Live data from Hacker News

Prof. Ross Anderson's response to a takedown request about security research

cl.cam.ac.uk

21–30 of 56 posts

Re: Prof. Ross Anderson's response to a takedown request about security research

#21

If one of the smartest computer security guys was prepared to do all this work and throw lots of expensive experts (well grad students) at finding your bugs - would you: 1, Send developers to all their seminars to learn something 2, Buy them drinks 3, Sue them

TRICK QUESTION.

1 and 2 are not mutually exclusive. Exactly why is the seminar not at the local pub?

Re: Prof. Ross Anderson's response to a takedown request about security research

#22

Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.t…

For the original complaint, see this PDF (via Light Blue Touch): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf

Re: Prof. Ross Anderson's response to a takedown request about security research

#23
post #11

Earlier quoted context omitted.

If anything, the banks promoting this technology should be sued for false advertising. in many cases banks refused to reimburse cardholders who reported unauthorised card use, claiming that their systems could not fail http://en.wikipedia.org/wiki/Chip_and_PIN

2 decades earlier they prosecuted people who reported ATM losses for fraud - because ATMs were perfectly secure.

reference?

Re: Prof. Ross Anderson's response to a takedown request about security research

#24

Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.t…

I don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?

Re: Prof. Ross Anderson's response to a takedown request about security research

#25
post #16

Earlier quoted context omitted.

But an unwritten constitution is easier to change, because there is nothing written down to refer to as a 'base.'

Canadian constitutional law has something called the 'living tree doctrine', which states that the constitution can grow and evolve over time, being reinterpreted in new contexts. To push the metaphor a bit further, I'd point out that a living tree is considerably more resilient than a dead tree, and is likely to adapt to conditions which might otherwise destroy it. I don't think anyone can seriously claim that the c…

  The Congress shall have Power...
  To regulate Commerce with foreign Nations, and among the several States, and with the Indian tribes;"
It's not really a matter of living versus dead trees. The US judicial system has just plainly ignored the "among the several States" caveat for the last 100 years. I'm not advocating either side of this example, by how does growing and consuming marijuana on your own property fall under regulated commerce "among the several States?" I understand it was originally banned using taxation powers (i.e. charge a stamp tax on it, but don't sell the stamps), but that pretext seems to have now been dropped.

Re: Prof. Ross Anderson's response to a takedown request about security research

#27
post #12

An important but often overlooked fact is that while there's no universal freedom of speech in British Law (although the UK is a member of the European convention on human rights which has such a protection), universities specifically are required to act to protect freedom of speech of their members. The University of Cambridge is legally obliged to stand behind this research under the 1986 Education Act which states…

while there's no universal freedom of speech in British Law... Perhaps not in written law, but I think you'd have a hard time convincing a judge that the British constitution does not guarantee freedom of speech. As my legal friends as fond of pointing out, an unwritten constitution has the important advantage that its words can't be twisted the way that a written constitution can.

The Felony Treason Act 1848 is still on the books. Sure, a couple of Lords may have said that expressing anti-monarchist sentiment won't be punished, but where is the line drawn? [1]

Can you be transported to Australia for poking the Duchess of Cornwall with a stick? What about shouting "Off with their heads!" at the Prince of Wales? [2]

The absence of a constitutional guarantee of free speech, and the persistence of lèse majesté offenses should be a point of embarrassment.

[1] http://www.guardian.co.uk/media/2003/jun/26/pressandpublishi...

[2] http://thelede.blogs.nytimes.com/2010/12/09/video-of-protest...

Re: Prof. Ross Anderson's response to a takedown request about security research

#28

I really enjoyed the language!

Same here. After the first page, I was laughing aloud. The whole letter reads like a two page, very official statement claiming "You sir, are an idiot." Then again - he's British :) I love it, especially that my course this year included exactly that paper and we spent considerable time on it for comparison to many other types of attacks.

Re: Prof. Ross Anderson's response to a takedown request about security research

#29
post #23

Earlier quoted context omitted.

2 decades earlier they prosecuted people who reported ATM losses for fraud - because ATMs were perfectly secure.

reference?

Numerous paper's on ross's page

http://www.cl.cam.ac.uk/~rja14/Papers/wcf.html

Re: Prof. Ross Anderson's response to a takedown request about security research

#30

Earlier quoted context omitted.

A service provider terminating Wikileaks for AUP violations after they began publishing classified diplomatic cables; one of the oldest educational institutions on Earth standing up for a student's MPhil thesis. Totally the same thing. How did I miss this?

It seems that the point is that Wikileaks apparently broke no laws.

You don't have to break a law to violate an AUP.
Post reply on HN