Earlier quoted context omitted.
> it will be the end of open source Not if the rules are carefully targeted at SaaS and not at codebases. If the rules are targeted at SaaS, the liability is actually lower for open source because of the inherent transparency of everything open source code does.
Do you think Nancy Pelosi is going to ask Richard Stallman, the Debian Project Leader, and the Apache Foundation how the regulation should work? Or is she going to ask SalesForce, Google, Apple, and Microsoft?
The Insecurity Industry
331–340 of 386 posts
Re: The Insecurity Industry
#332> The greatest danger to national security has become the companies that claim to protect it No. The greatest danger is lack of software supply chain management followed by near-universal disrespect for formal complexity management methods. The only way I have found to win at this "are we actually secure" game is to minimize the number of parties you have to trust. The smaller you get this figure, the easier it becom…
There is no supply-chain accountability without liability. When adding a dependency, knowing it exposes you to prosecution if it becomes a vector for security violation would give pause. A premium on attested-secure components might develop. If Facebook depended on Zst being secure to be able to stay in business, we might be more inclined to use Zst than e.g. unmaintained Zlib.
1. Developer has a problem to solve
2. Developer does a few web searches and finds libXyz, which looks like it solves the problem.
3. Developer tries libXyz and it solves the problem.
4. Yolo! A libXyz dependency is added, and now it's part of the product that the company stakes its name and reputation on.
Total madness. What else does libXyz do? What data does it collect? What does it do with that data? What bugs does libXyz have, and do they put our product at risk? What about security risks? Does libXyz have tests, and do they pass? How extensive is its test coverage, and would that be sufficient at our company? Does libXyz impact the overall performance of our product? What is its maximum memory footprint? Does libXyz limit our product to a particular architecture? What is libXyz's license, and is it compatible with our product? Who is responsible if libXyz fails and our company gets sued?
You're lucky if the developer even thinks about one or two of these, let alone fully auditing the library. Staking your product on the suitability of a library but not actually thoroughly vetting the library. And some products out there have hundreds of dependencies, all added in the manner described above. We're just handing out loaded guns.
Re: The Insecurity Industry
#333Earlier quoted context omitted.
How would this make running a personal website risky from a legal liability perspective?
Are your HTTPD logs adequately secured? Are their security measures audited monthly, in keeping with established industry best practices? Do you have comments enabled on your blog? What's your policy for expunging blog posts about people exercising their right to erasure? How did this defamatory comment spam get past your comment filter? Did you know your open-source image thumbnailing software is being used on an il…
Re: The Insecurity Industry
#334Earlier quoted context omitted.
Side effects are expected. Vaccines provide enormous benefit but are not without risk. Patients must receive information about risks and choose whether to accept or reject treatments. This is not at all comparable to corporations slurping up all data they can get their hands on for marketing purposes. Modern medicine provides enormous benefit for society. Surveillance capitalism... doesn't. Certainly not enough to ju…
I agree however allowing any company regardless of its business the opportunity to escape liability of consequences is dangerous. Pharma companies have in the past and will continue to have their scandals same as any other industry. There shouldn’t be exceptions. Who gets to define what industry is important or not and therefore avoids regulation is dangerous as it’s only as reliable as the “who’s” in control.
Widespread data collection on the other hand is totally unnecessary and should absolutely be a massive liability for any company that does it.
Re: The Insecurity Industry
#335Earlier quoted context omitted.
> Don't hire people who are under qualified. Its really that easy. I understand what you're saying, but I'm not sure I agree. For example, look at Google Chrome. They've got mountains of cash. They've got loads of people working for them, and loads of job applicants if they want more. They've got a strong business case to work on security. They've got in-house pen testers, and a bug bounty program. They've got code r…
So many CVEs are due to their bug bounty program, hackers are incentivized to sell vulnerabilities to Google rather than exploiting them. CVEs are publicly disclosed after they are fixed, of course.
Re: The Insecurity Industry
#336Earlier quoted context omitted.
