Live data from Hacker News

Give Me the Green Light Part 1: Hacking Traffic Control Systems

redthreatsec.com

1–10 of 94 posts

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#5
Part 2 article goes into a bit more of detail, but the funniest thing is that they requested access to the SNMP MIBs of the controller and never got them

> I requested MIBs from Q-Free but didn’t receive any follow-up after the request and I never received access to the MIBS, so it was back to square one.

Then you go look at https://www.freethemibs.org/advocates and... there they are, "advocates" for free MIB access. What clowns.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#6
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case.

Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#8
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case. Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’

> Anyone has the “ability” and freedom to make threats under the CFAA.

Certainly. What I’m saying is that it should be cheap or free to neutralize their threat. There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#9
post #8

Earlier quoted context omitted.

Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case. Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’

> Anyone has the “ability” and freedom to make threats under the CFAA. Certainly. What I’m saying is that it should be cheap or free to neutralize their threat. There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.

>There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.

Who's going to check it to make sure that "your responsible disclosure letter" actually is a responsible disclosure letter and not just nonsense?

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#10
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case. Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’

You may not get the feds to prosecute the case, but it's very possible for the feds to investigate you with varying levels of fervor.

If you're a well lawyered security researcher this is probably fine.

If you're some IT related person that does something else as your primary job this may or may not be fine if the FBI shows up and starts asking lots of questions about all kinds of things.

Post reply on HN