Give Me the Green Light Part 1: Hacking Traffic Control Systems
11–20 of 94 posts
Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#12Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#13Earlier quoted context omitted.
> Anyone has the “ability” and freedom to make threats under the CFAA. Certainly. What I’m saying is that it should be cheap or free to neutralize their threat. There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them.
>There should be a lawyer-free portal where you can upload their threat letter and your responsible disclosure letter, and get some kind of legal order blessing your work that you can throw back at them. Who's going to check it to make sure that "your responsible disclosure letter" actually is a responsible disclosure letter and not just nonsense?
Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#14If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.
https://www.justice.gov/opa/pr/department-justice-announces-...
Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#15Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#16If we’re as serious about cybersecurity as all the noise that gets made about it indicates, we really need legal immunity for unsolicited responsible disclosure. You shouldn’t have any ability to beat someone with the CFAA who is trying to help you.
Anyone has the “ability” and freedom to make threats under the CFAA. Because there are no consequences for doing so. This particular company wouldn’t get the feds to prosecute this case. Another annoying problem is that this company seems to think that their “policy” overrides first sale doctrine wrt their products: ‘we don’t know where or how you got that device, therefore CFAA violation threat.’
If I am a person interested in how these systems work, and maybe making some money off my work in the area, this sort of threat, both its severity (potentially years of costly litigation and or/jail) and how frequently it happens (seems we read of such incidents many times per year, which is only the tip of the iceberg) would make someone seriously question the straight white-hat path. Why not find the exploits and sell them on the dark web? One might even justify it with "they wouldn't listen anyway and it's their fault for releasing a system with such stupid vulns." and/or "they'll fix it only when they see real-world consequences and if they don't it doesn't matter". One's moral compass need not be very compromised to lean on such excuses.
There REALLY needs to be a Safe Harbor law with basic requirements that the work is documented, first revealed to the company security dept (perhaps citing the Safe Harbor law?), no action taken by the researcher to allow it to be disclosed or released publicly for 90 days, and perhaps a few other reasonable safeguards.
and how often it happens
Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#17Same time, RedThreat's email was kinda (maybe rightly) hostile. Read from the other side it's basically "You have 90 days to work (/maybe pay) me before you start hearing your name on TickTok under the label 'wanna hack the city?'".
"Work with your team" leaves a ton of negotiating opportunity for a company that obviously does this for a living and expects to make money somewhere.
Re: Give Me the Green Light Part 1: Hacking Traffic Control Systems
#18Sounds like the company realised they can't solve the issue in 90 days. Betting a combination of infrastructure scale problems, terrible tech, no-longer-building old solutions, no maintenance fee's built in and contractors who hate them. So they pulled the only lever they had left, which was the lawyers. Same time, RedThreat's email was kinda (maybe rightly) hostile. Read from the other side it's basically "You have…
The biggest problem when faced with a zero-day is that it’s unknown who else knows about it. This helps the the company’s security team justify the work due to the fire lit under the company to take action - especially if their corporate structure does not allow for more “elective” fixes.