> the mere capability renders the machine fundamentally untrustworthy.
I've said this a couple of times before, but I find it fairly astonishing that we don't have legislation covering what manufacturers are allowed to do to a product with embedded devices after a user has purchased it.
I want to be very clear - after I have bought a product, ANY CHANGE WITHOUT MY CONSENT done by the embedded software at the behest of the manufacturer is essentially breaking and entering (Computer Fraud and Abuse Act (CFAA)). They have the ability to stick a "little green man" inside the car, that should not absolve them of the legal repercussions of using it without my permission.
I don't believe that sticking a term/clause into a user agreement that is not negotiable is an acceptable way to deal with this situation.
This is rapidly becoming one of my strongest political beliefs. I think the concept of ownership is at stake.
My wishlist is essentially:
1. Devices that contain digital locks MUST provide all keys to all locks to the buyer at time of purchase. The user can opt into allowing the manufacturer to keep a copy, but they must be allowed to opt out.
2. Devices that require remote services must explicitly list all services and features that depend on those services. The user must have the option to opt out of remote services.
3. Buyers of devices that choose to opt out of remote services are revoking consent for manufacturer access to the device. Any future access by the manufacturer (at all, from updating code to reporting usage to remotely starting a car) will be considered a violation of the CFAA.
4. Manufacturers must justify why a feature requires a remote service. "Profit" is not an acceptable answer.