshot, we probably all agree with you that everyone has personal responsibility for their actions. There are still situations where we want attorneys to listen to their clients though.
The most extreme example of a thing you can find is not usually the ideal example to use for most contexts. Rather than clarifying things, if it dwarfs the context, it then appears automatically ridiculous even if the basic argument is sound.
This is not an example for official upholding of personal responsibility.
> there are millions of better examples for this context.
This is hand-waving. I used the Nuremberg trials specifically to not hand-wave.
Now that is funny, though I suspect unintentionally, and in horrifically bad taste either way.
I did not intend to be funny nor do I see why it was bad taste.
My question for a better example was genuine.
It was meant as a pejorative label for him stating
there are millions of better examples for this context
without providing one valid example. I provided a valid example.
No, you did not.I asked for "a better example where personal responsibility was officially upheld". Your example was explaining a child agency, which _does not_ include officially upholding personal responsibility.
Furthermore, I did not draw any comparison between the Nuremberg Trials and the case in question, but used them only to substantiate my argument for personal responsibility. Reread what I wrote if you are doubting.
Don't assume everybody does cheap puns and invalidly makes up connections between what was said. If I mean it, I say so.
Add an adult to the story then. Hell, add a teacher, knock yourself out. For making the point of not merely doing as instructed though and having personal responsibility, this need for official confirmation in the metaphor seems awfully weird.
Don't assume everybody does cheap puns and invalidly makes up connections
I didn't, I said I thought you were probably being unintentionally funny.
Add an adult to the story then. Hell, add a teacher, knock yourself out.
I don't know a better example. If I had one, I wouldn't have asked. In my experience people defend themselves by saying they were told to do it or that there are laws forcing them. For making the point of not merely doing as instructed though
and having personal responsibility, this need for official
confirmation in the metaphor seems awfully weird.
There are lot of things we might think that should be, but many are not officially recognized. Having my point officially recognized is essential for its substance.It is not a metaphor.
However, I think we were just misunderstanding each other. My question was serious and genuine.
I wouldn't say extreme, but fundamental. I referenced the Nuremberg Principles because they are so fundamental and I genuinely don't know a better example.
Several people in the community misuse down-votes. They down-vote on-topic, constructive and serious discussions which disagree with their opinion instead of simply articulating their criticism.
I suppose because "Godwin's law" is in the dictionary now you are free to add meaning as you like, but I wouldn't be happy about this stackoverlow like meta trivial pursuit at the expense of logic if I were Godwin.
So if he's not happy, he's only got himself to blame.
http://www.americanbar.org/groups/professional_responsibilit...
Many state bar associations have rules like that one. Lawyers can make good-faith arguments that their client's behavior isn't illegal. They can't break the law for their clients or help their clients break the law.
No one should be stuck, unable to get a lawyer and put up a fair legal fight, just because some part of the population condemns them as amoral, but can't pass a law expressing that condemnation that stands up to civil liberties challenge. Lawyers should serve hated people, too, and ideally do for them just as they would do for themselves if they understood the law and the system.
Lawyers who can do that for truly loathsome clients are superheroes. They often set aside deep feelings and strongly held personal convictions in the service of the greater value of a fairer legal system. It's a real-life Gom Jabbar test, and repeat sittings have driven many good lawyers to self-destruction, one way or another.
So: If you don't want lawyers helping assholes, try and pass a law against being an asshole. It would be vague. Prejudiced assholes would wield it against legitimate non-assholes. Good lawyers defending actual assholes would kill it in court.
More succinctly: https://youtu.be/WMqReTJkjjg?t=2m10s
What I'm trying to say is that perhaps the sometimes it's not just the law's fault - but the lawyers also like having said law and abusing it.
Also, this is going to get even worse if Obama has his way with the new "enhanced" CFAA law that can jail people even for breaking a company's ToS.
According to that one, it is not acceptable for a lawyer to file the petition his client wants him to file, if that petition doesn't meet the court's standards. If judges can censure lawyers for acceding to their clients' demands, so can the rest of us.
How much time does it take to withdraw as counsel?
Why do developers keep doing this? As a programmer, I've never worked with crypto implementation and I don't really know much about it on a practical level, but the one thing I do know is that you never store anything sensitive in plaintext. Ever! So how do so many devs who have, at the very least, spent far more time than I have Googling about crypto implementation, keep missing this?
It's as if there was an epidemic of wet kitchen floors sweeping the nation because thousands of plumbers, working independently, all repeatedly forgot to install traps under their sinks. Why does this one rank-amateur mistake keep happening?
Could you explain what alternative should be used in this case?
Sounds like their lock is really just a "digital key", with wires sending bits that take the place of tumblers.
Hashing is for passwords, not for keys.
It's NOT like you can walk up to one with a thumb drive and pwn it.
So you walk up to the unguarded bike shed, take your time chopping off the lock with a hacksaw, and now you have access to the storage area. Normally the guard would come around before you'd be able to cut off that lock, but since you now have a key it's much quicker, and you wouldn't look suspicious to the guard anyway.
This works so long as attackers have no more resources than the average guy in the street.
I think it would be interesting to sue a company like CyberLock for false advertising ... "impossible to clone keys" is clearly false.
Chances are that just changes the lawsuits to defamation ones.
See http://en.wikipedia.org/wiki/Strategic_lawsuit_against_publi... for a variety of examples of such suits.
I'm all for releasing a vulnerability after it a) is mitigated or b) becomes clear the responsible party has no plans to address the vulnerability in a timely fashion.
One day is in no way responsible unless the researchers were told pointedly that there was no plan to address the issues.
IMHO.
I really don't support people throwing around the DMCA, but if the company's lawyer's complaints are accurate (if) then IOActive sounds like they prioritized having a quasi-journalistic "scoop" over professionalism.
https://plus.google.com/118103547235676487972/posts/Sot7Tp1C...
Maybe they wanted to try to stealth-fix it without admitting an issue ever existed, and ran out of time?
Or it might be incompetence rather than malice. Maybe someone failed to take action until day 28.
we started a 30 day clock and if at any point someone had responded and said "we need more time", we could have provided more time (to some limit of course).. we even gave them a few extra days after they contacted us on day 29 since no one has done the math
A convenient approach since it lets them whine like children about how they weren't given enough lead time.
Why? They are the ones who let a vulnerable system onto the market. Why should I be forbidden from going public with legally obtained information when I have no contract with them? I should not share in any blame for their security vulnerabilities as I was never allowed to share it any of their profits (monetary or otherwise).
Will I be paid for the effort? Or am I expected to give them information for free when they would never do the same for me? Ethics is a two way street and after superfish (among other issues) I owe this company no ethical obligations.
>If you release it to the world before they're even aware of it, there's a gap where there is absolutely no mitigation whatsoever.
Quite a convenient way to blame me for their security flaw in their product. No, this is solely on them, and as I already pointed out, they have aready burned up any professional ethical obligations.
Well, IANAL, but I can pretty much guarantee they are going to get sued.
As many people say, you only get one reputation, and you must defend it vigorously.
And as many other people say, don't piss into the wind and expect not to get wet...
Can people in the US really sue each other for reputational damage even for saying only true things? If so, that is bizarre IMO.
Be careful this is a dangerous interpretation of UK law. Slander/Libel must contain some element that the person doing the saying/publishing cannot prove in court. Note the burden of proof lies on the person saying/writing rather than the person sueing.
(I am not a lawyer and this post does not constitute legal advice.)
Literally laughed out loud. It's just become too much of a joke now.