Live data from Hacker News

Give Me the Green Light Part 1: Hacking Traffic Control Systems

redthreatsec.com

11–20 of 94 posts

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#13
post #9
post #8

Earlier quoted context omitted.

> Anyone has the “ability” and freedom to make threats under the CFAA. Certainly. What I’m saying is that it should be cheap or free to neutralize their threat. There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.

>There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them. Who's going to check it to make sure that "your responsible disclosure letter" actually is a responsible disclosure letter and not just nonsense?

The firm funded by fines for making unfounded threats with scary lawyer letters.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#14
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

We do have that now, as of 2022! The new Justice Department policy now instructs prosecutors not to prosecute security researchers who acted in good faith for the public benefit and who avoided any harm to individuals or the public.

https://www.justice.gov/opa/pr/department-justice-announces-...

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#16
post #3

If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.

Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case. Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’

Yup. I submit that this sort of threat poisons the well and makes security worse for everyone, including those making the threat (but it's a bit of a commons problem because the worsening security is industry-wide, but for the threat-maker it seems to improve their situation).

If I am a person interested in how these systems work, and maybe making some money off my work in the area, this sort of threat, both its severity (potentially years of costly litigation and or/jail) and how frequently it happens (seems we read of such incidents many times per year, which is only the tip of the iceberg) would make someone seriously question the straight white-hat path. Why not find the exploits and sell them on the dark web? One might even justify it with "they wouldn't listen anyway and it's their fault for releasing a system with such stupid vulns." and/or "they'll fix it only when they see real-world consequences and if they don't it doesn't matter". One's moral compass need not be very compromised to lean on such excuses.

There REALLY needs to be a Safe Harbor law with basic requirements that the work is documented, first revealed to the company security dept (perhaps citing the Safe Harbor law?), no action taken by the researcher to allow it to be disclosed or released publicly for 90 days, and perhaps a few other reasonable safeguards.

and how often it happens

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#17
Sounds like the company realised they can't solve the issue in 90 days. Betting a combination of infrastructure scale problems, terrible tech, no-longer-building old solutions, no maintenance fee's built in and contractors who hate them. So they pulled the only lever they had left, which was the lawyers.

Same time, RedThreat's email was kinda (maybe rightly) hostile. Read from the other side it's basically "You have 90 days to work (/maybe pay) me before you start hearing your name on TickTok under the label 'wanna hack the city?'".

"Work with your team" leaves a ton of negotiating opportunity for a company that obviously does this for a living and expects to make money somewhere.

Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems

#18

Sounds like the company realised they can't solve the issue in 90 days. Betting a combination of infrastructure scale problems, terrible tech, no-longer-building old solutions, no maintenance fee's built in and contractors who hate them. So they pulled the only lever they had left, which was the lawyers. Same time, RedThreat's email was kinda (maybe rightly) hostile. Read from the other side it's basically "You have…

The 90 day window is an industry standard for zero-days, how the author worded it is neither here nor there. 90 days is ample time for even a half-functioning organization to address the issue in some way. I agree with Red Threat’s decision to not show their hand in the first email. The altruistic take on this is that they do not want the email to fall upon deaf ears (or even a bad actor within a company) and would prefer to have a channel of communication open with the security team before outlining the details.

The biggest problem when faced with a zero-day is that it’s unknown who else knows about it. This helps the the company’s security team justify the work due to the fire lit under the company to take action - especially if their corporate structure does not allow for more “elective” fixes.

Post reply on HN