Earlier quoted context omitted.
Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…
> after being rooted by 4 lines of JavaScript Could you provide any sort of source for this extraordinary claim of yours?
FBI tells router users to reboot now to kill malware infecting 500k devices
81–90 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#82If you're infected, you need a new router. Period. Telling people that they can resecure their routers with just a reboot is irresponsible.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#83What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#84Earlier quoted context omitted.
No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)
Boy is that ever not true. https://www.woodshopnews.com/.amp/news/table-saw-suit-nets-1... This guy was given a table saw with the guard already removed, and was using it on the floor (a table saw should be used at table height, so that you can have a foot forward to prevent falling into the blade). He was apparently not using push-sticks. Somehow, the table saw manufacturer was found 65% liable in the case, because…
Oh, did I mention the members have many more ridiculous patents than gass? They've sued each other over patents on worksite radios before. https://insight.rpxcorp.com/litigation_documents/3919186
They are also multi billion dollar conglomerates, often in countries with little respect for IP, so I imagine one reason he patented so much was to protect himself.
They are also a lobbying org, and he misses all the things they did, yet points out what sawstop did.
PTI has done a great job of lobbying here, unfortunately.
I am generally not a fan of the CPSC (what they did on magnets was beyond the pale), but here he also missed the biggest point they made: the cost of table saw injuries, to the government and insurers, is greater than the value of the table saw market!
I could go on. He seems like a mostly reasonable person (moreso than most on this issue), but yeah.
There really are two sides to that part. Neither side is deserving of adoration, honestly.
The court case is much simpler. For defective design liability in a lot of states, it's enough to show a feasible alternative design that would not have impacted function or price in a serious way. Most of the argument was about the latter.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#85Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#86Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
Yeah, definitely. Especially for infrastructure.
I realize the implications of this are significant.
I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are absolutely absurd.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#87Earlier quoted context omitted.
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#88Earlier quoted context omitted.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Is there no laws w.r.t. negligence that can be used to punish negligent actors? If a door manufacturer is negligent in their construction of the door and someone gets robbed as a result, in violation of how they expected their door to work, is there nothing currently in the law that could help them?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#89How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?
The US agencies have a very close relationship with router manufacturers. TCP 32764 for example was a backdoor many suggest they used cover ops to create and exploit.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#90Earlier quoted context omitted.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Is there no laws w.r.t. negligence that can be used to punish negligent actors? If a door manufacturer is negligent in their construction of the door and someone gets robbed as a result, in violation of how they expected their door to work, is there nothing currently in the law that could help them?
At least users can apply workarounds in that condition. As it stands, there are no options for the owner of the device.