Which parts? I'm surprised this isn't well known already. Large parts of Android are written in Java. Amongst other things: * All the UI libraries, networking APIs code. * All the system apps and services like the home screen, the keyboard, the system server, the window manager, the telephony subsystem (very important!) and so on. * Many of the system APIs including services like the alarm manager, dropbox manager, s…
Apparently the idea that Android is a Linux distribution is hard to dispel, because most rather read what is written in some random blog posts patting their backs about "Linux victory" than actually read what is going on at AOSP and Gerrit PR.
It is not GNU/Linux, which is what people think about when talking about Linux distributions.
Richard Stallman is known to throw a tantrum every time someone omits the "GNU" part but now, with Android, he has a point.
Re: The Insecurity Industry
#337Earlier quoted context omitted.
Can you please supply examples from law, medicine, trades, engineering, etc where you feel that lobbying of the government has led to the kind of outcomes you're envisioning?
Texas' ERCOT. It's a government appointed regulation body, not a branch of gov't. Are you really doubting that this is something that "might" happen? Edit: FAA allowing Boeing to self-certify 737MAX. FDA allowing/not allowing trials of drugs, or allowing a drug meant for one thing to be tried for something else totall untested (ex: AZT).
I don't know that bodies like FAA and ERCOT are really comparable to professional associations; the market conditions make them especially vulnerable to corruption because they both "oversee" such a small number of large players, so you end up with a revolving door. In any case, these are also odd examples to bring up, because in both cases their failure was not about market capture, it was about failure to protect the public. So it seems your argument is amounting to "the regulation provided by the FAA isn't perfect, so it shouldn't exist, just like regulation for security-critical software shouldn't exist."
I specifically asked for examples from "law, medicine, trades, engineering", because those are cases that I feel are much more aligned to what it would be with a professional body overseeing practices for secure software development— they're cases where you have a large number of mostly small-time practitioners, and where the professional oversight mechanism is working in terms of enforcing safe and consistent practices, while also evolving those over time in response to changing conditions.
Re: The Insecurity Industry
#338Do people really think any of this is ever going to change? Governments don't give a shit, they time and again say they won't do something only to later do it in secret. We should at this point accept that this isn't going to change and move ahead with the belief that your data is already hacked and is not private anymore. We should discuss more on the exact consequences of this and take actions accordingly.
Re: The Insecurity Industry
#339Earlier quoted context omitted.
Texas' ERCOT. It's a government appointed regulation body, not a branch of gov't. Are you really doubting that this is something that "might" happen? Edit: FAA allowing Boeing to self-certify 737MAX. FDA allowing/not allowing trials of drugs, or allowing a drug meant for one thing to be tried for something else totall untested (ex: AZT).
I'm not doubting that it might happen and may even actually happen in some cases. I'm asserting that society and government is built on compromises and a principle of taking the path of least harm. We shouldn't avoid a 90% solution because we can imagine possible flaws in it, particularly if we have close analogues already deployed in the real world and those flaws don't largely seem to manifest. I don't know that bo…
This is far from what I'm suggesting. I'm just saying that if it is a gov't regulated anything, those regulations will incur wacky decision making due to the influence of outside money. Nobody likes to be regulated against, and if they are in the position to do so, they will use any mechanism available to them to keep the status quo.
I'm also suggesting that any gov't regulation body is not always the panacea people may be dreaming it will be. Anytime a regulation body is proposed, I don't have rose colored glasses. I'd rather be pleasantly surprised that something turns out to be a good thing than having high expectations crushed.
Re: The Insecurity Industry
#340Earlier quoted context omitted.
Apparently the idea that Android is a Linux distribution is hard to dispel, because most rather read what is written in some random blog posts patting their backs about "Linux victory" than actually read what is going on at AOSP and Gerrit PR.
Android is Linux because it uses the Linux kernel. It is not GNU/Linux, which is what people think about when talking about Linux distributions. Richard Stallman is known to throw a tantrum every time someone omits the "GNU" part but now, with Android, he has a point.
Targeting Android/Linux, if you so wish, it is no different than targeting Windows from GNU/Linux point of view.