Live data from Hacker News

The Insecurity Industry

edwardsnowden.substack.com

381–386 of 386 posts

Re: The Insecurity Industry

#381
post #272

Are there any compelling reasons why it should be legal to sell exploits to anyone other than the company whose software is vulnerable? By neatly bundling these exploits up and selling the hacking tool to the highest bidder, this company is giving nation-state spying capabilities to cartels and dictators who would otherwise not have had that. I don't see why that shouldn't be regulated the same way as if they were se…

Iirc the software sold by the NSO group is considered a weapon under Israel law, so it is somewhat regulated. Not as heavily as nukes though. This begs the question: Is there a compelling reason why selling weapons to other states should be legal?

In Germany, our economy pretty much depends on weapons and cars, so that.

But apart from economic reasons, not really.

Re: The Insecurity Industry

#382
post #235

Earlier quoted context omitted.

Eh, contract law gives you all the tools you need to create liability. If you want software where the vendors are liable, you can get that today.

Ahh, yes, the free market. The bastion of privacy. What about those not even doing business with Equifax and getting their info stolen?

I was talking about currently available legal options. Not about any free market.

I don't know anything about Equifax? What are they doing?

I assume whatever Equifax is accused of doing is already illegal by current laws? Would making it 'more illegal' help?

Re: The Insecurity Industry

#383
I definitely agree with Snowden's call to action with making spyware illegal, I think the execution is plausible but unlikely for the same reasons he stated in the article. Every country is working to produce these things themselves for cyber security self defense.

I am unsure about his comments regarding unsafe code. Like many of the people have already stated here, that's a blurry line that has good intention but seems nearly impossible. I think more regulation and certification for both employees and companies is a much more likely to be successful.

Re: The Insecurity Industry

#384
>If hacking is not illegal when we do it, then it will not be illegal when they do it—and “they” is increasingly becoming the private sector.

Not sure I follow the logic here. The State has a monopoly on many things that are never allowed in the private sector -- violence being the most obvious one. We don't seem to have a huge problem with the split here; why we couldn't do the same for hacking?

Re: The Insecurity Industry

#385
post #230

Earlier quoted context omitted.

The guy selling food on the street has liability in proportion to his profits; fifteen customers, fifteen potential food-poisoning cases. He can set his prices accordingly. Simon Tatham doesn't have any profits, but his PuTTY is installed on every developer's Windows machine. OpenSSL is installed on even more machines. How long do you think it would take your proposed regulatory regime to find that Kurt Roeckx owed s…

Simon Tatham doesn't have any profits, but his PuTTY is installed on every developer's Windows machine. then isnt it up to the commercial vendor who bundled the software to properly vet it? someone taking non-commercial products and commercializing it is where the line is drawn right?

That depends entirely on how the law is written. Legislators will ask commercial vendors how to write the law. Why would the commercial vendors choose to write it in the way you're describing?

Re: The Insecurity Industry

#386
post #319
post #294

Earlier quoted context omitted.

Clearly you've never had to be responsible for PCI compliance. PCI auditors have no patience for arguments like "When's the last time that kind of setup was exploited? If you add more complexity, you add more attack vectors!" and just want you to install the damned antivirus software like their guidelines say. Yes, even though you're running Linux. No, they don't care that there's a CVE in ClamAV every two months. Th…

You're assuming quite a lot about me and not actually responding very directy to what I'm saying. However, reading this and some of your other responses makes it a bit more clear what the concern you're raising is. > Listen, you know and I know that you can serve a personal website perfectly well with /var/www and a stock Apache config. But the proposal we're discussing here is precisely to take that judgment call aw…

I wasn't responding directly to what you said because it's irrelevant. You were pointing out that in fact hosting a personal website doesn't in fact expose its visitors to a lot of risk, especially if it's a static site instead of a blog or something. But that doesn't imply that people hosting their own personal websites will find it easy to comply with a regulatory regime tailored to raising the barriers to entry for "the next Facebook". More likely they will find it infeasible.

It's true that imposing liability for publishing defective software is logically independent from imposing liability for collecting unnecessary PII that leaks. But pjmlp's quote from the article we were commenting on explicitly proposed doing both of these:

> For example, if you want to see Microsoft have a heart attack, talk about the idea of defining legal liability for bad code in a commercial product. If you want to give Facebook nightmares, talk about the idea of making it legally liable for any and all leaks of our personal records that a jury can be persuaded were unnecessarily collected.

So my argument does not, as you say, "rely on a bit of a non-sequitur: [that] expanding the scope of data collection/handling regulations will inevitably extend to regulating the publishing of software." The proposal in question is to both regulate software publishing and also regulate data handling, so it's irrelevant whether or not the scope would thus "inevitably extend" from one to the other.

Probably it is true that the most favorable situation for the current incumbents would be to have no liability, as at present, or as minimal liability as they can get away with. But the second-most-favorable situation, and one that is definitely politically viable even if the current situation is not, would be to have a regulatory regime that raises the barriers to entry for new entrants as much as possible and prevents disruption to their markets, by enshrining in law the particular way they're doing business today: AI melody recognition for prior restraint of free speech, combined with armies of outsourced moderators to watch for terrorism and pornography, centrally-controlled app-store platforms, locked-down end-user hardware (with a grandfathered carve-out for desktops and laptops), real-name policies, fax-us-your-passport ID verification, "two-factor" authentication that turns out to be one-factor, and so on. Anything that encourages you to post stuff on your own blog or website would be a big drawback for GitHub, YouTube, and Fecebutt.

Post reply on HN